News: 1652940131

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Your snoozing iOS 15 iPhone may actually be sleeping with one antenna open

(2022/05/19)


Some research into the potentially exploitable low-power state of iPhones has sparked headlines this week.

While pretty much no one is going to utilize the study's findings to attack Apple users in any meaningful way, and only the most high-profile targets may find themselves troubled by all this, it at least provides some insight into what exactly your iOS handheld is up to when it's seemingly off or asleep. Or none of this is news to you. We'll see.

According to the research, an Apple iPhone that goes asleep into low-power mode or is turned off isn't necessarily protected against surveillance. That's because some parts of it are still operating at low power.

[1]

Under iOS 15, some chips inside an iPhone in either of those two power states remain active so that the owner can always wirelessly locate their lost cellphones via the Find My iPhone functionality, open their nearby locked cars, or make payments. Low-power Bluetooth, near-field communications (NFC) and ultra-wideband (UWB) connectivity are kept alive in the phone to make this possible.

[2]

[3]

There is firmware in the device that runs when the phone is in low-power mode (LPM) to handle this wireless functionality; it is this firmware, tied to a Bluetooth controller chip, that can be altered to contain malware that essentially runs all the time, whether the iPhone is awake or asleep or off, presumably until the battery is completely dead. This malware could be designed to track and report the user's movements, snoop on them, and so on.

These [4]findings were put together by a team at the Secure Mobile Networking Lab (SeeMoo) of the Technical University of Darmstadt, Germany.

[5]

"The current LPM implementation on Apple iPhones is opaque and adds new threats," they wrote in their 11-page paper, adding that because this is by design happening at the hardware level, "it has a long-lasting effect on the overall iOS security model. Design of LPM features seems to be mostly driven by functionality, without considering threats outside of the intended applications."

Don't panic

There are some significant caveats to this. The biggest one is that in order to infect the LPM firmware, so that malicious code can continue running even when the phone is seemingly asleep or off, the device needs to be completely compromised. Whoever has this necessary level of control over your phone can already snoop on your messages, steal your data, change your apps, and so on. Modifying the firmware is the cherry on the cake for whoever has infiltrated your device; it's an unnecessary step against the vast majority of victims, and only necessary for some truly high-level targets.

That said, it appears that once you have this privileged access, there are no protections in the device to stop you changing the LPM firmware.

"On modern iPhones, wireless chips can no longer be trusted to be turned off after shutdown," the SeeMoo academics wrote. "This poses a new threat model."

It takes a switch

The researchers said they responsibly disclosed these findings to Apple engineers before the paper was publicly distributed. However, the team said they received no feedback from Apple. The academics recommend Apple add a hardware-based switch to disconnect the battery to improve security and protect valuable surveillance targets such as scientists, activists, politicians, and journalists.

Some countries secretly installed NSO Group's [6]controversial Pegasus spyware on smartphones to covertly and remotely track people, including reporters, campaigners, and other citizens. It's perhaps this level of snoopware that would take advantage of the lack of protections around LPM firmware.

Jaye Tillison, director of security strategy at Axis Security, told The Register SeeMoo's research is important though the threat right now is muted: it's non-trivial to fully exploit.

[7]

That said, "if threat actors begin targeting iOS devices with new malware this could have a huge impact on businesses, and their attack surface – which has now expanded to every user device and across all working locations – both in and out of the office," Tillison said.

"We typically see a significant percentage of end-users connecting through an iOS device. If you think about the 300 million users just within the Fortune 2000 accounts alone, with 2.5 end user devices per user, that number can be huge."

[8]Apple emits macOS, iOS, iPadOS patches for 'exploited' security bugs

[9]Apple preps fix for Safari's web-history-leaking IndexedDB privacy bug

[10]Don't make an iOS of yourself – Apple's patched its OSes, you know the drill

[11]Think your phone is snooping on you? Hold my beer, says basic physics

It's also a warning as businesses continue to use more of these technologies: "Security must become embedded into the fabric of IoT [Internet of Things]," he said. "For far too long, we've coasted and coasted along. We've ignored security due to cost. This is not a good road to keep traveling down."

