https://arstechnica.com/security/2023/12/exploit-used-in-mass-iphone-infection-campaign-targeted-secret-hardware-feature/

Reply to this note

Please Login to reply.

Discussion

🎄🎁🫡

Wild. Crazy times.

“Due to the closed nature of the iOS ecosystem, the discovery process was both challenging and time-consuming, requiring a comprehensive understanding of both hardware and software architectures. What this discovery teaches us once again is that even advanced hardware-based protections can be rendered ineffective in the face of a sophisticated attacker, particularly when there are hardware features allowing to bypass these protections.”

It makes me wonder how many people were injured or killed as a result of this one?

that's an incredibly impressive attack. it's a good reminder that no pure technical measures will ever be enough- got to have the tradecraft.

Better skills than even Pegasus??

"Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or was included by mistake. Since this feature is not used by the firmware, we have no idea how attackers would know how to use it"

👀

Ok, anybody else's first thought 3-letter agencies?

👀

I promise I'm trying not to be impressed by the problem/puzzle solving that went into this, seeing as how it was malicious and depressing from a privacy standpoint, but... holy shit.