Live data from Hacker News

Dear Jailbreak Community

evasi0n.com

1–10 of 72 posts

Re: Dear Jailbreak Community

#2
Am I the only one who thinks this makes evad3rs look even more shady?

One example: they carefully avoid denying the presence of malware in their jailbreak. Instead,

"We are saddened by the accusations that we would ever do such a thing, or sell weaponized exploits. If anyone ever attempted to include malware in a jailbreak, we are confident that the many security experts combing through jailbreak software would find it."

The explanations about Saurik and piracy in their Chinese pals' app store comes off as similarly evasive.

Re: Dear Jailbreak Community

#4
I do not believe that helping a Chinese company that is related to Qihoo360, which has a very bad ethical record will in anyway benefit the Chinese users. I also don't see how is this benefiting the jailbreak community, except for the compensation they took in.

Re: Dear Jailbreak Community

#5
This is interesting. The jailbreak community is a weird place on the edge of free software- normally, "just open source it" is an easy answer to security concerns, but there are understandable reasons not to open-source exploits. However, the whole competition thing between evad3rs and saurik seems kind of strange. Honestly, I wish Apple would just get with the times and allow an appropriate degree of freedom on their devices; even if evad3rs are as innocent as they claim in this instance, forcing users to install potentially sketchy obfuscated third-party system-level code in order to do basic things like set default apps seems like a recipe for eventual disaster.

Re: Dear Jailbreak Community

#6
Malware should be easy enough to detect by MiTMing the device, assuming the baseband is unmodified and cellular is shut down. (edit: no, it doesn't-- shouldn't post before I'm awake) I have just updated my phone and I have no traces of the chinese app store mentioned here, for what it's worth.

Re: Dear Jailbreak Community

#7

I do not believe that helping a Chinese company that is related to Qihoo360, which has a very bad ethical record will in anyway benefit the Chinese users. I also don't see how is this benefiting the jailbreak community, except for the compensation they took in.

One thing I don't understand... why do you think it is wrong for them to make money out of their work? I am not saying that what they did was good for the community but what if the alternative was not getting anything? They are still offering it for free...

Re: Dear Jailbreak Community

#8
I don't think this really helps evad3rs build credibility.

They put a giant, user-facing blob payload into their jailbreak with no transparency about how it got there or what it is. Reading between the lines they were paid for it, but they don't even manage to come out and say that outright in this "letter."

There's always some level of faith involved in installing an early iOS jailbreak, because exploits often aren't documented or open-sourced until long after their release (for a variety of reasons - vanity, ripoffs, weaponization, etc.). But at least most of the jailbreaks released in the past have been transparent and configurable.

In the Dev Team jailbreaks, all userland packages were optional and if a user wanted, they could uncheck the "Install Cydia" box in the payload configuration, configure their own Cydia (because the source is open, imagine that!), or install a completely different set of user-land applications. Plus a variety of parties with various interests in the development community were given previous jailbreaks early, which provides at least a cursory level of auditing and sign-off. This evad3rs release offers none of these reassurances.

I certainly wouldn't call any iOS jailbreak "trustworthy" in the truest sense but this one is definitely the worst so far.

Re: Dear Jailbreak Community

#9

This is interesting. The jailbreak community is a weird place on the edge of free software- normally, "just open source it" is an easy answer to security concerns, but there are understandable reasons not to open-source exploits. However, the whole competition thing between evad3rs and saurik seems kind of strange. Honestly, I wish Apple would just get with the times and allow an appropriate degree of freedom on thei…

> but there are understandable reasons not to open-source exploits

Legit question, What reasons could there be?

Re: Dear Jailbreak Community

#10
post #9

This is interesting. The jailbreak community is a weird place on the edge of free software- normally, "just open source it" is an easy answer to security concerns, but there are understandable reasons not to open-source exploits. However, the whole competition thing between evad3rs and saurik seems kind of strange. Honestly, I wish Apple would just get with the times and allow an appropriate degree of freedom on thei…

> but there are understandable reasons not to open-source exploits Legit question, What reasons could there be?

Two of them come to mind:

* They don't want the exploit "stolen" or reused by another party (for good or evil)

* They don't want to make it too easy for Apple to patch it.

Post reply on HN