Google says hackers have put ‘monitoring implants’ in iPhones for years
Get link
Facebook
X
Pinterest
Email
Other Apps
Google says hackers have put ‘monitoring implants’
in iPhones for years
Visiting hacked sites was enough for
server to gather users’ images and contacts
Alex HernFri
30 Aug 2019 03.03 EDTLast modified on Fri 30 Aug 2019 09.25 EDT
·An unprecedented iPhone hacking operation, which attacked
“thousands of users a week” until it was disrupted in January, has been
revealed by researchers at Google’s external security team.
The operation, which lasted two and a half years, used a small
collection of hacked websites to deliver malware on to the iPhones of visitors.
Users were compromised simply by visiting the sites: no interaction was
necessary, and some of the methods used by the hackers affected even fully
up-to-date phones.
Once hacked, the user’s deepest secrets were exposed to the
attackers. Their location was uploaded every minute; their device’s keychain,
containing all their passwords, was uploaded, as were their chat histories on
popular apps including WhatsApp, Telegram and iMessage, their address book, and
their Gmail database.
The one silver lining is that the
implant was not persistent: when the phone was restarted, it was cleared from
memory unless the user revisited a compromised site. However, according to Ian
Beer, a security researcher at Google: “Given the breadth of information
stolen, the attackers may nevertheless be able to maintain persistent access to
various accounts and services by using the stolen authentication tokens from
the keychain, even after they lose access to the device.”
Beer is a member of Project Zero, a
team of white-hat hackers inside Google who work to find security vulnerabilities in
popular tech, no matter who it is produced by. The team has become
controversial for its hardline approach to disclosure: 90 days after it reports
a bug to the victim, it will publish the details publicly, whether or not the
bug has been fixed in that time.
In total, 14 bugs were exploited for
the iOS attack across five different “exploit chains” – strings of flaws linked
together in such a way that a hacker can hop from bug to bug, increasing the
severity of their attack each time.
“This was a failure case for the
attacker,” Beer noted, since even though the campaign was dangerous, it was
also discovered and disrupted. “For this one campaign that we’ve seen, there
are almost certainly others that are yet to be seen.
“All that users can do is
be conscious of the fact that mass exploitation still exists and behave
accordingly; treating their mobile devices as both integral to their modern
lives, yet also as devices which when compromised, can upload their every
action into a database to potentially be used against them.”
Google said it had reported the
security issues to Apple on 1 February. Apple then released an operating system update which
fixed the flaws on 7 February.
BMW traps alleged thief by remotely locking him in car Stealer's Wheel? Seattle police department quotes "Watchmen" movie in a recap of the recent arrest. Tech Culture by Gael Fashingbauer Cooper December 4, 2016 5:00 PM PST It's maybe the most satisfying arrest we can imagine. Seattle police caught an alleged car thief by enlisting the help of car maker BMW to both track and then remotely lock the luckless criminal in the very car he was trying to steal. Jonah Spangenthal-Lee, deputy director of communications for the Seattle Police Department, posted a witty summary of the event on the SPD's blog on Wednesday. Turns out if you're inside a stolen car, it's perhaps not the best time to take a nap. "A car thief awoke from a sound slumber Sunday morning (Nov. 27) to find he had been remotely locked inside a stolen BMW, just as Seattle police officers were bearing down on him," Spangenthal-Lee wrote. The suspect found a ke...
World’s 1st remote brain surgery via 5G network performed in China Published time: 17 Mar, 2019 13:12 · A Chinese surgeon has performed the world’s first remote brain surgery using 5G technology, with the patient 3,000km away from the operating doctor. Dr. Ling Zhipei remotely implanted a neurostimulator into his patient’s brain on Saturday, Chinese state-run media reports . The surgeon manipulated the instruments in the Beijing-based PLAGH hospital from a clinic subsidiary on the southern Hainan island, located 3,000km away. The surgery is said to have lasted three hours and ended successfully. The patient, suffering from Parkinson’s disease, is said to be feeling well after the pioneering operation. The doctor used a computer connected to the next-generation 5G network developed by Chinese tech giant Huawei. The new device enabled a near real-time connection, according to Dr. Ling. “You barely feel that th...
New cash machines: withdraw money with veins in your finger Cash machine technology that reads the pattern of finger veins is already available in Japan and Poland By Telegraph Reporters 6:59PM BST 15 May 2014 Cash machines could soon be installed with devices that identify customers by reading the veins in their fingers. The technology is already being rolled out in Poland, where 1,730 cash machines will this year be installed with readers, negating the need for a debit card and Pin. Developed by Hitachi, the Japanese electronics firm, the machines read the patterns of the veins just below the surface of the skin on your finger using infra-red sensors. The light is partially absorbed by haemoglobin in the veins to capture a unique finger vein pattern profile, which is matched to a profile. The technology is used by Japanese banks and also in Turkey, offering “groundbreaking levels of accuracy and speed of authentication”, Hitachi said, which in t...
Comments
Post a Comment