Tuesday, March 9, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Google to Apple: Want a more secure iPhone? Cut surplus iMessage code

August 9, 2019
in Internet Security
Google to Apple: Want a more secure iPhone? Cut surplus iMessage code
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Apple disables FaceTime after serious security flaw found
Apple iPhone users discovered a serious FaceTime bug that lets you hear audio from another iPhone or even view live video without the recipient’s knowledge.

Think your iPhone is hard to hack? By the size of rewards for remote iPhone hacks, it would appear to be. But Google’s crack squad of hackers at Project Zero recently showed that with skill and determination, iPhones can be hacked just by receiving an SMS message. 

You might also like

Intel joins DARPA in search of encryption ‘holy grail’

Microsoft Exchange zero-day attacks: 30,000 servers hit already, says report

Ezviz C3X outdoor security camera review: Simple setup, superb features Review

Thanks to Google Project Zero, who were behind a fistful of patches in Apple’s recent iOS update, iOS devices are more secure than they were a few months ago. 

But the team that found all those iOS bugs has now called on Apple to make iMessage less prone to remote attacks by reducing the ‘attack surface’ of its software, or in tech slang, cutting the ‘cruft’ from iMessage, so that attackers have fewer vulnerable parts to exploit. 

“The majority of vulnerabilities occurred in iMessage due to its broad and difficult to enumerate attack surface. Most of this attack surface is not part of normal use, and does not have any benefit to users,” Google Project Zero researcher Natalie Silvanovich wrote in a blogpost. 

Silvanovich presented her and her colleagues’ findings at BlackHat on Wednesday, detailing 10 iOS bugs they found, including five of the six that were patched in iOS 12.4. One of them, CVE-2019-8641, still remains under wraps because Apple’s fix “did not fully remediate the issue”.  

The fixes Apple released in response to Google Project Zero’s findings are notable because they are ‘interactionless’ or ‘zero click’, meaning the flaws don’t require a single click by the end user to exploit. 

There have been a few stories about zero-click exploits for iOS, but not much evidence they exist. For example, a 2017 report by Reuters exposed a group of ex-NSA hackers working in the Middle East who were reportedly using an iPhone hacking tool called Karma. 

The tool was said to partly rely on a zero-day flaw in Apple’s messaging app, iMessage. However, the users didn’t understand how the vulnerability worked. Karma reportedly allowed the hackers to open a line to an iPhone even if the user didn’t use iMessage.   

And when it comes to messaging apps, exploit broker Zerodium – which offers $2m for zero-click iPhone exploits – has also claimed that iMessage is the least secure from a zero-day exploit perspective compared with Signal, WhatsApp, and even Telegram. 

But again, there was no evidence, which was the motivation for Google Project Zero’s research into zero-click attacks on iOS. 

Several of the bugs affected Apple’s iMessage messaging system. In some cases, just receiving an SMS or MMS message iMessage would be enough to do the trick for an attacker, putting this set of bugs on a similar severity scale to Google’s Android Stagefright bugs in 2015. 

Stagefright bugs could lead to a complete compromise just by an Android device receiving an SMS or MMS message and it affected 95 percent of Android handsets. 

Project Zero researchers focused on SMS, MMS, and newer fancy features of iMessage like Digital Touch, which arrived in iOS 10  and let iPhone users send drawings and animations to one another to keep up with WhatsApp and Facebook Messenger. One of the flaws Silvanovich found was due to an issue in Digital Touch.   

As she notes, SMS in iOS was a “good starting point” for their research because of Apple’s design choices.

“Unlike Android, SMS messages are processed in native code by the iPhone, which increases the likelihood of memory corruption vulnerabilities,” she explained.  

Silvanovich suggests that Apple could help improve iPhone security by cutting out unnecessary avenues for remote attackers to use. 

“Overall, the number and severity of the remote vulnerabilities we found was substantial. Reducing the remote attack surface of the iPhone would likely improve its security,” she wrote. 

Apple’s head of security engineering and architecture, Ivan Krstić, is scheduled to deliver a presentation today at Black Hat about iOS and Mac security.  


Credit: Zdnet

Previous Post

Using Python and R to Load Relational Database Tables, Part II

Next Post

2019 Back-to-School Spending Trends | Infographic

Related Posts

Intel joins DARPA in search of encryption ‘holy grail’
Internet Security

Intel joins DARPA in search of encryption ‘holy grail’

March 9, 2021
Microsoft Exchange zero-day attacks: 30,000 servers hit already, says report
Internet Security

Microsoft Exchange zero-day attacks: 30,000 servers hit already, says report

March 9, 2021
Ezviz C3X outdoor security camera review: Simple setup, superb features Review
Internet Security

Ezviz C3X outdoor security camera review: Simple setup, superb features Review

March 9, 2021
Supernova malware clues link Chinese threat group Spiral to SolarWinds server hacks
Internet Security

Supernova malware clues link Chinese threat group Spiral to SolarWinds server hacks

March 9, 2021
McAfee sells its enterprise business to private equity group as it focuses on consumer security
Internet Security

McAfee sells its enterprise business to private equity group as it focuses on consumer security

March 9, 2021
Next Post
2019 Back-to-School Spending Trends | Infographic

2019 Back-to-School Spending Trends | Infographic

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Intel joins DARPA in search of encryption ‘holy grail’
Internet Security

Intel joins DARPA in search of encryption ‘holy grail’

March 9, 2021
Microsoft Exchange Hackers Also Breached European Banking Authority
Internet Privacy

Microsoft Exchange Hackers Also Breached European Banking Authority

March 9, 2021
How Automation can be used for faster recovery, revival, and improved resilience in the wake of COVID-19
Data Science

How Automation can be used for faster recovery, revival, and improved resilience in the wake of COVID-19

March 9, 2021
Introduction to Machine Learning Model Evaluation
Machine Learning

Introduction to Machine Learning Model Evaluation

March 9, 2021
Microsoft Exchange zero-day attacks: 30,000 servers hit already, says report
Internet Security

Microsoft Exchange zero-day attacks: 30,000 servers hit already, says report

March 9, 2021
Is investing in AI the highest ROI opportunity?
Data Science

Is investing in AI the highest ROI opportunity?

March 9, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Intel joins DARPA in search of encryption ‘holy grail’ March 9, 2021
  • Microsoft Exchange Hackers Also Breached European Banking Authority March 9, 2021
  • How Automation can be used for faster recovery, revival, and improved resilience in the wake of COVID-19 March 9, 2021
  • Introduction to Machine Learning Model Evaluation March 9, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates