Bitcoin Forum
June 15, 2024, 07:12:21 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: Bitcoin wallets on older iphones are insecure  (Read 540 times)
bbc.reporter (OP)
Legendary
*
Offline Offline

Activity: 2968
Merit: 1452



View Profile
September 29, 2019, 01:16:11 AM
Merited by Red-Apple (1)
 #1

The people that go to cryptocoin conferences should be more skeptical if their iphone was lost and then returned to them by a good samaritan hehehe.

In any case, sharing this article here instead of the press subforum for more views. Keep your iphones safe.


Litecoin Foundation’s full-time developer, Loshan T recently stated on Twitter that Bitcoin and Litecoin wallets were no longer safe on iPhones older than and including iPhone X. This was followed by the developer recommending users to upgrade their iPhone devices, considering that several people use smartphone according to Litecoin Foundation’s internal data. Additionally, Loshan explicity stated that updating iOS would not solve the problem as it is “an unpatchable exploit.”

Loshan made the statement in the wake of a Tweet made by Axi0mX. The Twitter handle had stated,

“EPIC JAILBREAK: Introducing checkm8 (read “checkmate”), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices. Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip).”


Read in full https://ambcrypto.com/litecoin-and-bitcoin-wallets-on-iphones-older-than-and-including-iphone-x-are-insecure-says-ltc-developer/

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18587


View Profile
September 29, 2019, 01:42:03 AM
 #2

Here is an interview with the developer of this exploit, which contains a lot of good information: https://arstechnica.com/information-technology/2019/09/developer-of-checkm8-explains-why-idevice-jailbreak-exploit-is-a-game-changer/

Essentially, the attacker must have physical access to the device, can't access any data that is stored behind the Secure Enclave PIN, and any code that is injected doesn't persist through restarts. It is a very specific exploit. If you have an iPhone 6 or later, and are using proper security measures, then an attacker can't access your data unless you unlock the phone for them, and if you reboot your phone into iOS any malware or malicious code that has been injected will no longer run. For those reasons, I don't really see this as a valid attack on cryptocurrency wallets. In addition, any good mobile wallet should have its own PIN or password which will encrypt its contents.

That's not to say mobile wallets are otherwise safe. I would only advocate storing small amounts of day to day spending money on a mobile wallet.
joromz1226
Sr. Member
****
Offline Offline

Activity: 798
Merit: 258


View Profile
September 29, 2019, 02:12:24 AM
 #3

The people that go to cryptocoin conferences should be more skeptical if their iphone was lost and then returned to them by a good samaritan hehehe.

In any case, sharing this article here instead of the press subforum for more views. Keep your iphones safe.


Litecoin Foundation’s full-time developer, Loshan T recently stated on Twitter that Bitcoin and Litecoin wallets were no longer safe on iPhones older than and including iPhone X. This was followed by the developer recommending users to upgrade their iPhone devices, considering that several people use smartphone according to Litecoin Foundation’s internal data. Additionally, Loshan explicity stated that updating iOS would not solve the problem as it is “an unpatchable exploit.”

Loshan made the statement in the wake of a Tweet made by Axi0mX. The Twitter handle had stated,

“EPIC JAILBREAK: Introducing checkm8 (read “checkmate”), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices. Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip).”


Read in full https://ambcrypto.com/litecoin-and-bitcoin-wallets-on-iphones-older-than-and-including-iphone-x-are-insecure-says-ltc-developer/

Do you mean that according to Loshan and all iPhone device units are no longer advisable to use in case the user downloads Bitcoin or litecoin apps for wallet use? Is this what you want to convey on this topic that you did dude? But other device units like Samsung, Oppo, and Vivo are okay. Do I understand correctly that I'm right?
pooya87
Legendary
*
Offline Offline

Activity: 3486
Merit: 10643



View Profile
September 29, 2019, 04:18:38 AM
 #4

that is what happens when you are using closed source software (that is iPhones operating system that is mostly closed source), the company (specially when it is located in US) always injects backdoors in their software intentionally and also like always backdoors will exist unintentionally and won't be caught for long times and will be exploited a lot.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Kyraishi
Hero Member
*****
Offline Offline

Activity: 952
Merit: 513



View Profile
September 29, 2019, 05:00:35 AM
 #5

Crazy how fast technology moves and advances in our world. The iPhone X was one of the most flagship phones apple ever made, and now your telling me, that after only 2 years of it being out, it can easily get hacked and exploited? That's crazy.

