Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
China Iphone Security

How China Turned a Prize-Winning iPhone Hack Against the Uyghurs (technologyreview.com) 38

An attack that targeted Apple devices was used to spy on China's Muslim minority -- and US officials claim it was developed at the country's top hacking competition. An anonymous reader shares an excerpt from an MIT Technology Review article: The Tianfu Cup offered prizes that added up to over a million dollars. [It was held in November 2018, shortly after the Chinese banned cybersecurity researchers from attending overseas hacking competitions.] The $200,000 top prize went to Qihoo 360 researcher Qixun Zhao, who showed off a remarkable chain of exploits that allowed him to easily and reliably take control of even the newest and most up-to-date iPhones. From a starting point within the Safari web browser, he found a weakness in the core of the iPhones operating system, its kernel. The result? A remote attacker could take over any iPhone that visited a web page containing Qixun's malicious code. It's the kind of hack that can potentially be sold for millions of dollars on the open market to give criminals or governments the ability to spy on large numbers of people. Qixun named it "Chaos."

Two months later, in January 2019, Apple issued an update that fixed the flaw. There was little fanfare—just a quick note of thanks to those who discovered it. But in August of that year, Google published an extraordinary analysis into a hacking campaign it said was "exploiting iPhones en masse." Researchers dissected five distinct exploit chains they'd spotted "in the wild." These included the exploit that won Qixun the top prize at Tianfu, which they said had also been discovered by an unnamed "attacker." The Google researchers pointed out similarities between the attacks they caught being used in the real world and Chaos. What their deep dive omitted, however, were the identities of the victims and the attackers: Uyghur Muslims and the Chinese government.

Shortly after Google's researchers noted the attacks, media reports connected the dots: the targets of the campaign that used the Chaos exploit were the Uyghur people, and the hackers were linked to the Chinese government. Apple published a rare blog post that confirmed the attack had taken place over two months: that is, the period beginning immediately after Qixun won the Tianfu Cup and stretching until Apple issued the fix. MIT Technology Review has learned that United States government surveillance independently spotted the Chaos exploit being used against Uyghurs, and informed Apple. (Both Apple and Google declined to comment on this story.) The Americans concluded that the Chinese essentially followed the "strategic value" plan laid out by Qihoo's Zhou Hongyi; that the Tianfu Cup had generated an important hack; and that the exploit had been quickly handed over to Chinese intelligence, which then used it to spy on Uyghurs. The US collected the full details of the exploit used to hack the Uyghurs, and it matched Tianfu's Chaos hack, MIT Technology Review has learned. (Google's in-depth examination later noted how structurally similar the exploits are.) The US quietly informed Apple, which had already been tracking the attack on its own and reached the same conclusion: the Tianfu hack and the Uyghur hack were one and the same. The company prioritized a difficult fix.

This discussion has been archived. No new comments can be posted.

How China Turned a Prize-Winning iPhone Hack Against the Uyghurs

Comments Filter:
  • So is the author accusing a ethnic Chinese researcher giving the vulnerability to the CCP to oppress the Uyghurs then because the CCP didn't pay (?) the researcher, he submitted it in a competition to win a cash prize? Western companies are still actively using Uyghur slave labor in China, so maybe Apple purposely didn't provide the patch to Uyghurs devices as quid pro quo to the CCP?
    • by edis ( 266347 )

      Like oppressing on ethnic grounds is anything normal. Building up contemporary means of genocide is not.

  • by Gabest ( 852807 ) on Thursday May 06, 2021 @08:37PM (#61356984)

    iPhones use is insignificant outside countries like USA, Japan, etc. No one can spend two or three full months worth of salary on a phone.

    • by dargaud ( 518470 )
      That's what I was about to ask. How many Uighurs, an impoverished and subjugated population, can afford an iphone ? That number is probably ridiculously low so that makes me ponder the whole point of the story.
      • I am pretty sure that every Uighur must by law install a government tracking app on their phone. And it would be unwise to be seen without the phone on you.

        Plus they have unfettered access to all the Baidu and WeChat data etc.

        We should look at this and tremble in fear.

      • Not a large portion by percentage, I imagine, but the richer ones certainly. Given that those are likely to have the most influence, this would still represent a significant security breach.
  • “Root out the harmful members of the herd,” said Chen Yixin at a recent Communist party meeting, as quoted in a August 21,2020 NY Times story about the new Maoist campaign led by the Central Political and Legal Affairs Commission. “Root out ‘two-faced people’who are disloyal and dishonest to the party.”
  • They all have a last generation iPhone, I can see where the international outcry comes from

    • I'm still using a first gen iPhone SE. It is just incredible that these things are over 5 years old and still get updates. I plan to use it as long as I can, this has been a much better experience than anything the low end Android world can offer. Even if you can afford to spend more, there's just so much value in these used/old iphones.
  • It's cool for the Muzlims, Tibetans, Falung Dafa, Hong Kong people et al to be persecuted, tortured, imprisoned and executed, as long as it is not me...Why should we care? It is long known that Apple products are made by exploited Foxconn workers, but they're Chinese, so it's okay. As long as it is not my race and country, you can stuff them in ovens or wholesale execute after they are done. All this is just fine. It's 100% cool as long as someone else is suffering.

"Protozoa are small, and bacteria are small, but viruses are smaller than the both put together."

Working...