Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No. Apple updates are digitally signed by Apple with a key only they possess.

This is also why jailbreaking an iPhone is so difficult. Nobody else has that key, so the best you can do is find a bug in something Apple approved and try to gain root with it.

There hasn’t been one of those in… years… and as for one that will allow an unsigned persistent update? Not since iOS 9. Almost a decade ago. Nobody has found a persistent jailbreak since.

The last true chip exploit, which Apple cannot patch, was with the A10 Fusion seven years ago. It also required a USB cable, a Mac to inject the payload, and you had (and have) to connect the phone to the Mac every time you reboot it because it can’t persist itself.



It is still however an attack vector.


> signed by Apple with a key only they possess.

Oh, so its okay as long as we trust Apple to tell us when their key is stolen...


I mean if you don't have that trust you shouldn't use an Apple device at all


Yeah if that’s gone and we don’t know it, we’re all a bit screwed.


Everything secure requires a key of some abstraction.


That’s literally how every secure mobile phone works. Same for Samsung, same for Pixel, same for GrapheneOS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: