back to article Update your iPhones, iPads right now – govt spy tools exploit vulns

Apple has pushed out an emergency security update for iPhones, iPads and iPods after super sophisticated spyware was found exploiting three iOS vulnerabilities. The iOS 9.3.5 upgrade plugs three holes that, according to researchers, are being used right now by the Pegasus surveillance kit – a powerful commercial malware …

Page:

  1. Randy Hudson

    It's time for Apple to allow users to install 3rd party browsers that run as regular sandboxed apps, so that browsing the web doesn't end up installing a root kit

    1. Anonymous Coward
      Gimp

      That'll be the day!

      You'll be suggesting they should allow their flock to dump iTunes next, you crazed heretic.

      Requisite icon seems extra appropriate today ---->

      1. ThomH

        When's the last time anybody was compelled to use iTunes? iOS 4, maybe?

        Switching to a non-WebKit browser, were Apple to stop being so controlling, would also appear to answer only one out of three vulnerabilities?

    2. Anonymous Coward
      Anonymous Coward

      3rd party browsers

      have been available on iPads & iPhones for quite a while now.

      iCab, Opera, Firefox, Chrome immediately spring to mind (plus a few obscure ones).

      1. Jordan Davenport

        Re: 3rd party browsers

        "iCab, Opera, Firefox, Chrome immediately spring to mind (plus a few obscure ones)."

        Of those, only Opera can kinda sorta claim to be a different browser since it does most of its rendering on remote servers. All the rest you just named are just re-skins of Safari with different features and lacking the faster of the JavaScript engines.

        1. Ed 11

          Re: 3rd party browsers

          I think all browsers have access to the faster JavaScript engines now, and I feel like they have done for a while.

      2. Planty Bronze badge
        Stop

        Re: 3rd party browsers

        I think you have been fooled by Apple's pathetic spin. All those browsers you mention are forced to use Apple's webkit (and slow JS engine), so you are still using Safari, but with a Chrome skin.

        Essentially this is the downfall, the sample exploit will work on ANY iOS browser, as you aren't actually using any other browser...

  2. NoneSuch Silver badge
    Coffee/keyboard

    Reporters who must be plotting some sort of terror plot, obviously. Maybe they were planning on telling the truth about various governments. The horror. The horror.

    1. ThomH

      No, no, no. The anti-terror legislation is for monitoring alleged benefits cheats, isn't it?

    2. phuzz Silver badge
      Alert

      If it's not terrorists then it must be pedos. Won't someone please think of the children! etc.

      1. Anonymous Coward
        Facepalm

        WTF? Are they cracking down on pedometers now?

        Where will it end?

        1. Version 1.0 Silver badge

          Makes a change from pediatricians

  3. Anonymous Coward
    Anonymous Coward

    A speedy patch release

    for Apple. Usually, they seem to take an age to issue patches.

    1. Anonymous Coward
      Anonymous Coward

      Re: A speedy patch release

      The last few years they have been VERY quick to release security patches, especially for something like this.

      1. TheVogon

        Re: A speedy patch release

        "The last few years they have been VERY quick to release security patches, especially for something like this."

        Presumably because jailbroken iphone = potentially lost AppStore sales.....

    2. Lord Elpuss Silver badge

      Re: A speedy patch release

      Apple are generally the Usain Bolt of the patch world. Pretty damn speedy. (And screwing everything they can when they think they can get away with it)

  4. Anonymous Coward
    Anonymous Coward

    We'll never be "safe, safe", so lets keep our freedoms instead.

    People need to wake up and realise that no security in the world will make things "safe" from someone determined to cause physical harm (you need to look (and be interested) in the causes why these people want to cause you physical harm in the first place)

    But it will definitely will instead, eventually control you and your life, to a point you're locked down in a dead end job, paying most of your disposable income away in (statistically head clipping) fines for parking/speeding etc because CCTV/ANPR Cameras supposedly in place to make you 'safe', are actually turned against you, to control you and more importantly, control the people/activists that speak against the grain, against such technology.

    Technology supposedly used for "security" is today, eroding democracy, locking down people in the UK, rather than acting as an enabler for people to reach their true potential. Its been used for profiling, stereotyping and keeping people in their place.

    We've passed the tipping point, its about time the UK population started been far more sceptical to Theresa May's motives regarding of all this extra "security to keep you safe" mantra. You'll wake up in virtual chains, and wondered why you didn't speak up earlier.

    1. if(i == alive) { live_free = true; government = NULL; }

      Re: We'll never be "safe, safe", so lets keep our freedoms instead.

      Absolutely spot on, although you can anonamise yourself to some degree by not registering your car, having a trader's policy and not putting it on the MID etc. Living in that grey area at the edge of the law really winds them up and is the best that people can do as individuals. Hopefully one day there will be enough individuals to form a big enough group and to fight back for our freedoms and our democracy (there are signs of fledgling ones now, but nothing near big enough).

      I always said that leaving the EU is just the beginning and the walk to freedom is a very long one, but at least we now appear to be on the right path and every day will take us a step closer (whether we use peaceful or violent methods to get there will entirely depend on whether the politicians listen; so we will just have to wait and see).

