Apple's latest security feature could literally save lives
- Reference: 1657135870
- News link: https://www.theregister.co.uk/2022/07/06/apple_lockdown_mode/
- Source link:
The functionality, coming with iOS/iPadOS 16 and macOS Ventura, dramatically shrinks an iDevice's attack surface by disabling many of its features. It's designed to protect the small number of Apple users who, "because of who they are or what they do, may be personally targeted by some of the most sophisticated digital threats, such as those from NSO Group and other private companies developing state-sponsored mercenary spyware," Apple [1]said in a statement.
Lockdown, thus, effectively reduces the number of potential vulnerabilities spyware could exploit to compromise a device, cutting the possible routes into surveillance targets' kit.
[2]
It's no coincidence that Apple called out Israeli spyware maker NSO by name. The US mega-corp [3]sued the outfit in October 2021 for infecting iPhones with its Pegasus malware that snoops on practically every element of the device and the data it contains. Pegasus is used by [4]multiple nation-states to spy on dissidents, journalists, and other perceived troublemakers.
[5]
[6]
Apple hopes that Lockdown Mode will be a way for those at risk of being targeted by [7]Pegasus and similar malware to protect themselves, which it will do by:
Blocking all attachment types (other than images) and disabling link previews in Messages
Disabling some web technologies, such as just-in-time JavaScript compilation, unless a site is added to a Lockdown Mode allow-list
Blocking incoming FaceTime calls, invitations and service requests from unknown parties, unless the device owner has previously contacted them
Not allowing wired connections to computers or peripherals when the device is locked
Blocking the installation of configuration profiles and mobile device management enrollment
Apple says it will be adding additional protections to Lockdown Mode over time. The feature should release this fall with major OS updates, and it's unclear whether Lockdown Mode is available in current beta builds of Apple's OSes. We have reached out to learn more and will update this story when we hear back.
Pegasus: A potentially fatal cyberattack
The threat of spyware from companies like NSO is no light matter. It is how, for instance, the Saudi Arabian government was able to allegedly track down and assassinate Washington Post columnist [8]Jamal Khashoggi .
Ivan Krstić, head of security engineering and architecture at Apple, said the company knows the types of attacks faced by Khashoggi and [9]other [10]public [11]figures are very rare, but it doesn't mean they shouldn't be fought.
Apple is "continuing to design defenses specifically for these users, as well as supporting researchers and organizations around the world doing critically important work in exposing mercenary companies that create these digital attacks," Krstić explains.
[12]
Along with the announcement of Lockdown Mode comes a tempting target for bug hunters: up to $2 million for qualifying findings in Lockdown Mode.
Apple also provided an update on its $10 million donation to the Dignity and Justice Fund at the Ford Foundation, [13]first mentioned when it filed its lawsuit against NSO. The company says the DJF plans to issue the first grants in late 2022 and early 2023 with funding focused on approaches to exposing mercenary spyware and better protecting targets. Krstić serves as a technical advisor to the fund. ®
Get our [14]Tech Resources
[1] https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsYF-evygZXwrX32oo5OxQAAAFE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/11/23/apple_nso_group/
[4] https://www.theregister.com/2022/06/24/nso_customers_eu_pegasus/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsYF-evygZXwrX32oo5OxQAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsYF-evygZXwrX32oo5OxQAAAFE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/07/16/microsoft_candiru_malware/
[8] https://www.theregister.com/2021/03/01/in_brief_security/
[9] https://www.theregister.com/2022/04/11/nso_spyware_eu/
[10] https://www.theregister.com/2022/04/18/uk_catalan_spyware/
[11] https://www.theregister.com/2022/05/02/spain_pegasus_malware/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsYF-evygZXwrX32oo5OxQAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/
[14] https://whitepapers.theregister.com/
Re: Nokia 3310
The article listed the restrictions. That list didn't include turning off all applications. They would still end up being very different products.
Images...
Would be interesting to know if the number of allowed image types is limited to jpg, png and gif. I seem to remember that one of the more ingenious iPhone hacks was based on exploiting a decades old fax file format.
Re: Images...
It was a GIF that contained some decades old fax format (which was then used to implement a primitive CPU) so checking file types wouldn't have prevented that NSO group hack.
Better for this type of user to completely disable that route for everything including all image types. Just because there is no zero day exploit against JPEG today, doesn't mean it is 100% impossible there won't be one tomorrow.
"coming this fall"
fall!?!??!!??!
Don't panic, the seasons don't need to be capitalized.
WebKit, anyone?
Not sure how this is going to work when the EU forces Apple to accept any old browser engine that the user cares to install from some random place on the internet.
Re: WebKit, anyone?
Yeah that would be a problem, since that mode couldn't disable Chrome from using its own Javascript engine if such a user uses Chrome and loses such protection.
And given that there was a severe 0 day against WebRTC in Chrome patched just yesterday...
Re: WebKit, anyone?
It sounds as if you're suggesting that the people who care enough about their security and privacy to enable this lockdown mode are also likely to install 'any old browser engine that the user cares to install from some random place on the internet'.
I don't think that this is going to be the problem that you seem to think it is.
It would be nice
If there was a way to select some of these options without taking them all, for those of us who aren't going to be targeted and don't need full "lockdown mode" but might want to disable some things "just in case" if we don't need them. Hopefully that comes in a future update.
And the TLAs?
If it works, they won’t like it I would think.
There’s a $10m bounty…
…and yet a certain subset of commentards will happily believe their half-arsed brain farts will pierce Apple’s Lockdown Mode.
Lockdown Mode being a feature (lest we forget) designed specifically for Apple’s very own operating system; running on, well, what can only be described as proprietary Apple hardware; and rustled up by actual Apple-pays-their-salary engineers
Stroll on
Nokia 3310
So they're turning an iPhone into a Nokia 3310. Maybe just buy a Nokia and save a grand or more?