The Apple Backdoor Explained.

Поділитися
Вставка
  • Опубліковано 8 чер 2024
  • Apple Backdoor on iPhones? Let's dive into these exploits and everything we know so far. Also clearing up some of the misinformation/disinformation and why Lockdown is so powerful!
    Referenced Videos:
    Coverage of lockdown mode: • I Used Apple’s Lockdow...
    2023 Digital Rights Awards: • Digital Rights Awards ...
    Primary Sources:
    Ars Technica Coverage: arstechnica.com/security/2023...
    Hardware Mystery Research Paper: securelist.com/operation-tria...
    Assessing signs of a compromise: securelist.com/triangulation-...
    🔐 Our Website: techlore.tech
    🕵 Go Incognito Course - to learn about privacy: techlore.tech/goincognito
    🏫 Techlore Coaching - to get direct support: techlore.tech/coaching
    💻 Techlore Forum - to connect with other advocates: discuss.techlore.tech
    🦣 Mastodon - to stay updated: social.lol/@techlore
    We cannot provide our content without our Patrons, huge thanks to:
    BRIGHTSIDE, Clark, Ente, Larry, Afonso, Boori, Brad, Casper, Cookie, Floyd, JohnnyO, kevin, love your content, NotSure, Poaclu, x
    🧡 Join them on Patreon: / techlore
    💚 To see our production gear, privacy tools we use, and other affiliates: techlore.tech/affiliates
    💖 All Techlore Support Methods: techlore.tech/support
    00:00 Super quick intro
    00:12 Breaking down the story
    06:54 Personal Analysis & My takes
    #apple #backdoor #security
  • Наука та технологія

КОМЕНТАРІ • 92

  • @comosaycomosah
    @comosaycomosah 5 місяців тому +88

    if anything kaspersky researchers should be praised for finding it

    • @techlore
      @techlore  5 місяців тому +20

      The amount of detail and effort kaspersky put into this was INSANE, 💯 agree. This has been going on and unfolding for a long time too! Someone on our forum has been doing a great job of relaying the updates as they come along: discuss.techlore.tech/t/new-zero-click-ios-malware-infects-kaspersky-iphones/3927

    • @comosaycomosah
      @comosaycomosah 5 місяців тому +1

      @@techlore for real yea! I'll check it out I been following it too they did an awesome

    • @climate-moneymakingcampaig305
      @climate-moneymakingcampaig305 5 місяців тому

      Kaspersky themselves are being exposed innpolitical level to have been working with russian and israely intelligent agencies for political porposes.
      Ofc they would try hard to bring down a company that looks like an innocent child compared to intel , microsoft and qualcomm that are heavily compromised (actuall backdoors are designed in them)

    • @myxobe
      @myxobe 5 місяців тому

      mfs be working in Kaspersky getting 50k a year in russia while in the us they would get around 100-200k

    • @SlitheringDemon
      @SlitheringDemon 5 місяців тому +1

      ​@@myxobethat's the reason why they were able to disclose this publicly without getting fcked. All the more praise to them! They have foregone more money working in US, instead deciding to disclose such critical exploits.

  • @camelotenglishtuition6394
    @camelotenglishtuition6394 5 місяців тому +30

    As an ethical hacker, I enjoyed the video but respectfully disagree. If you watch the team's presentation it shows that a code is needed to parse custom instructions to an unregistered part of the arm chip memory. So, you're saying that not only were the malware devs so good they found the secret code - a 1 in a million find( the hash given in the presentation) but they also knew how to implement it in unregistered memory? Also another 1 in a million find. Dude, this is the mother of all leaps of faith. If you look at the backdoor on x86 chips ( blackhat presentation - God mode), a very similar technique is used. This screams gov having a word with apple to implement some empty memory address space. Also, they say in the presentation that lockdown mode didn't defeat this attack ( to the best of my memory).

    • @CocolinoFan
      @CocolinoFan 4 місяці тому +3

      Yes, it hurts to see. Ideology and propaganda ruins even the sharpest of minds.

  • @llpolluxll
    @llpolluxll 5 місяців тому +15

    I am so ready to criticize apple for their garbage business practices but I think this is one of the few areas in which they should be praised and I would like to see a feature like this on non-apple devices. As much as I don't like apple, they do good work in some areas.

  • @KngSovereign
    @KngSovereign 5 місяців тому +6

    12:26 - "I wish there was a lockdown mode for Linux"
    SELinux is definitely a thing and when in "enforcing mode" will do some serious restrictions.

