Interesting that this company is able to do this without threat of being sued into a smoking crater by Apple. They'd have to use Apple's software to build their product, and to do that they'd be bound by the license agreement. Apple could forbid the research in the license. Oracle created the DeWitt Clause that forbids researchers from publishinging benchmarks for their products, and this apparently stands up in cour…
"Oracle created the DeWitt Clause that forbids researchers from publishing benchmarks for their products, and this apparently stands up in court." Was this "DeWitt Clause" ever challenged specifically in a trial ? If yes, can you give us some details, e.g., date, the name of the opposing party, the venue, etc.? If it has never been challenged specifically, and gone through litigation all the way to a trial, can we ho…
Cellebrite claims it can unlock any iPhone, many new Android phones for police
31–40 of 90 posts
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#32This is almost certainly a way to brute-force passwords without the rate limit which is enforced by default. The only reason passwords can be brute-forced is that they're numeric and have few digits. If you use an alphanumeric passcode with at least 8-10 digits, you're fine.
What makes you so certain of that?
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#33Earlier quoted context omitted.
The radio interfaces do not have total access to the device but they have enough that it is feasible to compromise a device via a compromise of a radio component.
Can you be more specific about the nature of the exploit you are imagining? For example, how can a radio interface have "enough" access to facilitate decryption of an encrypted volume?
Get code execution on the radio chip, use that to harvest the decryption keys from RAM and the rest is pretty trivial.
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#34This is almost certainly a way to brute-force passwords without the rate limit which is enforced by default. The only reason passwords can be brute-forced is that they're numeric and have few digits. If you use an alphanumeric passcode with at least 8-10 digits, you're fine.
What makes you so certain of that?
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#35This is almost certainly a way to brute-force passwords without the rate limit which is enforced by default. The only reason passwords can be brute-forced is that they're numeric and have few digits. If you use an alphanumeric passcode with at least 8-10 digits, you're fine.
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#36Earlier quoted context omitted.
"Oracle created the DeWitt Clause that forbids researchers from publishing benchmarks for their products, and this apparently stands up in court." Was this "DeWitt Clause" ever challenged specifically in a trial ? If yes, can you give us some details, e.g., date, the name of the opposing party, the venue, etc.? If it has never been challenged specifically, and gone through litigation all the way to a trial, can we ho…
What would the nature of that specific challenge be?
It might be possible to require a publication delay as a condition to a license, but an outright ban on publication might not be enforceable. The only way to know for sure is a lawsuit that goes to trial. Of course, even if we never actually find out because it never actually is the basis of any litigation that goes to trial, inclusion of a "DeWitt Clause" in a license could still intimidate licensees and effectively discourage publication.
The 2002 story linked on the Wikipedia page for "DeWitt Clause" mentions a telephone call to DeWitt's employer asking for him to be terminated. However it says nothing about a lawsuit based on breach of this particular "DeWitt Clause".
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#37Earlier quoted context omitted.
>First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from ? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple? That's one way to look at it. Another is that they provide law enforcement the ability to c…
One way or another, they are facilitating (in fact profiting from) one human to forcibly access a sensitive device belonging to another human, with the consent of the latter. The sex offender spectre doesn't change that.
It's like saying that because hidden recording devices can be abused it should be illegal (or at least one should be ashamed of) to create it.
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#38Earlier quoted context omitted.
Can you be more specific about the nature of the exploit you are imagining? For example, how can a radio interface have "enough" access to facilitate decryption of an encrypted volume?
The radios quite probably use DMA to blast bits to/from main memory. Get code execution on the radio chip, use that to harvest the decryption keys from RAM and the rest is pretty trivial.
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#39I think what makes this statement interesting is that Apple recently introduced anti-replay counters into their A12 SOC to defeat replay attacks that just reset the memory after each attempt.
I think this might represent a new generation of attacks that either have found a bug in the secure enclave OS itself or some kind of local timing/side channel attack.
The secure enclave has been getting more complex (things like neural net for FaceID) and I have no idea if it has modern mitigations like ASLR so there is reasonable chance people can get execution there. Really just another local privilege escalation.
The side-channel idea is also really interesting because a lot of the row-hammer and SPECTRE style attacks seem far-fetched in real scenarios but attacking a different ring of your own chip with full kernel access makes any kind of hardware attack seem much more reasonable.
Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police
#40First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from ? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple? Annnyway, more importantly: are there any details about how their claims are even possible?…
Flaunting this is great advertising for them - and most importantly free advertising for them. Not saying it’s right, but this is how they get customers when direct word of mouth is too slow.