Slashdot Mirror


Apple iPhone X, Samsung Galaxy S9 and Xiaomi Mi 6 Smartphones Hacked At Pwn2Own Tokyo (securityweek.com)

wiredmikey writes: Apple iPhone X, Samsung Galaxy S9 and Xiaomi Mi 6 smartphones were all hacked on the first day of the Pwn2Own Tokyo 2018 contest taking place this week alongside the PacSec security conference in Tokyo, Japan. Pwn2Own Tokyo 2018 participants earned a total of $225,000 on the first day of the event. On the second day, at least two teams will make additional attempts to hack the iPhone X and the Xiaomi Mi 6.

37 comments

  1. Why? by Opportunist · · Score: 1

    Don't they know what a working iPhoneX hack fetches these days?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re: Why? by Anonymous Coward · · Score: 0

      *felches

    2. Re: Why? by Anonymous Coward · · Score: 0

      Tim?

    3. Re: Why? by Anonymous Coward · · Score: 0

      True, but do you know how fucking stupid those people who pay for them are?

      They're no better off than any other OS.

  2. iPhone X? by 110010001000 · · Score: 3, Funny

    Who still owns an iPhone X? Old tech. I threw mine away as soon as the Xs came out.

    1. Re:iPhone X? by olsmeister · · Score: 1

      Can you maybe buy a few more? We're below $200 a share now. They make amazing stocking stuffers.

    2. Re:iPhone X? by Anonymous Coward · · Score: 0

      Mine works just fine. No reason to upgrade really.

    3. Re: iPhone X? by Anonymous Coward · · Score: 0

      Im still using my 5s. Not upgrading anytime soon.

    4. Re:iPhone X? by 110010001000 · · Score: 1

      Sure...I'll throw some in for the kids.

    5. Re:iPhone X? by Anonymous Coward · · Score: 0

      Just wait until the next ios release.

    6. Re: iPhone X? by Anonymous Coward · · Score: 0

      Iâ(TM)ll second that. Iphone 5s still going strong. So is my mid-2010 MacBook Pro, used as a music production workstation in studio and onstage.

  3. Apple is super secure, by ReneR · · Score: -1, Troll

    the fans said, ..! ;-)

    1. Re:Apple is super secure, by Anonymous Coward · · Score: 1, Insightful

      Still more secure than Big Brother Google looking over your shoulder and then selling everything you do, type, say, browse, download, and go to anyone willing to buy it.

    2. Re:Apple is super secure, by Anonymous Coward · · Score: 0

      Google should abandon their current business model and abandon leveraging the data they collect and just start charging 1 cent a search and 1 cent for ever URL you visit via a link in their search results. The amount of revenue collected would make all their other revenue streams look like rounding errors. Of course people will complain and bitch and finally plead with Google to revert back to relying on revenue generated using the data they collect on everyone using one of their services.

    3. Re:Apple is super secure, by Anonymous Coward · · Score: 0

      Exactly this!!
      Its annoying enough that apple tells these lies ( Thats understandable; they are a marketing company after all. Lies are apples stock and trade.) But to hear the zealot sheep regurgitate that bullshit is simply nauseating.

    4. Re:Apple is super secure, by TheFakeTimCook · · Score: 2

      Exactly this!!
      Its annoying enough that apple tells these lies ( Thats understandable; they are a marketing company after all. Lies are apples stock and trade.) But to hear the zealot sheep regurgitate that bullshit is simply nauseating.

      Says the ANONYMOUS COWARD, who is too pusillanimous to even LOG IN and risk their KARMA like a MAN!

    5. Re:Apple is super secure, by Anonymous Coward · · Score: 0

      Citation required

    6. Re:Apple is super secure, by Anonymous Coward · · Score: 0

      Apple devices transmit encrypted data with an encryption key that you cannot access to decrypt the messages "your" device is sending to Apple and that is enough for all but the most brown-nosed, unthinking Apple shill to know that they are not to be trusted. Do you question why they don't give you that encryption key? No of course you don't because you're just an Apple sheep incapable of rational thought, Apple tells you what to think and say and then you parrot your corporate apologist bullshit here.

