10 ms·
Analyzing iOS 16 Lockdown Mode: Browser Features and Performance
- dellIsBetter 4y agoThe lockdowm mode modify apple telemetry?
- frankjr 4y ago> Apple is previewing a groundbreaking security capability that offers specialized additional protection to users... That's an amazing marketing spin. It's not their admittance of failure of engineering to make the features secure, no, it's a groundbreaking security capability! To be fair, I do appreciate that they acknowledge the problem in the first place and are trying to do something about it.
- kergonath 4y agoA large tech company acknowledging that flashy convenience features can be a security risk is groundbreaking in itself. No need to be so cynical, this is a step in the right direction.
- mixmastamyk 4y agoFinally a feature I’m interested in and they drop support for the 6s.
- madmod 4y agoI wonder how lockdown mode affects apps that use WKWebView? (Not SFWebView which afaik is supposed to be more like the Safari app with things like password manager support.) Eg would this break a WebRTC meeting in a native app?
- samwestdev 4y agoI had no idea you could use Photoshop document (PSD) as an image on a webpage!
- olliej 4y agoIf it is a format supported by macOS internally it's likely viewable in Safari - webkit basically passes image decoding to the system image decoders (hand wavey here)
- stefan_ 4y agoNow that sounds like a truly terrifying, terrible idea.
- Syonyk 4y agoThat seems to be how one of the exploits from a year or two ago worked. https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i... It exploited an archaic Xerox format parser to make its own virtual machine, and then went out from there. So I'd agree, throwing anything on a webpage (or incoming message) into the "Can you parse this weird thing?" pipeline is a bad idea!
- astrange 4y agoJBIG2 is a mandatory part of PDF, not its own weird image format. (Though I think it's also allowed in TIFF files and those might count as weird.)
- Ansil849 4y agoIt's not clear to me if Lockdown Mode would have prevented Hermit, the latest mobile APT which targeted iOS via sideloading by enrolling in the Apple Developer Enterprise Program. The list of lockdown features don't seem to explicitly list that in-house app sideloading is disabled - is it? If not, then this mode seems like security theater from Apple, in that it doesn't actually lock down the parts of the attack surface that are actively being leveraged. How about instead, or better yet alongside this, Apple explains how they granted entry in the Enterprise program to the spyware company, and what measures they're taking to prevent it from happening again.
- jon-wood 4y ago> Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on. (From the article) So this would have prevented Hermit as you'd need to install a new configuration profile to allow sideloading of applications from that source.
- Ansil849 4y ago> So this would have prevented Hermit as you'd need to install a new configuration profile to allow sideloading of applications from that source. Are you sure that's true? I haven't seen a Hermit sample firsthand, but from everything I've read about it targets did not need to install an MDM profile, they simply needed to click a link. Looking at Apple's distribution guidelines - https://support.apple.com/en-bw/guide/deployment/depce7cefc4d/web https://support.apple.com/en-bw/guide/deployment/depce7cefc4... - MDM is listed as one option, and simply going to a link is listed as another: > There are two ways you can distribute proprietary in-house apps: > > Using MDM > > Using a website It seems like the latter was used, so I don't think installation of a custom profile was required, which brings me back to my original question of whether Lockdown would have prevented it.
- olliej 4y agoRunning an enterprise app still is not a trivial single tap on iOS. Obviously with the new EU legislation mandating support for unrestricted malware of this kind, that's kind of a moot factor in EU and EU-adjacent markets.
- 0x0 4y agoThe missing icons are probably web fonts being disabled?
- pizlonator 4y agoYup.
- kemayo 4y agoYeah, those are FontAwesome icons.
- thewebcount 4y agoAh, that explains a lot. I do heavy ad and tracker blocking, including blocking loading of all web fonts. I constantly find various arrows and other tiny images not rendering and didn't know why. You'd think for something like a left and right arrow, you could at least set the alt text to the unicode character for left or right arrow, or at least ASCII art (i.e. "->" and "<-"). It would also make it make sense for people using screen readers.
- traceroute66 4y agoIt will be interesting to see how this fits in with Supervised Mode. For example, I'm assuming "configuration profiles cannot be installed" will only to apply to unsupervised devices. Otherwise it could make Supervised Mode rather, erm, tricky ! Also "Allow access to USB accessories when device is locked" option has already been available in Supervised Mode for years. So I wonder if Lockdown Mode is more removing some of the "supervised only" restrictions from certain options (e.g. the "USB when locked" is currently "supervised only" option, but it looks like Lockdown Mode will bring this option to all users). Overall, I think this is a good move by Apple though even if some of the details remain to be seen.
- galad87 4y agoExisting configuration profiles will continue to work after enabling the lockdown mode.
- Sporktacular 4y agoAh, so it's just the MDM enrolment/control that stops with Lockdown? IT still works with Supervised Mode?
- Linda703 4y ago[dead]
- coldcode 4y agoWould such a thing be possible in Android world? I wonder since there are so many phone manufacturer and ISP mods that might not be under Google's control.
- cornedor 4y agoEvery third party browser you install on Android already has a differeny JIT, so all those apps probably need to implement their own rules.
- stefan_ 4y agoAndroid fully supports alternate browsers (you don't have the "skins" for the Apple engine that you get on iOS) so nothing is stopping e.g. Firefox from introducing such a mode.
- mrex 4y agoBut that's only a single application. Lockdown Mode affects the operation of the entire OS, and all applications that use certain iOS features.
- omegacharlie 4y agoGrapheneOS[1] includes similar 'defense in depth' mechanisms of which predate and some go above iOS 'Lockdown Mode'. Unfortunately just for Pixel devices. [1] https://grapheneos.org https://grapheneos.org
- AshleysBrain 4y agoDisabling WebGL will block a lot of HTML5 games. I think there will be a lot of "WebGL not supported" or "browser out of date" messages that will need updating to include "please turn off lockdown mode"...
- jon-wood 4y agoIn practice I wouldn't expect many devices to have lockdown mode turned on, and the people who are turning it on probably aren't also using the same device to play Fruit Ninja in a browser. This is a feature explicitly designed for people who have reason to believe they're being personally targeted by national intelligence agencies, or other extremely well funded organisations.
- hedora 4y agoI suspect it will be much more popular than that. <Insert rant about how I miss my Windows 8 phone because it had less crap on it here.> The only thing I saw in the writeup that I can imagine normal people over 25 missing is web font icons, and maybe emailing PDFs around to sign with iMessage. (Though those come in as jpegs from cameras or PNG screenshots half the time anyway...)
- AshleysBrain 4y agoThe blog says "Should You Turn it On? Yes. Seriously. Turn it on when you have a supported OS and don’t look back." If that becomes the general advice, I imagine it will end up getting more broad use - even if most of the people who turn it on don't really need the extra security.
- Syonyk 4y agoI am writing to a somewhat technical audience on my blog... but, yes, I don't care if my devices can't play some online WebGL game if the tradeoff is far better security in general. Also, since you can turn it off for specific domains, it's easy enough to re-enable WebGL for some site, while still having Lockdown mode apply to all the random ad serving backends and such you come across. If you're not someone who might be specifically targeted, I think that's entirely reasonable. Secure by default, drop the security level somewhat, by concrete actions I've taken, for some site I want to do something more on. At some point, I'd assume attackers will try to get people to turn it off so they can attack, but you've made an awful lot more noise by that point.
- saagarjha 4y agoFun fact, the browser limitations used for lockdown mode are very similar to the existing restrictions that Apple already had in place for rendering captive portal screens :)
- pizlonator 4y agoNope. Captive portal mostly just disabled JIT. This is more comprehensive.
- saagarjha 4y agoSeems like the stuff got added sometime last year, which I hadn't noticed. Thanks for clarifying!
- jeshin 4y agoif there's one thing I hate, it's websites "supporting" tor by redirecting from a specific article to the main page of their (in this case non-functional) onion URL. twitter did this too a while back, they made a big show of how they're supporting tor now, and now whenever i click a link to a tweet via tor, it redirects me to their frontpage. thanks, can you stop supporting tor now please, so I can use the site with tor again?
- Syonyk 4y agoYou know, I don't think I tested specific pages when I put the Tor meta support in. That's a fairly recent addition I was messing around with. It's a '<meta http-equiv="onion-location"' tag, and it points to the base URL even on the blog pages. I'll get that fixed to point to the actual page of interest (should be easy enough in Jekyll to just re-render things). It's handled client side in your browser, so you should be able to tell the browser to ignore that.l But as far as I can tell, the Onion address is up and operating.
- jeshin 4y agoYes, unfortunately this is often the case. people who don't really use or test the site in tor put in some half-baked support and it just ends up making things worse. But my grievances aside (and please don't take this personally, it's just an issue that I've encountered one too many times, so it gets on my nerves), thank you for fixing it, and indeed it looks like the onion URL is now online, it wasn't working for me earlier.
