Hacker News new | ask | show | jobs
by omegacharlie 544 days ago
Considering iOS devices are locked down to hell and back and achieving reboot persistence is extremely difficult, how hard is it to extract a sample of a malware payload in memory for purpose of forensics?
2 comments

AFAIk it's extremely difficult. Even white-hat iOS forensics revolves around (ab)using old exploits in unpatched iPhones in order to access data.
I don't think this accurately describes the state of iPhone forensics today.
Quite difficult on production devices