  • @kxvrol
    @kxvrol 5 місяців тому +3

    Linux actually has a lockdown mode. If you boot your computer with secure boot the kernel is launched locked down. This prevents any unsigned libraries from being loaded, prevents any kernel ram modifications, prevents hibernation etc. I get that it's not the kind of apple lockdown, but it certainly improves the security of the device.

  • @KishoreKumarmaistry
    @KishoreKumarmaistry 5 місяців тому +14

    🎯 Key Takeaways for quick navigation:
    00:29 📰 *Kaspersky discovered a highly sophisticated exploit impacting Apple devices, highlighting four zero-day vulnerabilities.*
    01:40 🌐 *The exploit, transmitted via iMessage, granted access to sensitive data, but most infections didn't survive a reboot.*
    03:02 🛡️ *Apple's Advanced Hardware-based Memory Protections faced a rare defeat, emphasizing the challenges in securing complex systems.*
    06:18 🕵️ *Lockdown mode, a commendable Apple feature, reduces the attack surface, offering a powerful defense against sophisticated exploits.*
    11:27 🤔 *Concerned users can enable lockdown mode for added security, acknowledging its real limitations for convenience.*

  • @SamSung-jq4ho
    @SamSung-jq4ho 5 місяців тому +6

    Techlore: Linux needs a lockdown mode.
    *screaming in BSD*

    • @techlore
      @techlore  5 місяців тому +2

      BSD LOCKDOWN MODE 🔥

  • @NomadOutdoorAdventures
    @NomadOutdoorAdventures 5 місяців тому +4

    That’s one of the main reasons I use lockdown mode on my iPhone ever since it came out not because I’m a high target just because I love to be safe instead of be sorry later

    • @jogurcik13
      @jogurcik13 5 місяців тому +1

      >using iphone
      Good job

    • @vick92v
      @vick92v 5 місяців тому

      The researchers confirmed lockdown would do nothing against this

  • @umarfarooq8038
    @umarfarooq8038 5 місяців тому +4

    My question is, do you trust Apple with your data? I mean being a privacy advocate and techie, you think these big tech cares about privacy and want to help people in achieving total control over their data? How can anyone trust apple when they scan photos in the name of child **x? How can anyone trust a USA based company to respect privacy when almost all the privacy companies are located in Europe like Proton, Tuta, etc? Even after what Edward Snowden revealed, do you think the US gov will let these big firms respect privacy even if they genuinely want to do so? The US gov wants to scan each and every device on earth just to keep control and maintain their hegemony, even their own citizens. I cannot and will not trust Apple or any other big tech and also any hardware/software (except open source) manufactured in US or China.

  • @cheesium238
    @cheesium238 5 місяців тому +1

    It would be interesting to see something similar under FOSS Unix OSs, other than qubes, hopefully immutable distros will spawn a real privacy/security option in the future

  • @K2HWY
    @K2HWY 5 місяців тому +2

    Ironic you are wearing a Go Incognito shirt, can we maybe get the updated version finally😁

  • @thatchinaboi1
    @thatchinaboi1 5 місяців тому +9

    The only disinformation is in your claim that this isn't a backdoor.

  • @aris6927
    @aris6927 5 місяців тому +58

    There was a backdoor there is no getting around it. It is a straw man argument to say that people equate the software exploits with the backdoor. The secret hardware registers is the backdoor, not the software. What was the purpose of this backdoor? Well only Apple knows for sure. These hardware registers were closed by Apple now that they were being exploited. This hardware was not documented in official documentation. Apple designs their own chips, they should have intimate knowledge about their own chips and what they ship.

    • @techlore
      @techlore  5 місяців тому +20

      Absolutely. Again, myself and many people want to know what the hardware feature was used for. The video directly addresses the backdoor. Where I think it’s disingenuous is when people immediately spread information this is an actively malicious backdoor baked in from the ground up for the sole purpose of exploitation. (Which is a VERY different tone & accusation to make)
      Reminds me of the China-made surveillance chip story:
      ‘Graham argues that the presence of backdoors is widespread, about 20% of home routers and around 50% of industrial control computers have a backdoor. Not all backdoors of course have a malicious purpose, in many cases they are used to debug software and firmware contained in the product.’ (securityaffairs.com/5889/security/china-made-us-military-chip-security-backdoor-or-debugging-functionality.html)
      I hope we get more insight into this! Either way, yep Apple screwed up. But I’m still more than impressed with the response and the mitigations we have access to now as a result of it 👌 And I personally believe that Apple’s response to threats like this one speak to the likelihood that they weren’t actively creating the problem themselves on purpose, but that’s my personal take of course :P

    • @thatchinaboi1
      @thatchinaboi1 5 місяців тому +11

      ​@@techloreWhat is disingenuous and downright dishonest is to claim that this isn't a backdoor, when you can't prove it. But go ahead and deny you aren't being a shill.

