Live data from Hacker News

Any iPhone can be hacked with a modified charger in under a minute

geek.com

21–28 of 28 posts

Re: Any iPhone can be hacked with a modified charger in under a minute

#21
post #5

With hardware access all bets are off.

To some extent, sure, but we don't have to make it easy to get root access. Encryption on hard drives, removing the USB auto-play feature from windows, having to enter the PIN on a WP7 device before being able to deploy a developer app over USB, ect, are such examples that can make it considerably harder to get root access despite having the physical machine.

Re: Any iPhone can be hacked with a modified charger in under a minute

#22
post #8

Earlier quoted context omitted.

In almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be expl…

Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.

You're right, but then again, I also like being able to run my own software on my own devices.

If secure means closed well, that is not a trade off a lot of people are not willing to make. Just take a look at the outrage from the Windows 8 secure boot loader that can theoretically stop linux from being installed.

Personally, I like it when companies include some physical mechanism of getting root access to the machine. Whether we have to get root access through the charger port, or pressing F12 when the PC is booting, this mechanism will by definition have to be a 'vulnerability.' Of course, root access in this sense is referring to bootloader root access, not the operating system - that would be bad. We can only assume which type of root access is being referred to in the hack above.

Re: Any iPhone can be hacked with a modified charger in under a minute

#23
post #12
post #5

With hardware access all bets are off.

I dunno - with USB debugging turned off, you can't do much to an Android device even if you can plug an arbitrary device into its USB port. There's a reason I make sure it's turned off every time I leave the house!

On stock JB, even with USB debugging turned on, it's been tightened down. http://android-developers.blogspot.com/2013/02/security-enha...

Re: Any iPhone can be hacked with a modified charger in under a minute

#24
post #8

Earlier quoted context omitted.

Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.

You're right, but then again, I also like being able to run my own software on my own devices. If secure means closed well, that is not a trade off a lot of people are not willing to make. Just take a look at the outrage from the Windows 8 secure boot loader that can theoretically stop linux from being installed. Personally, I like it when companies include some physical mechanism of getting root access to the machin…

If secure means closed well, that is not a trade off a lot of people are not willing to make

You're living inside a tech bubble. The vast majority of iPhone owners don't care about "open". They care about "it works". These people are benefited greatly from having a "closed" yet secure system.

Re: Any iPhone can be hacked with a modified charger in under a minute

#25
post #8

Earlier quoted context omitted.

Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.

You're right, but then again, I also like being able to run my own software on my own devices. If secure means closed well, that is not a trade off a lot of people are not willing to make. Just take a look at the outrage from the Windows 8 secure boot loader that can theoretically stop linux from being installed. Personally, I like it when companies include some physical mechanism of getting root access to the machin…

> I also like being able to run my own software on my own devices.

Don't use an iPhone :) Vote with your wallet! And for the Windows 8 lock down of Linux, there are still numerous ways to get a Linux-enabled laptop, or to ensure that what you buy will work well.

Re: Any iPhone can be hacked with a modified charger in under a minute

#26
post #8

Earlier quoted context omitted.

Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.

You're right, but then again, I also like being able to run my own software on my own devices. If secure means closed well, that is not a trade off a lot of people are not willing to make. Just take a look at the outrage from the Windows 8 secure boot loader that can theoretically stop linux from being installed. Personally, I like it when companies include some physical mechanism of getting root access to the machin…

I too would like to run my own software on my iPhone, yet i would rather it be closed and as secure as possible then open. It, to me, is a phone first, and a computing device second and its security is more important then anything else.

Re: Any iPhone can be hacked with a modified charger in under a minute

#27

Hardware access is root access.

That rule of thumb usually refers to having unfettered access to the hardware - to be able to crack it open, snoop on internal signals etc.

In this case the problem is that the dock is expected to be a safe interface (untrusted), when it actually isn't. For ex, people would be surprised if their computer could be hacked by plugging it into a malicious power socket. And likewise they'll be surprised if they find out their phone can be hacked by putting it on an alarm-clock ipod dock in their hotel room.

Re: Any iPhone can be hacked with a modified charger in under a minute

#28
post #8

Earlier quoted context omitted.

Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.

You're right, but then again, I also like being able to run my own software on my own devices. If secure means closed well, that is not a trade off a lot of people are not willing to make. Just take a look at the outrage from the Windows 8 secure boot loader that can theoretically stop linux from being installed. Personally, I like it when companies include some physical mechanism of getting root access to the machin…

> I also like being able to run my own software on my own devices.

And you can. Visit http://forecast.io from iOS Safari and add the icon to your home screen, then run that.

This is the app distribution method Jobs tried to sell developers on. Developers mostly don't want want it.

Of course, you can also run your literally own apps, native apps, by installing them yourself. You only need the App Store to sell them.

Finally, you can set up your own distribution platform. See TestFlight.

Post reply on HN