    7. Re:Apple is super secure, by Anonymous Coward · · Score: 0

      He is sickening isn't he. A hateful little person only too eager to hurt people for the sake of a soulless company. Its sad people like him exist.

    8. Re:Apple is super secure, by TheFakeTimCook · · Score: 1

      Apple devices transmit encrypted data with an encryption key that you cannot access to decrypt the messages "your" device is sending to Apple and that is enough for all but the most brown-nosed, unthinking Apple shill to know that they are not to be trusted. Do you question why they don't give you that encryption key? No of course you don't because you're just an Apple sheep incapable of rational thought, Apple tells you what to think and say and then you parrot your corporate apologist bullshit here.

      As usual, where is the PROOF?

      Seriously.

    9. Re:Apple is super secure, by Anonymous Coward · · Score: 0

      apps looking over your shoulder and then selling everything you do, type, say, browse, download, and go to anyone willing to buy it.

      ftfy

      But sure, keep believing in privacy checkboxes on your facetweets, believe in the delete button. I'm sure amazon backs off when they see you doing searches with a super-private-club apple phone.

      Both of you. I see you down there with the +1 balls in your mouth.

  4. APK Hosts File Engine now w/ port filtering... apk by Anonymous Coward · · Score: -1

    See subject: APK Hosts File Engine 3.0++ 64-bit for Linux/BSD h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER + NATIVELY 4 less!

    Vs. "Bolt on 'MoAr' illogic-logic" slowing u hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily detected & blocked addons + firewall filtering drivers) & their complexity leads to exploit!

    * ONLY 1 of its kind in GUI 4 Linux/BSD & supports port filters!

    APK

    P.S.=> Protects vs. all speculative execution exploits + scripts/trackers (faster vs. NoScript @ kernelmode level)/ads/DNS request tracking + redirect poisoned or downed DNS/botnets/malware/malcript/email malicious payloads... apk

  5. why is faggoty shit on /. by Anonymous Coward · · Score: -1

    what is this faggoty ass shit?

  6. SIMPLE TEST u FAIL & FACT U IMPERSONATE ME by Anonymous Coward · · Score: -1

    0.0.0.0 test1.com:53
    0.0.0.0 test2.com:53
    0.0.0.0 jowie.com
    0.0.0.0 jealous.com
    0.0.0.0 jowie.com
    0.0.0.0 test3.com
    0.0.0.0 borlnd.com
    0.0.0.0 tester.com

    * RUN THAT DATASET THRU MY PROGRAM & WHAT RESULTS COME OUT THAT HAVE A "PORT FILTER" ATTACHED?

    NONE!

    Only borlnd.com, tester.com, test3.com, jealous.com & jowie.com (last 2 are for YOU, lol) REMAIN (no filters on them)

    MY PROGRAM EVEN PREVENTS THAT MISTAKE!

    APK

    P.S.=> THIS PROVES MY PROGRAM'S OUTPUT DOES NOT ALLOW "PORT FILTERING" ENTRIES IN HOSTS as I said!

    ALL DESPITE you IMPERSONATING ME & LYING (for YEARS now) saying hosts do + STALKING ME via UNIDENTIFIABLE ANONYMOUS too (loser weezil).

    It's LONG PROVEN YOU DO THAT c6gunner https://linux.slashdot.org/com...

    + your LIES saying I have a MacOS model (I don't YET) OR that hosts cure Spectre/Meltdown (hosts don't but you LIE impersonating ME saying they do - FILTERS in hosts too!)... apk

  7. YUO FAIL IT by Anonymous Coward · · Score: -1
  8. IMPERSONATING me AGAIN? apk by Anonymous Coward · · Score: -1

    You're caught impersonating me c6gunner (your name's the submitter signing "APK") https://linux.slashdot.org/com... & you ALTERED /.ers PRAISE of my work (not yours you don't even HAVE).

    (Don't throw stones if you live in a glass house vs. me: RIGHT ZIP? https://yro.slashdot.org/comme... )

    LIAR ZIP says he has no account "I don't have an account, so I don't have mod points" https://news.slashdot.org/comm...

    Yet LIAR ZIP says he downmods my posts (IMPOSSIBLE MINUS AN ACCOUNT on /.): "I down-modded a few of your post on other threads" - by Anonymous Coward "ZIP" on Thursday October 11, 2018 @11:31AM (#57461058) FROM https://yro.slashdot.org/comme...

    APK

    P.S.=> GROW UP weezils - you do it to yourselves trying to "take me on" & FAILING like you always do (especially on tech) + so then you start STALKING me by UNIDENTIFIABLE anonymous posts OR by IMPERSONATING me (weak BITCH tactics only a HOMO would do, lol)... apk

  9. On SPECULATIVE EXECUTION (you may be right) by Anonymous Coward · · Score: -1

    Hosts can stop portsmash (blocking downloads of it) https://it.slashdot.org/commen... not Spectre/Meltdown AFAIK - & U FAIL a PORTFILTERING TEST https://yro.slashdot.org/comme... ... apk

    HOWEVER: In your "impersonations" trying to make me "look bad" or a liar (like your kind is)? Hope you're RIGHT (considering I'm only sure hosts stop portsmash vs. Spectre/Meltdown) https://tech.slashdot.org/comm...

    APK

    P.S.=> ADDITIONALLY: You MAY also be RIGHT on Spectre/Meltdown being PREVENTABLE via hosts blocking downloaded software (script or exe) per your statement in that last link above also (thanks but NOT TOTALLY SURE here vs. say, RPC using them which would be REMOTE vs. LOCAL as in portsmash above) per https://meltdownattack.com/mel... &/or https://spectreattack.com/spec... ACADEMIC RESEARCH into their mechanics... apk

  10. apk - not a chance by link-error · · Score: 1

        With all the spamming for APK... I wouldn't touch it with a ten foot anti-virus.

    --
    -Unresolved symbol? Byte me!
  11. link-error = fake name massive human fail by Anonymous Coward · · Score: -1

    See subject: Your MASSIVE FAIL in this life is you're nothing more than a chattering little do-nothing "ne'er-do-well" online & you know it...

    * Is that the best your "phantasyland FAKE NAME" (for your fake lie of a so-called 'life') can manage?

    When a FAKE NAME do nothing like YOU does better than I have? Then talk (you're all talk & no action)...

    You can't help you're an immature little BUTTHURT no-mind, lol! I blew you away in TONS OF PLACES and easily dust your no-mind bullshit blatherings.

    APK

    P.S.=> The TRUE PRICE of your UNIDENTIFIABLE FAKE NAME do-nothing selves like you that I can ALWAYS CASH IN ON (lol) is that I can use FACT/TRUTH on them to SHATTER their all TOO fragile delusional egos that they actually know A DAMN THING in computing, lol... apk

  12. Plenty of others & results say otherwise by Anonymous Coward · · Score: -1

    See my subject: Blame those impersonating me. I only post on hosts IF they stop threats OR to speed you up. I don't off topic.
    I've got my own "psycho fanclub" IMPERSONATING me & spamming + lying about MY work (I don't post about it unless it applies to STOP THREATS or SPEED YOU UP).

    They also STALK ME constantly by UNIDENTIFIABLE anonymous posts like whackos!

    * They're a pack of BUTTHURT little wannabes & psychos I've torn to shreds before & this is their "effete 'revenge'" & "ReTaLiAtiOn" lol apparently!

    Especially GOOFS like c6gunner CAUGHT IMPERSONATING ME https://linux.slashdot.org/com...

    (His name's on that post link as the SUBMITTER yet signing "APK" as I do while he ALTERED users words of praise of my work (since he tried INSULTING me & I simply issued a FAIR CHALLENGE to him that HE SHOW HE CAN DO BETTER - he hasn't to date & NEVER will (wannabe))).

    ZIP is another I've had to PUBLICLY SHAME & he tried HIDING facts that show he's a FOOL & A LIAR here, twice https://news.slashdot.org/comm...

    APK

    P.S.=> See subject & this link for DOZENS of registered /.ers & SECURITY PROS etc. saying otherwise https://it.slashdot.org/commen... ... apk

    1. Re: Plenty of others & results say otherwise by Anonymous Coward · · Score: 0

      You sound crazy and unstable. I wouldn't run any software created by some loony-tune on my PC.

