Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

31–40 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#31
post #4

Remember, this is an iPhone 5C, which doesn't have Touch ID or the Secure Enclave; the security model for this phone is significantly different from that of more recent iPhones. On phones with a Secure Enclave, the wipe-on-failures state is managed in the coprocessor (which runs L4), and is not straightforwardly backdoor-able. If you're worried about the police brute-forcing your phone, enable Touch ID and set a pass…

Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.

[deleted]

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#34
post #8

Earlier quoted context omitted.

Wouldn't Apple (or the manufacturer) know the key of the security enclave?

No. From Apple's iOS security guide[1]: > The device’s unique ID (UID) and a device group ID (GID) are AES 256-bit keys fused (UID) or compiled (GID) into the application processor and Secure Enclave during manufacturing. No software or firmware can read them directly; they can see only the results of encryption or decryption operations performed by dedicated AES engines implemented in silicon using the UID or GID as…

It sounds like since the UID is fused it cannot be erased; it's probably the GID that's erased, and it sounds like the GID is known to Apple.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#35
post #11
post #2

> Apple ... will probably have little time to debug or test it overall, meaning that this feature it is being ordered to build will almost certainly put more users at risk. Eh? They are not being asked to install it to the public at large, just one phone. Of all reasons to object, this reason makes little sense.

That's true. In fact, if it's possible for Apple to accomplish what DOJ is demanding of it, the best outcome would be for DOJ to succeed, and do so publicly: * There is an authentic need to get at the data on that phone * There's no likelihood at all that other users will be impacted by the backdoor * We'll all be on the same page about how secure these phones are versus the USG. It's possible that they can prevail a…

> There is an authentic need to get at the data on that phone

What is the authentic need? The shooters are dead. Do we have reason to believe that there is evidence of any pending crimes or any old unsolved crimes on the phone?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#37
post #35
post #11

Earlier quoted context omitted.

That's true. In fact, if it's possible for Apple to accomplish what DOJ is demanding of it, the best outcome would be for DOJ to succeed, and do so publicly: * There is an authentic need to get at the data on that phone * There's no likelihood at all that other users will be impacted by the backdoor * We'll all be on the same page about how secure these phones are versus the USG. It's possible that they can prevail a…

> There is an authentic need to get at the data on that phone What is the authentic need? The shooters are dead. Do we have reason to believe that there is evidence of any pending crimes or any old unsolved crimes on the phone?

Sure, of course that's a legitimate concern: they may have talked to other people planning attacks.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#38
post #13

Earlier quoted context omitted.

Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

If you do this on purpose after asked to unlock your phone you will probably be charged with destruction of evidence or something like that.

However, while a court is (afaik) able to ask you to put your finger on the fingerprint reader, you do not need to tell them which of the fingers the correct one is. So instead of purposely using a wrong finger, I'd ask the court to explicitly tell me which of my fingers I should use to unlock the phone.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#39
post #13

Earlier quoted context omitted.

Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

The countermeasure is for the authorities to push your finger of their choice by force.

Thumb and index finger should cover 98% of people.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#40

Why the worry about auto-wiping? Is it not possible to make a copy of the encrypted data and then play around with it as much as you want?

Yeah I've got the same question. Is there some hardware safeguard that prevents copying the memory itself? You'd think the first rule of crypto forensics is to work on a copy.
Post reply on HN