    • @techlore
      @techlore  5 місяців тому +21

      At what point did I claim there simply wasn’t a backdoor 🤔 I directly address the hardware component. Literally directly citing the primary researcher who discovered this and what they had to say on the matter 👌

    • @jordank249
      @jordank249 5 місяців тому +5

      @@thatchinaboi14:43.

    • @climate-moneymakingcampaig305
      @climate-moneymakingcampaig305 5 місяців тому +2

      ​@@thatchinaboi1the "china-boi" call others "shill"
      Arguing with u is a waste of time

  • @chuctanundaspiderbone5407
    @chuctanundaspiderbone5407 5 місяців тому +7

    Nice analysis, thanks. Yes, it would be nice if all OSes had a similar safety feature. QUESTION: When is it appropriate to use lock-down mode (LDM)? How can users tell when it is necessary to use LDM and when to disable it? TY. EDIT: Just found the link to "I Used Apple’s Lockdown Mode So You Don’t Have To," Which sort of answered my questions, and raised other ones. Maybe as developers work on solutions for non-apple devices, the approach that Apple uses will be refined to ameliorate the limitations? What are the chances?

    • @techlore
      @techlore  5 місяців тому +1

      I know I already mentioned it a few times but I highly recommend the lockdown video, it’ll show you side by side comparisons and things to expect so you’ll know exactly what will happen beforehand, and it addresses who should try it out. If you’re curious, it’s just a toggle on your settings that you can turn back off after a reboot with no consequences. The video:
      ua-cam.com/video/ENuGWhz10UY/v-deo.html

    • @laarsss
      @laarsss 5 місяців тому

      I use lockdown mode myself and I think there's no disadvantage not using it. some apps and websites break, but for that you can just disable it just like you can with content blockers. I often don't even notice it, also no real slowdown compared to when it came out.

  • @aquatrax123
    @aquatrax123 5 місяців тому +4

    CVE-2023-38606 is 100% a back door added by Apple. It allows direct access to the memory. Using the exploit requires each command to be hashed with a secret table. This was not a mistake; it was deliberate. I highly doubt that lock down mode would prevent CVE-2023-38606.

  • @jlara36
    @jlara36 5 місяців тому +2

    Not the backdoor I was hoping for

  • @Dhirajkumar-ls1ws
    @Dhirajkumar-ls1ws 4 місяці тому +1

    It is definitely a backdoor.

  • @linuxstreamer8910
    @linuxstreamer8910 5 місяців тому +1

    if you need to know if you will be a victim of this backdoor what is your threat model if it is very high yes if not no

  • @skatcat743
    @skatcat743 5 місяців тому +5

    undocumented hardware feature is the most critical issue. Fuse it off if no one is supposed to use it.

  • @subfloor2022
    @subfloor2022 5 місяців тому +16

    Got it, Apple built in a backdoor, now I'm off to tweet about it.

  • @NeptuneSega
    @NeptuneSega 5 місяців тому +1

    I mean, they need a way to wipe phones that are iCloud locked, but this is way overbuilt for that.

  • @Randomly_Facts
    @Randomly_Facts 5 місяців тому +1

    I updated my Samsung phone, and there is a new setting called auto blocker. It also seems to block some functions, like ADB to increase security.
    Edit; this is what i remembered i checked and it doesn't block ADB(or only partially)

  • @sbradyork
    @sbradyork 2 місяці тому

    Not just describing Tim Cook then?

  • @cysecgnz
    @cysecgnz 5 місяців тому

    "A very powerful adversary." Watch, it turns out to be some 12 year old in their mothers basement. lol

  • @darkhorseman8263
    @darkhorseman8263 5 місяців тому +1

    This is what Australia has done to every device in the country.

  • @anigmatic2949
    @anigmatic2949 5 місяців тому

    My guy

  • @JonLikesStats
    @JonLikesStats 5 місяців тому +4

    I first heard of this two weeks ago from a (relatively popular) UA-camr who strongly suggested apple worked with the US government to make this exploit. Call it a backdoor or not, I was just glad to hear someone discuss the facts as established by the researchers.

