7 ms·
My prediction is that Apple will start to use attestation (device check) to lock down iMessage. The problem is that this would require a software update for old
by bgorman 3y ago
My prediction is that Apple will start to use attestation (device check) to lock down iMessage. The problem is that this would require a software update for older devices.
- ocdtrekkie 3y agoApple already provides security updates to all iOS devices made in the last 5ish years at least, so it would probably take a pretty trivial number of years for them to have an update deployed to nearly all iOS devices that see active use.
- gafage 3y agoThe iPhone 5s (released ten years ago) received an update earlier this year.
- uf00lme 3y agoI think that is how BBM worked, but I could be wrong. I'd be surprised if it is part of the over arching OS security. Sounds like something that should be in their lockdown mode at the very least.
- kotaKat 3y agoThey already partially do. > Warning: In order to generate the “validation data”, pieces of information about the device such as its serial number, model, and disk UUID are used. This means that not all validation data can be treated equivalently: just like with Hackintoshes, the account age and “score” determine if an invalid serial can be used, or if you get the “customer code” error. The "customer code" error is a prompt from Apple, basically an attestation failure -- you have to contact Apple Support to get your Apple ID unlocked once you've tripped the failure. Legitimate customers will breeze right through (eg, just approving your login from your legit device), but Hackintosh users use crafty means to fake their way through the process.[1] [1]https://old.reddit.com/r/hackintosh/comments/gij9rt/getting_imessage_to_work_with_customer_code/ https://old.reddit.com/r/hackintosh/comments/gij9rt/getting_...
- blibble 3y agoremote attestation would mean it's not possible to pull out the binary and run it externally you'd need the key from the TPM/secure enclave too, which is much much harder to extract
- SpaghettiCthulu 3y agoIt's only a matter of time until a company starts selling TPM dumps, right?
- blibble 3y agomaybe, but for a task like this it doesn't really scale Apple aren't going to allow one phone to attest 5000 new iMessage clients
- kotaKat 3y agoThat's... amusingly, also a thing in Chinese marketplaces, for a similar purpose. iCloud Activation Lock, on non-cellular devices (eg, Wi-Fi only iPads), relies on the device's serial number, Wi-Fi MAC, and Bluetooth MAC addresses as the three identifiers required to clear the Activation Lock check. Via special debug cables (eg, a "DCSD cable") there are ways to write in new SysCfg data to the flash to change those variables. This can also be done to Apple Watches (pre-Series 6) with a special dock also sold on the Chinese market. You can (sort of easily) get your hands on a "clean" serial/MACs set for under $10-15 or so on the market.
- Eriksrocks 3y agoInteresting. I assume this is mostly used to "wash" stolen devices to make them appear legitimate for resale? I'm surprised Apple designed the hardware to allow this without any sort of authentication.
- Eriksrocks 3y agoYou can't "dump" a TPM. That's the whole point. They are designed such that the cryptographic secrets they hold (including ones loaded at manufacturing) are unrecoverable without an electron microscope and nation-state level resources (and even then, it would be extremely difficult if not impossible on modern process nodes).
- WD40forRust42 3y ago[dead]
- cavisne 3y agoIt would require a hardware update for older devices I believe, ie any that don’t have TPMs
- thomasahle 3y agoMaybe, but they also just announced RCS support: https://9to5mac.com/2023/11/16/apple-rcs-coming-to-iphone/ https://9to5mac.com/2023/11/16/apple-rcs-coming-to-iphone/ so maybe they've just decided that this is a good opportunity to take the charge opening things up.