 |
 |
6 Reasons iOS 6 Jailbreaks Will Be Tough |
 |
10-16-2012, 11:17 PM
|
#1
|
|
Obsessive iPhone Disorder
shahpriyankd is offline
Join Date: Aug 2009
Device: iPhone 4
iOS Version: 5.1.1
iTunes Version: iTunes 10
Carrier: Other
OS: Windows 7
Location: India
Posts: 296
Thanks: 364
Thanked 334 Times in 112 Posts
|
6 Reasons iOS 6 Jailbreaks Will Be Tough
Waiting for a jailbreak for the latest iOS 6 devices such as the iPhone 5? You might have to wait a while.
Jailbreaking your iPhone is now legal in the United States, even if Apple has historically discouraged the process. With Apple's release last month of iOS 6, iPhone hackers have, of course, set their sites on jailbreaking the new OS. So far no automated jailbreak is available for latest-generation iOS devices that run iOS 6. But software hacker Grant Paul claimed, to All Things Digital, that he'd jailbroken an iPhone 5 less than 24 hours after its release.
Last month, meanwhile, iPhone Dev-Team released Redsn0w, a tethered jailbreak for iOS 6, but it works only on A4-based and earlier devices, including the iPhone 4, iPhone 3GS, and iPod Touch 4th-generation. It won't, however, work on newer devices, including the iPhone 4s and 5, or the two latest generations of iPads.
Could a full iOS 6 jailbreak, including for the latest Apple devices, be just around the corner? Don't bet on it. Here are six of the top challenges that would-be jailbreak developers will face:
1. Finding sufficient vulnerabilities takes smarts. "Jailbreaking is just overwriting some values in memory," said security researcher Charlie Miller, in a presentation at the RSA Conference in San Francisco earlier this year. (Miller is now a member of Twitter's security team.) But to overwrite those values, would-be jailbreakers must find unknown, exploitable vulnerabilities in iOS and then successfully chain these vulnerabilities together.
For example, Miller said, "JailbreakMe.com 3 was an end-to-end exploitation of all the security mechanisms that are in iOS 5." He noted that the software's developer, Comex, also found code signing bugs in iOS 2, and again in iOS 5, that would allow exploit processes to create memory regions to make exploitation easier.
Such knowledge is difficult to come by. "All the jailbreak developers are really freaking smart," said Dino Dai Zovi, CTO of security research firm Trail of Bits, at the RSA conference. As a result, he said, all of the exploits that have been used for jailbreaking have either been discovered by teams of researchers, "or [by] Comex, who's from the future."
2. Vulnerability hunting takes time. Finding new iOS bugs that can be chained together takes time. The self-described "Jailbreak Dream Team" behind the first untethered jailbreak for the iPhone 4S and iPad 2, dubbed Absinthe 2.0 and introduced in January 2012, said it took them 10 months to figure out how to jailbreak the new A5 chip used on those devices.
3. Website-based untethered jailbreaking is insanely difficult. The aforementioned Comex isn't legendary in jailbreaking circles just for creating jailbreaking software by himself, but also for allowing people to do it via a website. Indeed, unlike other jailbreaks, which require a USB cable, Comex's can be installed simply by visiting the JailbreakMe.com website. But Comex's last release was JailbreakMe version 3, in July 2011, and it works only on iOS devices up to the iPhone 4.
The real identify of the iOS hacker who calls himself Comex was last year revealed by Forbes as a 20-year old Brown University student named Nicholas Allegra. Interestingly, Allegra last year announced that while on a break from Brown, he would be interning for Apple. Might Apple developers have gleaned some proactive iOS security suggestions from him? If so, it would mean further trouble for would-be jailbreakers.
4. Apple's update clock begins ticking after jailbreaks are released. Once they go public, exploits have a short shelf life. Indeed, whenever a new jailbreak appears, Apple begins patching the exploited vulnerabilities. "Let's talk about jailbreakme.com 2 [which debuted in July 2010]," said Zovi, who together with Miller helped co-author the iOS Hacker's Handbook, which was released in May 2012.
"Once you drop all these bugs, it gets fixed instantly," Zovi said, noting that after version 2 of jailbreakme.com debuted, it took Apple just two weeks to release an update that blocked the vulnerabilities that the jailbreak had used.
5. Early iOS 6 exploit was not a jailbreak. At the Hack in the Box conference in Kuala Lumpur earlier this month, Azimuth Security researchers Mark Dowd and Tarjei Mandt demonstrated a kernel exploit that allowed them to install and run Cydia--an application that can be used to search for and install apps onto a jailbroken iPhone--on an iPhone 5 running iOS 6. But they noted that their kernel exploit alone couldn't be used to jailbreak iOS 6 devices.
6. Apple keeps locking down iOS. Unfortunately for would-be jailbreakers, iOS 6 will arguably be the toughest mobile Apple OS to crack. According to Dowd and Mandt's presentation, Apple has added a number of features that have improved iOS 6 security, in part by better hardening the iOS kernel--the central component of the operating system--against exploits, better protecting against memory or heap corruption errors, and improving stack overflow prevention. In addition, Apple added new information leakage mitigations, including zeroing out some application programming interfaces (APIs) that had previously been used to execute successful kernel-level exploits. Apple also made address space layout randomization (ASLR) even more random and thus more difficult to circumvent.
All told, these iOS 6 mitigations significantly raise the bar, according to the researchers, who noted that many of the old tricks don't work, including bugs that previously could have been exploited to help trigger a jailbreak.
In Search of Jailbreaks
With the above discussion of jailbreaks, a caveat: there's a reason that information security managers discourage--if not actively block--jailbroken iPhones or iPads from accessing the corporate network. "What happens when you do jailbreak your phone--what does it do to the security architecture?" said Miller at RSA. "It turns out that it breaks everything. ... It turns off code signing, of course--that's why you jailbreak it. But code signing is tied to app permissions ... [and] all the things you download can run as root." That means there's no sandbox to prevent attackers from exploiting an app, then using it as a stepping stone to exploit the device in other ways.
The JailbreakMe website, however, has this to say in its FAQ: "By itself, jailbreaking does not make you vulnerable. However, a common mistake for jailbreakers is to install OpenSSH but forget to change the passwords for root and mobile; this lets anyone log into your device over the Internet."
Miller, however, disagrees. "After jailbreaking an iOS device," he said, "you really increase the risk of something bad happening."
|
Iphone 5 16GB Factory Unlocked.
Iphone 4 16GB 5.1.1 Factory Unlocked jailbroken using absinthe untethered.
Iphone 3gs 8GB 5.0.1 Ultrasn0w Unlocked jailbroken using Redsn0w untethered.
Iphone 2g 3.1.3 Custom Firmware by Whited00r.
Ipad 1 3g 5.1.1 Jailbroken with Absinthe untethered.
Iphone 4s 5.1.1 jailbroken with Absinthe untethered.
|
|
|
|
|
The Following 36 Users Say Thank You to shahpriyankd For This Useful Post:
|
@it (12-02-2012), ali22l (10-24-2012), amm451981 (10-28-2012), ashion7 (10-27-2012), awzx_77 (11-24-2012), boogles1 (10-23-2012), Charlieaw (10-17-2012), chillout (10-30-2012), dreanew (10-23-2012), gansta (10-30-2012), GorgonSin (10-23-2012), ibax (12-02-2012), ILetTheSoonersOut (11-16-2012), InSaNiTy (10-31-2012), jamaican191 (11-21-2012), kc6nsf (11-24-2012), khaigarusi18 (10-31-2012), kingof9x (10-17-2012), knightflt (12-02-2012), livinlarge (12-03-2012), mandi47 (10-28-2012), MASTASLY (10-24-2012), mb23 (10-28-2012), mickish1953 (10-17-2012), mohseen (11-23-2012), norvaldu (11-19-2012), OOCHAOS (11-29-2012), Paradroid (10-19-2012), pepsih (10-17-2012), philfrancia (10-21-2012), rasputin007 (10-17-2012), robsbrutal (10-17-2012), tayvon22 (12-24-2012), wekwek (11-10-2012), xandros9 (10-20-2012), yasin (10-31-2012) |
10-17-2012, 12:07 AM
|
#2
|
|
Stay Brutal
robsbrutal is offline
Join Date: Aug 2010
Device: iPhone 4S
iOS Version: 6.0
iTunes Version: iTunes 10
Carrier: Verizon
OS: Mac OS X
Location: Washington
Posts: 907
Thanks: 107
Thanked 185 Times in 126 Posts
|
Good read!
|
|
|
|
|
|
10-17-2012, 12:35 AM
|
#3
|
|
Custom iPhone customer
rasputin007 is offline
Join Date: Nov 2009
Device: iPhone 4S
iOS Version: 6.0
iTunes Version: iTunes 10
Carrier: o2
OS: Other
Location: UK
Posts: 214
Thanks: 80
Thanked 79 Times in 33 Posts
|
Interesting point of view!