  13. IMPERSONATING me AGAIN? apk by Anonymous Coward · · Score: -1

    You're caught impersonating me c6gunner (your name's the submitter signing "APK") https://linux.slashdot.org/com... & you ALTERED /.ers PRAISE of my work (not yours you don't even HAVE).

    (Don't throw stones if you live in a glass house vs. me: RIGHT ZIP? https://yro.slashdot.org/comme... )

    LIAR ZIP says he has no account "I don't have an account, so I don't have mod points" https://news.slashdot.org/comm...

    Yet LIAR ZIP says he downmods my posts (IMPOSSIBLE MINUS AN ACCOUNT on /.): "I down-modded a few of your post on other threads" - by Anonymous Coward "ZIP" on Thursday October 11, 2018 @11:31AM (#57461058) FROM https://yro.slashdot.org/comme...

    APK

    P.S.=> GROW UP weezils - you do it to yourselves trying to "take me on" & FAILING like you always do (especially on tech) + so then you start STALKING me by UNIDENTIFIABLE anonymous posts OR by IMPERSONATING me (weak BITCH tactics only a HOMO would do, lol)... apk

  14. Did Slashdot management post the parent? by Anonymous Coward · · Score: -1

    Ordinary users can't post the n-word because of the lameness filter, yet there it is in the parent. The lameness filtering of the n-word seems pretty ironclad, so posting it would seem to require that the lameness filter not apply to the comment at all. Only Slashdot management would seem to have the access needed to altogether circumvent the lameness filter and post comments that would otherwise be blocked. These posts seem to show up in just about every article, and I suspect they're from a bot run by Slashdot, itself. In fact, there is precedent for this when CmdrTaco had a bot that would grab first post, then later delete the comment, for the purpose of discouraging trolls to make such posts. Is Slashdot management also responsible for these posts?

  15. Just a test by raymorris · · Score: 0

    NlGGER is a horrible word.

    1. Re: Just a test by Anonymous Coward · · Score: -1

      Donald?

  16. Water is yet by Anonymous Coward · · Score: 0

    If you let a device get out of your hands somebody somewhere can figure out how to hack it. There will never be a hack proof device.

  17. ZIP/c6gunner: IMPERSONATING me AGAIN? apk by Anonymous Coward · · Score: 0

    See how STUPID "ZIP" (Zach I. Patterson) CHIMP is (taking credit for what I solved before him) https://tech.slashdot.org/comm... (he needs to LEARN TO READ)!

    I even SHOW ways to do it YOURSELF https://tech.slashdot.org/comm... (he couldn't).

    LYING CHIMP "ZIP" SHOT DOWN FOR HIS LIES & TECH FUCKUPS vs. me https://games.slashdot.org/com...

    "I'm a much better programmer than APK" - by Anonymous Coward ZIP on Monday October 08, 2018 @11:27PM (#57449082) FROM https://yro.slashdot.org/comme... yet nothing to show in programs. I can from registered /.ers liking/using/praising my work (& 100k users worldwide too). He can't.

    LIAR ZIP says he has no account "I don't have an account, so I don't have mod points" https://news.slashdot.org/comm...

    Yet LIAR ZIP says he downmods my posts (IMPOSSIBLE MINUS AN ACCOUNT on /.): "I down-modded a few of your post on other threads" - by Anonymous Coward "ZIP" on Thursday October 11, 2018 @11:31AM (#57461058) FROM https://yro.slashdot.org/comme...

    c6gunner CAUGHT impersonating me (his name's the submitter signing "APK") https://linux.slashdot.org/com... & you ALTERED /.ers PRAISE of my work (not yours you don't even HAVE).

    BOTH = mere talkers (all talk "ne'er-do-well" DO-NOTHINGS).

    APK

    P.S.=> Hosts can stop portsmash (blocking downloads of it) "You basically have to already be able to run your own evil code on a machine in order to PortSmash it." from https://www.theregister.co.uk/... not Spectre/Meltdown AFAIK (but it's POSSIBLE it might but NOT TOTALLY SURE here (vs. say, RPC using them which would be REMOTE vs. LOCAL as in portsmash above) per https://meltdownattack.com/mel... &/or https://spectreattack.com/spec... ACADEMIC RESEARCH into their mechanics ) - & U FAIL a PORTFILTER TEST https://yro.slashdot.org/comme...