Live data from Hacker News

GrayKey iPhone unlocker poses serious security concerns

blog.malwarebytes.com

61–70 of 97 posts

Re: GrayKey iPhone unlocker poses serious security concerns

#61

Earlier quoted context omitted.

It’s not at odds with it - it’s pretty obviously using a vulnerability to run a crack against the passcode. Once the passcode is found, that is used to unlock the phone and this the Secure Enclave.

I agree it’s not at odds with it, but it’s not even that simple - the passcode is enforced by the Secure Enclave itself. It’s not a case of “try passcodes until you find the right one then tell the SEP” - it has to be exploiting a vulnerability in the SEP itself, assuming what we know of the design and attack is true.

Technically, this does not absolutely have to be a SEP vuln. It's possible that the PIN is being stored (not properly zero'd-after-use) somewhere outside the SEP, i.e. a pinpad entry buffer or something. Often criminals do not think of, or are unable to, turn off their phone when being arrested. Furthermore the iPhone battery is not removable and some portions of its DRAM - in theory anyway - could persist even when the phone is "off". Apple has (or at least - prior to public outrage - had) a fairly loose definition of "off" for other aspects of the system, such as bluetooth.

Re: GrayKey iPhone unlocker poses serious security concerns

#62
post #48

Earlier quoted context omitted.

>or even better --- not leaving your brain at all. The faintest of ink will outlast the best of memory, or something like that.

"A dull pencil is better than the sharpest mind." Thats the way I've always heard it.

I’ll have to write that down so I don’t forget it.

Re: GrayKey iPhone unlocker poses serious security concerns

#63
post #48

Earlier quoted context omitted.

"A dull pencil is better than the sharpest mind." Thats the way I've always heard it.

I’ll have to write that down so I don’t forget it.

Make sure you use a dull pencil, we have no data about how others types compare with minds.

Re: GrayKey iPhone unlocker poses serious security concerns

#64

Earlier quoted context omitted.

The DMCA specifically criminalises the circumvention of copyright protection methods , not all access controls.

I’m not a lawyer, but quoting from the Wikipedia article the DMCA “also criminalizes the act of circumventing an access control, whether or not there is actual infringement of copyright itself.” You could argue that you hold copyright on for example a photo you’ve taken, and the passcode is the access control method.

I’m also not a lawyer, but I have no reason to believe that would be an arguable case; the fact that an access control method incidentally makes gaining access to copyright materials harder doesn’t make it a copyright protection method.

Re: GrayKey iPhone unlocker poses serious security concerns

#65
post #56

I thought iPhone were electronically secure, it seems they are not. I thought the FBI had to just do some Xray of some chip to read some ROM thing. Sometimes I wonder if real security is really and theoretically possible, or if it's just engineers who never manage to achieve it because designers want things to be usable for consumers. What ever happens it doesn't seem really secure, consumer oriented device do exist.…

What is real security? Is it absolute security?

Are you willing to pay $500k for a phone? Is there a vendor who is willing to put R&D investment of $20mil so you can buy one? How much more phones they would sell? If you would be Ed Snowden would you even trust that company?

Are you going to buy a safe to keep family photos in it?

What does it even mean for you to have absolutely secure phone if you are going to be hit by a bus tomorrow?

Re: GrayKey iPhone unlocker poses serious security concerns

#66

I bet there is lawsuit in works by Apple et al! I mean if they truly broke and iPhone lock, then it means they had to be tampering with a true Apple device (not a dummy) in order to make their device work. Therefore, they violate Apple TOS that I am sure forbids any sort of backdooring. I doubt they will go after a rouge chinese jailbreaker sitting in moms basement and trying to make a name for him/herself, but here…

[deleted]

Re: GrayKey iPhone unlocker poses serious security concerns

#67

Passphrases are always going to be the strongest, but you can have more than 6 digits in your pincode. Select "Custom Alphanumeric Code" in Passcode Options[1], but only enter digits using the keyboard. iOS will display a pin pad on the lock screen that will accept any number of digits[2]. I picked this up from the delicious iOS 11 security whitepaper[3]. [1] https://i.imgur.com/KEEC71B.png [2] https://i.imgur.com/Yr…

This is plainly brilliant. Just done that and the interface seems to not give any clue about the expected number of digits. Meaning that an attacker have no mean to even estimat the time needed to unlock. One could only figure out that complexity of password increased after failing all attempts with less digits (which will already take a lot of time).

But of course alphanumerical would be even safer.

Re: GrayKey iPhone unlocker poses serious security concerns

#68
post #21

If this actually works there has to be some huge, embarrassing vuln in Apple's Secure Enclave Processor on par with the "CTS Labs" AMD secure coprocessor hoopla that hit the news just this week.[1][2] The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper sa…

It seems like they don't have the exponential delays, but they do have delays. Why else would it take 3 days to unlock the phone if it has a 6-digit passcode? Apple's security paper says it would take more than 50 years to brute-force an alphanumeric 6-digit passcode at 80ms per iteration. I suspect that's still correct here (if “3 days or more” is for 6 numeric digits).

er, that should say 5 years, not 50. typo.

Re: GrayKey iPhone unlocker poses serious security concerns

#70
I wonder: Apple has hundreds of billions in overseas cash. Why don't they go after Cellebrite and Grayshift and offer the owners something to the tune of 1-2 billion US$ in hard cash? Given the reputation hit once this knowledge becomes widespread, a couple billion dollars are pocket change.
Post reply on HN