AssetManifests + Signing: Tricking iOS into getting OS assets from custom sources by circumventing AssetManifestSigning?

Viewed 734

The main question:

iOS verifies that system downloads (custom voices for Siri, over-the-air updates, etc.) have been signed by Apple. Would it be possible for me to generate a certificate (and make iOS trust that certificate) to make iOS download operating system assets from a custom source? If so, how?

Background

I have recently been missing Siri's old voice circa iOS 11 (I am using iOS 12). iOS 7-10 used a voice known as "Nicky," while iOS 11 introduced a new voice called "Nora". On my Mac, I was able to get Siri to use the old voice by simply swapping some of the files for Nicky's voice into the folder for Nora's voice in /System/Library/Speech/NoraSiri.SpeechVoice/Resources. Wanting to do the same thing for my iPhone, I realized it wouldn't be as easy, as without a jailbreak I would be unable to modify the necessary system files in iOS. I reasoned that instead, I could possibly trick my iPhone into downloading Siri's voice files (which I would modify to include Nicky's voice) from my computer.

Using a proxy utility called Charles (and installing the Charles Root Certificate on my iPhone in Settings>General>Certificate Trust Settings), I was able to intercept web traffic coming from my iPhone. It turns out that in downloading a new voice for Siri, iOS makes a request to an Apple server over HTTPS to download a manifest file that contains information about all the downloadable voices, their URLs on Apple's servers, their SHA-1 hashes, and more. Then, using the URL in the manifest file for the desired asset (voice), iOS downloads the asset (over HTTP) and then verifies that the SHA-1 of the downloaded file matches the one in the manifest before actually installing the files.

After using my Charles Proxy to serve my iPhone the custom Nicky voice files for the URL that would normally download Nora's, I (obviously) ran into the problem that the custom Nicky files I served from my computer to my iPhone didn't have the expected SHA-1 hash as specified in the manifest for Nora's voice. I then tried to use Charles to serve a modified manifest file to my iPhone.

But upon inspecting the logs from my iPhone, it appeared that iOS was smart enough to recognize that the manifest file is fake, as messages like the following appeared:

iPhone mobileassetd[8810] <Error>: mobileassetd - _MobileAssetDecryptAndVerifySignature: Could not verify signature using public key: -9809
iPhone mobileassetd[8810] <Error>: mobileassetd - _MobileAssetVerifyAssetMapSignature: Could not validate asset map signature

Here is where my understanding is very fuzzy (especially given my little knowledge in cryptography). It appears that the manifest XMLs include several important fields that help to verify that the manifest XML itself is valid:

Certificate : Appears to be a certificate that will help verify the signature of the XML.

Signature : This is the actual signature of the XML, presumably after being signed by private key.

Signing Key : This field is usually "AssetManifestSigning," and it appears to be an instruction to iOS verify the signature of the XML with the "AssetManifestSigning" public key stored on the device.

My Questions

I have several main questions:

  1. Why is Certificate included in the XML when the Signing Key field seems to tell iOS which internal certificate to use in verification? I don't see the point of even having Certificate -- it would seem ridiculous to conclude that the certificate needed to verify the file would be included in the very file that needs to be verified.
  2. Suppose that only Certificate is used to verify the XML (which I doubt as described above). How might I generate my own certificate, include it in the XML, and sign my own XML?
  3. Suppose that iOS actually uses an internal certificate specified by "AssetManifestSigning" to verify the XML. Would it be possible for me to generate my own "AssetManifestSigning" certificate and install it onto iOS to make it trust any asset manifests that I create?
  4. (Bonus) Suppose (2) and (3) are impossible. Any other suggestions on how to get Nicky instead of Nora? I really miss Nicky ...

I am happy to provide more information if necessary. I understand that my knowledge of certificates/keys/cryptography is severely lacking, but any pointers in the right direction are appreciated!

Further references

An example asset manifest file:

https://mesu.apple.com/assets/com_apple_MobileAsset_VoiceServices_GryphonVoice/com_apple_MobileAsset_VoiceServices_GryphonVoice.xml

Some related information about iOS asset manifests:

http://web.archive.org/web/20131101032903/http://www.hydrantlabs.com/Security/iOS/OTA/

https://www.reddit.com/r/ReverseEngineering/comments/1n7h3u/i_reversed_the_ios_ota_update_protocol_enjoy/ccg55uq/?context=8&depth=9

0 Answers
Related