Live data from Hacker News

GrayKey iPhone unlocker poses serious security concerns

blog.malwarebytes.com

21–30 of 97 posts

Re: GrayKey iPhone unlocker poses serious security concerns

#21
If this actually works there has to be some huge, embarrassing vuln in Apple's Secure Enclave Processor on par with the "CTS Labs" AMD secure coprocessor hoopla that hit the news just this week.[1][2]

The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper says it's supposed to survive restarts now.[3]

Based on the screenshots it looks like it can load custom firmware on the iPhone. That's bad.

[1] https://www.anandtech.com/show/12525/security-researchers-pu...

[2] HN discussion: https://news.ycombinator.com/item?id=16597626

[3] p15: https://images.apple.com/business/docs/iOS_Security_Guide.pd...

Re: GrayKey iPhone unlocker poses serious security concerns

#22

Passphrases are always going to be the strongest, but you can have more than 6 digits in your pincode. Select "Custom Alphanumeric Code" in Passcode Options[1], but only enter digits using the keyboard. iOS will display a pin pad on the lock screen that will accept any number of digits[2]. I picked this up from the delicious iOS 11 security whitepaper[3]. [1] https://i.imgur.com/KEEC71B.png [2] https://i.imgur.com/Yr…

It was rumors of this process that made me encourage everyone to use a 12-digit or greater passcodes.

Re: GrayKey iPhone unlocker poses serious security concerns

#24
post #5
post #4

How much bounty would Apple pay, say if somebody steals one and sends it to them? Is it illegal to them to make such an offer?

The ‘offer’ isn’t illegal - going through with it would be though, for both sides. Grand theft and receiving stolen goods. Both not great, plus you’d be actively acting against the law enforcement system which would ensure a zealous prosecution.

Of course it is. You can't broadcast a bounty on someone's life, or their property, or any other illegal act. It is solicitation.

Re: GrayKey iPhone unlocker poses serious security concerns

#26
post #17
post #10

Is it just me or does the price point seem extremely low? They have a device that should be in high demand globally, and maybe one competitor. And they are charging 15-30k, for basically unlimited usage?? You can't tell me federal law enforcement wouldn't pay at minimum ten times that amount for metered usage...

I bet they realize the lifespan of this device is very short and are trying to maximize ROI short-term.

That was my thought as well - but on the flip side, by dealing in quantity they are a lot more likely to have one leak and be reverse engineered, and thus have Apple render them all useless.

It's certainly an interesting problem of profit maximization!

Re: GrayKey iPhone unlocker poses serious security concerns

#28
post #23
post #4

How much bounty would Apple pay, say if somebody steals one and sends it to them? Is it illegal to them to make such an offer?

You would obviously just refrain from discussing the manner in which the device was acquired.

The cops have never heard that one before.

Re: GrayKey iPhone unlocker poses serious security concerns

#29

However, it does mean that an iPhone’s security cannot be ensured if it falls into a third party’s hands. That was and will always continue to be true. Even secure cryptoprocessors of the type used in smartcards and HSMs can be cracked with enough determination and time. There are companies in China who will read and clone them for surprisingly little money. It has always amused me somewhat how scared (or the impress…

>or even better --- not leaving your brain at all.

The faintest of ink will outlast the best of memory, or something like that.

Re: GrayKey iPhone unlocker poses serious security concerns

#30
post #17

Earlier quoted context omitted.

I bet they realize the lifespan of this device is very short and are trying to maximize ROI short-term.

That was my thought as well - but on the flip side, by dealing in quantity they are a lot more likely to have one leak and be reverse engineered, and thus have Apple render them all useless. It's certainly an interesting problem of profit maximization!

Unless the vulnerability is in the CPU/DMA/whatever and not easily patched. Everyone assumes that Apple has no idea what it is, maybe they are keenly aware and it’s just not fixable.
Post reply on HN