Apple previews Lockdown Mode(apple.com)
apple.com
Apple previews Lockdown Mode
https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/
742 comments
I am so excited about this news. I understand that some people are pessimistic, and view it as a "giving up" on complete security against nation-states. I think that's the wrong way to analyze the situation.
The dream I have is someone making a phone that is purpose-built to be secure against state actors. Unfortunately, this makes very little economic sense, and probably won't happen (maybe if some rich person started a foundation or something?). The phone would need to have pretty restricted functionality and would not be generally appealing to mass market consumers.
As it stands, securing a mass market modern smartphone, even from just remote attacks, is just intractable. We should not bury our heads in the sand and wishfully think that if they just spend a little more money, close a few more bugs, and make the sandboxing a little better, somehow iOS 16 or Android 13 will finally be completely secure against state actors. The set of features being shipped will grow fast enough that security mitigations will not someday 'catch up'.
This is the next best thing! The more we can give users the freedom to lock down their devices, the more the vision of an actual solution comes into view. This is the first step towards perhaps our only hope of solving this someday - applying formal methods and lots of public scrutiny to a small 'trusted code base', and finally telling NSO group to fuck off.
Even this dream may not pan out, but at least we can have hope.
The dream I have is someone making a phone that is purpose-built to be secure against state actors. Unfortunately, this makes very little economic sense, and probably won't happen (maybe if some rich person started a foundation or something?). The phone would need to have pretty restricted functionality and would not be generally appealing to mass market consumers.
As it stands, securing a mass market modern smartphone, even from just remote attacks, is just intractable. We should not bury our heads in the sand and wishfully think that if they just spend a little more money, close a few more bugs, and make the sandboxing a little better, somehow iOS 16 or Android 13 will finally be completely secure against state actors. The set of features being shipped will grow fast enough that security mitigations will not someday 'catch up'.
This is the next best thing! The more we can give users the freedom to lock down their devices, the more the vision of an actual solution comes into view. This is the first step towards perhaps our only hope of solving this someday - applying formal methods and lots of public scrutiny to a small 'trusted code base', and finally telling NSO group to fuck off.
Even this dream may not pan out, but at least we can have hope.
With this announcement, Apple are saying "we will protect you from state actors", which is a role usually performed by states. Apple is saying "we operate at the same level as nation states; we are a nation-state level entity operating in the "digital world": It's a flag-raise.
It's the first such flag-raise I've seen. Security researchers talk about protections from state actors all the time, and there are tools which support that... but this is the first public announcement, and tool, from a corporation with more spare, unrestricted capital than many countries. It comes at a time when multiple nation states are competing for energy and food security; and Apple are throwing up a flag for a security-security fight (or maybe data-security). This is not just handy tech, it's full-on cultural zeitgeist stuff. Amazing.
It's the first such flag-raise I've seen. Security researchers talk about protections from state actors all the time, and there are tools which support that... but this is the first public announcement, and tool, from a corporation with more spare, unrestricted capital than many countries. It comes at a time when multiple nation states are competing for energy and food security; and Apple are throwing up a flag for a security-security fight (or maybe data-security). This is not just handy tech, it's full-on cultural zeitgeist stuff. Amazing.
This is great, but also clever.
By offering users a more locked down option with clear tradeoffs, (a) users can make a choice between security and convenience, and (b) given user agency, negative press around hacks of not locked-down devices loses potency.
Meanwhile, the choice seems straightforward on most of these...
Lockdown Mode includes the following protections:
- Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
GREAT!
- Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
GREAT!
- Apple services: Incoming invitations and service requests, including FaceTime calls, are blocked if the user has not previously sent the initiator a call or request.
GREAT!
- Wired connections with a computer or accessory are blocked when iPhone is locked.
GREAT! (Used to have to do this yourself with Configurator if you wanted to be hostile border-crossing proof.)
- Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on.
HMM ... there are hardening settings only available through Configurator or MDM profiles. Will those be defaulted on as well?
By offering users a more locked down option with clear tradeoffs, (a) users can make a choice between security and convenience, and (b) given user agency, negative press around hacks of not locked-down devices loses potency.
Meanwhile, the choice seems straightforward on most of these...
Lockdown Mode includes the following protections:
- Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
GREAT!
- Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
GREAT!
- Apple services: Incoming invitations and service requests, including FaceTime calls, are blocked if the user has not previously sent the initiator a call or request.
GREAT!
- Wired connections with a computer or accessory are blocked when iPhone is locked.
