Live data from Hacker News

Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

buzzfeed.com

21–30 of 61 posts

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#21
post #18

More confirmation, as if anyone needed it, that this case is not about the months-old data on one particular phone, but rather about breaking the security of all phones.

Sorry, but how does this confirm that? It sounds to me as though someone screwed up by changing the password rather than it being intentionally changed so they could request that Apple build an iOS with a backdoor.

Hanlon's Razor, eh? Very rational. Would you be interested in purchasing shares in the Golden Gate Bridge?

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#22

Mind blown, if this is true!

Buzzfeed's news reporters are as good as any among the top organizations, including in tech. Recently their work made the top of HN, as their reporting led to the major shakeup at Zenefits http://www.buzzfeed.com/williamalden/how-high-flying-zenefit...

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#23
post #18

More confirmation, as if anyone needed it, that this case is not about the months-old data on one particular phone, but rather about breaking the security of all phones.

Sorry, but how does this confirm that? It sounds to me as though someone screwed up by changing the password rather than it being intentionally changed so they could request that Apple build an iOS with a backdoor.

How does one change the password they supposedly do not know and need Apple's assistance to retrieve?

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#24
Is there a reason Apple can't take apart the phone and access the hard drive directly?

Maybe put the hard drive on a dev board of sorts. AFAIK, most cell-phones have dev board versions that the mfg's engineers use to test various component hardware revisions no?. There they can access it through root? I might be missing something here.

It would be hilarious if after all this, they find nothing on the phone. GENIUS!

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#25
post #18

More confirmation, as if anyone needed it, that this case is not about the months-old data on one particular phone, but rather about breaking the security of all phones.

Sorry, but how does this confirm that? It sounds to me as though someone screwed up by changing the password rather than it being intentionally changed so they could request that Apple build an iOS with a backdoor.

Maybe the FBI should concentrate their efforts on finding that someone and asking them what the password is.

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#26
post #18

Earlier quoted context omitted.

Sorry, but how does this confirm that? It sounds to me as though someone screwed up by changing the password rather than it being intentionally changed so they could request that Apple build an iOS with a backdoor.

How does one change the password they supposedly do not know and need Apple's assistance to retrieve?

They probably did a reset, and since the phone was owned by the employer, they probably had access to the email and user details required to initiate an iCloud password reset.

Unfortunately resetting the iCloud password disabled automatic iCloud backups when the phone was on a known wifi network.

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#27

Earlier quoted context omitted.

The employer[1]: > The FBI obtained a warrant to search the iPhone, and the owner of the iPhone, Farook's employer > the owner, in the hours after the attack, was able to reset the password remotely, but that had the effect of eliminating the possibility of an auto-backup (the first quote is on page 1 of [1]; the second quote is footnote 7 on page 18 of [1] as pointed out by another commenter[2].) I think — and frank…

in terms of amount of information, would it be trivial to count the number of nonzero bytes on the phone's disk? then compare that to the backup?

The information on the backup had month-old timestamps, while the iPhone was in use more recently. Thus, the backup must be old.

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#28
post #25
post #18

Earlier quoted context omitted.

Sorry, but how does this confirm that? It sounds to me as though someone screwed up by changing the password rather than it being intentionally changed so they could request that Apple build an iOS with a backdoor.

Maybe the FBI should concentrate their efforts on finding that someone and asking them what the password is.

I would assume they have found that person. It's curious that anyone took it upon themselves to initiate the password reset without authority, but I'd bet they have simply forgotten what they changed it to.

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#29
iCloud backups are not protected by your iCloud password. I know this because I've personally reset my password and then successfully recovered an iCloud backup to a new phone with the new password.

However, the auto-backup feature, which would have pushed the most recent data from the phone onto iCloud just by leaving the phone powered on... apparently that is disabled when the iCloud password is reset. Which makes sense if you think about it, the phone still has the old iCloud password, and it would need the new password in order to authenticate to iCloud. So they inadvertently disabled the backup feature by locking the phone out of iCloud!

The first question this raises is can the auto-backup be made to start working again by Apple changing their backend iCloud authentication code to specifically allow this device to login to iCloud with the "wrong" (old) passsword? That would not involve touching the phone and seems like a much cleaner solution. Unless there is code on the phone which disables or destroys the iCloud authentication token / stored password after encountering a login error, which really would surprise me, because API errors could be spurious, but I guess it's possible if they are looking specifically for an "invalid login" return code and then dumping the old token in order to trigger a UI prompt to enter a new password.

The second question is why are the existing backups a month and a half old? Doesn't this imply the device was not even turned on or connected to the network for that last month and a half?

The other interesting tidbit in the article is the statement the FBI was able to verify that the phone was never paired with any devices to obtain data. How in the world could they know that?

(Cross-posting this comment from another article, because it's more relevant here)

Re: Terrorist’s Apple ID Password Changed In Government Custody, Blocking Access

#30
post #24

Is there a reason Apple can't take apart the phone and access the hard drive directly? Maybe put the hard drive on a dev board of sorts. AFAIK, most cell-phones have dev board versions that the mfg's engineers use to test various component hardware revisions no?. There they can access it through root? I might be missing something here. It would be hilarious if after all this, they find nothing on the phone. GENIUS!

[deleted]
Post reply on HN