It isn't as bad as it's made out to be though, they need to have physical access regarding the device and it's very specific and hard to do.

So just don't let other people use your phone if you have BTC or other coins on it - invest in a desktop wallet.

Wexnident
Hero Member
*****
Offline Offline

Activity: 2562
Merit: 666


I don't take loans, ask for sig if I ever do.


View Profile
September 29, 2019, 05:55:37 AM
 #6

Crazy how fast technology moves and advances in our world. The iPhone X was one of the most flagship phones apple ever made, and now your telling me, that after only 2 years of it being out, it can easily get hacked and exploited? That's crazy.

It isn't as bad as it's made out to be though, they need to have physical access regarding the device and it's very specific and hard to do.

So just don't let other people use your phone if you have BTC or other coins on it - invest in a desktop wallet.
Yea and this is why I mainly invest in desktop wallets instead of my mobile phones. But the portability of a mobile wallet is really nice so it can't really be helped that people want to use them instead of desktop wallets.

Do you mean that according to Loshan and all iPhone device units are no longer advisable to use in case the user downloads Bitcoin or litecoin apps for wallet use? Is this what you want to convey on this topic that you did dude? But other device units like Samsung, Oppo, and Vivo are okay. Do I understand correctly that I'm right?
Well if I read that correctly then yes. Only iPhone devices are affected and other device units should be safe from the exploit stated by the poster. That is considering the current information at hand regarding the safety of using Android devices anyway.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
Lorna111
Member
**
Offline Offline

Activity: 280
Merit: 11


View Profile
September 29, 2019, 06:52:42 AM
 #7

I do believe that phones that can't withstand fraudulent actions are a threat for investors and client. That's why I always use my computer and high ended security phone whenever I transact with other people using my Bitcoins. It is much safer to use. Those iphones that you were talking about are vulnerable on fraud attacks.
bitcoinposts
Member
**
Offline Offline

Activity: 448
Merit: 10


View Profile
September 29, 2019, 09:19:34 AM
 #8

Those who are holding crypto currencies in old iPhone and old anriod  wallets they should change their mobiles immediately in order to protect their money
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18587


View Profile
September 29, 2019, 09:27:06 AM
 #9

Do you mean that according to Loshan and all iPhone device units are no longer advisable to use in case the user downloads Bitcoin or litecoin apps for wallet use?
Mobile wallets were never that safe. They should only be used for small amounts of crypto. Your main holdings should be on a hardware wallet, airgapped machine, or other cold storage.

that is what happens when you are using closed source software (that is iPhones operating system that is mostly closed source), the company (specially when it is located in US) always injects backdoors in their software intentionally and also like always backdoors will exist unintentionally and won't be caught for long times and will be exploited a lot.
This is all true, but this particular exploit is targeted at the hardware, rather than the software, hence the reason it is unpatchable.

The iPhone X was one of the most flagship phones apple ever made, and now your telling me, that after only 2 years of it being out, it can easily get hacked and exploited? That's crazy.
Technically, the exploit has been there since day 1, it just wasn't known about. And you shouldn't be placing your trust in any device just because it is "flagship". Nothing is completely secure, regardless of how well it is marketed.
Lucius
Legendary
*
Offline Offline

Activity: 3276
Merit: 5723


Blackjack.fun🎲


View Profile WWW
September 29, 2019, 10:23:37 AM
 #10

This news reminded me of a case where one user reports how he and some other users lost a significant amount of BTC on blockchain.info/com, and they all have something in common : In most cases we were using Apple environment (mainly newest iPhones and official blockchain app).. The specific case may not be related to exploit posted in OP, but it is a good warning to all Apple users to be very careful when using crypto on this OS.

