Live data from Hacker News

Usbliter8: an A12/A13 SecureROM Exploit

ps.tc

21–30 of 39 posts

Re: Usbliter8: an A12/A13 SecureROM Exploit

#21

This is awesome news! It isn't a jailbreak in and of itself, but it is the first step. Right now we only have a reliable jailbreak (checkm8) for up to iOS 18 (and that's only thanks to one iPad model). Some app developers are pretty aggressive about dropping support for older iOS versions. This affects iPhone XR, XS, 11, SE 2nd gen, and a smattering of iPads. Many of these devices got the iOS 27 beta and will likely…

Also great new for Cellebrite?

Re: Usbliter8: an A12/A13 SecureROM Exploit

#22
post #21

This is awesome news! It isn't a jailbreak in and of itself, but it is the first step. Right now we only have a reliable jailbreak (checkm8) for up to iOS 18 (and that's only thanks to one iPad model). Some app developers are pretty aggressive about dropping support for older iOS versions. This affects iPhone XR, XS, 11, SE 2nd gen, and a smattering of iPads. Many of these devices got the iOS 27 beta and will likely…

Also great new for Cellebrite?

Reboot your phone after the feds have it before you unlock it again

Re: Usbliter8: an A12/A13 SecureROM Exploit

#23
I'm curious what this will lead to, both security wise and jailbreak hobbyist wise. I saw this overview: https://www.reddit.com/r/jailbreak/comments/1ua58xd/usbliter... which mentions that it won't let an attacker gain full access to iOS on a passworded device without another exploit:

> BPR, or Boot Process Register, was a feature implemented in iOS 14 in order to additionally secure devices from bootROM based attacks. Crucially, it restricts data access when a device is booted directly from DFU mode, which is required by both checkm8 and usbliter8. In iOS 14 and 15, this manifested as the requirement to disable your passcode when jailbreaking A11 devices with checkra1n/palera1n, and is the reason why A11 devices must be first erased if they previously had a passcode before jailbreaking with palera1n. A10 devices were not affected by this as they had a SEP exploit, known as blackbird, which prevented this issue from arising. We do not have a SEP exploit for A11 and newer.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#24
post #22
post #21

Earlier quoted context omitted.

Also great new for Cellebrite?

Reboot your phone after the feds have it before you unlock it again

Once the feds have the phone, they aren't going to allow him to touch it, much less reboot it.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#25
post #22

Earlier quoted context omitted.

Reboot your phone after the feds have it before you unlock it again

Once the feds have the phone, they aren't going to allow him to touch it, much less reboot it.

They have to reboot it to use a bootloader exploit. Reboot it again after you get it back to erase whatever they did.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#26
post #17
post #13

I first thought of SecuROM, a CD/DVD copy protection scheme applied to computer game discs: https://en.wikipedia.org/wiki/SecuROM

That's what I thought as well. I read the headline and was surprised that SecuROM was still around and was confused what it had to do with Apple... until I saw your comment.

They are still around, under the name Denuvo :)

Re: Usbliter8: an A12/A13 SecureROM Exploit

#27

Since this can only underflow and some written bits are not attacker-chosen, does this not imply that the patchable part of the software could reliably detect this just in time and panic on suspected USB DMA corruption? Where is the catch?

The exploit happens before any patchable software is running, it's not called ROM for nothing.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#28

Ohhhh this is interesting!!!!! I really miss the glory days of jailbreaking, it just unlocked so many handy, fun, and cool stuff. From running webservers to speeding up the terribly slow animations.

...or adding system-wide Copy and Paste when the iPhone first launched without it...

ouch. imagine going back in time and tell someone that in your own pocket computers, it would be a forbidden art to spend 2min to code, and be allowed to run, a copy and paste application.

(well, to be honest this is a bad example to show the system is closed, because copy and paste was difficult on linux too during wayland)

Re: Usbliter8: an A12/A13 SecureROM Exploit

#29
post #25

Earlier quoted context omitted.

Once the feds have the phone, they aren't going to allow him to touch it, much less reboot it.

They have to reboot it to use a bootloader exploit. Reboot it again after you get it back to erase whatever they did.

I realized they might have added a fake reboot menu. So either use the exploit yourself to check it's the real bootloader (no realistic chance the FBI made a fake bootloader exploit in the fake reboot menu) or let the battery run out or remove it.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#30
post #29
post #25

Earlier quoted context omitted.

They have to reboot it to use a bootloader exploit. Reboot it again after you get it back to erase whatever they did.

I realized they might have added a fake reboot menu. So either use the exploit yourself to check it's the real bootloader (no realistic chance the FBI made a fake bootloader exploit in the fake reboot menu) or let the battery run out or remove it.

Nobody is going to add a fake reboot menu
Post reply on HN