Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

171–180 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#171
post #138

Earlier quoted context omitted.

No, I support China being able to spend an appreciable amount of time to crack each phone they have physical possession of, following a court order. I never suggested the ability for remote compromise (what Huawei is accused of), and my exact point is that we can create a cost to cracking each phone — in hashing power and time spent — if we compromise on the topic. No such cost exists now, because they achieve access…

> my exact point is that we can create a cost to cracking each phone — in hashing power and time spent This is not at all how encryption or security works

It’s exactly how it works:

You create a hash chain, then use the final result as an encryption key of your secret (in this case, the key for the data), then store only the start of the chain and encrypted secret.

The only way to retrieve the secret is to recompute all the hashes, from the start, to recreate the key and decrypt the data.

So it’s secure unless you believe there’s a weakness in the underlying encryption or hash function.

Further, you can parallelize this via encrypting the start of chains with other chains — giving a significant advantage to the chain creator: they can do 1000 chains in parallel, but unlocking requires decrypting them sequentially. At that ratio, if you want decryption to take a month of steady hashing, you need only do a little under 1 hour of hashing yourself. 1 hour of 1 GPU is about a dollar of expense, and has more than 1000 parallel tracks.

My suggestion would be that Apple create a chain for each phone and then load it with that phone specific wrapping key — which it uses to return the actual encryption key wrapped in. The only way to decrypt that key is get the necessary information from Apple and a signed request so the SE will emit the encrypted key at all.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#172

Earlier quoted context omitted.

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content. Instead of pontificating, the tech industry should innovate. There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal syst…

The objections to a golden key are irrespective of whatever system permits the golden key access. Your hashchains are completely irrelevant. The courts will use some key to sign their request, and that key will leak. Cryptography reduces message security to key security, nothing more.

That’s why it’s a two stage system: leaking the key only permits forged requests, but an attacker still has to spend the time reversing the hash chain. For each and every phone they want to crack.

Apple has also done a reasonable job of holding onto their signing keys, to date.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#173
post #96

Earlier quoted context omitted.

No, I support China being able to spend an appreciable amount of time to crack each phone they have physical possession of, following a court order. I never suggested the ability for remote compromise (what Huawei is accused of), and my exact point is that we can create a cost to cracking each phone — in hashing power and time spent — if we compromise on the topic. No such cost exists now, because they achieve access…

The "hashing time per crack" reminds me of the old 48-bit encryption which was mandated to have short, crackable keys. Or even the previous attempt at doing this with the "LEAF". Are you proposing some sort of work function within the crypto enclave ? ie you leave the device brute-forcing for a few days and it spits out the key? The "appreciable time" is going to be subject to constant downward pressure, both politic…

I was purposing each phone be loaded with a unique “export key” while being built. For about 1 dollar of GPU time, you can force an attacker to take a month of continuous hashing, on similarly performing hardware. (Okay, people with fancy ASICS could get that down to a week... but that still seems like a big win.)

More details here: https://news.ycombinator.com/item?id=19040252

I agree that it would be a consistent political battle — but it’s already that, and it’s clear people with power are getting fed up with technologists attempting to impose their ideology without compromising with other social needs.

That’s what prompts laws about wiretapping or mandated backdoors.

I haven’t heard the same arguments about safes I do about encryption — and the reason is because there’s an understood bypass, if they gain access, have time and money.

By compromising and allowing targeted cracking, we split the faction pushing for backdoored phones, solve most of the issues, and give ourselves a viable path to accomplish something rather than being forced into backing down or completely compromising systems. Further, by being willing to compromise, we gain a voice on shaping how that discussion looks — rather than largely being excluded.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#174
post #84

Earlier quoted context omitted.

Nobody credible believes for a second that Apple was involved, for whatever it’s worth.

I was not trying to suggest that, I was trying to convey that once a spy agency has remote access (sanctioned or otherwise) we can see by this example how it is proliferated and abused.

yeah, but the Australian Government is busy passing laws to require companies like Apple to do something pretty much exactly like this.