However, everything is in constant change. The "cat and mouse" game between Apple and the Jailbreakers always went on. Agreed, the level on which they battle is getting higher and higher (that is the constant change bit  ), but so far there has not been a 100% secure and unbreakable operating system and iOS 6 is no exception.
As always it is just a question of time when iOS 6 will be jailbroken.
|
Nothing is impossible, only miracles take a bit longer!
|
|
|
|
|
The Following 2 Users Say Thank You to rasputin007 For This Useful Post:
|
|
10-17-2012, 02:18 AM
|
#4
|
|
Banned because I'm a TOOL!!!
classy56 is offline
Join Date: May 2012
Device: iPad 2
iOS Version: 5.1.1
iTunes Version: iTunes 10
Carrier: Other
OS: Windows 7
Location: UK
Posts: 389
Thanks: 94
Thanked 162 Times in 97 Posts
|
I appreciate Apple might have made the Kernel security harder to break, but in my opinion IOS6 is no different from previous IOS, it's just a case of "seek and ye shall find".
|
|
|
|
|
|
|
The Following User Says Thank You to classy56 For This Useful Post:
|
|
10-17-2012, 03:37 AM
|
#5
|
|
Obsessive iPhone Disorder
Wirerat is online now
Join Date: Aug 2011
Device: iPad 2
iOS Version: 6.0.2
iTunes Version: iTunes 10
Carrier: AT&T
OS: Windows 7 x64
Location: Kicking a dead horse
Posts: 568
Thanks: 137
Thanked 227 Times in 126 Posts
|
Noted a error in the report.
Jailbreakme was never for ios 5. Comex already worked for apple when it released. Prolly a typo.
|
|
|
|
|
|
|
The Following User Says Thank You to Wirerat For This Useful Post:
|
|
10-17-2012, 05:08 AM
|
#6
|
|
Jailbroken
sohaf is offline
Join Date: Jun 2010
Device: iPhone 4
iOS Version: 4.2
iTunes Version: iTunes 10
Carrier: Other
OS: Windows 7
Location: pakistan
Posts: 88
Thanks: 1
Thanked 16 Times in 11 Posts
|
Where is Geo Hot when we need him to pwn every idevice for life
|
|
|
|
|
|
|
The Following 5 Users Say Thank You to sohaf For This Useful Post:
|
|
10-17-2012, 06:42 AM
|
#7
|
|
Jailbroken
sadiphone is offline
Join Date: Jun 2010
Device: iPhone 4S
iOS Version: 6.0
iTunes Version: iTunes 10
Carrier: AT&T
OS: Mac OS X
Location: NJ
Posts: 41
Thanks: 10
Thanked 11 Times in 6 Posts
|
I dont know why apple makes it hard for JB when all the do is still the ideas of all the cydia tweaks thanks to the JB community. If apples is not carful people are going to go over to android.
|
|
|
|
|
|
|
The Following 4 Users Say Thank You to sadiphone For This Useful Post:
|
|
10-17-2012, 07:30 AM
|
#8
|
|
Glory Glory Man Utd!
RedDevil is offline
Join Date: Aug 2009
Device: iPhone 5
iOS Version: 6.0
iTunes Version: iTunes 10
Carrier: AT&T
OS: Mac OS X
Location: State of Confusion
Posts: 374
Thanks: 34
Thanked 87 Times in 57 Posts
|
They (the dev team) have way to much money to lose if they dont. Look for that other article on how much money Cydia paid to developers..... 8 million dollars. Those developers arent making that kind of money from the apple app store
|
|
|
|
|
|
|
The Following User Says Thank You to RedDevil For This Useful Post:
|
|
10-17-2012, 08:34 AM
|
#9
|
|
Jailbroken
joshuax is offline
Join Date: Dec 2009
Device: iPhone 4S
iOS Version: 5.1.1
iTunes Version: iTunes 10
Carrier: Other
OS: Mac OS X
Location: pa
Posts: 85
Thanks: 31
Thanked 19 Times in 13 Posts
|
They'll have to pry my jailbroken 4S from my cold, dead hands.
|
|
|
|
|
|
|
The Following 3 Users Say Thank You to joshuax For This Useful Post:
|
|
10-17-2012, 08:37 AM
|
#10
|
|
/var/mobile
Sinned_Elmeerrr is online now
Join Date: Mar 2011
Device: iPhone 4S
iOS Version: 6.1.x
iTunes Version: iTunes 11
Carrier: T-Mobile
OS: Mac OS X
Location: California
Posts: 115
Thanks: 83
Thanked 21 Times in 16 Posts
|
Quote:
Originally Posted by sohaf
Where is Geo Hot when we need him to pwn every idevice for life
|
Geohot got arrested for drug trafficking in Mexico last time i checked.
|
If I've helped you in any way, and you don't hit the Thanks button, you're an ass because that's the least you can do for me. 
|
|
|
|
10-17-2012, 09:49 AM
|
#11
|
|
n00b
boyantcho is offline
Join Date: Nov 2010
Device: iPhone 3GS
iOS Version: 4.2
iTunes Version: iTunes 9
Carrier: AT&T
OS: Windows XP
Location: IL
Posts: 17
Thanks: 15
Thanked 0 Times in 0 Posts
|
The whole article mostly talks about JailbreakMe.com which should be easy to assume that will be very hard to achieve nowadays. If I have to bet that there will be a untethered JB or not, I would bet in favor of it. Will it take time? I would also bet, that it will. To me the obvious reason is that most likely we will see a few new 6.0.x updates by Apple to take care of some minor issue and then we may see more news on the JB front. It easily could take a few months.
The bigger question is will we ever see a discovery of a vulnerability like limera1n again, for A5 or A6 iDevices? Most likely not, but you never know.
|
|
|
|
|
|
 |
|
 |
10-20-2012, 04:16 PM
|
#12
|
|
Obsessive iPhone Disorder
DeepUnknown is offline
Join Date: Jan 2010
Device: iPod Touch 2
iOS Version: 4.2
iTunes Version: iTunes 10
Carrier: Other
OS: Windows 7
Location: Damascus, Syria
Posts: 1,949
Thanks: 270
Thanked 383 Times in 253 Posts
|
Quote:
Originally Posted by sadiphone
I dont know why apple makes it hard for JB when all the do is still the ideas of all the cydia tweaks thanks to the JB community. If apples is not carful people are going to go over to android. 
|
I guess they are doing that so they don't get sued by app developers, since after jailbreak any cracked app can be installed.
And they want their OS to be the safest mobile platform.
|
----------------------------------------------
Daughter - i Pod
Son - i Phone
Mom - i Pad
Dad - I Pay -_- ----------------------------------------------
No Gains Without Pains 
----------------------------------------------
(R.I.P) iPod Touch 2G MB Model, Running 4.2.1
Jailbroken By: Redsn0w 0.9.6
----------------------------------------------
|
|
|
|
 |
10-20-2012, 07:31 PM
|
#13
|
|
┌∩┐(◣_◢)┌∩┐
King Kaos is online now
Join Date: Jun 2012
Device: iPod Touch 4
iOS Version: 6.1.x
iTunes Version: iTunes 11
Carrier: Other
OS: Linux
Location: Kentucky
Posts: 1,442
Thanks: 351
Thanked 753 Times in 409 Posts
|
in other words:
devs are looking for new recruits of coders, next gen crackers.
|
|
|
|
|
|
10-20-2012, 08:12 PM
|
#14
|
|
Obsessive iPhone Disorder
TheRealPorkchop is offline
Join Date: May 2012
Device: iPhone 4
iOS Version: 5.1.1
iTunes Version: iTunes 10
Carrier: Verizon
OS: Mac OS X
Location: North Carolina
Posts: 245
Thanks: 41
Thanked 45 Times in 38 Posts
|
Quote:
Originally Posted by Sinned_Elmeerrr
Geohot got arrested for drug trafficking in Mexico last time i checked.
|
Wow, damn. You gotta be a smart mofo to know how to do this shit and then you go full retard and end up getting arrested for drugs? Damn, just damn.