- Syonyk 4y agoI very much appreciate it - as I said, it was something I'd missed in my dorking around with Tor. No idea why it was down earlier, unless it was just loaded - I haven't changed anything on the server related to Tor in a while. It seems any time a post of mine makes the HN rounds, I get some other weird corner case of my site pointed out, and it does improve things over time! Jekyll makes it easy to just re-render the site with changes like this too.
- 4y ago
- naillo 4y agoIt's not clear to me why you wouldn't just turn off your phone if you think you're being targeted by such an extreme attack.
- newscracker 4y agoTurn off the phone for how long? And how would one even know if they’re being attacked? Turning off the phone is not an easy option for investigative journalists and activists, especially in today’s world where communicating with people in different geographical locations may be necessary. Right out of the box, smartphones are more secure than mainstream personal computers (running Windows, macOS or Linux) that are connected to the Internet.
- saagarjha 4y agoBecause people generally do things that require being able to use a phone?
- ben174 4y agoPoliticians, executives, and celebrities are under constant attack. You can't just expect they halt communication.
- bugmen0t 4y agoI'd love to know if you can still use a third-party browser (e.g., Firefox) and if it would inherit lockdown settings per web page (given that all iOS browsers have to use webkit webview).
- dagmx 4y agoThe security is enabled at the WebKit layer, not the Safari layer. Otherwise it would be trivially defeated
- robertoandred 4y agoPut a point in the "no third-party web engines" column.
- execveat 4y agoAren't configuration profiles necessary for configuring VPN though? For the best security you'd want all your traffic to go through your own server for retrospective analysis.
- Gigachad 4y agoYou can have them, they just can’t be added while the mode is on. So they have to be added beforehand.
- rootusrootus 4y agoDepends on the VPN and use case. I don't use a configuration profile for mine right now, but if I wanted to do anything more than manual activation I would need to use a profile to accomplish that.
- newscracker 4y agoSince several web features are disabled with Lockdown mode enabled, I wonder what measures Apple is planning to implement to defeat (at least to some extent) fingerprinting attempts to detect the people/devices using Lockdown mode while browsing. > If you can’t stand the impact on performance or image rendering, well, maybe Lockdown isn’t for you. Apple claims only a tiny fraction of users will need it, though I’d argue an awful lot of users will want it. Of course, I want it! (I already go through many other inconveniences for privacy and security). > Should You Turn it On? > Yes. Seriously. Turn it on when you have a supported OS and don’t look back. Amen! I’ll be telling some laypeople to turn it on and try it out (along with instructions on how to turn it off selectively or completely).
- O__________O 4y agoHow would Apple counter fingerprinting? Already pointed out this issues in a prior point here 14-days ago: https://news.ycombinator.com/item?id=32006436 https://news.ycombinator.com/item?id=32006436 From that comment: “If Apple is logging if this feature is on and sending it back to Apple, it will result in targeting from nation states even if this feature is “invincible” - which I have no reason it is; basically, nation states demand list of users subject to its jurisdiction.” Obviously there are likely other ways to fingerprint Apple devices with lockdown mode on, but to me, at the point you need “lockdown mode” likely should realize the doing so will likely make you more of a target.
- tomxor 4y ago> If Apple is logging if this feature is on and sending it back to Apple, Apple (and most for profit entities), tend to exclude themselves from their definition of "privacy".
- deleted 4y ago[deleted]
- olliej 4y agoApple is not Google or Facebook: https://www.apple.com/privacy/ https://www.apple.com/privacy/ You have to explicitly opt into any logging in apple apps and the OS itself (iOS or macOS). Apple clearly goes to great lengths to ensure that they cannot access your information and data, and very clearly distinguishes stuff that is inaccessible to them from stuff that is encrypted but that they can technically access decryption keys. A result of this is of course that we get people complaining about apple not restoring their data. What you're doing is demonstrating how effective Google, Facebook, etc have been in convincing you that real privacy isn't actually possible, solely to protect it from legislative action, because their business models depend on violating it continuously Recall that Google deciding to trawl through the content of your email (assuming gmail) is why emails from amazon no longer include any details about the order. Or how "AI" required Google and Facebook, et al having access to everyone's pictures and information. The fact that G and FB have taken a "fuck our users" approach, doesn't mean that's how every company operates. The fact of the matter is that >75% of google's revenue comes from selling you out, and >90% of facebook's. >80% of apple's revenue comes selling hardware, the remainder from selling services and I assume store royalties (I'd be interested in the break out). You don't have to invade everyone's privacy to make money, it's just G and FB have chosen that approach every time the option is presented to them. In fact, if a company can decrypt your data then it becomes possible for a hacker of said company to also decrypt that data - a fairly solid reason IMO for either not collecting, or ensuring only the user can access info, unless absolutely necessary for functional or legal reasons.
