Key iPhone Source Code Leaked to Github 02-08-2018, 08:00 PM
#1
This is a Dev-Ops nightmare.
Key source pertaining to some of Apple's most trusted, proprietary boot-regulatory code has been leaked this morning to GitHub. GitHub has since taken it down but it was estimated that the code was up for about a day, as the DMCA is clearly notarized for February 7, 2018.
To quote Motherboard, Vice's tech arm:
This is bad news for Apple, assuming the code was live and is therefore probably forked into a private repo or part of underground source trading among hackers, crackers and code thieves around the world.
However, there is no way to know if this code is the whole iBoot source code, as indicated by the user who leaked it. There is virtually no way to tell whether or not this is the full repo, but evidence suggests that the DMCA, filed by Apple's attorney's, points toward this being valuable.
The iBoot code is essential for the secure signature verification of the rest of the boot process. Its design is that of the Windows BIOS. It verifies kernel integrity, executes boot-specific code and regulates the entire process of Apple's iOS every boot.
It is no doubt that Apple is scrambling to find the source of the leak but it may already be too late, according to some security researchers. This is not only a PR nightmare for Apple and their attorney's but also a bad sign for the big bounty program as a whole. The bug bounty program - which currently offers $200,000 U.S. per bug in its code - is detrimental to the ongoing security of iOS.
Source: Motherboard
Key source pertaining to some of Apple's most trusted, proprietary boot-regulatory code has been leaked this morning to GitHub. GitHub has since taken it down but it was estimated that the code was up for about a day, as the DMCA is clearly notarized for February 7, 2018.
To quote Motherboard, Vice's tech arm:
Quote:Having access to the source code of iBoot gives iOS security researchers a better chance to find vulnerabilities that could lead to compromising or jailbreaking the device, Levin said. That means hackers could have an easier time finding flaws and bugs that could allow them to crack or decrypt an iPhone. And, perhaps, this leak could eventually allow advanced programmers to emulate iOS on non Apple platforms.
This is bad news for Apple, assuming the code was live and is therefore probably forked into a private repo or part of underground source trading among hackers, crackers and code thieves around the world.
However, there is no way to know if this code is the whole iBoot source code, as indicated by the user who leaked it. There is virtually no way to tell whether or not this is the full repo, but evidence suggests that the DMCA, filed by Apple's attorney's, points toward this being valuable.
The iBoot code is essential for the secure signature verification of the rest of the boot process. Its design is that of the Windows BIOS. It verifies kernel integrity, executes boot-specific code and regulates the entire process of Apple's iOS every boot.
It is no doubt that Apple is scrambling to find the source of the leak but it may already be too late, according to some security researchers. This is not only a PR nightmare for Apple and their attorney's but also a bad sign for the big bounty program as a whole. The bug bounty program - which currently offers $200,000 U.S. per bug in its code - is detrimental to the ongoing security of iOS.
Source: Motherboard
![[Image: xHfwAca.jpg]](https://i.imgur.com/xHfwAca.jpg)
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)




