What is even greater problem is that this exploit is “an unpatchable exploit.”, so it would be wise not to buy a new iPhone and wait for some new exploits.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Insanity
Sr. Member
****
Offline Offline

Activity: 611
Merit: 250


Vave.com - Crypto Casino


View Profile
September 29, 2019, 10:39:14 AM
 #11

Since before, It is hard to used mobile wallet because it is easy for it to exploit by hackers. That is why I always suggest to have more security on the phone. Having a 2 form factor authentication is also start of our phone security. Also doing a system update also helps. Downloading antivirus apps also helps. But if the issue is hardware the only solution that we have is buying a new IOS/Android phone with has a new OS.

elda34b
Sr. Member
****
Offline Offline

Activity: 910
Merit: 351


View Profile
September 29, 2019, 11:14:15 AM
 #12

Hell yeah, so just for the sake of having a mobile wallet, you need to spend more than $1000 for a new iPhone? Sounds like a legit deal. Why not ask for a patch, or if the problem is the hardware, request Apple to give an "upgrade" of those old versions? That being said, it's not like this exploit will put every wallet at risk.

Those who are holding crypto currencies in old iPhone and old anriod  wallets they should change their mobiles immediately in order to protect their money

If you don't give your phone to random people so they can exploit the weakness then you don't have to. Btw, we don't talk about Android here. It was not mentioned except once in the article.
Red-Apple
Hero Member
*****
Offline Offline

Activity: 1470
Merit: 655


View Profile
September 29, 2019, 11:43:22 AM
 #13

thanks for the information.
one might argue that people shouldn't be keeping their coins inside their phones in first place. it would be like carrying around bags of cash (your lifesavings) around with you wherever you go! there is a place for storage and there is such thing as pocket money. the phone wallets are for the later.

--signature space for rent; sent PM--
Tipstar
Sr. Member
****
Offline Offline

Activity: 1792
Merit: 281



View Profile
September 29, 2019, 12:05:25 PM
 #14

User should be aware of their devices. And don't share their device to others. And not use their lost and found device util they are sure about it. A clean install of the firmware may solve any issues.
I too in the past have done something like inserting a shadow miner inside PC of unsuspecting colleagues to mine for me. But stopped doing it as the profit was not enough to sell my ethics.

▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
▀████████████████████████
░████████████████████████
░████████████████████████
░████████████████████████
░███████████████████████▀
░███████████████████████
░███████████████████████
████████████████████████
▀███████▀▀█████▀▀██████▀
| 
Low Fidelity - High Potential
|
▄███████████████████▄
█████████████████████
███▄░▄░███████▀▄███
█████▄▀█▄▀███▀▄██████
███████░██░▀▄████████
████████▄▀█▄▀████████
████████▀▄▀██░███████
██████▀▄███░██▄▀█████
████▀▄██████▄▀▀░▀████
█████████████████████
▀███████████████████▀

▄███████████████████▄
█████████████████████
███████████████████
██████▀░░▀▀▀░░▀██████
█████░░▄▄░░░▄▄░░█████
████▌░░██▌░▐██░░▐████
████░░░░▀░░░▀░░░░████
████▄▄░▀▄▄▄▄▄▀░▄▄████
█████████████████████
█████████████████████
▀███████████████████▀

▄███████████████████▄
█████████████████████
██████████████▀▀███
███████████▀▀░░░░████
███████▀▀░░▄▄▀░░▐████
████▀░░░▄██▀░░░░█████
███████░█▀░░░░░▐█████
████████░░▄▄░░░██████
██████████████▄██████
█████████████████████
▀███████████████████▀
YuginKadoya
Legendary
*
Offline Offline

Activity: 3038
Merit: 1169



View Profile
September 29, 2019, 01:57:23 PM
 #15

Well, first of all, I am not using iPhone but I am familiar with issue's that wallet on the iPhone are not really secure for the older version of IOS I guess this is a kind of problem for some users that have certain cryptocurrency stored in their iPhone, And I am an Android User and not like iPhone's that needs to be jailbreak to get certain free applications I really like to use Smartphone because of its user friendly features,

