@norkler

1 Followers
38 Following
6 Posts
Computer security and thunderstorms are my jam
@Petesmom @evacide You might be able to update it by plugging it into a computer and doing it that way rather than OTA
@x_cli @mshelton Would the U.S. government forcing Signal to record additional metadata be compelled speech and is that why it hasn’t been done?
@jordan @lorenzofb They’ve got a research arm that seems to find a lot of vulnerabilities in Apple OSs and I got to imagine those researchers are rolling their eyes
@azonenberg @mttaggart Correct, only Macs have the hardware LED (for the camera only)
@azonenberg @mttaggart I agree that that would be optimal, but since the “LED” is just pixels on the display, I’m guessing pure hardware isn’t trivial (especially when dealing with brightness, etc., which might add software-controllable attack vectors even if it’s hardware-controlled). iPhone 16+ and iPad Pro M4+ indicator light feature appears to run the software handling the light at a higher privilege level than the kernel (some sort of hypervisor?) so even a kernel compromise can’t stop it.
@azonenberg @mttaggart The JAMF article really should have mentioned that there’s a new hardware security feature that makes this attack no longer possible. On newer iPhones and iPads, the indicator lights are handled by the display controller and a “secure eXclave”.