GREAT! (Used to have to do this yourself with Configurator if you wanted to be hostile border-crossing proof.)
- Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on.
HMM ... there are hardening settings only available through Configurator or MDM profiles. Will those be defaulted on as well?
Last year I wrote: "In the world I inhabit, I’m hoping that Ivan Krstić wakes up tomorrow and tells his bosses he wants to put NSO out of business. And I’m hoping that his bosses say 'great: here’s a blank check.' Maybe they’ll succeed and maybe they’ll fail, but I’ll bet they can at least make NSO’s life interesting." [1]
Maybe this is the blank check :)
[1] https://news.ycombinator.com/item?id=27897975
Maybe this is the blank check :)
[1] https://news.ycombinator.com/item?id=27897975
I hope Apple expands this quickly through minor updates to the OS rather than waiting for a next major release. This needs faster iteration than anything else.
Quoting what’s in the first release:
> At launch, Lockdown Mode includes the following protections:
> Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
> Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
> Apple services: Incoming invitations and service requests, including FaceTime calls, are blocked if the user has not previously sent the initiator a call or request.
> Wired connections with a computer or accessory are blocked when iPhone is locked.
> Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on.
I’m not a target (I think, and hopefully don’t get to be one), but nevertheless I’d feel safer with this turned on (I very rarely use FaceTime, so not accepting it is not a big deal).
I’d also love more protections. Not allowing specific apps to connect to any network (WiFi included), Apple handling issue reports on apps with urgency (right now they seem to be ignored even when policy violations which are against the user’s interests are reported), etc.
Quoting what’s in the first release:
> At launch, Lockdown Mode includes the following protections:
> Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
> Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
> Apple services: Incoming invitations and service requests, including FaceTime calls, are blocked if the user has not previously sent the initiator a call or request.
> Wired connections with a computer or accessory are blocked when iPhone is locked.
> Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on.
I’m not a target (I think, and hopefully don’t get to be one), but nevertheless I’d feel safer with this turned on (I very rarely use FaceTime, so not accepting it is not a big deal).
I’d also love more protections. Not allowing specific apps to connect to any network (WiFi included), Apple handling issue reports on apps with urgency (right now they seem to be ignored even when policy violations which are against the user’s interests are reported), etc.
This is great but too big of a hammer for most use cases. What I really want is a per-application firewall.
For example, say I would like to install a photo editing application. It would need access to my photos. That is fine, so long as it is not allowed to connect to the Internet (or any other network). There is currently no way to ensure this.
For example, say I would like to install a photo editing application. It would need access to my photos. That is fine, so long as it is not allowed to connect to the Internet (or any other network). There is currently no way to ensure this.
"Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode."
Highly interesting, that Apple is doing this. This is a thing. MS and Google are also taking steps to harden Chromium security against JIT compiler issues with JavaScript. https://www.zdnet.com/article/securing-microsoft-edge-switch...
Highly interesting, that Apple is doing this. This is a thing. MS and Google are also taking steps to harden Chromium security against JIT compiler issues with JavaScript. https://www.zdnet.com/article/securing-microsoft-edge-switch...
Too bad that Google does not offer this same “Lockdown Mode” as Apple does.
Instead, they (Google Play Store) removed our ability to see what “app privileges” that an app would required BEFORE we do the installation step from the Google Play Store. What we got instead was an obfuscated “Data Security” section that is pretty much always “blank”.
My flashlight app should not require GAZILLION app privilegeS nor hide that fact before I can determine whether I can safely install it, much like Apple App Store can do by doing the CRUCIAL pre-reveal of any needed app privilege(s) … for our leisure perusual and applying any applicable but personalize privacy requirement BEFORE we do the app install.
Instead, they (Google Play Store) removed our ability to see what “app privileges” that an app would required BEFORE we do the installation step from the Google Play Store. What we got instead was an obfuscated “Data Security” section that is pretty much always “blank”.
My flashlight app should not require GAZILLION app privilegeS nor hide that fact before I can determine whether I can safely install it, much like Apple App Store can do by doing the CRUCIAL pre-reveal of any needed app privilege(s) … for our leisure perusual and applying any applicable but personalize privacy requirement BEFORE we do the app install.
If Apple was really serious about this, they would add one more feature to Lockdown mode: To delete and scrub permanently and definitively all your iCloud data.
You can close the proverbially "front door" by enabling "Lockdown mode" but if that same government sends a subpoena to Apple, then they will just give them a copy of all your iCloud private data.
