Live data from Hacker News

The Feds Can Now Probably Unlock Every iPhone Model

forbes.com

51–60 of 162 posts

Re: The Feds Can Now Probably Unlock Every iPhone Model

#51

Earlier quoted context omitted.

I'd assume things like these are generally difficult to release to the public in any meaningful way, since they often require hardware hacks like desoldering components.

What ? No they don't. All of the jailbreaks have just involved tethering your phone to iTunes or visiting a particular website or app. There's never been a need to do any desoldering.

All of the jailbreaks that were released as easily accessible jailbreaks. It's definitely plausible that this exploit requires direct access of pinouts on the motherboard.

The difference is just that those exploits which were difficult enough that they required soldering generally weren't released or didn't get much traction.

That being said, I remember soldering a modchip on my original xbox 16 years ago

Re: The Feds Can Now Probably Unlock Every iPhone Model

#52

Earlier quoted context omitted.

Breathalyzers are easily tampered with by police to provide false readings. One case of this in New Jersey could have potentially thrown out 20,000 DWI cases. But breathalyzer results in cases today are not thrown out after pointing this out.

> after pointing this out. What would you say, exactly? If you said: "your honor, breathalyzers can be tampered with to provide false readings" It seems quite easy for anyone to respond with "how so?". Do you refer to "this one time in New Jersey"?

i have an expert that can explain various methods. Also, please release the device for the defenses inspection.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#53
post #13

I wish there was a kind of "dead man switch" app that would wipe a device if it is not unlocked for x days or met some other kind of personalized criteria.

This is not exactly what you are looking for, but G Suite MDM has an "Auto Account Wipe" feature that "Automatically removes corporate account data when a device reaches a specified number of days of inactivity."

Presumably, this would automatically delete your G Suite email, contact, calendar, and other data from your device.

https://support.google.com/a/answer/6328708?hl=en#general

Re: The Feds Can Now Probably Unlock Every iPhone Model

#54
post #2

Bruce Schneier says¹: > There's also a credible rumor that Cellebrite's mechanisms only defeat the mechanism that limits the number of password attempts. It does not allow engineers to move the encrypted data off the phone and run an offline password cracker. If this is true, then strong passwords are still secure. ¹ https://www.schneier.com/blog/archives/2018/02/cellebrite_un...

They could also have iOS 11 jailbreak exploits in their possession. iOS 11 was already jailbroken recently and the Project Zero team has also informed Apple of exploits they discovered.

It's been many years since I've even glanced at an iOS jailbreak, but since when can you jailbreak a locked device?

Re: The Feds Can Now Probably Unlock Every iPhone Model

#55

Earlier quoted context omitted.

None of the executive team is Japanese (the CEO is Israeli), and most of the positions they are hiring for are located in Israel...

Ok then. I guess Apple's a Chinese company or an Irish Company or a Singaporean company because they have subsidiaries--each with a local CEO--in each of those countries: http://www.nytimes.com/interactive/2013/05/21/business/apple...

Cellebrite itself is an Israeli company, despite being a subsidiary of a Japanese one.

Apple is an American company, but they have foreign subsidiaries like Shazam Entertainment, which is a British company. If Apple Singapore is a full subsidiary, then sure, that's a Singaporean company, but Apple Inc wouldn't be.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#56

Earlier quoted context omitted.

Why would Cellebrite want to do this in the first place?

I don't know, but imagine Forbes would convince them. Isn't that what journalism is all about?

I think we can pretty safely assume that if they would have been willing to do this, Forbes would have been happy to report on it, because it's a damn good story.

Presumably they weren't, because there's nothing in it for them. And Forbes ran the story anyway. Would it really have been better for Forbes to not run it?

Re: The Feds Can Now Probably Unlock Every iPhone Model

#57
post #29
post #23

How is chain of custody maintained if the process is a secret? Couldn't a person argue that the data obtained was planted?

They'll probably drop the case if the defense points this out (seriously, look at Stingrays).

Or they just do parallel construction.

They gather the evidence illegally, and the conjure up a legal means to re-find the evidence they already know exists.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#58

Earlier quoted context omitted.

Cellebrite is a Japanese company, a subsidiary of Japan Sun Corporation.

None of the executive team is Japanese (the CEO is Israeli), and most of the positions they are hiring for are located in Israel...

Relative to the size of its population, Israel has a highly developed electronics engineering related industry. Part of it related to their state support of domestic defense contractors like IAI and their avionics/radar/C4I equipment. Aside from Cellbrite, companies like Ceragon, Alvarion, Radwin, ECI, Telrad, Elbit.

Second hand knowledge: Within international organizations that have worked extensively in the Israel-Lebanon border area it is well known that Israel has pwned most of the Lebanese telecoms and ISPs quite thoroughly. To the extent that Hezbollah started laying its own fiber optic cables.

https://www.google.com/search?client=ubuntu&channel=fs&q=hez...

Re: The Feds Can Now Probably Unlock Every iPhone Model

#59
post #9

Earlier quoted context omitted.

This is not true. You cannot just clone the data and run passcodes against it, because the data is not encrypted by your passcode. Instead, each file on iOS 11 is encrypted with a different AES 256-bit key, and cracking even one 256-bit key through exhaustive search is thought to be out of reach of humankind ( https://security.stackexchange.com/questions/6141/amount-of-... ). The file keys are wrapped by, among other…

or prying open the Secure Enclave to obtain the Unique ID People have been cracking secure coprocessors of the type used in payment cards, TPMs, and the like for a long time, dare I say even those which were designed to a higher level of security than Apple's. The fact that there is an entire phone attached to it doesn't make much of a difference, but the technology behind this (FIB, microprobing, etc.) has been stea…

Fwiw, Apple has a $100k bounty on this type of exploit (pulling secrets from the secure enclave).

Re: The Feds Can Now Probably Unlock Every iPhone Model

#60
post #14
post #9

Earlier quoted context omitted.

This is not true. You cannot just clone the data and run passcodes against it, because the data is not encrypted by your passcode. Instead, each file on iOS 11 is encrypted with a different AES 256-bit key, and cracking even one 256-bit key through exhaustive search is thought to be out of reach of humankind ( https://security.stackexchange.com/questions/6141/amount-of-... ). The file keys are wrapped by, among other…

I think he got the the idea right. Yes, you need the secret key burned into the CPU to decrypt anything, and yes, you can't easily extract the keys. but his claim is that by fully restoring the flash storage (presumably where the retry counter is stored), it's possible to bypass the "erase data after 10 failed attempts" policy by constantly resetting the counter back to its original state. It might take a while (you…

> constantly resetting the counter back to its original state

I wouldn't rule out some kind of electrical glitching attack.

Post reply on HN