(And in my mind at least, those laws are without doubt part of a coordinated five eyes security/law-enforcement campaign to push those kinds of laws through everywhere: "Look, it works in Australia!" the Canadians/UK/NZ/US will say...)

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#175

Earlier quoted context omitted.

The objections to a golden key are irrespective of whatever system permits the golden key access. Your hashchains are completely irrelevant. The courts will use some key to sign their request, and that key will leak. Cryptography reduces message security to key security, nothing more.

That’s why it’s a two stage system: leaking the key only permits forged requests, but an attacker still has to spend the time reversing the hash chain. For each and every phone they want to crack. Apple has also done a reasonable job of holding onto their signing keys, to date.

> Apple has also done a reasonable job of holding onto their signing keys, to date.

How do you know that?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#176

Earlier quoted context omitted.

How is he supposed to refer you to people not saying something? This is most definitely a rather silly request. Can you prove that magic doesn’t exist?

> How is he supposed to refer you to people not saying something? That's not what I was asking for. I was asking him to refer me to credible people saying that they don't believe Apple was involved. Here is what he said: > Nobody credible believes for a second that Apple was involved, for whatever it’s worth. I thought perhaps he had read about credible people making this claim, or had some other way of knowing what…

You seem to assume that “apple planted this backdoor” is a realistic enough claim that someone credible would be willing to waste their time on it.

Well, it isn’t.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#177

Earlier quoted context omitted.

That’s why it’s a two stage system: leaking the key only permits forged requests, but an attacker still has to spend the time reversing the hash chain. For each and every phone they want to crack. Apple has also done a reasonable job of holding onto their signing keys, to date.

> Apple has also done a reasonable job of holding onto their signing keys, to date. How do you know that?

Because whoever has stolen them has been reasonably discreet, and we don’t see compromised Apple things all over the place — which means if they’ve been stolen at all, it’s been by high class attackers.

If your goal is to stop the NSA et al stealing a key or owning a device, you’ll be sad.

But if your goal is to change the law and redefine the parameters of them owning devices, you might make progress. The political process will insist on a means to access these devices, and they’ll accomplish it by one means or another. By engaging with instead of fighting that, we gain the ability to have a say on what those means are.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#178
post #84

Earlier quoted context omitted.

I was not trying to suggest that, I was trying to convey that once a spy agency has remote access (sanctioned or otherwise) we can see by this example how it is proliferated and abused.

yeah, but the Australian Government is busy passing laws to require companies like Apple to do something pretty much exactly like this. (And in my mind at least, those laws are without doubt part of a coordinated five eyes security/law-enforcement campaign to push those kinds of laws through everywhere: "Look, it works in Australia!" the Canadians/UK/NZ/US will say...)

That's precisely the GP's point.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#179

Earlier quoted context omitted.

The ones who are capable of compelling the phone company to obey over political pressure from other sources. This is a strict improvement over the current situation, where the answer is “anyone who has money”.

Providing deliberate backdoors to the legal system does not preclude the discovery of other exploits, and the sale of those exploits to whoever has money.

It does not, but it changes the set of people looking to buy them and the way in which they’re used, both of which impact the general market for vulnerability sales — and additionally, re-aligns some present attackers to defenders.

Security researchers, strangely enough, seem to care who they sell to. If the NSA stopped buying and only the UAE was interested, I expect we’d see some firms move to other business models or targets for “research”.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#180
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content. Instead of pontificating, the tech industry should innovate. There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal syst…

> What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails”. I think it’s been empirically demonstrated that won’t happen.

It's very much the other way. Strong encryption algorithms have been available to the public for a long time now. You can ban using them, but the only way to effectively enforce that ban would be for the government to require that all devices capable of running code from external sources run only code that's signed by that government.

Without that, you can ban all you want, but terrorists and others who need that stuff will have it anyway. So the only effect would indeed be no privacy for saucy emails. Of course, intelligence agencies would love that, since it would allow them to have a society-wide dragnet.

Post reply on HN