Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
21–30 of 87 posts
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#22What are "close access methods"? Would bluetooth or iBeacon or Wifi be used with that, or does it need a cable, or actual button pressing, for example?
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#23Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#24Earlier quoted context omitted.
Yeah, I've been shocked by how easy it is to get a brand new router and set it up with the same SSID and password and every device I have auto-connects like it's the same thing. If you have the AP password, it's trivial to set up a fake second router in the same vicinity (you don't even have to touch the original one) with a stronger signal and have everyone connect through your gateway. Of course, once you have the…
OSX and I assume iOS does do detection of this. If you connect to an AP that was WPA2 encrypted in the past, and has the same name but no encryption now, it gives you a big scary warning and bails out.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#25Earlier quoted context omitted.
looks like someone did http://pdf.yt/d/1dKWAxs03AvnYqkt
Tangent: This is a good site for PDFs, immensely better than scribd. Whenever I click a link in the PDF (for eg. pg 17), the document zoomed in permanently. I cannot find a way to revert back to original zoom, even opening the link again does not help. So whoever is running the site, please look into this bug.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#26Full text: https://pdf.yt/d/1dKWAxs03AvnYqkt
So much for iMessage security. Also, ProtonMail works much in the same way (central key management), for anyone wondering, so it should be vulnerable to the same type of attacks.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#27Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
Step 1: buy a Mac :-/
> iPhone Configuration Utility 3.6.2 for Windows
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#28Earlier quoted context omitted.
looks like someone did http://pdf.yt/d/1dKWAxs03AvnYqkt
Tangent: This is a good site for PDFs, immensely better than scribd. Whenever I click a link in the PDF (for eg. pg 17), the document zoomed in permanently. I cannot find a way to revert back to original zoom, even opening the link again does not help. So whoever is running the site, please look into this bug.
Though I see no reason why clicking a link should result in the zoom level changing, so it does seem like a bug.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#29Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
Has anyone tried using the configurator? I'd give it a go but it looks like it might completely wipe devices prior to applying the settings.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#30Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
Is there a video of this talk?