Peak messenger security: won't decrypt your own messages 🔒
Notices by jiska 🦄:fairydust: (jiska@chaos.social)
-
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Sunday, 13-Apr-2025 21:09:47 JST jiska 🦄:fairydust:
-
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Monday, 10-Mar-2025 03:16:34 JST jiska 🦄:fairydust:
Firmware memory access through HCI was never considered a threat, since an attacker requires at least code execution in the Bluetooth daemon/driver for getting code execution in the Bluetooth firmware.
This threat model changed slightly when we showed further privilege escalation, in particular code execution in the WiFi firmware via Bluetooth. Now, this interface is only available until Bluetooth firmware patches were applied at driver/daemon initialization.
-
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Monday, 10-Mar-2025 02:07:42 JST jiska 🦄:fairydust:
Tarlogic found a "backdoor" in the ESP32 chips: https://social.lansky.name/@hn100/114127956134801350
Broadcom and Cypress chips have the same HCI "backdoor" allowing to write to the Bluetooth chip's RAM. This feature is used for firmware patches.
We didn't request CVEs for that 9 years ago. Instead, we built the InternalBlue Bluetooth research framework: https://github.com/seemoo-lab/internalblue
-
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Tuesday, 26-Nov-2024 03:48:58 JST jiska 🦄:fairydust:
@LaF0rge Apple uses a custom variant of QMI where even 1/3 of their services are proprietary 🥲 but except from that, the working principle is quite similar.
In conversation from chaos.social permalink -
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Tuesday, 26-Nov-2024 02:57:45 JST jiska 🦄:fairydust:
@LaF0rge feel free to ping me at CCC, I'll bring some setup. :)
Might be possible via QMI modification/injection.
In conversation from chaos.social permalink -
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Monday, 18-Nov-2024 06:52:57 JST jiska 🦄:fairydust:
How does the new iOS inactivity reboot work? What does it protect from?
I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.
https://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html
In conversation from chaos.social permalink Attachments
-
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Saturday, 09-Nov-2024 01:11:22 JST jiska 🦄:fairydust:
Apple added a feature called "inactivity reboot" in iOS 18.1. This is implemented in keybagd and the AppleSEPKeyStore kernel extension. It seems to have nothing to do with phone/wireless network state. Keystore is used when unlocking the device. So if you don't unlock your iPhone for a while... it will reboot!
In the news: "Police Freak Out at iPhones Mysteriously Rebooting Themselves, Locking Cops Out"
https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/iOS version diffs to see yourself:
https://github.com/search?q=repo%3Ablacktop%2Fipsw-diffs%20inactivity_reboot&type=codeIn conversation from chaos.social permalink Attachments
-
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Sunday, 21-Jan-2024 19:39:06 JST jiska 🦄:fairydust:
OH: "ASN.1 is JSON for boomers."
In conversation from chaos.social permalink -
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Thursday, 14-Dec-2023 05:50:50 JST jiska 🦄:fairydust:
Wanted to charge my MacBook with a power bank. Worked well. Once the power bank was discharged, my MacBook started charging the power bank 🤡🤡🤡
In conversation from chaos.social permalink -
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Saturday, 18-Nov-2023 06:27:13 JST jiska 🦄:fairydust:
?????
In conversation from chaos.social permalink Attachments
-
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Sunday, 29-Oct-2023 05:05:16 JST jiska 🦄:fairydust:
@neingeist konnte in Onkel Jeff's Buchladen nicht finden :(
In conversation from chaos.social permalink -
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Sunday, 29-Oct-2023 05:05:13 JST jiska 🦄:fairydust:
@neingeist The Shop schickt sie dir schon per Drohne bevor du sie bestellt hast
In conversation from chaos.social permalink -
Embed this notice
jiska 🦄:fairydust: (jiska@chaos.social)'s status on Sunday, 29-Oct-2023 03:54:19 JST jiska 🦄:fairydust:
Gerade gelernt, dass es nicht "Regalbrettmetallnupsies" heißt, sondern "Bodenträger" 🤔
In conversation from chaos.social permalink Attachments