Enterprises need to adopt technologies that don't allow infected devices to connect to the corporate network, and equipment that inspects traffic – even private traffic – to keep sensitive data from flowing down to compromised devices, and to realize that employees need to be educated to protect themselves, he said. ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YoYVSkqaGfpODq7uScSIPAAAAAM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoYVSkqaGfpODq7uScSIPAAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YoYVSkqaGfpODq7uScSIPAAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://arxiv.org/abs/2205.06114

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoYVSkqaGfpODq7uScSIPAAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/04/18/uk_catalan_spyware/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YoYVSkqaGfpODq7uScSIPAAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/03/31/apple_emergency_patches/

[9] https://www.theregister.com/2022/01/21/apple_safari_webkit_indexeddb/

[10] https://www.theregister.com/2021/12/14/apple_os_updates/

[11] https://www.theregister.com/2021/10/18/information_wants_to_be_free/

[12] https://whitepapers.theregister.com/



"wireless chips can no longer be trusted to be turned off after shutdown"

Pascal Monett

So it is true, the mafia types are right to put smartphones in lead boxes when they meet.

Re: "wireless chips can no longer be trusted to be turned off after shutdown"

Dave 126

Doubtful - if they only out their phones in Faraday cages *when* they meet, the location upon which they converged can still be known. They would be better to just leave their phones at home.

This is separate, if related, to the security concerns Mafia types might have about live audio transmission (Faraday cage would help) or audio recording (Faraday cage wouldn't help).

Of course Mafia types might choose to put phones in boxes purely for reasons of etiquette. You don't want to be the twerp whose phone rings in the middle of the Boss's speech, any more than you would want it to ring when you're in the audience of a theatre.

Re: "wireless chips can no longer be trusted to be turned off after shutdown"

sreynolds

Yeah but their choice of foot apparel really weighed you down and the first was quite tight as the material was poured around your feed.

2 Minds

anonanonanonanonanon

Having had my phone pickpocketed, twice, one recovered, one lost, I like the idea of being able to run find my to track it down.

One phone was pinched at a concert, some croat had gone round the packed crowd, grabbing everything they could. I realised quickly enough, alerted security, and thanks to find my, we could tell the scumbag was still in the area. He was caught before he could escape, had a car with a boot full of phones.

Second time, just a couple of guys pulled a distraction on me, bumped into me and lifted the phone. I chased after them but it was too late and too dark. They were smart enough to turn the phone off immediately, but I locked it remotely, several months later, it briefly pinged somewhere in africa, hopefully they never managed to break into it. If find my worked in low power mode, I could have recovered

It appears to be difficult

sabroni

but these days it's a pain/impossible to pull the battery out of these devices so a functioning OFF button should be provided. You know, for when I, as the device owner and user, want to switch it off?

A simple "No features of this device work when OFF " message would explain the issue and allow the user to make a choice.

Re: It appears to be difficult

sreynolds

Or just don't waste your money buying them

Twas always so...

Anonymous Coward

...people forget that these are phones, so sometimes people call them and they need to ring.

To do that, they need to be in contact with a nearby phone mast.

With the phone 'switched off'?

Mike 137

" ... so that the owner can always wirelessly locate their lost cellphones via the Find My iPhone functionality, open their nearby locked cars, or make payments "

The first option might make some sense (provided the range is sufficient), but the other two seem little more than 'labour saving' options (saving the labour of switching the phone on?). And supposing the phone is lost/in the wrong hands, are they really advisable? Unless I've misunderstood (never owned an iAnything) the phone should (and probably does) require an authenticator for switching on, but if you can unlock the car from a switched off phone that would seem to be hazardous.

Dave I can produce equivalently valid microbenchmarks showing Linux works
much better with the scheduler disabled. They are worth about as much as
your benchmarks for that optimisation and they likewise ignore a slightly
important object known as "the big picture"

- Alan Cox on linux-kernel