Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

81–90 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#81
post #19
post #15

Earlier quoted context omitted.

> (tip: 5 presses of the lock button on iPhone wipes in-memory encryption keys, essentially exiting "AFU mode") Is this the same thing as holding down the lock button and one of the volume buttons on one of the newer iPhones? I'm referring to this doc: https://support.apple.com/en-us/HT208076

Yes, it's basically a side effect of activating Emergency SOS. The five-press shortcut works on all iPhones as far as I'm aware. As the doc says: "If you use the Emergency SOS shortcut, you need to enter your passcode to re-enable Touch ID, even if you don't complete a call to emergency services. "

I have an iPhone X and I have it set to not use FaceID for unlocking the phone itself.

But I temporarily enabled it now to test. Maybe I am pressing the power button wrong but rapidly pressing it five times does not prevent it from allowing FaceID to unlock the phone. Whereas power plus volume up button does indeed.

Btw, when I normally have FaceID disabled from unlocking the phone, does it wipe in-memory encryption keys when locked with a single touch to the power button or not? I was assuming that it did, but I realized now that this assumption might not be correct.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#82
post #46

Earlier quoted context omitted.

Yeah exactly, we can't read cypher text and so aren't included in the end to end encryption contract of signal. Frankly this is nothing to do with signal and everything to do with phone security.

Does Signal still require you to register and verify using a real cell phone number?

Yes. But note that Signal doesn't know your number. Usernames are being promised this year too.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#83
post #55

Earlier quoted context omitted.

Your understanding of baseband attacks is not correct. Having a baseband exploit would not facilitate this. Nor would exploits/backdoors in any particular app.

Why couldn't a baseband attack facilitate this? It was shown at least as far back as 2017[0] that a program on a baseband could affect the memory of the application processor, and in 2018[1] that a specially crafted message can achieve an RCE on a baseband. Since then, cell modems have gotten even more integrated with APs. [0] https://comsecuris.com/blog/posts/path_of_least_resistance/ [1] https://i.blackhat.com/us-1…

>Why couldn't a baseband attack facilitate this?

Because this is about the iPhone, where the baseband is just a USB peripheral. There simply is no DMA. iPads and Macs have DMA controls in place as well. There are other iPhone attacks for sure, but they have been fairly conscious about keeping the baseband isolated for a good long while. So it's less likely to be the vector. Apple didn't spend a ton of money on a custom security processor and OS stack just to let a 3rd party vendor firmware walk all over it. From page 41 of their old iOS Security Guide:

>"To protect the device from vulnerabilities in network processor firmware, network interfaces including Wi-Fi and baseband have limited access to application processor memory. When USB or SDIO is used to interface with the network processor, the network processor can’t initiate Direct Memory Access (DMA) transactions to the application processor. When PCIe is used, each network processor is on its own isolated PCIe bus. An IOMMU on each PCIe bus limits the network processor’s DMA access to pages of memory containing its network packets or control structures."

You'll notice in those papers you link, that "iPhone" and "Apple" do not appear as subjects of the paper. Cellebrite and the like are probably doing other things.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#84

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

This should bring into question even more Signal's implementation of using real phone numbers for accounts. It is NOT privacy focused. Even if this 'hackability' is an issue only with the security of the phone/hardware - able to be hacked and thus reach the decrypted signal messages - That also means, that person's Signal contacts also have their real identities exposed. (Where they wouldn't be if the account names/i…

> It is NOT privacy focused.

It’s not anonymity focused.

If I want to have private conversations with friends, family or colleagues signal is fine.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#85

Earlier quoted context omitted.

Does Signal still require you to register and verify using a real cell phone number?

Yes. But note that Signal doesn't know your number. Usernames are being promised this year too.

> But note that Signal doesn't know your number

Courts can compel them to keep these records, and require them to not disclose to their customers that they are doing so.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#86

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

This is why I keep a "universal hammer" at my desk. If the gov boys walk in all I have to do is use it on my phone / laptop.

Problem solved.

Thinking about upgrading to a small commercial grade shredder or microwave.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#87
post #7

How is it possible that the FBI has so much advanced stuff when I’ve never met a skilled developer willing to work for what the government pays? Are their tools developed by high paid contractors?

People sometimes have a hard time seeing outside their bubble. For example, how many Mormons do you know?

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#88

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

The iPhone's terrible battery life isn't a bug, it's a privacy feature! I wonder if the FBI's evidence protocol involves immediately plugging in an iPhone to maintain the vulnerable state:

> That latter acronym stands for “after first unlock” and describes an iPhone in a certain state: an iPhone that is locked but that has been unlocked once and not turned off. An iPhone in this state is more susceptible to having data inside extracted because encryption keys are stored in memory.

I do wish Apple would add "restart" as one of the system actions in the Shortcuts app.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#89
post #65

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> Monitoring shouldn't be the default but only happen when there is a warranted reason to monitor, preferable with a literal warrant. In many cases, well-done E2EE like Signal stops dragnets and targeted efforts. Even with a literal warrant.

No they don't, they just force the police to do regular police work and infiltrate the group the old fashioned way rather than using mass surveillance.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#90

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital

Those folks walked over on public roads from a Trump rally down the street, live streaming on a hundred cameras as they did it. Of all the things that went wrong on the 6th, surveillance was clearly not one of them.

What I think you're remembering is more the point that Signal and Telegram provide harder-to-surveil forums for the people who got radicalized. That having all that chatter be private by default means that we won't see the next extremist faction before its born. And that's a fair enough point. Q communities on Facebook and Twitter made it easy to see where these people were coming from.

But even there, the nature of radicalization is that it happens in a big group. There may be surveillance-proof channels on Telegram where modern right wing extremists are assembling to find like minded souls, but finding them isn't a problem at all. The ones that are hard to find die out by definition.

Post reply on HN