You can close the proverbially "front door" by enabling "Lockdown mode" but if that same government sends a subpoena to Apple, then they will just give them a copy of all your iCloud private data.
Apple's been making it real difficult to pick Android lately. Only thing Android still has going for it is the ability to flash custom ROMs, eg CalyxOS or Graphene.
Extreme? This sounds like the way I have my computing environment configured by default (to the extent that I'm able to do so with browser extensions and whatnot).
> Most message attachment types other than images are blocked.
Who wants to bet that this reflects minimum requirements dictated for user experience, rather than reflecting what Apple are actually securing today ?
The correct model here, the one that would actually defeat these adversaries, is to start with what you can actually secure and expand from there, prioritising customer needs. This delivers security improvements for all customers, but it makes the calculus simple for Lockdown customers, whatever Lockdown allows will be OK.
Suppose today Apple has a working safe BMP reader, and a working safe WAV reader, but they're still using their ratty JPEG and MP3 implementations. As described, this feature says you can receive a JPEG attachment (which takes over your phone and results in your cousin who remains in the country being identified as a contact and imprisoned) but you can't listen to the WAV file an informant sent you because that's "dangerous"...
Who wants to bet that this reflects minimum requirements dictated for user experience, rather than reflecting what Apple are actually securing today ?
The correct model here, the one that would actually defeat these adversaries, is to start with what you can actually secure and expand from there, prioritising customer needs. This delivers security improvements for all customers, but it makes the calculus simple for Lockdown customers, whatever Lockdown allows will be OK.
Suppose today Apple has a working safe BMP reader, and a working safe WAV reader, but they're still using their ratty JPEG and MP3 implementations. As described, this feature says you can receive a JPEG attachment (which takes over your phone and results in your cousin who remains in the country being identified as a contact and imprisoned) but you can't listen to the WAV file an informant sent you because that's "dangerous"...
This seems to mimic, or at least rival, Google's Advanced Protection Program which has been running for a few years to offer similar protections to Google/Android users.
My concern about enabling this would be that I'm unsure how much this puts barriers in place to prevent the owner of an account regaining access should it be stolen by a threat actor (i.e. could this backfire on the account owner?).
It's still unclear to me how much Apple really protects against (for example) sim swaps to take over an iCloud account - and the documentation around when they'll truly insist on having something like a Recovery Key if it's enabled is sparse. It almost reads as if the right amount of begging will socially engineer access to a locked iCloud account by a threat actor with the right personal information to hand, which if coupled with Lockdown mode, seems pretty dangerous to the true account holder.
My concern about enabling this would be that I'm unsure how much this puts barriers in place to prevent the owner of an account regaining access should it be stolen by a threat actor (i.e. could this backfire on the account owner?).
It's still unclear to me how much Apple really protects against (for example) sim swaps to take over an iCloud account - and the documentation around when they'll truly insist on having something like a Recovery Key if it's enabled is sparse. It almost reads as if the right amount of begging will socially engineer access to a locked iCloud account by a threat actor with the right personal information to hand, which if coupled with Lockdown mode, seems pretty dangerous to the true account holder.
This lockdown mode looks like what ought to be default security behavior.
Weren't SMS messages used to root iPhones in one exploit?
https://www.wired.com/story/imessage-interactionless-hacks-g... https://www.cnet.com/news/privacy/researchers-attack-my-ipho...
https://www.wired.com/story/imessage-interactionless-hacks-g... https://www.cnet.com/news/privacy/researchers-attack-my-ipho...
since it has been memory holed.
apple is/was a part of prism (https://www.theguardian.com/world/2013/jun/06/us-tech-giants...)
"An Apple spokesman said it had "never heard" of Prism."
apple is/was a part of prism (https://www.theguardian.com/world/2013/jun/06/us-tech-giants...)
"An Apple spokesman said it had "never heard" of Prism."
If you are "a target" and going to take measures of basically disabling everything on your iPhone, wouldn't it just make sense to get a burner dumb phone?
Hasn't this been happening for years (drug dealers, anonymous, etc..)?
Hasn't this been happening for years (drug dealers, anonymous, etc..)?
Most of the features of this lockdown mode should be on by default.
When reading through this list at each feature I can't help but go "why isn't this in regular iOS?"
[Disclaimer: I worked in Apple Red Team]
What if this isn’t a good news for 99% of Apple users?
That’s obviously an amazing measure for the 1% high targets out there.
But what about the other 99%? Does that create an incentive for Apple to strengthen Lockdown Mode security to the detriment of the regular mode (should we call it Unsafe Mode)?
