Live data from Hacker News

The Feds Can Now Probably Unlock Every iPhone Model

forbes.com

41–50 of 162 posts

Re: The Feds Can Now Probably Unlock Every iPhone Model

#41
post #24

Earlier quoted context omitted.

That doesn’t work as well because the counter is kept in the Secure Enclave so it’s not part of the flash contents. Also the exponential delay in attempts is enforced by the enclave. Previous iOS versions used to have some small window where you could race and power off after trying a passcode but before the enclave had incremented the counter, but that bug was fixed long ago. Maybe there are others unknown bugs of s…

>That doesn’t work as well because the counter is kept in the Secure Enclave so it’s not part of the flash contents I skimmed the secure enclave documentation at https://www.apple.com/business/docs/iOS_Security_Guide.pdf (page 5, 14, 15), and I can't find anything to confirm that.

It makes the most sense that it's in the Secure Enclave. Once you have control of the counter, you can run through the passphrase space in no time.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#42
post #3

Not too surprising based on economics alone. Presumably a security professional selling a usable exploit to a company like Celibrite pays far better than the $0 that comes from releasing it as a "jailbreak" to the general public.

I'd assume things like these are generally difficult to release to the public in any meaningful way, since they often require hardware hacks like desoldering components.

What ? No they don't.

All of the jailbreaks have just involved tethering your phone to iTunes or visiting a particular website or app. There's never been a need to do any desoldering.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#43
post #27

Earlier quoted context omitted.

I imagine Cellebrite is very picky about who gets to be there customer. Wouldn't want someone sending a trojan device that reveals their secrets.

Go to Apple store with reporter. Buy phone. Have reporter take selfie and set passcode. Take phone, unlock, show reporter selfie.

Why would Cellebrite want to do this in the first place?

Re: The Feds Can Now Probably Unlock Every iPhone Model

#44
post #9

Earlier quoted context omitted.

This is not true. You cannot just clone the data and run passcodes against it, because the data is not encrypted by your passcode. Instead, each file on iOS 11 is encrypted with a different AES 256-bit key, and cracking even one 256-bit key through exhaustive search is thought to be out of reach of humankind ( https://security.stackexchange.com/questions/6141/amount-of-... ). The file keys are wrapped by, among other…

>In the end, the only options are: bruteforcing passcodes on the original device while attempting to trick the device into allowing more than 10 failures, or prying open the Secure Enclave to obtain the Unique ID — both options a lot more complicated than just cloning the data and trying passcodes on it. If I'm understanding correctly, obtaining the unique ID would simply mean the strength of the AES key becomes the…

You will still be trusting Apple to securely use your entire password rather than always truncating it to, say, 3 characters, and/or "backing up" some or all of it to their cloud - things that are rather difficult to independently verify.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#45
post #13

I wish there was a kind of "dead man switch" app that would wipe a device if it is not unlocked for x days or met some other kind of personalized criteria.

Many years ago someone (possibly/probably Dan Kaminsky) suggested storing your gpg-encrypted+signed full device encryption key in the global DNS cache. If you don't do a lookup every X days, it'll expire from the cache and the drive will be unrecoverable assuming no other copies of the key exist.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#46

Earlier quoted context omitted.

Go to Apple store with reporter. Buy phone. Have reporter take selfie and set passcode. Take phone, unlock, show reporter selfie.

Why would Cellebrite want to do this in the first place?

I don't know, but imagine Forbes would convince them. Isn't that what journalism is all about?

Re: The Feds Can Now Probably Unlock Every iPhone Model

#47
post #23

How is chain of custody maintained if the process is a secret? Couldn't a person argue that the data obtained was planted?

Even if you can't authenticate evidence (chain of custody, disclosure of technical process, etc), you can still use the fruits of the analysis as long as acquisition of the phone wasn't illegal and the fruits can be proven independently after the fact. I imagine that in most situations law enforcement can make their case once information on the phone points them in the right direction, especially in high-profile cases where the government would spend a lot of money on a secret process.

Authentication is necessary because the prosecutor has the burden of proof, and part of meeting that burden of proof is making a facially sound case about the authenticity and reliability of each piece of evidence. But unlike, say, an illegal search, failure to meet that burden doesn't poison derivative evidence as long as that evidence is independently submissible.

Importantly, you don't need to authenticate evidence _before_ getting a warrant to take possession of the phone; at least not to the extent required at trial. And as far as I know there are no laws limiting how the government can extract information from a phone it legally possesses for investigatory purposes, which means any technical process would be entirely irrelevant to the legality of the search. So there's no way to force the government to divulge the process as long as they don't try to submit the information gained by that process directly as evidence.

But maybe I'm missing something.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#48

Earlier quoted context omitted.

I'd assume things like these are generally difficult to release to the public in any meaningful way, since they often require hardware hacks like desoldering components.

What ? No they don't. All of the jailbreaks have just involved tethering your phone to iTunes or visiting a particular website or app. There's never been a need to do any desoldering.

I think he's just talking about attacks against locked devices. I'd consider that a different category of thing than jailbreaks (rooting an unlocked device).

Re: The Feds Can Now Probably Unlock Every iPhone Model

#49
post #2

Bruce Schneier says¹: > There's also a credible rumor that Cellebrite's mechanisms only defeat the mechanism that limits the number of password attempts. It does not allow engineers to move the encrypted data off the phone and run an offline password cracker. If this is true, then strong passwords are still secure. ¹ https://www.schneier.com/blog/archives/2018/02/cellebrite_un...

They could also have iOS 11 jailbreak exploits in their possession. iOS 11 was already jailbroken recently and the Project Zero team has also informed Apple of exploits they discovered.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#50

Earlier quoted context omitted.

Breathalyzers are easily tampered with by police to provide false readings. One case of this in New Jersey could have potentially thrown out 20,000 DWI cases. But breathalyzer results in cases today are not thrown out after pointing this out.

> after pointing this out. What would you say, exactly? If you said: "your honor, breathalyzers can be tampered with to provide false readings" It seems quite easy for anyone to respond with "how so?". Do you refer to "this one time in New Jersey"?

Are you asking me to explain how trial law works?
Post reply on HN