Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

181–190 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#181

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand" ( https://9to5mac.com/2016/12/05/uk-police-have-a-new-tactic-f... ) I remember reading this a few years back. The title says it all. Why bother cracking codes etc when you can get a judge to sign THAT for you? :) Going through the PDF of the legal document, on page 10, the scr…

> Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand"

PSA: On an iphone if you hold down the power button and a volume button for a second, your phone will lock into the state its in just after you turned it on. From here it can only be unlocked with your passcode. You can perform this gesture without taking your phone out of your pocket.

(Edit: When the phone is unlocked, you need to use power + volume down. Power + volume up while the phone is unlocked takes a screenshot.)

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#182
post #179
post #125

Earlier quoted context omitted.

One thing they did do: if you bring up the power off screen (by holding power, or power+volume up, depending on model) then it disables biometric unlock, even if you don't power it off. Bringing up the power off slider screen is sufficient to force a passcode-only unlock.

You can also disable biometrics by spamming the lock button.

On the latest iOS, on the latest/largest iPhone, this does not appear to be true any longer.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#183

Earlier quoted context omitted.

Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand" ( https://9to5mac.com/2016/12/05/uk-police-have-a-new-tactic-f... ) I remember reading this a few years back. The title says it all. Why bother cracking codes etc when you can get a judge to sign THAT for you? :) Going through the PDF of the legal document, on page 10, the scr…

To defend against on-device attacks or iCloud backups, Telegram would need to do its own, separate encryption of its storage and prompt the user for a passphrase at app launch. The typical security model for iOS apps assumes that the local device is secure, as its storage is already encrypted by the system based on its passcode/biometrics (on initial power-up biometrics aren't available). End-to-end encryption within…

> To defend against on-device attacks or iCloud backups, Telegram would need to do its own, separate encryption of its storage and prompt the user for a passphrase at app launch.

This isn’t quite correct. iOS applications can exclude files from iCloud backups.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#184

But would it do that and admit that when it's not really worth? Din't you have to be really really notorious for them to use this kind of evidence in a court? If I were them and could decrypt something I would prefer to keep this fact secret.

Presumably a defence lawyer could ask for demonstration of the technical details: prove that they have the ability to obtain such evidence and didn't just fabricate it.

Then everybody would know they can and no people of those they could want to hunt would rely on the compromised technologies anymore.

There are rumors they can even decrypt HTTPS but I bet they would do their best to hide that if they actually could.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#185

Earlier quoted context omitted.

Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand" ( https://9to5mac.com/2016/12/05/uk-police-have-a-new-tactic-f... ) I remember reading this a few years back. The title says it all. Why bother cracking codes etc when you can get a judge to sign THAT for you? :) Going through the PDF of the legal document, on page 10, the scr…

> Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand" PSA: On an iphone if you hold down the power button and a volume button for a second, your phone will lock into the state its in just after you turned it on. From here it can only be unlocked with your passcode. You can perform this gesture without taking your phone out of y…

> hold down the power button and a volume button for a second

On android phones, it takes a screenshot.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#186
I wonder if Apple's relentless march towards eliminating all physical ports on the phone is at least in some small part an attempt to harden against these GrayKey / Cellebrite tools that can attack the phone.

I am not particularly familiar with them, but having previously been someone who jailbroke my phone, several of the exploits used were originally delivered via plugging the phone in to another device, i.e. through the data port on it. Elimiating this may be to them a way to harden the phone against this, for both better (these tools) and worse (the JB scene).

This of course does not prevent remote or semi-remote wireless attacks, such as through the cellular baseband.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#187
post #46

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

Yeah exactly, we can't read cypher text and so aren't included in the end to end encryption contract of signal. Frankly this is nothing to do with signal and everything to do with phone security.

How about if Signal encrypted all your stored communication when not in use and required a password (and 2FA) to decrypt it? Thus the app's security is ~independent of phone security, at least for forensic seizure analysis.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#188

Earlier quoted context omitted.

Yes it does, since it's not presented as factual.

It's written as a statement, not as a figure of speech. If it's not intended to be factual, it should be annotated as such. It literally claims theft as it stands, which makes the article seem juvenile in use of language.

https://www.dictionary.com/browse/figure-of-speech

It doesn't have to be labeled in big flashing letters "THIS IS A FIGURE OF SPEECH" for reasonable people to construe it as a figure of speech.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#189
post #185

Earlier quoted context omitted.

> Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand" PSA: On an iphone if you hold down the power button and a volume button for a second, your phone will lock into the state its in just after you turned it on. From here it can only be unlocked with your passcode. You can perform this gesture without taking your phone out of y…

> hold down the power button and a volume button for a second On android phones, it takes a screenshot.

Just checked + updated my comment.

iOS also takes a screenshot when the phone is unlocked if you use power + volume up. Holding power + volume down hard locks the phone even when its unlocked

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#190

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

Seems like this is partially Signal's fault to me. Why doesn't Signal independently encrypt the message db when not in use? It's well known at this point that iPhone is easily cracked, and thus Signal provides no security for a stolen phone.

Edit: it seems that Signal uses db protection but in a way that fails for a cracked phone like this (?): https://news.ycombinator.com/item?id=26096778

Post reply on HN