Live data from Hacker News

Israeli firm can steal phone data in seconds

phys.org

31–40 of 120 posts

Re: Israeli firm can steal phone data in seconds

#33
post #21
post #12

Confused why they didn't demo it breaking a modern iPhone instead of a random Android device.

Probably because they couldn't? Far easier to show of a random android handset.

They probably chose the device they have the best success cracking. I wonder what phone they used ... checks ... LG G4 ... damn it, that's my phone.

Re: Israeli firm can steal phone data in seconds

#34
post #22

Earlier quoted context omitted.

Too bad Google made the boot password the same as the screen unlock password. Since virtually everyone wants to be able to quickly unlock their phone, this makes security a Hobson's choice.

Yeah I can see that being the case for the vast majority of users. Also it's a damned shame that Google enforces a limit of 16 characters for the password. My own password is a random 16 character string.

Fortunately the community has addressed both these claims, although you need root to set it up (you can remove after).

An app on F-droid known as "Cryptfs Password" can change the encryption password separately from your screen unlock password. It also bypasses the 16 character limit, as the encryption key I used on my last phone was 27 characters. At the end of the day Android encryption runs using dm-crypt, so the same sort of rules apply. The 16 character limit is a UI limitation, and there's no technical reason for it.

* Note: I fully acknowledge that Google needs to do better here, as I would never assume a normal user could root + install Cryptfs password + unroot after, but at least for those of us who can, we can do something in the meantime.

Re: Israeli firm can steal phone data in seconds

#35
You'd think if they could crack the latest iPhone/iOS they'd crow about it.

The article seems to paint it as a "we're confident we could" - which seems bizarrely vague. Why would they do that when they claim they can crack an LG G4 wide open?

Re: Israeli firm can steal phone data in seconds

#36
post #16

It will be interesting if Apple went after Cellebrite under the DMCA anti-circumvention clauses. I would laugh if their product became illegal in the United States.

Probably not, it's an Israeli firm.

Any sales to US firms could be curtailed or punished.

Just like security itself - the goal is to provide enough barriers so predators go looking elsewhere for easier prey.

Re: Israeli firm can steal phone data in seconds

#37
post #2

"But privacy and rights activists worry such powerful technology can wind up in the wrong hands, leading to abuses." Am I to believe that this firm is the right hands? Or government? Please...all hands are the wrong hands. These vulnerabilities need to be closed. I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known. Gee, I sound paranoid. What am I…

> I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known. It looks like your are unsure, so let me clarify. There really are companies whose only business is to find and sell vulnerabilities to states. (Whether it's exclusive is just a matter of negotiations).

Most US "charity" ends up in Israel too. Best to think of them as if they were an entirely US-funded university you then have to pay to use the services of.

Re: Israeli firm can steal phone data in seconds

#38
post #35

You'd think if they could crack the latest iPhone/iOS they'd crow about it. The article seems to paint it as a "we're confident we could" - which seems bizarrely vague. Why would they do that when they claim they can crack an LG G4 wide open?

From the article:

> Ben-Peretz remains confident his company can crack even the newest iPhones.

Re: Israeli firm can steal phone data in seconds

#40
post #8

"Could you do anything to deprive them from throwing a stone at someone or from driving a car and running over people? "You can't blame the car manufacturer at that point for delivering a car that was utilised to commit that kind of crime," he said. This is specious reasoning. The point of a car is not to run over people; it's to go from point A to point B. This technology, on the other hand, has only one purpose: to…

"Ben-Peretz said the company vets clients and always respects local laws, but the governments are primarily responsible."

Just following orders and the local laws...

Post reply on HN