Earlier quoted context omitted.
That doesn’t work as well because the counter is kept in the Secure Enclave so it’s not part of the flash contents. Also the exponential delay in attempts is enforced by the enclave. Previous iOS versions used to have some small window where you could race and power off after trying a passcode but before the enclave had incremented the counter, but that bug was fixed long ago. Maybe there are others unknown bugs of s…
>That doesn’t work as well because the counter is kept in the Secure Enclave so it’s not part of the flash contents I skimmed the secure enclave documentation at https://www.apple.com/business/docs/iOS_Security_Guide.pdf (page 5, 14, 15), and I can't find anything to confirm that.
The Feds Can Now Probably Unlock Every iPhone Model
41–50 of 162 posts
Re: The Feds Can Now Probably Unlock Every iPhone Model
#42Not too surprising based on economics alone. Presumably a security professional selling a usable exploit to a company like Celibrite pays far better than the $0 that comes from releasing it as a "jailbreak" to the general public.
I'd assume things like these are generally difficult to release to the public in any meaningful way, since they often require hardware hacks like desoldering components.
All of the jailbreaks have just involved tethering your phone to iTunes or visiting a particular website or app. There's never been a need to do any desoldering.
Re: The Feds Can Now Probably Unlock Every iPhone Model
#43Earlier quoted context omitted.
I imagine Cellebrite is very picky about who gets to be there customer. Wouldn't want someone sending a trojan device that reveals their secrets.
Go to Apple store with reporter. Buy phone. Have reporter take selfie and set passcode. Take phone, unlock, show reporter selfie.
Re: The Feds Can Now Probably Unlock Every iPhone Model
#44Earlier quoted context omitted.
This is not true. You cannot just clone the data and run passcodes against it, because the data is not encrypted by your passcode. Instead, each file on iOS 11 is encrypted with a different AES 256-bit key, and cracking even one 256-bit key through exhaustive search is thought to be out of reach of humankind ( https://security.stackexchange.com/questions/6141/amount-of-... ). The file keys are wrapped by, among other…
>In the end, the only options are: bruteforcing passcodes on the original device while attempting to trick the device into allowing more than 10 failures, or prying open the Secure Enclave to obtain the Unique ID — both options a lot more complicated than just cloning the data and trying passcodes on it. If I'm understanding correctly, obtaining the unique ID would simply mean the strength of the AES key becomes the…
Re: The Feds Can Now Probably Unlock Every iPhone Model
#45I wish there was a kind of "dead man switch" app that would wipe a device if it is not unlocked for x days or met some other kind of personalized criteria.
Re: The Feds Can Now Probably Unlock Every iPhone Model
#46Earlier quoted context omitted.
Go to Apple store with reporter. Buy phone. Have reporter take selfie and set passcode. Take phone, unlock, show reporter selfie.
Why would Cellebrite want to do this in the first place?
Re: The Feds Can Now Probably Unlock Every iPhone Model
#47How is chain of custody maintained if the process is a secret? Couldn't a person argue that the data obtained was planted?
Authentication is necessary because the prosecutor has the burden of proof, and part of meeting that burden of proof is making a facially sound case about the authenticity and reliability of each piece of evidence. But unlike, say, an illegal search, failure to meet that burden doesn't poison derivative evidence as long as that evidence is independently submissible.
Importantly, you don't need to authenticate evidence _before_ getting a warrant to take possession of the phone; at least not to the extent required at trial. And as far as I know there are no laws limiting how the government can extract information from a phone it legally possesses for investigatory purposes, which means any technical process would be entirely irrelevant to the legality of the search. So there's no way to force the government to divulge the process as long as they don't try to submit the information gained by that process directly as evidence.
But maybe I'm missing something.
Re: The Feds Can Now Probably Unlock Every iPhone Model
#48Earlier quoted context omitted.
I'd assume things like these are generally difficult to release to the public in any meaningful way, since they often require hardware hacks like desoldering components.
What ? No they don't. All of the jailbreaks have just involved tethering your phone to iTunes or visiting a particular website or app. There's never been a need to do any desoldering.
Re: The Feds Can Now Probably Unlock Every iPhone Model
#49Bruce Schneier says¹: > There's also a credible rumor that Cellebrite's mechanisms only defeat the mechanism that limits the number of password attempts. It does not allow engineers to move the encrypted data off the phone and run an offline password cracker. If this is true, then strong passwords are still secure. ¹ https://www.schneier.com/blog/archives/2018/02/cellebrite_un...
Re: The Feds Can Now Probably Unlock Every iPhone Model
#50Earlier quoted context omitted.
Breathalyzers are easily tampered with by police to provide false readings. One case of this in New Jersey could have potentially thrown out 20,000 DWI cases. But breathalyzer results in cases today are not thrown out after pointing this out.
> after pointing this out. What would you say, exactly? If you said: "your honor, breathalyzers can be tampered with to provide false readings" It seems quite easy for anyone to respond with "how so?". Do you refer to "this one time in New Jersey"?