thewayne: (Default)
The Wayne ([personal profile] thewayne) wrote2021-09-01 07:52 am

Yet another iPhone Message hack that currently can't be stopped

Amazing stuff. The Bahrain gov't bought a hack that allows them to send a text message to an iPhone owned by a journalist, anti-government protester, cheating mistress, whoever, and the phone is compromised. You don't have to click on a link, open a document, play a video. No interaction whatsoever. Receive the message, and your phone is rooted.

They probably paid a few million bucks for it, but they're the Bahrain government - what do they care for such a tool?

Apple has been fighting these zero-click attacks and instituted a good defense, but this latest one blasts right through it. The problem is that "we" (not me) want emojis, embedded videos, photos, etc. and that requires access deeper into the phone's infrastructure, and that all by definition makes things more vulnerable. If the app only allowed messages without any frills to be sent back and forth, and you had to use emails to attach the fun stuff, then the Messages app could be completely secure. But where would be the fun in that?!

So Apple gets to play an on-going game of whack-a-mole.

They're releasing a new version of IOS, 15, probably in October, which should increase security, but that security will certainly be broken at some point and the whack-a-mole will resume.

Myself, Apple occasionally ticks me off with changes to IOS. For example, I think it was when 11 was released, they broke their podcast player, and I foolishly updated my phone literally the day I was to drive to Phoenix, a nice long 500 mile drive. The break? Let's say you want to listen to four or five Wait Wait Don't Tell Me episode. You play the oldest and the next one automatically starts. Except the program broke and it wouldn't start the next, so you're zipping down the interstate at 75 MPH and have to fumble with your phone to start it. How the hell did this not turn up in testing?

So on occasion I think about buying a flip phone that has a 4G hotspot, plus an iPod Touch to hold all my apps, music and podcasts, and data stores and go back to something resembling the late '90s.

https://www.wired.com/story/apple-imessage-zero-click-hacks/
dewline: Text - "On the DEWLine" (Default)

[personal profile] dewline 2021-09-01 02:16 pm (UTC)(link)
Thanks for nothing helpful to the rest of us humans, Mamlakat al-Baḥrayn!
elayna: (Keanu Whoa)

[personal profile] elayna 2021-09-01 02:45 pm (UTC)(link)
For some reason, I’ve been having trouble every new release, that it won’t update on my phone. And I read the More Info page, and follow all the suggestions, but last time it gave an error message that wasn’t even on their list. So now I’m just relieved when it finally hits that time where it tells me that it’s just going to do it, and gets it done, and stops asking me every time I plug my phone in if I want to do it.

Also, while I doubt anyone would send me a scary hack, I think I’ll remember to plug it in regularly and keep it backed up! That’s unnerving.
bibliofile: Fan & papers in a stack (from my own photo) (Default)

[personal profile] bibliofile 2021-09-02 06:04 am (UTC)(link)
With my flip phone, I could receive only plain text messages (SMS), which meant that group texts from iPhones were Right Out (because they were MMS). Then with my first Android phone, I was able to switch on/off the ability to receive MMS messages. I'm not sure I can do that anymore, unless it's by turning off cellular data period. But IIRC the default format for iPhone texts is now MMS? Because they don't download if I have my data off (er, until I get to wifi someplace).

Fortunately, I avoid automatic updates where possible, so I wait to install my iOS updates until I know for sure that the update is okay. Or necessary. (Alas, Windows no longer gives you that option: updates are either allowed or not. Argh, Microsoft.)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)

[personal profile] silveradept 2021-09-04 12:08 am (UTC)(link)
So much fun, the ways in which the things that would otherwise be nice additions for people that want it turn out to be vectors for attacks by people who want to do bad things.
motodraconis: (Default)

[personal profile] motodraconis 2021-09-04 06:11 am (UTC)(link)
I've a chum who works at a high level in a big company, and they won't say anything controversial near their phone... because they've met the people being paid to listen in on it.