Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Victims in range cannot do anything about it. Think about the impact of launching such an attack on Wall Street, or maybe at the world’s busiest airports, or at large utility plants. The results would be catastrophic.

While I can certainly agree it would be annoying, a nuisance and productivity-hindering, calling this "catastrophic" is probably overdoing it a tad much.

Catastrophic means by definition that it's related to or involves a catastrophe. iPhone-users not being able to use their iPhones hardly counts as that, no matter where on the planet that happens.

With all that said: Neat hack. Now I feel like reproducing it :)



Please do try to reproduce it - the company that is responsible for this "discovery" also happens to be selling a product that is supposed to prevent this attack, and the tone of their PR has got my BS-detectors ringing.

An example of the sort of thing that gives me doubts. They refer to another supposed demonstrated attack called "Wifigate", which no-one has been talking about, except for themselves. And when you read the details, they claim that iPhones come preloaded with a bunch of WiFi SSIDS that the phone will automatically connect to. mostly telecommunications companies. Up until recently I used to work for one of those listed companies, and I have owned iPhones continuously since the iPhone 3G. I can tell you categorically that iPhones do not automatically connect to SFR wifi hotspots like this company claims. This fact destroys an important part of their claim for this current "attack", that you can be affected even if you've never connected to a Wifi hotspot.

So that's one guaranteed example of exaggeration right there, which seeing as it's the only piece of information in the article that I'm capable of verifying myself, makes me very distrustful of the entire article.


My iPhone do connect auto-magically to FreeWifi_secure networks which is the preloaded SSID for the other french operator listed by Skycure.

However it's supposed to connect with EAP-SIM [1]. Skycure mentions that "some of [those] bundles include SSID passwords". Do they mean that only those would make devices vulnerable? Could you let us know if SFR uses EAP-SIM or a basic PSK?

It could be that iPhones connect automatically only to EAP-SIM preloaded networks.

[1] https://mobile.free.fr/assistance/262.html


>I can tell you categorically that iPhones do not automatically connect to SFR wifi hotspots like this company claims.

My understanding is that AT&T wifi users have to connect just once to attwifi and then going forward it will connec to the SSID whenever it sees it, which is a lot considering its in every McDonalds and Starbucks and other locales.

Some people say their phone connects to attwifi without once first connecting to it. This article from last year supports that claim:

> Settings for AT&T iPhones, for instance, frequently instruct the devices to automatically connect to a Wi-Fi network called attwifi when the signal becomes available. Carriers make the Wi-Fi signals available in public places as a service to help subscribers get Internet connections that are fast and reliable.

>Sharabani said the settings that cause AT&T iPhones to automatically connect to certain networks can be found in the device's profile.mobileconfig file.

http://arstechnica.com/security/2013/06/iphones-can-auto-con...

If anything, this shows how unreliable wifi security is. I could see a next-gen wifi that uses SSL cert-like signing to verify identity and stop spoofers. Wifi is still the wild west.


> When combined with an earlier vulnerability, named “Wi-Figate”, which lets attackers force a device to automatically connect to a given WiFi network

I'm not fully up on exploitable iOS tricks, but it sounds like they're spoofing a BSSID to be one that the iOS device has already connected to (because iOS devices broadcast this when scanning for networks IIRC?), but has RADIUS authentication with a specially crafted server certificate that manages to crash the network stack.


> (because iOS devices broadcast this when scanning for networks IIRC?)

Not anymore, Apple fixed that in recent iOS versions. Probe requests are not divulging SSIDs anymore. However WifiGate uses common SSIDs and network operators preloaded ones as honeypots.


Seems that wasn't fixed reliably. Still seeing lots of probe requests. Is there a https://support.apple.com/HT... talking about it?


Not aware of anything from Apple about this issue. It was just an assumption, sorry. What I did is test up to date devices (i think i even tested an up to date iOS 6) and couldn't get any specific SSID. The probe requests were still there, but SSID parameter was always set to Broadcast.

However I did see a lots of probe requests WITH a SSID parameter set but those were not coming from my devices :). I assumed they were not up to date.

I am very interested to know if the probe requests you're seeing are also coming from unknown devices: if they aren't, could you provide us with the iOS version you're using/testing with?


The devices I know are several iPhones 6/6+ running iOS 8.3.


“With heavy use of devices exposed to the vulnerability, the operating system crashes as well. Even worse, under certain conditions, we managed to get devices into a repeatable reboot cycle, rendering them useless.

So it only crashed the whole device if the device was under 'heavy use', which seems to contradict the claim that it renders devices unusable immediately.


Shame, though. I'd love a guerrilla enforcement tactic for the Quiet Carriage on our local trains.


Let's hope that the iPads used as electronic flight bags (containing charts, etc) by pilots all have their wifi disabled.


They're likely all in airplane mode.


I can't tell if this is a joke or not :)


With wifi on?


Let's pray pilots flying air crafts are not relying on an iPad as their only navigation instrument.


Phone jamming is a great way to prevent people from calling 911, friends, or family, so there's that.


Large utility plant? Mind runs down list of catastrophy vectors for iOS in large utility plants

Large utiltity plant... iOS... large utility plant... iOS... Did I miss the post where large utility plants said "Why we stopped using closed control systems for our reactors and switched to iPads" ?


It could be used to paralyze communication networks and, in conjunction with other actions, could be catastrophic. Or even just used to interrupt iOS service for anyone that uses it in part of their job. You could go small and interrupt a small business's iPad POS, or you could disable an airplane's usage manual running on the cockpit iPad. There's a lot of stuff you could do with this exploit.


Hospital staff communicates with text messages


[flagged]


It doesn't sound like you're in any position to judge or complain about other people, given how little respect you show for others.


I know it doesn't just happen with any certificate but:

How illegal is it to set up a Wi-Fi network with an SSL certificate? Are you responsible for the fact that iOS has a bug in the certificate handling?


> How illegal is it to set up a Wi-Fi network with an SSL certificate? Are you responsible for the fact that iOS has a bug in the certificate handling?

If you're crashing/DOSing a remote internet-server by exploiting your knowledge of a bug in the server-software, you may technically just be "sending data", but in court it's the intent which makes it hacking, vs just accidentally crashing something.

I would expect this to be treated similarly, but ofcourse legal IT is a jungle of randomness in itself, so I won't make any guaranteed predictions :)


Okay, then I'm going to start kicking air, like this! And if any part of you should fill that air, it's your own fault!


How illegal is it to type on a keyboard?


Btw, how reproduce it? I can't find any technical details about this hack


The last paragraph in the article:

"The researchers say they have warned Apple of the error, and are refraining from releasing technical details about it until after the company has issued a fix. Apple did not respond to a comment request ahead of publication."


They haven't disclosed technical details publicly.


What a shame. This would've been a neat prank at work (I'm the only Android user in an office full of iPhone/iPad users).


Judging by the degree to which my girlfriend is glued to Facebook on her iPhone, she probably would classify getting hacked this way as a 'catastrophe' :)


We are a bunch of wimps now. Anything that is mildly inconvenient is now called an emergency or catastrophe or tragedy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: