back

by Obscurity4340·2y ago·view on hn ↗
Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface.

And everybody parrots the nonsense caveat that everyone shouldn't use it, only those special enough should like it was a zero-sum game or scarce resource. Everyone should use it because it disables a lot of nonsense that doesn't serve you and probably even saves battery power. Also, the more people use it, the less it can be used to fingerprint specific users.

9 comments
It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people.

I'd prefer a third mode that compromises between the two, perhaps letting you lower your security for a few minutes when you need the extra functionality. For example, Safari could detect when JavaScript is being slow and pop up an offer to re-enable JIT.

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.
That fact that Apple blended iMessages, SMS text messages, and email into an extremely confusing mess may also be the reason for so many security issues related to iMessage. Perhaps not directly responsible for this particular NGO exploit, but I find iMessage's logic and behavior bewildering at times.

For example: If you stop using WhatsApp for example, nothing bad happens if you try to send messages another way. But if you stop using iMessage, then you can no longer send a normal SMS to someone with whom you've communicated before using iMessage. The Messages app will tell you, "You must enable iMessage to send this message", even if it's an SMS text message to a normal phone number! Why shouldn't that work?

To be able to again send SMS text messages to someone you used to talk with is to disable iMessage of course, then sign out of Facetime (who could imagine that as a necessary step?), sign out of iCloud, reboot the iPhone, and wait some minutes to hours to days until you are "deregistered" from iMessage. I'm talking about the same phone with the same SIM chip. The problem can become much worse if you've switched phones or SIM card.

The source code for iMessage must be a nightmare having integrated SMS and email and a new messaging system all together.

There is no email (the protocol) in iMessage (the app). You can use somebody's email address as the recipient for an iMessage (the protocol). No email is ever sent.
> For example: If you stop using WhatsApp for example, nothing bad happens if you try to send messages another way. But if you stop using iMessage, then you can no longer send a normal SMS to someone with whom you've communicated before using iMessage. The Messages app will tell you, "You must enable iMessage to send this message", even if it's an SMS text message to a normal phone number! Why shouldn't that work? To be able to again send SMS text messages to someone you used to talk with is to disable iMessage of course, then sign out of Facetime (who could imagine that as a necessary step?), sign out of iCloud, reboot the iPhone, and wait some minutes to hours to days until you are "deregistered" from iMessage. I'm talking about the same phone with the same SIM chip. The problem can become much worse if you've switched phones or SIM card.

That’s simply not true. I just turned off iMessage and instantly switched to the Message app and sent a SMS to someone I have a iMessage chat with and it worked without any problems

For a new iPhone user are there alternatives to using iMessage for texts to avoid this?
"but but my precious text bubble colors!!1"

Yeah, it seems iMessage in iPhone is like IE in Windows, a needlessly ingrained mess for market segmentation purposes

That is because iMessage has the same function as the night men in the Eagles song Hotel California:

   "Relax,” said the night man, “We are programmed to receive
   You can check out any time you like but you can never leave"
Somehow fittingly that song is about the excesses of American culture ... also about the uneasy balance between art and commerce [1] according to one of its authors, Don Henley while also having been interpreted as being all about American decadence and burnout, too much money, corruption, drugs and arrogance; too little humility and heart and a metaphor for hedonism, self-destruction, and greed ....

[1] https://www.smoothradio.com/features/the-story-of/eagles-hot...

> I would argue that iMessage is way to problematic to be used safely, at all.

Maybe I'm missing something but every single time the only part of iMessage (actually Messages.app) that is insecure is the bit that automatically unfurls attachments and the payload is exploiting a vulnerability elsewhere. So any other app unfurling the attachment thus triggering the payload would be equally vulnerable.

Imagine ping had a privilege escalation vulnerability and someone does ssh foomachine ping <payload> to get root, it'd be a bit weird to call out ssh as being unsafe because it can execute commands, one of them being able to privesc.

Disabling ssh would be a mitigation, and I do wish Messages would disallow unfurling for senders not in the recipient's contact list.

> So any other app unfurling the attachment thus triggering the payload would be equally vulnerable.

