iMessage Bug Allows Attackers to Decrypt Photos and Videos
Researchers at John Hopkins University have found a bug in the instant messaging client iMessage which, if exploited, could allow an attacker to decrypt photos and videos sent as secured messages. "Even Apple, with all their skills -- and they have terrific cryptographers -- wasn't able to quite get this right," said Matthew D. Green, whose team of graduate students at the aforementioned university found the bug. "So it scares me that we're having this conversation about adding back doors to encryption when we can't even get basic encryption right." Apple acknowledged the bug to The Washington Post, adding that it had "partially" fixed the glitch with iOS 9 software update last year. The company assures that it will be offering a complete patch for the bug with iOS 9.3, which will be released on Monday.
Short on details.
Although the students could not see the key’s digits, they guessed at them by a repetitive process of changing a digit or a letter in the key and sending it back to the target phone. Each time they guessed a digit correctly, the phone accepted it. They probed the phone in this way thousands of times.
Was it -really- operating like the launch codes in Wargames? "The phone accepted it" is pretty ambiguous.
Except that Apple deprecated OpenSSL in favor of open source CDSA in their own OS 3 years before HeartBleed was found. Also, Apple using standards is something you are against?
Well, there's spam egg sausage and spam, that's not got much spam in it.
Close the blast doors! Close the blast doors!
are designed and built by humans - they have bugs in them...get over it.
nothing to see here - move along
Sure, if you can get a dead guy to unlock the phone and send a picture (previously stored on iCloud) through a WiFi AP that you control.
Easy Peasy.
(RTFA).
Faster! Faster! Faster would be better!
I like how they found a flaw in the code all vulnerable after a year but yet still pats them on the back.
Any other company would have been crucified and practically insulted.
Yes, the media always has bias.
Besides, no company has cryptographers. There's no point - they just pass it through the OS's built in or prewritten stuff. See OpenSSL or dmcrypt.
We're talking Apple, so they are kind of responsible for the OS, too (even if it's based on BSD).
And to everybody else who are still user older devices: fuck you!
Seriously, can't they update the older iOS versions? Or are the FBI/CIA/NSA preventing them from doing so?
One byte at a time and see if the other end "accepts" it sounds like a padding oracle attack. Those are in vogue now also.
The padding oracle works with cbc ciphers where there is a padding check before the actual decryption. You change on byte and see whether you get a padding error. If the byte is correct, you don't get the padding error. When you've found one byte, move on to the next byte.
Sounds like this researcher only wants to make headlines. Encrypting your OS and device won't ever protect you from an application that has a security flaw. Encryption protects a user at the physical level. We all know the saying that if you can get console access you're compromised. Not the case with encryption. Nor is it the case with the imessage app. I'd like to see them break into a phone when they can't unlock it.