      If the worst comes to the worst then on the plus side we know that the government has a propensity to rely on youth as their cannon fodder, so we can be thankful that the vast majority are snowflakes.

      1. ZSn

        Re: We'll never be "safe, safe", so lets keep our freedoms instead.

        Leaving the EU is is just the beginning? So instead you want Theresa May unencumbered by anything like social justice? I must point out that in Germany and Austria they even fine you if you take pictures of people from the dashboard of your car.

        1. Anonymous Coward
          Anonymous Coward

          Re: We'll never be "safe, safe", so lets keep our freedoms instead.

          So presumably I shouldn't have sneaked a pic of a Pokemon chatting breezily to local military brass at national Army Day ? Not DE though ;) No way is that going on the Net, don't want to end up in the Brig.

      2. tiggity Silver badge

        Re: We'll never be "safe, safe", so lets keep our freedoms instead.

        Leaving the EU likely a road to *less* freedom, previously there was a chance of EU acting as some form of brake on the worst UK excesses of invading its citizens privacy.

        Now May et al will not have to pay lip service to any pro privacy strictures (ditto workers rights, environment, anything resembling sensible long term strategy etc.).

        I'm no fan of the EU (just like I'm no fan of the house of lords) but they at least meant some dubious govt legislation did not sail through quiet as easily / had to be amended

        Disclosure: voted remain solely in hope of retaining a bit of sanity control on UK gov!

  5. Jerry G.

    Phone Security

    If you want to have privacy and security with a phone Blackberry is the way to go. With Blackberry we don't hear about these problems as like we are hearing about with the others. This is why governments, medical field where privacy is a concern, leaders of countries, and high position people in corporations only use Blackberry.

    I myself and my family have been using Blackberry. I have no issues with this phone, and I feel very secure with it.

    1. Nick Collingridge

      Re: Phone Security

      Probably because no-one else buys Blackberrys, so no-one bothers to try and develop malware for it and no-one is looking for vulnerabilities. It is highly unlikely that Blackberry have some sort of secret technique that enables them to develop totally clean and attack-vector free code. You are probably safe, but not because of the technology - more safety through the fact no-one is interested.

      Regarding this iOS security update - there will not be a vast rush of malware targeting it because not only have Apple quickly released an update to fix the vulns, but also because as is usual a very high percentage of iOS devices will quickly be updated. So no vast number of vulnerable devices out there for malware developers to target.

      If this were Android, however, that would not be true, and it won't be until Google re-architect enough to be able to roll out generic updates to fix vulnerabilities. As a result the malware developers can jump on new zero day vulnerabilities in the knowledge that there will be a vast number of devices to attack.

      1. Daniel B.

        Re: Phone Security

        Blackberries are used by top level government officials. The surface area may be small, but there is definitely an interest in hacking these devices.

        The NSA was unable to hack Angela Merkel's Blackberry. That should show how well they fare.

        1. TheVogon

          Re: Phone Security

          "The NSA was unable to hack Angela Merkel's Blackberry"

          Uhm no. They WERE able to monitor it. For years:

          https://www.theguardian.com/media/2015/jul/02/wikileaks-us-spied-on-angela-merkels-ministers-too-says-german-newspaper

          1. Daniel B.

            Re: Phone Security

            Ah, the MS shill chimes in.

            No, they weren't able to hack her Blackberry. They did hack her other handset, a Nokia 6260 Slide. The Blackberry Z10 wasn't.

            http://www.theatlantic.com/international/archive/2013/10/all-the-chancellor-s-phones/280913/

    2. Anonymous Coward
      Anonymous Coward

      Re: Phone Security

      Or of course a Google Nexus. Just as secure as a blackberry. Android 7 patch level august 5th on all my devices, and file level encryption

    3. if(i == alive) { live_free = true; government = NULL; }

      Re: Phone Security

      I have a feeling that is the reason why Blackberry have pretended to abandon BB10. I think that BB10 will become a propriety OS sold only to high security organisations. I know that the uk police are looking for a replacement for BT Airwave (tetra) radios and have been considering 4g options. A hardened version of BB10 with BES would fit the criteria. Chen isn't as stupid as he sounds.

      1. Emperor Zarg

        Re: Phone Security

        I always assumed that the BES or BIS server had a direct connection to Fort Meade. Canada is one of the Five Eyes, so a high degree of cooperation should be expected.

        1. JetSetJim
          Black Helicopters

          Re: Phone Security

          Blackberry has always allowed Legal Intercept into its consumer service - they weren't allowed to sell in India until they caved to the govmt

        2. bitmap animal

          Re: Phone Security

          AFAIK if you set your own key in BES then it's secure. Using the default key may not be, I don't know the details though.

    4. Anonymous Coward
      Anonymous Coward

      Re: Phone Security

      I know I am considering a BB for my son. Its more secure and it's so butt ugly I won't ever have to worry about him being that guy on an episode of 16 and pregnant. A remarkably effective form of birth control.

      1. Anonymous Coward
        Anonymous Coward

        Re: Phone Security

        I hate to break it to you, but even with an iPhone he won't be able to get pregnant.