What you're missing is that iPhone's app sandboxing applies to other apps, not to iMessage.

Sure, imessage does have blastdoor and some sandboxing, but it also still has imagent: https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...

imagent runs as root and processes incoming messages. whatsapp or signal or whatever cannot ship an unsandboxed always on daemon like imagent.

signal/whatsapp/etc have to parse incoming messages inside the app sandbox. iMessage doesn't.

(I'm saying this all very confidently because the quickest way to get the right answer is to be confident about the wrong one and get corrected by a techbro)

I'm no security pro, but last night I iMessaged a friend a TikTok video and according to him, the link initiated an App Clip. Perhaps it's totally safe and I'm just naive but it just seems like the risks of a link initiating code like that outweigh any rewards. Even if it's totally safe and all involved can be trusted, that experience is enough to creep me out.
It’s an attack vector because it’s convenient. If iMessage didn’t exist people would email you exploits.
Are there zero click exploits in email?
> It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

If you are using a phone, you have a phone number. Targeting the phone and SMS handling apps will always be the go-to vector for these sorts of attacks, because you don't want to tell your customer that they can only spy on targets that have Evernote installed and configured.

I agree, and there really need to be controls on it. I understand they want the "IMessage Network" to have predictable functionality, but I care about security more, and IMessage has been demonstrably unsafe for a long time.

I would really prefer to keep it text-only, and am fine with the goofy symbols. If they want to make photo exchange safe, they have the hardware to securely sign images taken on-device and only allow those.[1] (Although that would probably piss off regulators even more.)

[1] With some work, this could be a new feature, used to demonstrate images haven't been altered. With some lockdown of the clock, it could have secure timestamps. (Location could still be spoofed with a GPS hijack.)

It's also insecure. The sync keys for iMessage are backed up in the non-e2ee iCloud Backup, which means that iCloud serves as a key escrow for iMessage's e2ee, rendering it useless (as Apple, which is definitively not an endpoint, has a private key of the participant and can read all the messages in real-time).

iMessage should be assiduously avoided.

This is less true now, with the option to enable “advanced data protection”. Turning this setting on disables Apple’s access to your iMessage keys along with a bunch of other stuff, though of course if you get locked out, Apple can’t help you
You don't have to use iCloud Backup.
I’d settle for being able to toggle the individual controls (specifically iMessage attachments) instead of full lockdown mode.
YES! Current lockdown mode proposition of all-or-nothing is inconvenient.
I think attackers would just try to make the system offer to disable security whenever possible then. Anything as easy as clicking an already offered option by the OS itself will be used often enough to negate most of the security benefits of that mode IMO, meaning you deal with it being slower be default and probably not as secure as you think because people will opt out often for convenience, so the worst of both worlds.

As I understand it this was a real problem with earlier versions of Windows where it kept asking for admin privileges all the time for simple things, and people got conditioned to just authorize it. They made a concerted effort to provide APIs that didn't require it for most actions to combat this.

You can turn off lockdown mode per site and per-app in safari. I had to do that to get Obsidian to work, but I also use it for specific trusted sites.
What do you mean "per-app in safari"? I'd like to turn it on globally, with a single exception: I want to be able to continue using shared photos albums with my two best friends.

I don't care enough about JS performance or, more generally, the mobile web, to want to disable it on safari, or even parts of it.

The only bothersome issue I see on lockdown mode is not being able to search through text messages anymore :’(

Please bring that back (safely) if you can, Apple.

Wait, seriously? Do you know what the rationale is?
>And zero-day spyware is usually targeted towards important individuals,

Yeah but have you ever had someone ImportantTM's old phone number?

What about their IP?

> Apple wants to avoid making iOS feel slower or clunkier than Android

Then they should let us selectively disable all background processes

> Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface.

If they didn't want people to have all of the background stuff running, they wouldn't put it on there in the first place. It's not super surprising that they want people to use the features (whether "nonsense" or not) that they purposely put there.

Capitalist view: If they didn't emphasize it, some first-time Apple customers might be convinced by concerned friends and family to enable Lockdown Mode by default, and then might complain to Apple / return their device because it "doesn't do the things it was advertised to do" (because those features don't work in Lockdown Mode.)