  • @ddotmada
    @ddotmada 5 місяців тому +5

    Sorry the hardware was the backdoor. Saying you don't know if it was ARM or Apple who put it there is stupid. Apple designs their own chips they know everything that was in that silicon. Sure the way they got there was with exploits this just proves that you can't secure a backdoor.

  • @OMNITEK
    @OMNITEK 5 місяців тому +8

    i'm not an Apple user, but i think Apple has taken more measures towards security than most other platforms (main stream platforms)...now, do i agree with everything Apple?..NO..but there's not a single system that any of us will find everything we ever wanted...for now..Apple wins in my book.

  • @longlost8424
    @longlost8424 5 місяців тому +4

    ALL systems connected to a network are able to be compromised. always have been, always will be.......

  • @bitegoatie
    @bitegoatie 5 місяців тому +3

    Rebooting does not help with any serious root exploit (and it will restart tracking agents you may have taken pain to defeat - which is more difficult on Apple devices than any others). Do not bother rebooting your device on a daily basis if you consider yourself a candidate for nation-state targeting (or, more distressingly, targeting by freelancing agents or contractors of nation-state lawlessness-enforcement and misdirected-intelligence departments). This is a major problem across the board in modern computing. The companies are (all of them) indeed complicit in the backdooring of all computing. I am not going to get into the how and why of this complicity in the surveillance problem, but let me say this: it is not a problem limited to a few people or one company and it is absolutely not cured by lockdown mode.
    Lockdown mode is good publicity for Apple, but in the end it defeats anything like normal use of a computer. Worse, it keeps out the riff-raff, but it does not keep out the people it is intended to keep out. It cannot, because software (even hardware-assisted software) fixes will not help with deeper problems. All the difficult problems lie at lower levels than lockdown mode addresses. Frankly, the hamstringing of the system by lockdown mode is too high a price to pay to keep out the riff-raff. Practicing good computing hygiene (giving up your web-porn habit, for example) addresses a sufficient portion of common-criminal attacks without lockdown. That one needs to disable and to slow down so much just to limit the general attack surface is a demonstration of just how bad things have become on the internet. That this drag of a user experience does next to nothing to address the real problems should be a point around which everyone can rally to demand change in computing - and change in the behavior of the agencies driving the complicity of the industry.
    Unfortunately, we would rather tell ourselves stories about how only certain people need to worry about indefensible personal surveillance devices that run increasingly important parts of our lives, and how the companies should be praised for superficial mitigations of ongoing problems. Humans are extremely good at not facing unpleasant facts. (I have watched programmers and tech-support professionals look right at hidden subsystems within computers and, after initial worry, fabricating stories to explain away the existence of the unwanted files and code - it's remarkable to see grown professionals stick their heads in the sand rather than deal with unpleasant realities.) We readily generate straw-man arguments and draw silly parallels to encourage others to continue doing nothing about these (and many other) problems. If we could attach fear, hatred, or greed to every problem society faces, maybe we would get more traction regarding actually organizing to demand action - or, more unlikely, to act collectively to improve societal ills. But it's so much easier just to wave away the idea that, in this instance in computing, the exploits people detail are just the part of the iceberg we see from our security-researcher rowboats.
    Don't be afraid of backdoors and hardware-rooted computers (or the people and bots making use of them without your consent). You cannot, in any case, protect yourselves. Be angry and let tech companies and politicians know it. The problem is not one company or one country (though one country created and continues to lead the current computing and networking problem, which has spread to many others) - it is deep and widespread and state agencies and high-level corporate interests share blame for a deplorable state of affairs.

  • @YannMetalhead
    @YannMetalhead 5 місяців тому

    Good video.

  • @GocygoOffical
    @GocygoOffical 5 місяців тому

    👍🏻.

  • @robertlee6338
    @robertlee6338 4 місяці тому

    Amatuer hour or is this guy just a FANBOI

  • @tonyzone8999
    @tonyzone8999 5 місяців тому +1

    Sounds like our intelligence

  • @guilherme5094
    @guilherme5094 5 місяців тому

    👍

  • @kiyoponnn
    @kiyoponnn 4 місяці тому +1

    Interesting, but you don't need to glaze apple. Considering how overpriced iphones are they should be infinitely better than their android counterparts and yet in many ways they are worse than sub $400 phones(repairability, privacy, foss apps, downlading music etc.)

