Earlier quoted context omitted.
Tangent: This is a good site for PDFs, immensely better than scribd. Whenever I click a link in the PDF (for eg. pg 17), the document zoomed in permanently. I cannot find a way to revert back to original zoom, even opening the link again does not help. So whoever is running the site, please look into this bug.
It appears to be a bug in pdf.js (or the PDF format itself): https://github.com/mozilla/pdf.js/issues/5064 As somebody else mentioned, you can use the arrow/triangle to display the regular viewer toolbar, and zoom out. This is obviously not ideal, but there's not much else that can be done until a fix comes from pdf.js upstream, I suppose.
Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
61–70 of 87 posts
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#62Earlier quoted context omitted.
> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…
There's another reason this won't happen: very few users really care. If users really wanted it and clamored for it and showed a clear market preference for secure and privacy-respecting companies, then you might get somewhere.
What would they buy, today, in order to "show a clear market preference"?
It's a bit difficult to show statistical evidence of people making choices which are unavailable to them.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#63Earlier quoted context omitted.
-$2000 is fairly common. As mentioned below, authors have to pay publication fees. Most journals are for profit and closed-access, though this is starting to change somewhat. Somewhat ironically, being published in these journals is a prerequisite for how researchers actually do get paid: by grants, usually taxpayer funded.
Is it also true that some organisations also pay their employees if they publish papers, I've heard this happens in the security field.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#64Earlier quoted context omitted.
Yes, but one issue is that you could be pressured into pairing the device. Or someone can brute force the passcode to access the pairing UI. The slides mention a way to bypass pairing, but I don't think ever mentioned how.
Apple can boot the device over USB using a custom image that doesn't require the passcode. Other people can't because it needs to be signed with Apple's key in order to run.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#65Earlier quoted context omitted.
Yeah, I've been shocked by how easy it is to get a brand new router and set it up with the same SSID and password and every device I have auto-connects like it's the same thing. If you have the AP password, it's trivial to set up a fake second router in the same vicinity (you don't even have to touch the original one) with a stronger signal and have everyone connect through your gateway. Of course, once you have the…
OSX and I assume iOS does do detection of this. If you connect to an AP that was WPA2 encrypted in the past, and has the same name but no encryption now, it gives you a big scary warning and bails out.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#66Earlier quoted context omitted.
Yeah, I've been shocked by how easy it is to get a brand new router and set it up with the same SSID and password and every device I have auto-connects like it's the same thing. If you have the AP password, it's trivial to set up a fake second router in the same vicinity (you don't even have to touch the original one) with a stronger signal and have everyone connect through your gateway. Of course, once you have the…
OSX and I assume iOS does do detection of this. If you connect to an AP that was WPA2 encrypted in the past, and has the same name but no encryption now, it gives you a big scary warning and bails out.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#67Earlier quoted context omitted.
> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…
I disagree...Apple's size makes it ideal for resistance - the government has been very pro-business for the last decade, and congress has been way too receptive to lobbying groups. If Apple, Google, and a few others really put some muscle into it, they could make a real difference.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#68Earlier quoted context omitted.
yeah, if your device wasn't supervisioned before it would clean install - i guess but i haven't tried and/or checked otherwise if you can than reapply your backup.
I found a way: you can apply the restriction to a non-supervised device, which simplifies the process. You don't need to re-install or wipe. Just create a profile with the restrictions, then follow the instructions at: http://support.apple.com/kb/HT5833 (Edit to add: It's actually unclear if the non-pairing restriction gets applied when using this method, it doesn't seem to get listed in the profile details once on t…
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#69Earlier quoted context omitted.
I wasn't suggesting that, obviously. I was trying to be helpful and point out that students have free access.
OT: Technically, it is not free access. You (or at public institutions, the general public) paid for your access … in discussions on open access, I often learn that many researchers, scientists etc. are under the impression that they already have open access although the simply get routed around paywalls because they use IP addresses of their paying institutions.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#70Earlier quoted context omitted.
OSX and I assume iOS does do detection of this. If you connect to an AP that was WPA2 encrypted in the past, and has the same name but no encryption now, it gives you a big scary warning and bails out.
I guess this is to combat password stealing attempts in particular, and not AP spoofing in general, since you could easily make the new AP WPA2?