I’m afraid that this architecture will make it harder to prioritize security features or fixes for the 99% users. Developers bandwidth is limited, they can’t fix all bugs. Hence if you have to choose between one bug impacting the 1% most important users (from a security standpoint) versus one bug impacting the 99% others, which would you choose?
Would such an architecture have led to the emergence of Blastdoor[1] - which attempts at mitigating iMessage attachement exploits, but is now useless in Lockdown mode?
My hope here is that by reducing attack surface, Lockdown mode will make exploits much easier to fix (as they’ll target a limited area), allowing to strengthen the system core while freeing bandwidth to implement longer term, Blastdoor like mitigations.
[1] https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...
What if this isn’t a good news for 99% of Apple users?
That’s obviously an amazing measure for the 1% high targets out there.
But what about the other 99%? Does that create an incentive for Apple to strengthen Lockdown Mode security to the detriment of the regular mode (should we call it Unsafe Mode)?
I’m afraid that this architecture will make it harder to prioritize security features or fixes for the 99% users. Developers bandwidth is limited, they can’t fix all bugs. Hence if you have to choose between one bug impacting the 1% most important users (from a security standpoint) versus one bug impacting the 99% others, which would you choose?
Would such an architecture have led to the emergence of Blastdoor[1] - which attempts at mitigating iMessage attachement exploits, but is now useless in Lockdown mode?
My hope here is that by reducing attack surface, Lockdown mode will make exploits much easier to fix (as they’ll target a limited area), allowing to strengthen the system core while freeing bandwidth to implement longer term, Blastdoor like mitigations.
[1] https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...
What if there is a little device that acts like network firewall and router appliances but somehow the phone proxies all connectivity via it. Something to carry around that shows ingress and egress connections, calls and anything in between. You can either set an allowed or blocked list, detects cell connection mitm attacks and spikes in traffic (to detect leaks). Mobile phones are like desktop computers and will always have security issues. It only makes sense to firewall them.
First, lets talk in the foggy dreamland of this article.
I can't imagine the threats security researchers deal with every day. And their innovative solutions. Extracting live code from samples to inject in other malware. Wow, so cutting-edge. It's wonderful to talk about, no stress there, no drama. We don't want wear and tear on our machines.
Like the article states, we're spending millions and billions on these problems.
And lockdowns are an innovative approach. I've been thankful for device lockout in the field before. It's saved my bacon. Captures the favorite philosophy of strong regulatory control. Nice, has network effects for other political goals. Very cool.
Better than Kevorkianing or Bricking a machine in the field.
Oh God, Oh God, Oh God. Sorry for that narrative-scape shattering. Dementia is a serious issue. Ok, back to sanity.
Some really fucking smart people showed me a study on evolutionary computation and diversity in investigator-guided processes. Hand-edited synthetic organisms may be less evolutionary successful than purely evolved ones.
Like my storytelling, right? It's a fucking hot mess that isn't excersing my audiences mind as much as a more diverse author population.
Oh God, there I am breaking down story-wise. Back to stability. We have political goals like reduction of 99% of security threats. And the perfect is the enemy of the good, right?
I'm so sorry for my slips there, I know you lost time with loved ones and reading other comments talking about this in a more professional tone that captures the point.
In closing, I'd like to thank the sponsors who kept me fed for years.
I can't imagine the threats security researchers deal with every day. And their innovative solutions. Extracting live code from samples to inject in other malware. Wow, so cutting-edge. It's wonderful to talk about, no stress there, no drama. We don't want wear and tear on our machines.
Like the article states, we're spending millions and billions on these problems.
And lockdowns are an innovative approach. I've been thankful for device lockout in the field before. It's saved my bacon. Captures the favorite philosophy of strong regulatory control. Nice, has network effects for other political goals. Very cool.
Better than Kevorkianing or Bricking a machine in the field.
Oh God, Oh God, Oh God. Sorry for that narrative-scape shattering. Dementia is a serious issue. Ok, back to sanity.
Some really fucking smart people showed me a study on evolutionary computation and diversity in investigator-guided processes. Hand-edited synthetic organisms may be less evolutionary successful than purely evolved ones.
Like my storytelling, right? It's a fucking hot mess that isn't excersing my audiences mind as much as a more diverse author population.
Oh God, there I am breaking down story-wise. Back to stability. We have political goals like reduction of 99% of security threats. And the perfect is the enemy of the good, right?
I'm so sorry for my slips there, I know you lost time with loved ones and reading other comments talking about this in a more professional tone that captures the point.
