Checkm8 creator says his iPhone exploit requires physical device access and lacks persistence after reboot, but will make jailbreaking more accessible and safer
@dangoodin001 interviews @axi0mX and gets all the details on the new iOS bootrom exploit. https://arstechnica.com/... Dan Goodin / @dangoodin001 : The jailbreaking exploit released Friday prompted lots of security concerns. But it turns out it's not remotely exploitable, doesn't have persistence, and can't bypass the Secure Enclave. That's not to say Checkm8 isn't impressive and important. Read on for why. https://twitter.com/...
HACKED! Verbose booting iPhone X looks pretty cool. Starting in DFU Mode, it took 2 seconds to jailbreak it with checkm8, and then I made it automatically boot from NAND with patches for verbose boot. Latest iOS 13.1.1, and no need to upload any images. Thanks @qwertyoruiopz pic.…
Revealed on Friday, the ‘Checkm8’ exploit isn't a big deal to #iPhone or #iPad users, and here's why https://appleinsider.com/... https://twitter.com/...
I'm with Eva here and to the various people pointing out you need physical access to jailbreak an iPhone: this is the stalkerware threat model. https://twitter.com/...
“You don't have to stay on an older version that has security vulnerabilities just so you can jailbreak, and you won't have to wait until a jailbreak is available. This is going to make jailbreaking a lot more accessible and a lot safer for everyone” https://arstechnica.com/...
This @arstechnica article has a great interview with @axi0mX on the ramifications of their BootROM exploit: https://arstechnica.com/... Spoiler: it's awesome work, but not as scary as most may think (because of the Secure Enclave and persistence is still hard, etc.)
The jailbreaking exploit released Friday prompted lots of security concerns. But it turns out it's not remotely exploitable, doesn't have persistence, and can't bypass the Secure Enclave. That's not to say Checkm8 isn't impressive and important. Read on for why. https://twitter.c…