top | item 32177966

(no title)

Ansil849 | 3 years ago

> So this would have prevented Hermit as you'd need to install a new configuration profile to allow sideloading of applications from that source.

Are you sure that's true? I haven't seen a Hermit sample firsthand, but from everything I've read about it targets did not need to install an MDM profile, they simply needed to click a link. Looking at Apple's distribution guidelines - https://support.apple.com/en-bw/guide/deployment/depce7cefc4... - MDM is listed as one option, and simply going to a link is listed as another:

> There are two ways you can distribute proprietary in-house apps: > > Using MDM > > Using a website

It seems like the latter was used, so I don't think installation of a custom profile was required, which brings me back to my original question of whether Lockdown would have prevented it.

discuss

order

buran77|3 years ago

An yet I wouldn't immediately jump to the conclusion that it's "security theater" because it only protects you from the vast majority of attacks and it may still be vulnerable to many 0-days. By this definition we have nothing but security theater in everything. And as the saying goes, if everything is security theater, nothing is security theater.

Ansil849|3 years ago

Lockdown is literally presented by Apple as being for people targeted by APTs like those developed by NSO Group, therefore I expect it to prevent attack vectors used by these APTs, like exploitation of the Developer program to facilitate sideloading malicious apps. I don't feel like this is an unrealistic expectation, and not having the mode actually do that amounts to security theater, which is a far cry from decrying everything as such.

olliej|3 years ago

Running an enterprise app still is not a trivial single tap on iOS.

Obviously with the new EU legislation mandating support for unrestricted malware of this kind, that's kind of a moot factor in EU and EU-adjacent markets.

Ansil849|3 years ago

> Running an enterprise app still is not a trivial single tap on iOS.

Yes, but still successful, as Hermit demonstrated. So my question is whether Lockdown mode would have prevented APTs like Hermit which it claims to prevent against. If not, then the move is security theater which doesn't address the actual flaws (like poor vetting into the Enterprise Program) being successfully leveraged in the wild.