Live data from Hacker News

Why can't Apple decrypt your iPhone?

blog.cryptographyengineering.com

111–120 of 132 posts

Re: Why can't Apple decrypt your iPhone?

#111

> (Apple pegs such cracking attempts at 5 1/2 years for a random 6-character password consisting of lowercase letters and numbers. PINs will obviously take much less time, sometimes as little as half an hour. Choose a good passphrase!) Do not use simple pin passwords on your phone. In particular, if you use fingerprint access, there is no reason not to have a long, complex password.

Fingerprints should not be treated as a substitute for a password. A password is "what you know", and a fingerprint is "what you have". If you also throw in "who you are" (retina sensors, blood biometrics, etc.), you have to combine at least two to have a proper system. By allowing the fingerprint scanners to become ubiquitous, they (Apple and Samsung) are training their users poorly.

Now one could make the argument that the fingerprint is more secure than a poor password, for most use cases. I'd tend to agree with that, with the caveat that it is no longer your decision (read: subject to your interrogation resistance) to open your phone if you are captured.

Re: Why can't Apple decrypt your iPhone?

#112
post #50

Earlier quoted context omitted.

It sounds more like they are using a Cortex-A5 to gain access to TrustZone with an existing x86 core.

And it sounds like Apple is using a separate unspecified ARM processor (probably a Cortex-A5 since that's the cheapest possible one) to gain access to an existing A7 or A8 core.

In Apple's case, they use the ARM ISA but implement their own micro architecture and from vvhn's comment seems to also use a co-processor specifically for the secure enclave. But the link above on TrustZone hardware architecture mentions that this isn't a requirement.

"TrustZone enables a single physical processor core to execute code safely and efficiently from both the Normal world and the Secure world. This removes the need for a dedicated security processor core, saving silicon area and power, and allowing high performance security software to run alongside the Normal world operating environment."

I guess since Apple use the ARM ISA, it's still binary compatible with ARM but with a different implementation. AMD uses an x86/ARM hybrid where the ARM part is an off the shelf Cortex-A5 which already contain TrustZone.

Re: Why can't Apple decrypt your iPhone?

#113
post #90
post #84

Earlier quoted context omitted.

Maybe I don't understand the problem, but it seems to me that it would be very simple for apple to prevent the popup messages at their discretion, since they write and control the software that causes the popup to happen in the first place.

They would have to update the OS on the device first. And that's definitely not something that can be done silently. I'm assuming here that the OS already doesn't have the ability to suppress the popup, and I think that's a safe assumption because Apple doesn't want to have this ability.

>They would have to update the OS on the device first. And that's definitely not something that can be done silently.

how do we know that the iMessage protocol doesn't already have support for a "silent" flag, which, if set, will not cause the message to appear?

Re: Why can't Apple decrypt your iPhone?

#114
post #62

Earlier quoted context omitted.

There is an argument against using the fingerprint access and that is that a user gives up the right of consent while in custody. If law enforcement gets a judicial order to forcibly press the prisoner's finger to the sensor to unlock the device, then he or she has little recourse as the right to remain silent is not implicated. One cannot be similarly physically compelled to disclose a code only held in his or her m…

If you have the ability to lawyer it enough, I think you'd have a few layers of court required to sort out whether this is allowed (assuming they don't have proof you have something on the phone). You are basically forcing self-incrimination, a violation of the Fifth Amendment. I totally agree that, if you are really concerned about this, fingerprint is a bad idea, but the legal ramifications are interesting. Not qui…

Or can I just cut somebody's finger off to use it?

You don't need a finger to circumvent touchid. You can just obtain your victim's fingerprint from anywhere (e.g. a glass that they used) and create a fake "finger" using household items:

http://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid

Re: Why can't Apple decrypt your iPhone?

#115

Earlier quoted context omitted.

You should try 1Password: https://agilebits.com/onepassword It's the most recommended password manager on Hacker News.

Thanks, I'm aware of it but it doesn't work for me. Beyond what I described above, I need something that works on Windows and Windows Phone, and I need it to securely sync between the two.

Can you use KeePass and just sync the database via dropbox?

Re: Why can't Apple decrypt your iPhone?

#116
So the article's answer to "Why can't Apple decrypt your iPhone?" is: "Because Apple says that no software can extract the UID".

In our post-Snowden world this is just ridiculous and intellectually insulting. The author is either naive beyond belief or he got paid to write this PR shill piece.

cf. https://gigaom.com/2014/09/18/apples-warrant-canary-disappea...

Re: Why can't Apple decrypt your iPhone?

#117
post #29
post #24

Earlier quoted context omitted.

[deleted]

> Also, it's my understanding that authentication can be trivially bypassed if the phone is kept powered on? (ie. authentication data is stored in memory? Seems to be the case for at least Touch ID) It can be bypassed if the phone is kept powered on -and someone is able to start running code on it-. The normal approach of Apple signing a malicious recovery/update image would require rebooting first; there are probabl…

Contact names are not displayed in the lock screen until the first unlock (new in iOS 8).

Notice how now all devices, not only ones with Touch ID, say that your phone needs to be unlocked for full functionality after a reboot.

Re: Why can't Apple decrypt your iPhone?

#118
With all the talks about supper crypto tech use in the Iphone, isn't cloning phone's data as simple as declaring your phone is loss and paying a mobile phone store clerk a new phone and reset the password for the I-Account? The new iphone would have access to all your info, pictures, msg logs in 1-2 hours?

Is this any reasonable PI, police, FBI, hackers can easily social engineer via legal and/or illegal means?

Re: Why can't Apple decrypt your iPhone?

#119

Earlier quoted context omitted.

Your advise is good, I'm not trying to dismiss or counter it. > In particular, if you use fingerprint access, there is no reason not to have a long, complex password. Very, very often my fingerprint isn't recognised properly and I have to type in my password. It has been getting better as of the last few updates, but I still need to input my password multiple times per day.

Try training it for a few minutes for each finger (go to Touch ID setting, tap with your finger, see the background flash, repeat ad libitum slowly rotating your finger in any direction; be patient; eventually it should recognize each finger even if rotated almost 90 degrees). It should get much better afterwards

Or use multiple slots for the one or two fingers that you actually use to unlock. One doesn't need to have every finger's fingerprint stored.

Re: Why can't Apple decrypt your iPhone?

#120
post #62

Earlier quoted context omitted.

There is an argument against using the fingerprint access and that is that a user gives up the right of consent while in custody. If law enforcement gets a judicial order to forcibly press the prisoner's finger to the sensor to unlock the device, then he or she has little recourse as the right to remain silent is not implicated. One cannot be similarly physically compelled to disclose a code only held in his or her m…

> One cannot be similarly physically compelled to disclose a code only held in his or her memory. You can in the UK. https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...

It's amazing how hard it can be to remember a password that one has not typed in a long time, and has been subjected to solitary confinement.

"Grassian and Haney show that a cluster of different symptoms, which they refer to as SHU syndrome, occurred in something like 90 percent of the prisoners they studied. Included symptoms can be affective, like paranoia and depression; cognitive, like confusion, memory loss, perceptual distortions, hallucinations; or even physical, like headaches and insomnia. So there is documented, psychiatric evidence that even a comparatively short term in solitary confinement can have negative consequences" (source http://www.vice.com/en_au/read/solitary-confinement-is-a-leg...)

Post reply on HN