Live data from Hacker News

Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

i.blackhat.com

61–65 of 65 posts

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#61

Earlier quoted context omitted.

If scanning works on filesystem-level, just storing images in any non-standard format would be enough, you don't need root for that. Most likely even storing images in an sqlite would make them inaccessible for those scanners. Trying to force all apps in the world to use some scanning API for their images is unrealistic. Also you can use web apps with some website hosted in a free country with canvas drawing. They'll…

> targeting most popular apps and services If a competing photo storage site doesn't offer the same "feature" of scanning the files you upload, might Apple decide to prevent iOS devices from accessing it? I'm sure Apple would love to claim that the anti-trust authorities don't care about the children.

There's no precedence for any browser to censor any website outside of malicious website feature. So technically you're right, Apple surely could do that, but that will be another level of fence around garden.

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#62
post #60

Earlier quoted context omitted.

Unfortunately, it's now vital to child safety that iPhone users never be allowed to jailbreak their phones. Apple's recently-announced CSAM photo detection feature relies on Apple being sure that the real NeuralHash machine-learning model, not a fake that produces random data indistinguishable from a non-matching photo, is running on everyone's devices. So I'd say the odds of them loosening their grip here are pretty…

The EU is pretty resistant to Apple bullcrap. They will order Apple to switch to server-side scanning on unlocked devices.

The client will just never send the images, if someone writing it doesn't wants that.

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#63

for those looking for a TLDR: - Result: run unauthorized code on iOS 14 - 14 is the most secure toy phone OS to date, with kernel heap hardening, data PAC, userspace PAC hardening, tfp0 hardening, ipc_kmsg hardening - Exploit took advantage of multiple bugs, concentrating on PAC (Pointer Authentication Code, cryptographic signature on the pointer value, designed to resist memory disclosure attacks, for more context s…

Good summary.

As the owner of my device though, I would say the result is that it lets me run authorized code because I am the authority, not Apple.

By jailbreaking, I am asserting my legal authority as the owner.

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#64

for those looking for a TLDR: - Result: run unauthorized code on iOS 14 - 14 is the most secure toy phone OS to date, with kernel heap hardening, data PAC, userspace PAC hardening, tfp0 hardening, ipc_kmsg hardening - Exploit took advantage of multiple bugs, concentrating on PAC (Pointer Authentication Code, cryptographic signature on the pointer value, designed to resist memory disclosure attacks, for more context s…

Good summary. As the owner of my device though, I would say the result is that it lets me run authorized code because I am the authority, not Apple. By jailbreaking, I am asserting my legal authority as the owner.

But that's not the phone's defaults. Anything not approved by the monopoly is unauthorized, making the initial statement correct and the phone a toy from general computing criteria.

Re: Everything has changed in iOS 14, but Jailbreak is eternal [pdf]

#65
post #50
post #41

Earlier quoted context omitted.

A bright lad with a few years experience finds a way around the mitigations for a flaw found in the previous version. Bear in mind Apple is a $T1 organisation and he ... isn't. Not only does he perform a rather well polished dance but he writes it up in an entertaining and well presented way. I suspect english is a second language too which makes the whole thing even more impressive. Just to reiterate: he waltzes aro…

> A bright lad with a few years experience A few years experience specifically working with iOS. That doesn't say anything about how much existing experience he has in the security space. Here's a Java critical patch update from 2017 that references someone of the same name (probably him): https://www.oracle.com/security-alerts/cpujul2017.html

When I was his age, I had trouble finding my arse with both hands. He manages an attractive presentation of a pretty dry subject in a foreign language and presents it to an all star audience.

I suspect he'll do all right.

Post reply on HN