Realpolitik view: repressive regimes probably only allow Apple to release devices with this feature available, as long as they don't heavily push it / make it the default. If Lockdown Mode defaulted to "on" in China, and so was used by the majority of users, then Apple would be quickly booted out of China.

Yes, this is the angle I've been trying to capture. Its realpolitik, thank you for helping crystalize that. But I maintain that it extends to the US as well in terms of cooperation with domestic enforcement bodies.
How about the alternative capitalist view that they don't have to spend as much time on QA in lockdown mode? Seems like one of those things that could cause all kinds of unintentrd consequences across apps.
Many websites simply don't work with it enabled
I use Lockdown Mode on my Mac because I don’t use iMessage, FaceTime, or other apple services on that device. It’s literally just a computer for software dev and maybe YouTube videos. I haven’t noticed any difference with web content either, but I also use Firefox / Chrome instead of Safari. What I would really like to see is options. For example on iOS I use shared photo albums, so it would be nice to keep that feature but disable all the other capabilities.
> I haven’t noticed any difference with web content either, but I also use Firefox / Chrome instead of Safari

Lockdown mode only affects Safari. If you use another browser, it doesn't make any difference.

Here are some features that are disabled in Safari when lockdown mode is enabled:

- JIT

- Remote fonts

- WebAssembly

- WebGL

- WebRTC

- PDF Viewer

- MP3 Playback

- Gamepad API

- Web Audio API

- Speech Recognition API

- MathML

- JPEG 2000

- MediaDevices.getUserMedia()

You can configure most of those in Firefox and Chrome, but it has to be done manually and cannot be disabled easily on a per-site basis like in Safari.

> For example on iOS I use shared photo albums, so it would be nice to keep that feature but disable all the other capabilities.

I'm in the same boat. I was a bit confused, since I'm pretty sure I read somewhere that you could selectively disable it for some "apps", but I've never found out how to disable it for photos specifically.

My requirements of my phone being otherwise slim, I didn't encounter any other issue with lockdown mode.

Ironically, you need it all the more specifically on the devices you like to use those services with. Even moreso than on the devices you don't use them with. The fact of the matter is Lockdown makes iMessage as safe as is possible (I still wouldn't take the risk, personally, but YOLO). It doesn't hurt to be using Lockdown everywhere.
Lockdown mode? How do I enable it? As someone who owns a Macbook as their only Apple product, I hate seeing or dealing with Apple pushing their services to me
Sounds like it's not foolproof unless you enable lockdown mode on all devices.
I’ve noticed a lot of things that start going wonky with Lockdown mode on.

Continuity seems to go right out the window for me for one, which is something I really rely on.

Airplay also seems to become really temperamental.

All of this could just be my network but it only seems to have been the case since switching to lockdown mode.

Also, screen time requests don’t work which is a real pain.

Lockdown mode disables shared albums, which I use a lot.

I would rathe have a full app firewall with configurable profiles instead of lockdown mode.

> Everyone should use it because it disables a lot of nonsense that doesn't serve you and probably even saves battery power.

Lockdown mode acts as a natural ad block which is great (as a reader). But it also disables JIT. I assume this causes wasted CPU cycles and perhaps, on balance, worse battery life?

On the balance, I have found the opposite to my experience. Your phone spends more time passively carrying out a multitude of background tasks and analystics stuff then it does with you actively web browsing.
> They really do try to talk you out of it.

Who? Apple? I can't find any statements from them begging us not to use it. It's also a dumb argument since they can just --not-- release the feature if they don't want us to use it.

Just like disabling JavaScript in the browser by default, or using LTSC versions of Windows --- it's propaganda to keep you on the path they want, and not the path you want, because there are powerful interests in the former direction.
If this was true Apple would have never released the lockdown mode feature. A good conspiracy theorist will drop a theory when there's clear proof they're not up to anything.
Much like LTSC and the ability to disable JS still remains, it's merely a concession they don't actually want you to use, and in the case of lockdown mode, serves as a feature to tick off their privacy-oriented marketing.