It's stupid that Apple tries so hard to keep people from jailbreaking their devices, why? What the fuck does it hurt to jailbreak it? If it messes up the OS install, you just re-install it... no big deal. There surely is NO way in hell it could actually mess up hardware... is there?
|
|
|
|
|
|
10-20-2012, 08:53 PM
|
#15
|
|
Obsessive iPhone Disorder
iphonehckr is online now
Join Date: Apr 2010
Device: iPhone 5
iOS Version: 6.1.x
iTunes Version: iTunes 11
Carrier: T-Mobile
OS: Mac OS X
Location: New York
Posts: 1,157
Thanks: 190
Thanked 268 Times in 211 Posts
|
To Apple jailbreak means = Piracy
|
|
|
|
|
|
10-20-2012, 09:20 PM
|
#16
|
|
Stay Brutal
robsbrutal is offline
Join Date: Aug 2010
Device: iPhone 4S
iOS Version: 6.0
iTunes Version: iTunes 10
Carrier: Verizon
OS: Mac OS X
Location: Washington
Posts: 907
Thanks: 107
Thanked 185 Times in 126 Posts
|
Apple doesn't wanna be the bigger man and admit that some nobodies thought of things and made their OS amazing and incredible. It would be apple saying they are wrong and we all know that'll never happen
|
|
|
|
|
|
10-23-2012, 06:43 AM
|
#17
|
|
Super Maderotor ??
djmelee is offline
Join Date: Nov 2009
Device: iPhone 4S
iOS Version: 5.1.1
iTunes Version: iTunes 10
Carrier: o2
OS: Windows 7
Location: Pangaea
Posts: 4,117
Thanks: 822
Thanked 1,284 Times in 954 Posts
|
This whole article is a complete copy/paste from a different website (Xsel),
At least give the original author 'sadam' his credit.
|
Game Center - Yetunyahoo Yes I Am A Pirate, A Few Hundred Years Too Late. 'My dog updated my phone, what do I do??' Will You Hit It?
|
|
|
|
|
The Following 2 Users Say Thank You to djmelee For This Useful Post:
|
|
10-23-2012, 06:50 AM
|
#18
|
|
iPhoneaholic
BFoster108 is offline
Join Date: May 2012
Device: iPhone 4S
iOS Version: 6.0
iTunes Version: iTunes 11
Carrier: AT&T
OS: Windows 7
Location: Massachusettes
Posts: 156
Thanks: 35
Thanked 54 Times in 36 Posts
|
I think apple used comex to find out where he found theyre security flaws then when he found them they got rid of him.....waiting to find out who from the jailbreak community is next....if I were apple id try and get pod2g....doubt hed do it though...lol....then again money is money
|
|
|
|
|
|
10-23-2012, 07:50 AM
|
#19
|
|
Obsessive iPhone Disorder
[AMM]Viper is offline
Join Date: Jan 2010
Device: iPhone 5
iOS Version: 6.1.x
iTunes Version: iTunes 11
Carrier: AT&T
OS: Linux
Location: Texaz
Posts: 628
Thanks: 154
Thanked 142 Times in 81 Posts
|
So much for Comex helping Us out, with his time at apple he was helping out the wrong team on the security exploits -.-
|
|
|
|
|
|
10-23-2012, 08:12 AM
|
#20
|
|
Obsessive iPhone Disorder
GorgonSin is offline
Join Date: Oct 2010
Device: iPhone 5
iOS Version: 6.1.x
iTunes Version: iTunes 11
Carrier: AT&T
OS: Mac OS X
Location: USA/UK
Posts: 3,620
Thanks: 2,680
Thanked 696 Times in 530 Posts
|
Quote:
Originally Posted by sadiphone
I dont know why apple makes it hard for JB when all the do is still the ideas of all the cydia tweaks thanks to the JB community. If apples is not carful people are going to go over to android. 
|
only 8% of iphone owners care to jailbreak so if they go to android i doubt apple will acre..llolol
|
13 " MacBook Pro - OSX Lion - i5 8 gigs ram , 500GB HD
iPhone5 16Gig - iOS 6.1.2 (Jailbroken)
iPad4 16Gig - iOS 6.1.2 (Jailbroken)
iPod Touch 4G 64Gig - iOS 6.1.2 (Jailbroken)
|
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
All times are GMT -7. The time now is 12:22 AM.
|
 |
 |
|
|
 |