Just because you turned off your phone doesnât mean the NSA isnât using it to spy on you.
Edward Snowdenâs latest revelation about the NSAâs snooping inspired an extra dose of shock and disbelief when he said the agencyâs hackers can use a mobile phone as a bug even after itâs been turned off. The whistleblower made that eye-opening claim when Brian Williams of NBC Nightly News, holding his iPhone aloft during last Wednesdayâs interview, asked, âWhat can the NSA do with this device if they want to get into my life? Can anyone turn it on remotely if itâs off? Can they turn on apps?
âThey can absolutely turn them on with the power turned off to the device,â Snowden replied.
Snowden didnât offer any details on this seemingly magical feat. But a group of particularly cunning iPhone hackers say itâs possible. They also say you can totally and completely turn off your iPhone so no oneâ"not even the NSAâ"can use it to spy on you.
Your Phone Is Playing Dead
Like any magic trick, the most plausible method of eavesdropping through a switched-off phone starts with an illusion. Security researchers posit that if an attacker has a chance to install malware before you shut down your phone, that software could make the phone look like itâs shutting downâ"complete with a fake âslide to power offâ screen. Instead of powering down, it enters a low-power mode that leaves its baseband chipâ"which controls communication with the carrierâ"on.
This âplaying deadâ state would allow the phone to receive commands, including one to activate its microphone, says Eric McDonald, a hardware engineer in Los Angeles. McDonald is also a member of the Evad3rs, a team of iPhone hackers who created jailbreaks for the two previous iPhone operating systems. If the NSA used an exploit like those McDonaldâs worked on to infect phone with malware that fakes a shutdown, âthe screen would look black and nothing would happen if you pressed buttons,â he says. âBut itâs conceivable that the baseband is still on, or turns on periodically. And it would be very difficult to know whether the phone has been compromised.â
After Snowden told Williams his powered-down phone could be used as an eavesdropping tool, security consultant Robert David Graham immediately responded with a blog post arguing the trick is impossible. He soon amended the post to concede the NSA could, in fact, alter a phone ahead of time to enable that ultra-sneaky bugging. Its methods could range from a web exploit, like the 2011 Jailbreakme hack that disassembled the iPhoneâs security restrictions when users visited a carefully crafted webpage, to actually intercepting shipped phones before they reach users. That latter possibility might have sounded apocryphal until journalist Glenn Greenwald published photos last month showing the NSA opening boxes of Cisco routers to insert backdoors into the gear. âWith physical access, they could change the chips, the memory, the ROMs, the power system, anything they want,â Graham says.
But paranoid users seeking temporary privacy from NSA uber-hackers neednât resort to Snowdenâs famous precaution of putting phones in the fridge. Instead, McDonald suggests users turn off their iPhones by putting them into device firmware upgrade (DFU) mode, a kind of âpanicâ state designed to let the phone reinstall its firmware or recover from repeated operating system crashes. In DFU mode, says McDonald, all elements of the phone are entirely shut down except its USB port, which is designed to wait for a signal from iTunes to install new firmware. âItâs like an innocent little kid in kindergarten,â says McDonald. âIt doesnât know how to turn on the lights or the sound, it only knows how to turn on the USB port.â
Donât worry: Itâs easy to get your phone out of that state with no ill effects.
Total Radio Silence
To enter DFU mode, plug your iPhone in any power outlet or computer USB port. Then hold the power button. After three seconds, start holding the home button, too. Keep both buttons pressed for 10 seconds, then release the power button while continuing to hold the home button for another ten to fifteen seconds.
That intermediate step of holding the power button and the home button together, McDonald says, sends a âhardware resetâ to the phoneâs power management unit that overrides any running software, including any malware designed to fake a shutdown. âItâs a feature burned into the hardware,â says David Wang, another iPhone hacker and member of the Evad3rs. âAs far as I know, thereâs nothing that can stop that hard power-off.â
If youâve successfully entered DFU mode, the phone wonât turn on when someone holds the power button, nor will it power up when the phone is plugged into a power source. With your phone in this temporary undead state, you can go about your private conversation with the closest thing possible to full assurance that your phone isnât listening. To power the phone back on, hold the the power button and home button together until the Apple logo appears.
Hereâs a video tutorial on putting your iPhone into DFU mode:
An easier way of entering complete shutdown, says Wang, is a straightforward hardware power-offâ"simply hold the home and power buttons simultaneously for 10 seconds without the DFU button sequence. âIf the phone is in such a low-level state, I donât see how itâs possible for anything to interact with the baseband,â he says.
But McDonald cautions that unless you go into DFU mode, the phone partially reboots before turning off, as shown by the Apple logo appearing before the screen goes dark. During that brief window, the bootloaderâ"a portion of the iPhoneâs software that loads before the operating systemâ"awakes for a second or so, long enough that any highly advanced malware might be able to take over, spoof that dark screen shutdown and leave your phone vulnerable. âIf youâre going to be paranoid, you might as well be super paranoid,â McDonald reasons.
Of course, McDonald and Wang both caution that if you enter DFU mode incorrectlyâ"say, by screwing up the timing of the shutdown procedureâ"itâs possible for malware to detect your intention and fake even that obscure state of semi-death. But if the button sequence is performed correctly, no malware will be able to override it. And even imagining malware clever enough to anticipate and impersonate DFU mode starts to stretch credibility, says McDonald. âAt that pointâ he says, âyouâre talking about a countermeasure to a countermeasure to a countermeasure.â
Countermeasures against countermeasures are exactly the stock-in-trade of the worldâs best hackers. But even paranoia has its limits. At some point, it may best to give up the game and leave the phone at homeâ"or in the nearest fridge.
No comments:
Post a Comment