- infinityplus1 4y agoHow about some kind of Firewall which sends requests only to trusted domains and blocks everything else?
- kergonath 4y agoThis can already be done, there are several apps that do more or less this. Now, a GUI to manually block or allow specific hosts without having to go trough a pseudo-vpn would be cool.
- WhyNotHugo 4y agoSo lockdown mode disables any attachment except images on their messaging app, because parsing these has often been introducing exploits. The fascinating this is that this parsing would happen on a process which even _has_ privileges to trigger any exploits. Parsing a message should be done far far away from the core OS operations, high in userspace, by a sandboxed process that can't break anything. Based on previously seen exploits, it seems messages are handled by rather privileged processes. I wonder if there's a reason for that (e.g.: special messages can trigger privileged operations?)
- twobitshifter 4y agoIts not about privileges, the iMessage blastdoor exploit built a turing machine using a weird old image format and then escaped. https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html?m=1 https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- ylk 4y agoPrivileged is the wrong word, but GP is not entirely wrong. What you linked to is only the first part of the exploit and analysis. From the conclusion of the second post, which analyses the sandbox escape: > Perhaps the most striking takeaway is the depth of the attack surface reachable from what would hopefully be a fairly constrained sandbox. [...] The expressive power of NSXPC just seems fundamentally ill-suited for use across sandbox boundaries, even though it was designed with exactly that in mind. [...] (The above is severely cut down, reading at least the entire conclusion or even the whole post is worth it) https://googleprojectzero.blogspot.com/2022/03/forcedentry-sandbox-escape.html https://googleprojectzero.blogspot.com/2022/03/forcedentry-s...
- deleted 4y ago[deleted]
- why_only_15 4y agoParsing already does happen (mostly) on a process which doesn't have privileges. Read about Blastdoor.
- yessirwhatever 4y agoSo lockdown mode is IE6 on iOS?
- bni 4y agoDisabling old archaic image formats, link previews, ill advised web apis sounds like a great feature. I will definitely try this out.
- rootusrootus 4y agoWill this become entirely moot in the EU after they force Apple to throw open the gates to iOS?
- modeless 4y agoNo, why would it? Lockdown mode is a choice, and so is not using software from outside the app store etc.
- rootusrootus 4y agoEvery time someone says the word Android in this discussion, the next reply is that Android allows any <insert software here> you want, therefore it's up to that software to implement such a lockdown feature. Ergo, "lockdown mode" isn't able to be a thing on Android. And following from that, if iOS is forced to have all the same openings, then Lockdown Mode will be just as meaningless.
- modeless 4y agoYou're not making any sense. Google could easily implement a lockdown mode on Android in exactly the same way. Sure, you could choose to use a browser that doesn't have a lockdown mode. You could also choose to turn off lockdown mode! It's pretty much the same choice. Having that choice to disable lockdown doesn't make lockdown meaningless. Lockdown is voluntary.
- Sporktacular 4y ago"But it’s an admission that the complexity of a modern phone operating system (or tablet, or desktop OS) have just gotten too much to handle, so the best path forward is to offer the option to not do those things." Looking at non-consumer security mobile phones (like the one from Boeing) or those that are modified to be secure (like the Blackberry used by Obama) they all seem to employ this less-is-more approach to security. In other words, what's the minimum tolerable feature set we can offer without further compromising security? It follows from the question 'why use a phone at all? If there is a functionality the client can't do without, then how do we provide just that without any security downside?' It's a sensible approach which means Apple has just entered this market. Not in a big way yet - phones are made in China, modem chip firmware security has a long way to go. But lockdown is just beginning too and it shows Apple understands this is serious. But all this is just defense. Next step is the entire industry. Finfisher is done - next up: NSO, Candiru and Darkmatter, their investors, suppliers and scumbag employees before they dissolve/rebrand and scurry back out of the light.
- birdman3131 4y agoQuestion on part of this. He skips over it in the article. How do 2 locked down phones that have not done so before do a facetime call? As neither one will accept the others call.
