Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

231–240 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#231

Earlier quoted context omitted.

They're not anywhere near 99% of the way there; they've destroyed the heterogeneous decentralized ecosystem that broad security requires. Locking themselves out of the Secure Enclave isn't anywhere near sufficient. As long as the device software and trust mechanisms are totally opaque and centrally controlled by Apple, the whole thing is just a facade. There's almost nothing Apple can't push to the phone, and the aud…

Then again, nobody is suing over android phone crypto, and as recently as last November bugs have been discovered that sookmg things like entering an excessively long password allows you to bypass the lock screen.

In android world too many parties have the keys to kingdom and people that protect their devices take that into consideration. Also once the bootloader is unlocked and custom firmware put there - all bets are off.. I have yet to see viable attack against sufficiently strongly protected LUKS at rest.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#232
post #206

Earlier quoted context omitted.

Uhh, well it's probably pretty high. Considering their adoption rate for new software is sitting somewhere around 95%. iCloud backups default to on - just like automatic updates - when the user sets up their phone. Not to mention most Geniuses would ask to turn on iCloud backup when upgrading the device for convenience.

Well the specific phone that started this controversy didn't have any iCloud backups, so regardless of the percentage it doesn't pertain here.

It did have iCloud backups, but the latest was six weeks prior. The FBI requested the iCloud password be reset, which prevented a new iCloud backup they could have subpoenaed.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#233

Earlier quoted context omitted.

Is there anything preventing them from imaging the parts of the device that store data? The data in the image would be encrypted, of course, but wouldn't this give them essentially unlimited (or up to their budget) attempts at getting to the data?

It's encrypted against an effectively random 128 bit AES key. Unlimited time is not enough.

Unless there is weakness in the PRNG/RNG that creates the fused key in the secure enclave itself. Which is not out of question. I am not sure why FBI didn't ask apple politely how these keys are generated in the first place.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#235
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

Secure enclave as per their docs sounds just like their implementation of trust zone.. err "Trust Zone", most likely following ARM specs.

The main difference would be that everyone knows trust zone through Qualcom's implementation and software - as it's been broken many times. At the end of the day "its just software" though, which runs on a CPU-managed hypervisor with strong separation ("hardware" but really, the line is quite a blur at this level).

What that means is that you need to be unable to update the secure enclave without user's code (so the enclave itself needs to check that) which is probably EXACTLY what apple is going to do.

Of course, Apple can still update the OS to trick the user into inserting the code elsewhere, then FBI to use that to update the enclave and decrypt - though that means the user needs to be alive obviously.

Past that, you'd need to extract the data from memory (actually opening the phone) and attempt to brute force the encryption. FBI does not know how to do this part, the NSA certainly does, arguably, Apple might since they're designing the chipset itself.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#236
post #5

What is to stop the DOJ from requiring them to produce a phone that has a hardware backdoor? If they are required to produce a software backdoor then building an iphone which is immune to such vulnerabilities seemingly solves that problem but I don't see the leap towards compelling Apple to build vulnerabilities into hardware as a large one. I'm not well versed in security so excuse me for my ignorance but what if th…

All writs is for current investigation. FBI could theoretically compel Apple to produce a single backdoored phone that will be exchanged with evil maid attack with original device when they have ongoing investigation and a warrant.

But unless you can point at - This is Bill, we are targeting Bill, we have a warrant for Bill, we need 1 phone that we will make sure becomes Bill's - All Writs cannot help.

If Bill mails order a new iPhone they can compel apple store to give him compromised device. They could probably put FBI team presenting themselves as store employees in every store if Bill is high value enough target and expected to buy iphone today.

But they cannot say - compromise all of SF Bay Area iphones because we expect one of them to be bought by Bill.

Some of the lawyers here correct me if I am too wrong.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#237

This is one of those moments I wish Jobs was still here. Had he lost to the DOJ, here is what would (might) have happened: - he would gladly unlocked this phone and bill DOJ for the time spent on redesigning IOS - going forward, he would label each phone's box in red letters: CONTAINS GOVERNMENT-REQUIRED BACKDOOR (I doubt Gov can forbid him from doing that) - he would then stop selling devices in Apple stores directl…

And then Jobs would find himself for a long long prison term after the DOJ decides to go full power with him for something otherwise unrelated or small. You commit a lot of federal offenses by just existing in the USA. Or every other country. There is always something that they can nail you for.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#238

Earlier quoted context omitted.

I don't make that assumption, I worked on developing TPM modules myself in the 90s at research labs, and our prototypes had even more anti-tampering than so far revealed about Secure Enclave/Trustzone: we had micro-wire-meshes in the packaging to self-destruct on drilling or decapping, we had anti-ultrasonic and anti-TEMPEST shielding. I'm pretty familiar. The point is that state actors have vast resources to pull of…

> If the NSA really wanted to crack the Secure Enclave, I have very little doubt about their ability to carry it out. Well they certainly really want to crack the Secure Enclave, so maybe this case is moot.

The NSA cracking the Secure Enclave is not the same as the FBI cracking the Secure Enclave.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#239
post #153

Earlier quoted context omitted.

Could the "code equivalent" of your fingerprint be stolen by a rogue app if it's allowed to read it? I don't have a touchId phone but have wondered what would happen if your "print" is stolen -- passwords can at least be changed.

Speaking as an App Developer, we cannot touch stuff like that. We're allowed to ask Touch ID to verify things and process the results, but we don't actually get to use the Touch ID system. It's similar to how the shared keychain is used: We can ask iOS to do things, but then must handle any one of many possible answers. We don't actually see your fingerprint in any way. Now Cydia and 3rd party stuff? I have no clue.

iOS itself does not see fingerprints, it refers to SE.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#240
post #139

Earlier quoted context omitted.

What really burns me is that this strategy is so well known. 1984 was written almost 70 years ago, and yet we have millions of people begging for persistent, unavoidable surveillance by authorities as part of a never-ending war with an ambiguous enemy that our own policies are strengthening.

Referencing 1984 is childish in this context, we're talking about obtaining a warrant for known suspects or already convicted persons. The enemy isn't ambiguous, you're purposely muddying their image.

I believe the GP was making a generality and not talking about just this specific scenario. "Terrorism" is an ambiguous enemy and while the number of deaths to terrorism is disheartening, it pales in comparison to many other problems (e.g. car accidents or heart disease).
Post reply on HN