Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

21–30 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#22
post #13

Earlier quoted context omitted.

Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

As Apple says, it's not feasible to try 50,000 fingerprints since you only get 5 tries. But you can try a lot of passwords.

Anyway, how does any of this prevent rubber hose cryptography?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#23

Why wouldn't the FBI just clone the phone disk contents and crack the encryption on more dedicated systems?

Are there tools to dump and resume iPhone/Android states? Could easily dump state, null "tryCounter++", and resume cracking?

You'd probably need a kernel mode debugger.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#25

Earlier quoted context omitted.

Thanks. So only recourse for highly resourced adversary will be to decode key via hardware imaging (not sure if any research has been done on this), and after that they will still have to bruteforce the passphrase used to secure the phone, the effectiveness of which depends on the entropy of passphrase. I wonder what how Apple can help the law enforcement here.

A lot of research has gone into information recovery from silicon inspection since it's tied closely to reverse engineering ICs. It's not the most trivial of pursuits but widely done. There are some hardware HMACs (Atmel's in particular IIRC) where the process of opening the chip package destroys the area of silicon that encodes the private keys. I don't know if Apple used the same tech but if they did, any attempt t…

Quantum cryptography would be fullproof. Any attempt to view the algorithm instead of using it would render it useless.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#26
If you read the iOS security guide you'll know Apple built the phone in such a way as to wash its hands with these types of request. They'll say it's impossible and they won't be lying. Nothing is ever impossible, but it will be very impractical. The hardware and software is built to ensure this.

I think the real game here is to compel Apple to build a backdoor into future models. I expect to see a lot of rhetoric around this fact, until something forces Apple hand.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#27
post #22
post #13

Earlier quoted context omitted.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

As Apple says, it's not feasible to try 50,000 fingerprints since you only get 5 tries. But you can try a lot of passwords. Anyway, how does any of this prevent rubber hose cryptography?

In this case, the part where the phone's owner is dead.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#28

Earlier quoted context omitted.

Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.

I don't know about that but I'd be fairly certain a court would just order you to unlock the phone regardless of whether it's your finger locking it or a password.

In the USA the courts treat passwords as testimony, and in most cases you can invoke your 5th amendment right and refuse to provide passwords or encryption keys, given the state does not already know the contents of the device. This same protection does not extend to physical keys, which I think fingerprints would fall under.

http://www.uclalawreview.org/the-fifth-amendment-encryption-...

Post reply on HN