Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
261–270 of 364 posts
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#262Earlier quoted context omitted.
Brute forcing a password could take more time, with today's technology, than we have left on Earth depending on complexity and if there are known vulnerabilities. I'm not sure I would effectively consider this order an order to "unencrypt".
Passcodes are only 4 or 6 digits.
[1] http://observer.com/2015/03/watch-this-little-machine-brute-...
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#263Earlier quoted context omitted.
>evidence 14 dead people and a stack of unused guns and bombs.
two dead attackers, stack confiscated. case closed.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#264I expect to see an optional, configurable key stretching setup in future phones, for those whose privacy is worth a couple of seconds' delay when unlocking their phones.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#265I thought this was an excellent write-up regarding how the iOS security platform (recent iPhone models) works from someone obviously in the know, as posted in the forums of Apple Insider. (Source: http://forums.appleinsider.com/discussion/191851 ) " Apple uses a dedicated chip to store and process the encryption. They call this the Secure Enclave. The secure enclave stores a full 256-bit AES encryption key. Within th…
Thanks for this explanation. Does Android have anything like this?
[1] http://www.arm.com/products/processors/technologies/trustzon...
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#266Earlier quoted context omitted.
Thanks. So only recourse for highly resourced adversary will be to decode key via hardware imaging (not sure if any research has been done on this), and after that they will still have to bruteforce the passphrase used to secure the phone, the effectiveness of which depends on the entropy of passphrase. I wonder what how Apple can help the law enforcement here.
A lot of research has gone into information recovery from silicon inspection since it's tied closely to reverse engineering ICs. It's not the most trivial of pursuits but widely done. There are some hardware HMACs (Atmel's in particular IIRC) where the process of opening the chip package destroys the area of silicon that encodes the private keys. I don't know if Apple used the same tech but if they did, any attempt t…
Some criss/cross metal mesh as the topmost layer you would have to penetrate, or photodiodes that sense the light if you put a device under a microscope, ...
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#267Earlier quoted context omitted.
A lot of research has gone into information recovery from silicon inspection since it's tied closely to reverse engineering ICs. It's not the most trivial of pursuits but widely done. There are some hardware HMACs (Atmel's in particular IIRC) where the process of opening the chip package destroys the area of silicon that encodes the private keys. I don't know if Apple used the same tech but if they did, any attempt t…
Quantum cryptography would be fullproof. Any attempt to view the algorithm instead of using it would render it useless.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#268A thought experiment: Let's say the government makes hardware encryption standards in the style of FedRAMP that sets standards for preventing tampering by foreign governments. Then, imagine that a consumer electronics company voluntarily makes all devices comply with this standard. Could a court attempt to compel the company to defeat the standards which the government set as tamper-proof against governments? A secon…
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#269A thought experiment: Let's say the government makes hardware encryption standards in the style of FedRAMP that sets standards for preventing tampering by foreign governments. Then, imagine that a consumer electronics company voluntarily makes all devices comply with this standard. Could a court attempt to compel the company to defeat the standards which the government set as tamper-proof against governments? A secon…
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#270Earlier quoted context omitted.
Passcodes are only 4 or 6 digits.
After a few attempts the OS would rate-limit guesses to prevent exactly that. On some iOS versions it is possible to override this mechanism by cutting power at the right moment[1] but this exploit has been patched for a while and I doubt this device is vulnerable. [1] http://observer.com/2015/03/watch-this-little-machine-brute-...
(3) it will ensure that when the FBI submits passcodes to the SUBJECT DEVICE, software running on the device will not purposefully introduce any additional delay between passcode attempts beyond what is incurred by Apple hardware.