        :)

    5. TheVogon

      Re: Phone Security

      " you want to have privacy and security with a phone Blackberry is the way to go. "

      It really isn't. There have been well over 80 known security vulnerabilities so far in Blackberry OS 10 - versus ~ zero in Windows Phone 10. For instance the US government apparently had no issues in spying on the Germans when they were using Blackberry...

      And now Blackberry are moving to a "secure" version of Android - that's going to be like trying to keep water in a colander with a sieve....

      1. Anonymous Coward
        Pirate

        Re: Phone Security

        Um, there'll be no publicly known vulnerabilities in M$A's moribund WinPho platform, if that's actually the case, simply because no one has bothered to analyse one.

        Why would anyone waste their time? Are you seriously suggesting the obvious fact that nobody's bothered to look for them is somehow proof that it isn't crammed full of exploitable errors and NSA backdoors RICHTO? How wonderfully quaint. Hope you get a big bonus this week.

        "Security by obscurity" is no security at all.

        1. Anonymous Coward
          Anonymous Coward

          Re: Phone Security

          >> simply because no one has one to analyse one.

          Lots of companies are using them so they would interest hackers. For instance the FTSE 100 I currently work for recently replaced over 5000 BlackBerrys with Windows Phone (640)

          If you search it, there has been some public analysis by recognised hackers / security experts that has concluded that WinPho is one of the most secure mobile platform options...

        2. TheVogon

          Re: Phone Security

          "Um, there'll be no publicly known vulnerabilities in M$A's moribund WinPho platform, if that's actually the case, simply because no one has bothered to analyse one."

          They have sold over 100 million of them I seem to recall. If they were trivial to exploit we would likely have seen evidence by now.

          "somehow proof that it isn't crammed full of exploitable errors and NSA backdoors "

          Nope, but less of a worry than other mobile platforms that WE KNOW have lots of security issues!

          1. Anonymous Coward
            Joke

            Re: Phone Security

            100000000/2000000000 = 5%

            All time total winpho "sales" = ~5% of current smartphone ownership!??!?!!!

            Hahahahahahaha ahhha hah aahah ah ah hahha ah aha ah a aahhhhhh ---->

            I bet that "sales" figure of yours includes all the ones M$ wrote-off and dumped into landfill themselves too ("sales" to self) hahahahaha ahhha hah aahah ah ah hahha ah aha ahhhhahahahaha ahhha hah aahah ah ah hahha ah aha ah a aahhhhhhhahahahaha ahhha hah aahah ah ah hahha ah aha ah hahahahaha ahhha hah aahah ah ah hahha ah aha ah hhhahahahaha ahhha hah aahah ah ah hahha ah ahahaha ahhha hah aahah ah ah hahha ah aha ah a aahhhhhh

          2. Anonymous Coward
            Anonymous Coward

            Re: Phone Security

            I wonder what MS's Windows Phone sales were for the most recent financial quarter and 12 months...

          3. Anonymous Coward
            Anonymous Coward

            Re: Phone Security

            Why is this iThing thread suddenly about pushing MS Windows?

      2. Anonymous Coward
        Anonymous Coward

        Re: Phone Security

        Yeah, probably Symbian is pretty secure right now too :)

    6. JCitizen
      Devil

      Re: Phone Security

      That's funny? Then why did Obama have to fight his staff, and government security enforcers, tooth and nail to keep his Blackberry? I would have thought it would be the other way around? I don't know what brand they were pushing, but I suppose they wanted conformity to help in security SOP. The other side of the coin would be kind of like having a Hillary private server in the office?

  6. AlexS
    Coffee/keyboard

    The milk tray man in photo

    Do all hackers wear burkinis?

    1. Anonymous Coward
      Anonymous Coward

      Re: The milk tray man in photo

      Only in San Jose.

  7. asdf

    time to eat crow or shit I guess

    Just going on the record non anon after flinging so much poop about stage fright to say this is almost as bad. Still requires visiting a booby trapped web site as opposed to just receiving a unsolicited text and granted the vast majority of iThings will be patched much quicker (hell probably half of Android devices in wild still vulnerable to stage fright) but it is still far from acceptable. Guess security by obscurity and lack of apps (best way to prevent malware is have a garbage app store nobody visits) is the way to go via WP or BB 10 if want high security.

  8. Anonymous Coward
    Windows

    Safe and secure...

    Using my Microsoft Lumia 950

    1. Patrician

      Re: Safe and secure...

      "Using my Microsoft Lumia 950"

      HEHEHEHE! Oh, you weren't trying to be funny?

    2. Planty Bronze badge

      Re: Safe and secure...

      LOL. Security by obscurity.

    3. TheVogon

      Re: Safe and secure...

      "Using my Microsoft Lumia 950"

      Me too - 950 XL. Couple of orders of magnitude fewer security holes across all versions of Microsoft's mobile OS compared to Blackberry, Android or IOS...

      1. Neil Alexander

        Re: Safe and secure...

        That's a dangerous assumption to make, given that security holes in Windows Phone are much less likely to be as widely published given the comparatively minor market share. That doesn't mean that they aren't there and that the bad guys don't know about them.

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like