Live data from Hacker News

GrayKey iPhone unlocker poses serious security concerns

blog.malwarebytes.com

11–20 of 97 posts

Re: GrayKey iPhone unlocker poses serious security concerns

#12

I hate this stuff. I want to secure my device and not have the govt or companies steal it, I want to control my device. Still, it's fascinating to learn about. Did no one think, when they take someone's phone for 5 minutes at the border, they could be doing this to your phone.

Well, as the article makes it clear it takes from hours to days to crack, no - they’re not doing this in 5 minutes at the border.

Re: GrayKey iPhone unlocker poses serious security concerns

#13

This seems at odds with Apple’s claims about holding the device encryption keys in a secure coprocessor that only releases them in response to a valid passcode, and self-destructs the keys if too many passcodes are tried.

It’s not at odds with it - it’s pretty obviously using a vulnerability to run a crack against the passcode. Once the passcode is found, that is used to unlock the phone and this the Secure Enclave.

Re: GrayKey iPhone unlocker poses serious security concerns

#14

This seems at odds with Apple’s claims about holding the device encryption keys in a secure coprocessor that only releases them in response to a valid passcode, and self-destructs the keys if too many passcodes are tried.

It’s not at odds with it - it’s pretty obviously using a vulnerability to run a crack against the passcode. Once the passcode is found, that is used to unlock the phone and this the Secure Enclave.

The enclave software has supposedly been formally verified (It is based on the L4 microkernel).

This looks like a software flaw, not a hardware attack. It will be interesting to know how Apple screwed this up.

Re: GrayKey iPhone unlocker poses serious security concerns

#15
However, it does mean that an iPhone’s security cannot be ensured if it falls into a third party’s hands.

That was and will always continue to be true. Even secure cryptoprocessors of the type used in smartcards and HSMs can be cracked with enough determination and time. There are companies in China who will read and clone them for surprisingly little money.

It has always amused me somewhat how scared (or the impression that articles like this give) some people are of governments, while at the same time completely accepting and trusting to being herded and controlled by the companies they purchase these locked-down computers from. Anything you truly want to keep secret should be encrypted by systems you have knowledge of, with a key that only you know, or even better --- not leaving your brain at all.

Unfortunately, the IP-Box 2 became widely available and was almost exclusively used illegitimately, rather than in law enforcement

If by "illegitimately" you mean third-party repair shops... I know Apple doesn't like that, but the whole *-box series are aimed at the mobile repair industry (a huge business in China), not law enforcement.

Re: GrayKey iPhone unlocker poses serious security concerns

#16
post #5
post #4

How much bounty would Apple pay, say if somebody steals one and sends it to them? Is it illegal to them to make such an offer?

The ‘offer’ isn’t illegal - going through with it would be though, for both sides. Grand theft and receiving stolen goods. Both not great, plus you’d be actively acting against the law enforcement system which would ensure a zealous prosecution.

Would making the offer be considered conspiracy to commit crime, or some such?

Re: GrayKey iPhone unlocker poses serious security concerns

#17
post #10

Is it just me or does the price point seem extremely low? They have a device that should be in high demand globally, and maybe one competitor. And they are charging 15-30k, for basically unlimited usage?? You can't tell me federal law enforcement wouldn't pay at minimum ten times that amount for metered usage...

I bet they realize the lifespan of this device is very short and are trying to maximize ROI short-term.

Re: GrayKey iPhone unlocker poses serious security concerns

#18

I hate this stuff. I want to secure my device and not have the govt or companies steal it, I want to control my device. Still, it's fascinating to learn about. Did no one think, when they take someone's phone for 5 minutes at the border, they could be doing this to your phone.

Well, as the article makes it clear it takes from hours to days to crack, no - they’re not doing this in 5 minutes at the border.

They can routinely keep you at the border for a few hours though.

Re: GrayKey iPhone unlocker poses serious security concerns

#20
post #10

Is it just me or does the price point seem extremely low? They have a device that should be in high demand globally, and maybe one competitor. And they are charging 15-30k, for basically unlimited usage?? You can't tell me federal law enforcement wouldn't pay at minimum ten times that amount for metered usage...

That was my thought, too. Other than this report, has there been verifiable evidence the device even works?

The photo stagings remind me of ones I’d use on a pre-release marketing site for a vapor-ware product to test demand and a price point.

Post reply on HN