- castillar76 4y agoThis is a good writeup! A couple random thoughts that occurred to me while reading through it: - It would be really nice to be able to disable Lockdown Mode for specific people in iMessage the way you can for specific websites in Safari. I'm guessing you can't because the sandboxing isn't implemented the same way it is in Safari...but maybe that should be fixed! - Disabling WebRTC in Lockdown Mode is probably an overall win, but it may result in certain web-video-conferencing tools not working. In most cases, the correct answer will be "then install the app for that instead", but it may result in a few issues. On the other hand, users can also disable LM for those sites (and I like that you can do it easily, so I could do it temporarily and then flip it back off afterwards). - It will be interesting to see if the ability to turn this on is a feature available in MDM. I can imagine companies mandating that users traveling to certain areas of the world must have LM MDM-force-enabled on their phones at all times instead of taking a burner phone. - I wonder how the prohibition on wired accessories will work if the phone is unlocked when the accessory is plugged in. As an example, with LM enabled I could plug my phone into my car and use CarPlay, but does it then turn off when the phone locks? I'm assuming not, but if you're going full-bore-privacy-protections, there's an argument there that it should actually just disable the port fully when the phone locks (and that's certainly the easier option to code).
- Syonyk 4y ago> I can imagine companies mandating that users traveling to certain areas of the world must have LM MDM-force-enabled on their phones at all times instead of taking a burner phone. That only solves a few of the possible issues a content-free burner phone solves, though. I sure wouldn't travel to those bits of the world with a regular device with all my information on it. Rubber hose cryptography is a thing.
- castillar76 4y agoVery true, and important to note that ‘rubber hose cryptography’ doesn’t have to mean violence—it can take the form of ‘open your phone and let us dump your data or you don’t get to enter/leave the country’.
- A7med 4y agoprbly they shared how to pass by this mode with the pegasus team pebblydy
- amq 4y agoFirefox on Android could easily offer something similar for the web part. Sounds like a quick win to get some attention.
- trixie_ 4y agoI already use an extra iPhone as a secure platform crypto wallet, this feature sounds like it'll make it even better.
- epolanski 4y agoWhat about store apps privacy.
- olliej 4y agoThis post repeats the false claim that link previews in messages provide attacker controlled network loads. They do not. The page preview included in Messages is created on the sender side. On those occasions the sender can't create a preview you get a "click to load preview" message instead of a preview with the url. In other words, nothing more than just sending the url in the first place. I'm curious what "disabling link previews" actually means in lockdown.
- refulgentis 4y agoI'm a bit confused, aren't you describing that the attacker controls the network load? The preview is created by the sender?
- olliej 4y agoWhen you receive a link that has a preview, at least in Messages, what you get is the true url and an image that was created on the sender side. There is no networking unless you tap the link. If you tap the link then you've tapped the link and of course tapping links loads them. Hence I want clarification on what is involved here. [edit: s/server/sender/]
- londons_explore 4y agoI wonder if turning off the JIT is worth it? A lot of bugs exist around JavaScript engines, sure, but they tend to be in the interfaces with the bindings for all the html5 features (and corresponding opportunities for memory corruption). It's been a while since the last bug in the JIT itself - fuzzing tends to uncover those pretty quick.
- londons_explore 4y agoIf I wanted my computing device to be as secure as possible against state actors, I would compile all the software myself, and tweak a few compiler settings for my builds. It's super hard to make an exploit work when you don't know what options your target was compiled with. Also, simple things like swapping malloc implementations or changing some parameters of malloc will pretty much make your device immune to state sponsored attacks. Also, anytime you see an application crash, record all crashdumps - since they will contain evidence of a failed exploitation attempt.
- mark_l_watson 4y agoI am running Lockdown Mode on iOS and iPadOS right now. Generally I like it, but some web sites don't seem as responsive and the Mastodon web app uses a few web fonts that don't show up. Here is some irony: the linked article caused Safari on my iPhone with beta iOS 16 and Lockdown Mode to immediately crash every time I visit the page (about 5 tests trying to load the page). I have not seen that problem in any other web site.
- mmis1000 4y ago> But with Lockdown enabled, the list grows. Now, the browser no longer will render TIFF, BMP (24-bit), JPEG 2000, or PDF images. I am not sure why BMP is excluded specifically in lockdown mode. Isn't BMP 24bit simply a bit chunk of bytes filled with uncompressed rgb pixels? It don't even have any specific logic required to render. All you need is fill the render buffer with pixels.
- mark_l_watson 4y agoI am late to this conversation, but I have a question: both my iPad Pro and my iPhone 11 Pro seem to get slightly shorter battery life between charges. Has anyone else noticed this? Perhaps it is because Javascript runs slower?
- varenc 4y agoHave you enabled Lockdown mode on both devices? Then that's almost certainly the cause. Without the JIT you're going to be burning a lot more CPU cycles running JavaScript.