Live data from Hacker News

Apple iMessage Zero-Click Hacks

wired.com

81–90 of 156 posts

Re: Apple iMessage Zero-Click Hacks

#81

Does this mean that iMessage evaluates messages as code for some reason? Why on earth would that be the case? It's a foundational security principle to not do that. And even if they did then why is that so hard to fix?

It’s more like, if you send someone a photo, iMessage will decode the photo and display it. If the imaging library has a bug a maliciously crafted image may be exploitable.

iMessage has more integrations than that too. If you send someone a URL, e.g., the recipient will see a preview of the content.

iMessage does a lot to mitigate the attack surface, but people still get through.

Re: Apple iMessage Zero-Click Hacks

#83
Contrary to the article, blocking ALL media besides plain text from random senders who aren't in your contacts is exactly what most people would want and should be the default. I don't see any downsides to that approach.

Re: Apple iMessage Zero-Click Hacks

#85
post #9

Earlier quoted context omitted.

SMS is also exploitable though, right (Both types of messages go through Messages.app)? And you can't disable SMS entirely I don't think.

> you can't disable SMS entirely I don't think Buy a data-only subscription, and use Google Voice or some sort of PBX powered app to still be able to receive regular phone calls. Preferably I’d want a really basic voice only, open source PBX powered app for iOS that I could use. Then I could get me a data-only plan and SIM. Caveat: I still need Norwegian BankID to work with my SIM though. I dunno if any of the data-o…

That seems like an awful lot of effort to go to for what really ought to be a settings toggle.

Re: Apple iMessage Zero-Click Hacks

#87
post #46

Earlier quoted context omitted.

Well, send from what? Every iMessage comes from an account with an Apple ID, so I presume stolen credentials would be the only way to really do this, adding to the cost.

If you know the email address that is used for the Apple ID, you can send it a message without being in messages. You can also send a text to a phone number via email based on the carrier and knowing how to structure the address. So, it's not impossible to do this at all. No stolen credentials necessary.

>If you know the email address that is used for the Apple ID, you can send it a message without being in messages.

Though this option precludes the random war-dialing explanation.

Re: Apple iMessage Zero-Click Hacks

#88
I got corrected last time this topic came up. I originally thought Messages was part of the OS and not a pre-installed userspace app. However, if it's in userspace, why is it such a vulnerable vector for compromising the phone? Is there some privilege-escalation component to this that I haven't read about?

Re: Apple iMessage Zero-Click Hacks

#89

A small way to reduce attack surface - have iMessage just setup for your iCloud email address instead of phone number. Phone numbers are becoming increasingly useless. > In fact, Citizen Lab researchers and others suggest that Apple should simply provide an option to disable iMessage entirely. There's a checkbox in Settings > Messages that does exactly this? It seems strange they published this.

"... Citizen Lab researchers and others suggest that Apple should simply provide an option to disable iMessage entirely."

You can do this already. If you "manage" your iphone with Apple Configurator you have fine-grained control over every little thing it does. You can disable imessage (and many other things like the app store, etc.)

Re: Apple iMessage Zero-Click Hacks

#90

A small way to reduce attack surface - have iMessage just setup for your iCloud email address instead of phone number. Phone numbers are becoming increasingly useless. > In fact, Citizen Lab researchers and others suggest that Apple should simply provide an option to disable iMessage entirely. There's a checkbox in Settings > Messages that does exactly this? It seems strange they published this.

> Phone numbers are becoming increasingly useless.

Not really, there's a ton of government services that require you to have a phone number (depending on where you live). I don't see any real suggestion for an alternative to having a phone number. If nothing else, to receiving notification. You can't really rely on iMessage, WhatsApp, Signal and similar services, you need one system that you're sure will cover 98% for all people. 3. parties can't even integrate into many of these services.

You could use email, but I don't really see how that's any better and many seniors will use SMS, but not email to any great extend.

SMS is still the only unified messaging service you can be sure that all your friends and family will have.

Post reply on HN