Well, in my opinion, I guess this can be resolved when your IOS is updated to its latest version, but certainly, how about the old version of iPhones that don't have options in updating their IOS.
AniviaBtc
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 272


First 100% Liquid Stablecoin Backed by Gold


View Profile
September 29, 2019, 02:39:55 PM
 #16

Nowadays, the technology is really unpredictable. Hackers around the world are spreading so fast so you need to be mindful about your accounts and gadgets. Especially when you're using an iPhone. In 5 years, iPhone should provide  the best security they should create to improve quality in keeping BTC wallets or other coins.

Although it isn't easy to do instantly, they should take care of the security of IPhone users little by little.

Always look for your iPhone to prevent Bitcoin loss.


AniviaBtc
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 272


First 100% Liquid Stablecoin Backed by Gold


View Profile
September 29, 2019, 03:43:02 PM
 #17

Crazy how fast technology moves and advances in our world. The iPhone X was one of the most flagship phones apple ever made, and now your telling me, that after only 2 years of it being out, it can easily get hacked and exploited? That's crazy.

Absolutely! and not only iPhone users but also other brands because mobile wallet isn't that safe like desktop wallet that you can only secure in your house\home.

NewBet
Hero Member
*****
Offline Offline

Activity: 966
Merit: 500


View Profile
September 29, 2019, 03:47:21 PM
 #18

Crazy how fast technology moves and advances in our world. The iPhone X was one of the most flagship phones apple ever made, and now your telling me, that after only 2 years of it being out, it can easily get hacked and exploited? That's crazy.

Absolutely! and not only iPhone users but also other brands because mobile wallet isn't that safe like desktop wallet that you can only secure in your house\home.

You are right on the spot bro. Mobile phone wallets can be made by anyone, and there's no guarantee that they are secure or that they don't even have your private Keys. As soon as you deposit some cryptocurrency, since they have your private keys, they could steal everything. You never know who is behind these apps, unless it is a popular one like coinbase... Most of them could be scams. It's better to protect your cryptocurrency, to keep in your own hands, done trusting random apps.
JohnBitCo
Sr. Member
****
Offline Offline

Activity: 2030
Merit: 356


View Profile
September 29, 2019, 03:49:46 PM
 #19

Crazy how fast technology moves and advances in our world. The iPhone X was one of the most flagship phones apple ever made, and now your telling me, that after only 2 years of it being out, it can easily get hacked and exploited? That's crazy.

Absolutely! and not only iPhone users but also other brands because mobile wallet isn't that safe like desktop wallet that you can only secure in your house\home.

What do you mean by SAFE here ?
You people mean to say that if the iPhone / or any other phone is hacked, then anyone can get hold of our coins ?

OR

The current iPhone users using different wallets like bread wallet are at risk   Huh
2girls
Sr. Member
****
Offline Offline

Activity: 1002
Merit: 254


Tontogether | Save Smart & Win Big


View Profile
September 29, 2019, 03:55:02 PM
 #20

Crazy how fast technology moves and advances in our world. The iPhone X was one of the most flagship phones apple ever made, and now your telling me, that after only 2 years of it being out, it can easily get hacked and exploited? That's crazy.

Absolutely! and not only iPhone users but also other brands because mobile wallet isn't that safe like desktop wallet that you can only secure in your house\home.

You are right on the spot bro. Mobile phone wallets can be made by anyone, and there's no guarantee that they are secure or that they don't even have your private Keys. As soon as you deposit some cryptocurrency, since they have your private keys, they could steal everything. You never know who is behind these apps, unless it is a popular one like coinbase... Most of them could be scams. It's better to protect your cryptocurrency, to keep in your own hands, done trusting random apps.

There are so many Andriod and iOS  wallet apps coming every day in apple store and playstore. We never know if these apps can steal your money and run away anytime. Always store your funds in a wallet in which you have full control over its private Key.

Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!