In closing, I'd like to thank the sponsors who kept me fed for years.
> Wired connections with a computer or accessory are blocked when iPhone is locked.
Damn... if this was something that could be enabled by typing the pin in wrong, it would be the death of modern phone forensics. Actually, I would rather this be the default after a device is powered on... let me "restart in non-safe mode" when I need it.
Damn... if this was something that could be enabled by typing the pin in wrong, it would be the death of modern phone forensics. Actually, I would rather this be the default after a device is powered on... let me "restart in non-safe mode" when I need it.
> Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
That's very cool actually. You can keep JS enabled but choose to make it run more slowly in exchange for better sandboxing
That's very cool actually. You can keep JS enabled but choose to make it run more slowly in exchange for better sandboxing
Could a security expert enlighten me: is Windows more secure today than macOS, if we purely take OS-level and hardware-level security measures and ignore subjective factors? (like marketshare, attractiveness of targets, etc.)
Windows has all sorts of buzzwordy-sounding security features: Microsoft Defender Application Guard (Hyper-V for untrusted websites & Office files), kernel virtualization-based security (VBS), Code Integrity Guard, Arbitrary Code Guard, Control Flow Guard, and Hardware-enforced Stack Protection.
It's extremely hard to compare the two on a deep technical level (beyond "modern OS's are safe, install updates, you'll be fine") without having deep security experience. Any professional insights?
Windows has all sorts of buzzwordy-sounding security features: Microsoft Defender Application Guard (Hyper-V for untrusted websites & Office files), kernel virtualization-based security (VBS), Code Integrity Guard, Arbitrary Code Guard, Control Flow Guard, and Hardware-enforced Stack Protection.
It's extremely hard to compare the two on a deep technical level (beyond "modern OS's are safe, install updates, you'll be fine") without having deep security experience. Any professional insights?
This is great. Here in Australia, when you pass through the border, the goons can ask you for your phone, computer, devices etc. without a warrant. They’re not allowed to compel you to hand over passwords, PINs or have you unlock it for them (without a warrant) though, but apparently they’ll often imply that you have to, and if you don’t they can confiscate the devices for some time.
This mode sounds excellent, because all they can do without a warrant is try and attack it with a Celebrite or Graykey device, so having the extra protection from physical connection and other attacks sounds awesome.
I expect to always enable this while I’m doing international travel anywhere.
This mode sounds excellent, because all they can do without a warrant is try and attack it with a Celebrite or Graykey device, so having the extra protection from physical connection and other attacks sounds awesome.
I expect to always enable this while I’m doing international travel anywhere.
>Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
This should be ON by default. It would force webdevs to write efficient websites.
This should be ON by default. It would force webdevs to write efficient websites.
Does this offer any protection after you are already pwned? Is the expectation that you have it permanently on if you are a high value target or do you turn it on temporarily before clicking on a link for example?
putting rich media like images, GIFs, video etc embedded inline in chat applications presents a huge attack surface.
i'm even suspicious that signal does it.
if you really want to design a secure messaging system it needs to handle text ONLY.
i'm even suspicious that signal does it.
if you really want to design a secure messaging system it needs to handle text ONLY.
This is a huge step forward for iPhone users. Look, I get it. From the typical HN perspective, this potentially looks like a lot of hype. But many of you aren't looking at from a high level.
In the world we are now living in; even what's happening in the United States right now, being able to protect yourself from well-funded, determined attackers for the average person couldn't come at a better time.
There's a huge gap between Fortune 500 executives, government officials, etc. and regular people in terms of the resources available to them to prevent state-sponsored attackers. It doesn't take much these days to go from a nobody to being on somebody's radar.
If you're a woman seeking an abortion in a state where it's illegal or severely restricted, you could be the target of malware from your local or state government or law enforcement. In Texas, you can sue anyone who aids and abets a woman who attempts to get an abortion for $10,000, which is enough to get someone to trick someone into installing malware on a phone.
No, it's not China or Russia coming for you but it doesn't take much to ruin someone's life.
I don't think this is virtue signaling or marketing hype by Apple; if anything, this is right in alignment with the stance they've had on privacy for years. Even for a company the size of Apple, putting up $10 million to fund organizations that investigate, expose, and prevent highly targeted cyberattacks isn't pocket change.
At the end of the day, this is all good news for user privacy and security going forward. I also suspect if I lockdown my iPhone, my other compatible devices using the same Apple ID will also lockdown. No IT department required.