I'm linking this to article https://jamfnation.jamfsoftware.com/discussion.html?id=8483, this would be a continuation of sorts.
Also sup'd short for Supervised
AC short for Apple Configurator
So we started out by installing iOS 7.0.3 on an iPad right out of the gate. Once it was installed we sup'd the iPad and made sure that the "allow to connect to other macs …." was off. Sure enough when we connected to another machine, we got the warning on iTunes. So far so good.
Then we erased and reinstalled iOS 7.0.3. This time is was sup'd and the allow check box was checked. Now the message clearly states the following: "Devices can be connected to other Macs (PCs) to transfer photos and videos". That's all it states, right. Well when it was connected to another machine. We were able to transfer photos and music and apps as well. This could lead to some concerns. Next question, what if we backed up the iPad and restored back form the backup. So we tried it and AC still saw the device as sup'd. So far, so okay I guess.
Okay, this shouldn't work at all. So let's try it and find. This time we nuke'd and paved like before. Device was sup'd and it was not setup to be connected to another computer. Once the iPad was up, we tested it by connecting it to another computer. It prompted us right away, that it could not be used…… Now my colleague made an iCloud backup.
We put iPad in recovery mode once more and then reinstalled the iOS. Now he restores from the iCloud backup. iPad shows that it's sup'd. We connect to the Mac and it mounts, it allows to sync, pictures, music, video, everything. Even make a local backup if we wanted to. Now I take it and connect to my AC system and it reports that it sup'd and no flashing alerts are seen or generated. To let me know what it has been compromised. No bueno, muy malo.
We are writing this up for other people to test and confirm what we have seen. To think about how and when a user could try these steps to by pass security. Please let us know what you all find, we are extremely curious.
CarbonTechnologies
