Live data from Hacker News

Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

zdziarski.com

51–60 of 87 posts

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#51
post #2

Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.

I'm confused. Normally one cannot "pair" a device without entering the passcode to unlock it. Is this not the case?

Yes, but one issue is that you could be pressured into pairing the device. Or someone can brute force the passcode to access the pairing UI.

The slides mention a way to bypass pairing, but I don't think ever mentioned how.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#53
post #50

I know each publisher is different, but is there a guideline amount of how much each researcher gets when they are published in such journals?

-$2000 is fairly common. As mentioned below, authors have to pay publication fees. Most journals are for profit and closed-access, though this is starting to change somewhat. Somewhat ironically, being published in these journals is a prerequisite for how researchers actually do get paid: by grants, usually taxpayer funded.

Is it also true that some organisations also pay their employees if they publish papers, I've heard this happens in the security field.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#54
post #2

Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.

I'm confused. Normally one cannot "pair" a device without entering the passcode to unlock it. Is this not the case?

Yes, the device needs to be unlocked to pair it, otherwise it doesn't access to the keys needed to create the pairing record. The pairing record (stored on your desktop) helps avoid needing to unlock the device for subsequent access.

I believe the device still needs an AfterFirstUnlock key to decrypt the escrow keys, so a cold-booted device wouldn't be accessible even if it was paired.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#55
post #6

>This is due to iOS' behavior of automatically joining networks whose name (not MAC address) it recognizes, such as “linksys” or “attwifi”. Discriminating by MAC addresses would not help at all. MAC addresses are trivial to spoof, even though they are "in hardware". It would be cool if we had a standardized trust-on-first-use cryptographic authentication model for wireless APs, like we do with SSH right now. You conn…

This is the case with WPA2/EAP. You have to accept the cert (the first time) before entering your Active Directory/RADIUS credentials.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#57
post #14

Earlier quoted context omitted.

> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…

I disagree...Apple's size makes it ideal for resistance - the government has been very pro-business for the last decade, and congress has been way too receptive to lobbying groups. If Apple, Google, and a few others really put some muscle into it, they could make a real difference.

Lobbying against environmental or financial regulations is one thing. Taking on the national security state is something else entirely. I don't think it's loony or hyperbolic to say that the military/intelligence world really runs the U.S. at many levels. The U.S. has been a national security state at the highest levels since WWII transformed America from a civilian-centered economy to a military one and created what Eisenhower called the "military industrial complex." The whole topic makes for very interesting history... look into the national security act of 1947 for a starting point.

At lower levels you have a vestigial democracy and true "independent" free enterprise, but when you get to be a company the size of Apple you are too big to blend in with the ordinary civilian economy. Getting that large results in immediate audience before the king, which in America is the military/intelligence shadow state. I'd be very surprised if one can ascend to the billion-dollar stratum in America without some very interesting closed-door meetings with strict NDAs. I'm also sure that all kinds of next-level stuff kicks in when you start to become a major international corporation that does heavy business overseas, as Apple is.

There are endless forms of soft power that can be brought to bear against a large company, especially a publicly traded one. You've got the standard issue tax evasion practices of every major corporation for starters. Don't want to help us spy on users? How about a high-resolution IRS audit and some "offshore banking reform" specifically targeted at you? Then there's anti-trust, which is obviously selectively enforced. Does Apple have anything that could be called a monopoly or a monopolistic business practice?

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#58

Earlier quoted context omitted.

I'm confused. Normally one cannot "pair" a device without entering the passcode to unlock it. Is this not the case?

Yes, but one issue is that you could be pressured into pairing the device. Or someone can brute force the passcode to access the pairing UI. The slides mention a way to bypass pairing, but I don't think ever mentioned how.

Apple can boot the device over USB using a custom image that doesn't require the passcode. Other people can't because it needs to be signed with Apple's key in order to run.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#59
post #14

Earlier quoted context omitted.

Thank you very much - bookmarked. BTW, Apple is missing a great opportunity in my opinion. They don't need a ton of user data to make money and could evolve into the secure consumer device company. I see only upside for Apple if they work towards making as secure as possible devices.

> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…

There's another reason this won't happen: very few users really care.

If users really wanted it and clamored for it and showed a clear market preference for secure and privacy-respecting companies, then you might get somewhere.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#60
post #2

Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.

Has anyone tried using the configurator? I'd give it a go but it looks like it might completely wipe devices prior to applying the settings.

That is optional. (Source: Me, administers over 100 Apple devices with Configuration in day-to-day operations.) The software is so-so, but asynchronously managing USB connected devices is annoying, even with a shiny Apple interface.
Post reply on HN