maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   MeeGo / Harmattan (https://talk.maemo.org/forumdisplay.php?f=45)
-   -   NFC hack on N9 demonstrated at Black Hat USA 2012 (https://talk.maemo.org/showthread.php?t=85692)

Creamy Goodness 2012-07-25 15:55

NFC hack on N9 demonstrated at Black Hat USA 2012
 
https://www.blackhat.com/usa/bh-us-1...gs.html#Miller

http://arstechnica.com/security/2012...artphone-hack/

thedead1440 2012-07-25 16:06

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
Nokia's response is typical...We are secured by our obscurity...

Just shows why aegis was so flawed...Where's the security when you really need it?

Thanks CG for the links...

Creamy Goodness 2012-07-25 16:13

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
well, which app is the "word compatible reader" based on koffice? Maybe we should worry about that vulnerability ourselves, we can always uninstall or replace it.

Arie 2012-07-25 16:14

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
This was scary to watch in person... You have no idea... Made me think twice about using NFC on my N9 ever again.

Creamy Goodness 2012-07-25 16:15

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
you are there in Vegas?

thedead1440 2012-07-25 16:15

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
i always thought our documents app was based on the calligra active office suite...i think it refers to calligra instead of koffice...

Edit: From Wiki, In late 2010 most KOffice developers formed Calligra Suite that now contains a number of features present in KOffice 2.3 but not later versions.

Arie 2012-07-25 16:17

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
Quote:

Originally Posted by Creamy Goodness (Post 1242840)
you are there in Vegas?

Yup, I come to blackhat and defcon every year :)

Creamy Goodness 2012-07-25 16:20

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
I wish I lived in USA sometimes. Way more interesting stuff to do.

Arie 2012-07-25 16:22

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
Quote:

Originally Posted by Creamy Goodness (Post 1242843)
I wish I lived in USA sometimes. Way more interesting stuff to do.

I'd rather be a Canadian citizen living in the us, there are so many loopholes to being in that situation that are valuable overall.

Edit excerpts:
From a conversation I am having with a friend: (each line is another comment)
hence why i use an N9
the most secure (obscure) phone out there
no one will ever attack the N9
and charlie millers efforts are an utter waste to be honest
i think its great to show the security flaw for the future but no one cares overall
his mistake is i have to turn on nfc and get infected by something
i use nfc to connect my bluetooth in my car (alone)
and my speaker (again alone)
otherwise its off
it's impossible to attack an N9 in that situation
ya but once its on and you are near him you are screwed
that requires me to be near him when used
of course who would even dream of attacking the n9
he did the n9 in cuz its one of the few with built-in nfc
personally not using nfc is no loss to me
the whole point is its possible and he proved it
Now to see if oem's solve this issue

For everyone that reads this, there is no real threat unless NFC is on!

Creamy Goodness 2012-07-25 16:50

Re: NFC hack on N9 demonstrated at Black Hat USA 2012
 
Well, forget NFC, the exploit in the document reader is what worries me. Why couldn't that be exploited by something else you download from the store?


All times are GMT. The time now is 12:45.

vBulletin® Version 3.8.8