Google says hackers have put ‘monitoring implants’ in iPhones for years
Get link
Facebook
X
Pinterest
Email
Other Apps
Google says hackers have put ‘monitoring implants’
in iPhones for years
Visiting hacked sites was enough for
server to gather users’ images and contacts
Alex HernFri
30 Aug 2019 03.03 EDTLast modified on Fri 30 Aug 2019 09.25 EDT
·An unprecedented iPhone hacking operation, which attacked
“thousands of users a week” until it was disrupted in January, has been
revealed by researchers at Google’s external security team.
The operation, which lasted two and a half years, used a small
collection of hacked websites to deliver malware on to the iPhones of visitors.
Users were compromised simply by visiting the sites: no interaction was
necessary, and some of the methods used by the hackers affected even fully
up-to-date phones.
Once hacked, the user’s deepest secrets were exposed to the
attackers. Their location was uploaded every minute; their device’s keychain,
containing all their passwords, was uploaded, as were their chat histories on
popular apps including WhatsApp, Telegram and iMessage, their address book, and
their Gmail database.
The one silver lining is that the
implant was not persistent: when the phone was restarted, it was cleared from
memory unless the user revisited a compromised site. However, according to Ian
Beer, a security researcher at Google: “Given the breadth of information
stolen, the attackers may nevertheless be able to maintain persistent access to
various accounts and services by using the stolen authentication tokens from
the keychain, even after they lose access to the device.”
Beer is a member of Project Zero, a
team of white-hat hackers inside Google who work to find security vulnerabilities in
popular tech, no matter who it is produced by. The team has become
controversial for its hardline approach to disclosure: 90 days after it reports
a bug to the victim, it will publish the details publicly, whether or not the
bug has been fixed in that time.
In total, 14 bugs were exploited for
the iOS attack across five different “exploit chains” – strings of flaws linked
together in such a way that a hacker can hop from bug to bug, increasing the
severity of their attack each time.
“This was a failure case for the
attacker,” Beer noted, since even though the campaign was dangerous, it was
also discovered and disrupted. “For this one campaign that we’ve seen, there
are almost certainly others that are yet to be seen.
“All that users can do is
be conscious of the fact that mass exploitation still exists and behave
accordingly; treating their mobile devices as both integral to their modern
lives, yet also as devices which when compromised, can upload their every
action into a database to potentially be used against them.”
Google said it had reported the
security issues to Apple on 1 February. Apple then released an operating system update which
fixed the flaws on 7 February.
New cash machines: withdraw money with veins in your finger Cash machine technology that reads the pattern of finger veins is already available in Japan and Poland By Telegraph Reporters 6:59PM BST 15 May 2014 Cash machines could soon be installed with devices that identify customers by reading the veins in their fingers. The technology is already being rolled out in Poland, where 1,730 cash machines will this year be installed with readers, negating the need for a debit card and Pin. Developed by Hitachi, the Japanese electronics firm, the machines read the patterns of the veins just below the surface of the skin on your finger using infra-red sensors. The light is partially absorbed by haemoglobin in the veins to capture a unique finger vein pattern profile, which is matched to a profile. The technology is used by Japanese banks and also in Turkey, offering “groundbreaking levels of accuracy and speed of authentication”, Hitachi said, which in t...
Facebook Is Trying Everything to Re-Enter China—and It’s Not Working Since regulators blocked the service in 2009, CEO Mark Zuckerberg has hired well-connected executives, developed censorship tools and taken a ‘smog jog’ in Beijing—but the company has made no visible headway. By ALYSSA ABKOWITZ in Beijing, DEEPA SEETHARAMAN in San Francisco and EVA DOU in Wuzhen, China Jan. 30, 2017 10:45 a.m. ET Facebook Inc.’s chances of getting back into China appeared to take a rare turn for the better when an employee noticed an official posting online: Beijing authorities had granted it a license to open a representative office in two office-tower suites in the capital. Such permits typically give Western firms an initial China beachhead. This one, which Facebook won in late 2015, could have been a sign Beijing was ready to give the company another chance to connect with China’s roughly 700 million internet users, reopening the market as the social-media giant’s U.S.-growth...
Popular Antivirus Program Mistakenly IDs Windows as Threat, Creating Chaos by ALEX JOHNSON TECH APR 25 2017, 7:53 AM ET An antivirus service used by tens of thousands of businesses and millions of home users shut down an untold number of computers around the world Monday after it mistakenly identified core parts of Microsoft Windows as threats, the company confirmed. Webroot Inc. of Broomfield, Colorado, didn't immediately respond to a request for comment. But it confirmed on its support forum for customers that it issued an updated detection rule that "identified false positives" for critical Windows operating files Monday afternoon, resulting in those files' being "quarantined" and inaccessible to Windows. @SwiftOnSecurity, an anonymous but well-respected tech security Twitter account, reported that it appeared that the rule somehow allowed genuine "signed Microsoft files to be removed." The rule was distributed and appl...
Comments
Post a Comment