Black Box Version 1.0 Bedienungsanleitung Seite 29

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 31
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 28
Implications
• Device appears locked to user
• Processes “privileged” MDM commands
Can Install Profile, and re-enroll in MDM
• Access protected files via ssh (jb, obv.)
• Backup to a new desktop (if not encrypted)
• etc..
• Doesn’t survive a second lock or power cycle
• Bug is reasonably repeatable
So What?
• Couldn’t think of any useful “application”
• But implications are interesting
When you lock the device....
....you expect the keys to be thrown away
....and encryption to be enforced.
• What’s the mechanism for this bug?
Can it be triggered in userland?
Could an app periodically trigger the bug?
Would ensure it appears locked, but not truly secure
Though the device appears locked (and cannot be accessed through
the screen), the data is no longer protected because the keys remain in
memory. So operations like sync, installing profiles, etc., can all
succeed.
However, once the device has been unlocked and locked again, it's no
longer broken -- becuase unlocking the device via the screen sets that
(possibly imaginary) flag, which then ensures the keybag is erased the
next time it's locked. (and, obviously, turning the device off clears the
keybag from memory as well).
Seitenansicht 28
1 2 ... 24 25 26 27 28 29 30 31

Kommentare zu diesen Handbüchern

Keine Kommentare