Live data from Hacker News

Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

i.blackhat.com

31–40 of 65 posts

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#31
post #26

Earlier quoted context omitted.

ObKnuth: > Beware of bugs in the above code; I have only proved it correct, not tried it.

Layperson here: what does that mean?

It’s a joke. https://en.m.wikipedia.org/wiki/Formal_verification

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#33

When will start seeing laws making it illegal to disable the scanning for hashes?

Or illegal to reverse engineer the scanning code, to work out how to distort the images so the hashes no longer match (or distort innocent images so that they do match, and then send them to someone else's phone).

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#34
post #26

Earlier quoted context omitted.

ObKnuth: > Beware of bugs in the above code; I have only proved it correct, not tried it.

Layperson here: what does that mean?

It's a comment from a correspondence between Donald E. Knuth and Peter van Emde Boas (meant as a joke I think).

You can find it in this pdf at the end of the 7th page : https://staff.fnwi.uva.nl/p.vanemdeboas/knuthnote.pdf

Knuth mentions it in his FAQ (at the end) : https://www-cs-faculty.stanford.edu/~knuth/faq.html

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#35
post #34

Earlier quoted context omitted.

Layperson here: what does that mean?

It's a comment from a correspondence between Donald E. Knuth and Peter van Emde Boas (meant as a joke I think). You can find it in this pdf at the end of the 7th page : https://staff.fnwi.uva.nl/p.vanemdeboas/knuthnote.pdf Knuth mentions it in his FAQ (at the end) : https://www-cs-faculty.stanford.edu/~knuth/faq.html

I got that part. The part I don't understand is this: what does it mean for a program to be proven correct but still not work?

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#36
post #34

Earlier quoted context omitted.

It's a comment from a correspondence between Donald E. Knuth and Peter van Emde Boas (meant as a joke I think). You can find it in this pdf at the end of the 7th page : https://staff.fnwi.uva.nl/p.vanemdeboas/knuthnote.pdf Knuth mentions it in his FAQ (at the end) : https://www-cs-faculty.stanford.edu/~knuth/faq.html

I got that part. The part I don't understand is this: what does it mean for a program to be proven correct but still not work?

It means that the correctness properties that were formally proved are not necessarily what you would intuitively understand as "correct". E.g. you can formally prove that a buggy factorial(n) always outputs (n - 1)! by incorrectly defining what you want to prove. The function behaves according to what you proved, it's just not the expected behaviour.

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#37
post #34

Earlier quoted context omitted.

It's a comment from a correspondence between Donald E. Knuth and Peter van Emde Boas (meant as a joke I think). You can find it in this pdf at the end of the 7th page : https://staff.fnwi.uva.nl/p.vanemdeboas/knuthnote.pdf Knuth mentions it in his FAQ (at the end) : https://www-cs-faculty.stanford.edu/~knuth/faq.html

I got that part. The part I don't understand is this: what does it mean for a program to be proven correct but still not work?

It's a joke. You'd expect that a proof of correctness to be the Holy Grail. Nothing could be wrong, since it's proved correct. And yet, after running it, you could still find a bug in it, because you may have made a mistake in your proof.

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#38
The fact that Apple clearly cares a lot about software security from at least two angles--both securing the device for the user from external attackers (I know they truly care about this, even though they frankly seem to focus only on users in the west and have been known to throw people from the east under the bus without a fight: see their attempt to downplay Google Project Zero's critical discoveries a few years ago) as well as (sadly, but critically, as it establishes increased direct incentives) securing the software running on the device written by themselves and other content providers from the ostensible "owner" of the hardware (whether for digital rights management or anti-competitive purposes)--and has a centralized dedicated team that can learn from experience (to avoid making the same mistakes over and over across different releases, which was the norm at companies like Samsung for a long time) made up of incredibly smart people (including mercenary turncoats from the jailbreak community who either cared more about working on fun problems than fighting for the user or simply needed the cash so much the morals had to lose out) that has been staring at this problem now for well over a decade and who are on the cutting edge of deploying "mitigations" throughout both their software and hardware even if said mitigations cause multi-percent loss of performance for the user and even if it requires changes to some or all (omg) existing software AND YET--even if they have certainly made progress (the jailbreak ecosystem has been severely affected... I have given much longer talks on the status--such as the final segment of my "Hindsight can be 50/50" talk from 360|iDev a couple years ago, but the important thing to appreciate is that the time from having high-quality exploits for specifically-modern devices to when the vulnerabilities they rely on have been patched has gone from averaging months to averaging negative months as of a few years ago)--it SOMEHOW is STILL the case that people continue to find ways (even if they are highly costly to pull off and even if the resulting abilities are "limited": you really don't need much to do a denial of service or exfiltrate data... we focus a lot on what is required to build a high quality easy to use software modification stack, due to alternatives to the App Store like my Cydia, but that is "overkill" to someone merely trying to be malicious) to hack and slash through all of these defenses (even remotely!! the yearly iMessage exploit has almost become a trope) should be taken as a visceral demonstration that our industry simply seems incapable of developing secure software, and we either need an industry-wide "come to Jesus" moment whereby we reboot the entire thing with higher/safer abstractions written by fewer/smarter developers working in languages and with tools that allow us to prove the security of what we build (and no: Rust isn't enough... I give lectures at both college courses and hackathons on how real world jailbreak exploits have worked for both iOS and Android, and part of what makes it fun even for beginning developers is how many of the bugs are "conceptual"... it is absolutely true that memory safety helps, but we need to be striving for near-perfection here as the stakes are so high, and yet, somehow, we often manage to develop software that fails to provide safety for users without even a single incorrect use of memory storage primitives) which is going to require groundbreaking research that honestly might simply prove the impossibility of the task, or, maybe, we just need to give up and make sure that everyone everywhere lives in the same constant and healthy state of fear that every single computer we are surrounded by is a liability that could turn on us at any moment as those of us who "know better" do... and one day, it is going to happen: it isn't going to be a freedom fighter like Charlie Miller who figures out how to remotely disable the brakes on every Jeep Cherokee on the road simultaneously with a remote exploit--a true story that I believe every software developer should be taught in school in the same way that physicists are routinely taught about tragic historical mistakes in the handling of radioactive materials, to make sure no one casually deploys something that puts people's safety so directly tied to bugs in centralized servers--but it is going to be a "rogue nation state", "terrorist group", or, at this rate and with our luck the last few years, someone we might best describe as a "supervillain" (a movie where someone like George Hotz is the antagonist would be absolutely amazing: if anyone writes that script and needs a science advisor to help with making the technical details ridiculously accurate, hit me up) that gives civilization a serious and deadly lesson in cyber-security. :| :/ :(

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#39

Earlier quoted context omitted.

Agreed. PDFs are still considered very unsafe from unknown sources. Always be cautious. They are constantly used in phishing attacks.

All phishing attacks require you to click on a link embedded in the PDF, right? On the one hand, you'd think anyone technologically savvy wouldn't do that. On the other hand, accidentally clicking on links in PDF's is the bane of my existence. I constantly consume academic books and papers as PDF's on my iPad in the built-in Books app, tap somewhere with my Apple Pencil for any number of reasons (to pan, to zoom, to…

I mean, multiple jailbreaks merely required you to open the PDF: it isn't just phishing attacks that have made me wary of PDF files. (But we also have seen jailbreaks that rely only on JavaScript that can be run in the browser, so ¯\_(ツ)_/¯).

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#40
post #9
post #5

Earlier quoted context omitted.

I suspect they're concerned about the PDF format, which has been used in the past to deliver malicious payloads.

If there is concern there, use a reader without javascript or an online converter from PDF to another format.

The most famous exploits in Apple's PDF stack (notably not present in Adobe's renderers) came from bugs in freetype (a software font rendering stack also used by a lot of Linux systems), specifically in the VM (seriously: it is an interpreter for a stack machine) used to run the embedded bytecode truetype fonts use to "hint" their fit to the pixel grid.
Post reply on HN