Live data from Hacker News

Cellebrite claims it can unlock any iPhone, many new Android phones for police

wired.com

41–50 of 90 posts

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#41
post #3

First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from ? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple? Annnyway, more importantly: are there any details about how their claims are even possible?…

What? There are a lot of careless people not creating backups not setting up iCloud, but storing valuable data on their phone.

Why shouldn't they be able to access their data?

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#42

This is almost certainly a way to brute-force passwords without the rate limit which is enforced by default. The only reason passwords can be brute-forced is that they're numeric and have few digits. If you use an alphanumeric passcode with at least 8-10 digits, you're fine.

Is it certain that they encrypt the symmetric key with a hash derived from the alphanumeric one? It is not inconceivable that they assume the secure enclave is secure and just store the symmetric key verbatim. This seems like the only sensible option for PIN, so if you're already doing that, it is very possible they just use the same scheme for the alphanumeric passwords.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#43

Wouldn't such an ability, by virtue of having been tested at least once, run afoul of the DMCA? Of course, it is an Israeli company and not an American one, and we have no proof that they have the ability or have ever exercised it, and IANAL, but I am curious.

DMCA? How, they don't do this to access protected music/movie files. Or is that statute also covers other kinds of data?

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#44
post #28

This is almost certainly a way to brute-force passwords without the rate limit which is enforced by default. The only reason passwords can be brute-forced is that they're numeric and have few digits. If you use an alphanumeric passcode with at least 8-10 digits, you're fine.

What makes you so certain of that?

#1 it's the most plausible given that it's impossible to be patched upstream and apple aren't slouches regarding crypto. #2 I saw a demo a while back of such a mechanism, and it was obviously brute-forcing. Rest assured, I'm not working for cellebrite selling fake assurances; it's obvious alphanumerics aren't less secure than numeric PINs, and you shouldn't store anything actually sensitive on a biometric-enabled phone anyway.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#45

This is almost certainly a way to brute-force passwords without the rate limit which is enforced by default. The only reason passwords can be brute-forced is that they're numeric and have few digits. If you use an alphanumeric passcode with at least 8-10 digits, you're fine.

I don't think it's so obvious what the vulnerability is... or apple would want to patch it

Apple can't patch it. It's a fundamental limitation that, somewhere on the device, is stored a key; if you can extract that key, then you can run brute-force on it as much as you want from a supercomputer. And it has to be extractable because the phone itself has to use it.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#46

That is terrifying given how the phone is the single key to many people's digital identity and their finances. And that's what scared me into changing my relationship with my phone. I try to treat it as an ephemeral, disposable data terminal in which I have minimal trust. Every few weeks I back it up to the LAN and purge it. If I lose it I revoke its login certificates so that it can't access the mail and chat server…

You can also use apps and protocols like PhotoSync, GoodReader and WebDAV/CalDAV to wirelessly move data from phone to home NAS.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#47
post #36
post #31

Earlier quoted context omitted.

What would the nature of that specific challenge be?

For example, if there was a lawsuit for breach of license agreement based on publishing results in violation of the "DeWitt Clause", the defendant might argue that clause was unenforceable. It might be possible to require a publication delay as a condition to a license, but an outright ban on publication might not be enforceable. The only way to know for sure is a lawsuit that goes to trial. Of course, even if we nev…

I'm no lawyer but it seems to me the world is awash with contracts that include agreements by one or more parties not to disclose something or other. What's the sort of thing that would make this particular one 'not enforceable'?

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#48
post #43

Wouldn't such an ability, by virtue of having been tested at least once, run afoul of the DMCA? Of course, it is an Israeli company and not an American one, and we have no proof that they have the ability or have ever exercised it, and IANAL, but I am curious.

DMCA? How, they don't do this to access protected music/movie files. Or is that statute also covers other kinds of data?

It is my understanding that under the DMCA the security measures themselves are copyrighted works and breaking them is a violation of the DMCA in and of itself. That’s why breaking DRM, even if it’s to access public domain works is still illegal.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#49
post #20
post #17

Earlier quoted context omitted.

The radio interfaces do not have total access to the device but they have enough that it is feasible to compromise a device via a compromise of a radio component.

Can you be more specific about the nature of the exploit you are imagining? For example, how can a radio interface have "enough" access to facilitate decryption of an encrypted volume?

I do not think that a radio interface could have enough access to facilitate decryption of an encrypted volume. What I imagine it has enough access to do is to pivot to the OS running on the main CPU via a bug in the interface that is exposed for the radio to communicate with the main CPU.

From there they would likely have to exploit a number of other bugs to get into the position that they want to be in.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#50
post #12

Earlier quoted context omitted.

Are you seriously shocked that there are people out there that would be willing to assist law enforcement? It's not like they are advertising this service for anyone to drop by with any arbitrary phone to unlock. They are no worse than locksmiths advertising the ability to crack safes.

> Are you seriously shocked that there are people out there that would be willing to assist law enforcement? ... They are no worse than locksmiths advertising the ability to crack safes. It's more like a locksmith advertising the ability to break anyone's safe that contains details on every place you've ever been, purchase you've ever made, and person you've ever communicated with. Phones are far more ubiquitous and…

Are you suggesting a locksmith should refuse to help the police open safes that contain too many valuables or PII inside?
Post reply on HN