  • @Nohiding
    @Nohiding 5 місяців тому +1

    It is apple back door. If you notice that users can’t reset the ram on a running iPhone anymore. This is an agency request that apple complied with, because knowledgeable targets are to hard to track with the given exploit. Basically stupid feds need lots of help going into the future. All government exploits are developed by apple and google.

  • @macintush
    @macintush 5 місяців тому +3

    It’s already been patched for over a month or two now. Thanks for the sensational video tho 🙏

  • @CROSSBL4DE
    @CROSSBL4DE 5 місяців тому

    Was this targeting Russians? Or was it international? Or do we even not know?

    • @techlore
      @techlore  5 місяців тому +2

      According to this article yes it seems to have been heavily used against Russians. I’m not sure if we’re going to get an accurate scope of who/what/when/where/why for a long time unfortunately :/ Lots of theories to cook up I’m sure, but I don’t think we quite know the full story yet. (At least that I’ve seen)
      My guess is a very powerful government is behind this wild exploit chain.

    • @tonyzone8999
      @tonyzone8999 5 місяців тому +2

      Us

  • @Nohiding
    @Nohiding 5 місяців тому

    Too hard to believe. I know.. I’m true

  • @thatscrazy4487
    @thatscrazy4487 5 місяців тому +1

    I'm literally subscribed to this channel to watch the latest disinfo in the industry...it's like entertainment for me :))

  • @Dustin-fi8gj
    @Dustin-fi8gj 5 місяців тому +3

    Lockdown mode doesn’t protect from IMSI catchers.

    • @techlore
      @techlore  5 місяців тому +7

      actually your comment is a tiny bit incorrect!
      Apple updated lockdown mode to disable 2g by default which is one of the most common ways IMSI catchers are utilized :)
      EFF did a write up on this: www.eff.org/deeplinks/2023/09/apple-and-google-are-introducing-new-ways-defeat-cell-site-simulators-it-enough
      Even if it didn’t I think it’s worth reminding people as much as I love lockdown and would love to see other projects release similar functionality, it’s not foolproof and won’t instantly make you hack proof/private either. At the end of the day you can still install Facebook on an iPhone with lockdown after all :P

    • @guacfiend
      @guacfiend 5 місяців тому +3

      thank you for constantly being knowledgeable about the topic and not letting others step over you 💯@@techlore

  • @Nohiding
    @Nohiding 5 місяців тому

    This is not niche. This is an everyday use exploit.

  • @azminek7154
    @azminek7154 4 місяці тому

    The problem with Apple's security and privacy features that they will limit or disable it in a heart beat when an authoritarian regime comes knocking, like they did in Hong Kong.

  • @thatscrazy4487
    @thatscrazy4487 5 місяців тому +4

    What an apologetic video. Sad.

  • @brucoder
    @brucoder 5 місяців тому

    Thank you for tackling the reality of this instead of going mainstream with the celebrity of crying wolf. What I'd like is a "Phone-Only" more for all of my phones. How about it, Motorola - how about a modern version of the StarTAC?

  • @robgreene3956
    @robgreene3956 4 місяці тому

    For years I heard Apple users tell me "You should use Apple, because we are safe and never hacked". So yes, I would come down on Apple, just because of 15 years of their obnoxious comments.

  • @Embassy_of_Jupiter
    @Embassy_of_Jupiter 4 місяці тому +1

    Anyone who thinks there are no backdoors in their phone is living in fantasy land 😂
    The US and Chinese governments will never give up this trump card ever again

  • @surfingbilly9654
    @surfingbilly9654 3 місяці тому

    Hard to take you seriously when you use the words "misinformation" and "disinformation" unironically.

  • @princem5155
    @princem5155 5 місяців тому +6

    People just love to hate on Apple. It comes from jealousy

    • @fhesseti7976
      @fhesseti7976 5 місяців тому +28

      Jealousy of what? I hate Apple because they are locked down, restrictive, don't do anything competitors can't do, and they're anti consumer with their terrible stance on right to repair.

    • @KaranRajpal
      @KaranRajpal 5 місяців тому +17

      Yeah I'm extremely jealous of not being able to do what I want with my device that a bunch of elitists get butthurt over. Sure.

    • @BurgerKingHarkinian
      @BurgerKingHarkinian 5 місяців тому +8

      Jealousy... Truly the maturity of a 12 year old

    • @michaelcorcoran8768
      @michaelcorcoran8768 5 місяців тому +10

      Or their monopoly behavior, e-waste etc ....

    • @NeptuneSega
      @NeptuneSega 5 місяців тому +7

      Mature up, that’s an argument that a grade student would make. Keep drinking their snake oil