Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

241–250 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#241
post #28

NPR was playing this story up as if it's a blow for Apple - is it really? Isn't the vulnerability the fact that the phone has no secure enclave, and so the timeout/wipe can be worked around by external access to the flash? Isn't that the whole reason the newer phones were upgraded? Older device fails, newer device with improved security doesn't. That's not a blow to Apple, that's the way the world works.

As far as I've been able to figure out, the Secure Enclave does not have its own storage. The proposed attack of cloning the phone's flash memory would work just as well on a new iPhone 6s. A lot of people are assuming that the Secure Enclave would prevent this attack, but I've not yet been able to find any basis for that assumption. The main security advantage of newer phones in this context is that Touch ID makes i…

That's absolutely correct, come to find out. For some reason I thought the SE was responsible for holding some of the keys and the wipe counter, but instead it's a section of the NAND flash called "Effaceable Storage".

Their own whitepaper defines it:

A dedicated area of NAND storage, used to store cryptographic keys, that can be addressed directly and wiped securely. While >>it doesn’t provide protection if an attacker has physical possession of a device

(emphasis mine)

However, it appears that the FBI attack only worked because the people in question used the 4 digit pin. A strong passcode is the way to go and protects you from these kinds of brute force attacks.

Re: Your iPhone just got less secure. Blame the FBI

#242

Earlier quoted context omitted.

But in the actual game, you are always given the chance to switch. Here are the possible outcomes of the game, with the third column being what the contestant should do to win: You Pick Car Switch? ------- ----- ------ 1 1 N 2 1 Y 3 1 Y 1 2 Y 2 2 N 3 2 Y 1 3 Y 2 3 Y 3 3 N Without knowing anything else, switching means that you win 2/3 of the time.

Your comment (EDIT: Sorry, not yours, but parent) was talking about a random flip of coin determining which door Monty shows. That's not the actual game. If Monty is randomly showing a door without regard to goat/car, then you have to also consider the scenarios where he reveals a car and you lose early.

If, while randomly flipping a coin, he reveals the car then you have a 0% chance of winning. If he doesn't reveal a car then you have a 2/3 chance of winning if you switch doors.

Re: Your iPhone just got less secure. Blame the FBI

#243
post #219

Earlier quoted context omitted.

Doesn't this approach cast doubt on the legitimacy of any evidence obtained from the device?

Don't think so, it's basically like lock picking a suspect's apartment with a warrant. What is found should be valid evidence, no? Law enforcement can break the door or call a locksmith and pay him for his service. In this case Cellebrite's the locksmith.

That seems reasonable, but usually investigators would be on the scene while the locksmith works. If the process is a black box that happens while the device is in Cellebrite's possession isn't it more like calling up the locksmith from the precinct and saying "hey, could you open up the apartment at this address and call us when you're done? Don't go inside or touch anything though, thanks!" What prevents Cellebrite employees from planting or deleting evidence after the device is unlocked and before returning it? What guarantees are there that Cellebrite's unlocking process doesn't intentionally or unintentionally modify some other aspect of the device? Scouts honor? What if their process is to just flash a new rom filled with child porn and no passcode then skip merrily to the bank to cash their checks?

Re: Your iPhone just got less secure. Blame the FBI

#244

Earlier quoted context omitted.

believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. The problem here is that we're all just speculating. We suspect this to be the case, but we can't be sure. And we probably never will be. To take this a step further, the FBI has also learned the lesson to never take this public again. If you are worried about law enforcement attacks against any device protected by…

Dont forget Genode project https://genode.org/ and Crash safe http://www.crash-safe.org/

Thank you for these.

Re: Your iPhone just got less secure. Blame the FBI

#245
post #28

Earlier quoted context omitted.

As far as I've been able to figure out, the Secure Enclave does not have its own storage. The proposed attack of cloning the phone's flash memory would work just as well on a new iPhone 6s. A lot of people are assuming that the Secure Enclave would prevent this attack, but I've not yet been able to find any basis for that assumption. The main security advantage of newer phones in this context is that Touch ID makes i…

That's absolutely correct, come to find out. For some reason I thought the SE was responsible for holding some of the keys and the wipe counter, but instead it's a section of the NAND flash called "Effaceable Storage". Their own whitepaper defines it: A dedicated area of NAND storage, used to store cryptographic keys, that can be addressed directly and wiped securely. While >>it doesn’t provide protection if an attac…

I initially assumed the same as you, because it would just make so much sense.

And yes, it looks like all of this came down to the short PIN. It's likely a six-digit PIN would still fall, but a proper passcode would have made this whole affair moot. It looks like even the older phones are still totally secure in that case, although the lack of Touch ID can make it somewhat impractical.

This is a major problem I have with the "iPhones got less secure" idea. Apple has gone through heroics to make short passcodes somewhat secure, but there's only so much you can reasonably expect there.

Re: Your iPhone just got less secure. Blame the FBI

#246
post #243

Earlier quoted context omitted.

Don't think so, it's basically like lock picking a suspect's apartment with a warrant. What is found should be valid evidence, no? Law enforcement can break the door or call a locksmith and pay him for his service. In this case Cellebrite's the locksmith.

That seems reasonable, but usually investigators would be on the scene while the locksmith works. If the process is a black box that happens while the device is in Cellebrite's possession isn't it more like calling up the locksmith from the precinct and saying "hey, could you open up the apartment at this address and call us when you're done? Don't go inside or touch anything though, thanks!" What prevents Cellebrite…

Yep, I understand that. I don't think that was posed as a problem in the Italian case I know of, although I think that in the U.S. rules on the chain of custody are stricter, indeed. That's a good point.

Re: Your iPhone just got less secure. Blame the FBI

#247

Earlier quoted context omitted.

Your comment (EDIT: Sorry, not yours, but parent) was talking about a random flip of coin determining which door Monty shows. That's not the actual game. If Monty is randomly showing a door without regard to goat/car, then you have to also consider the scenarios where he reveals a car and you lose early.

If, while randomly flipping a coin, he reveals the car then you have a 0% chance of winning. If he doesn't reveal a car then you have a 2/3 chance of winning if you switch doors.

In this scenario, Monty's door choice and your door choice are completely independent actions. Because of this, you gain no new information from the door he reveals. In the classic version of this puzzle (where Monty always reveals a goat), you do gain information, because most of the time Monty's forced to choose the only other goat, and therefore avoid the car.

http://c2.com/cgi/wiki?NotTheMontyHallProblem

The switching strategy is effective because it relies on Monty's avoidance of the car. When Monty isn't trying to avoid the car, his revelation doesn't help you out at all. It just tells you that you either (A) now have a slightly better chance (50%), or (2) you've already lost. (0%).

EDIT: Also see the table on this wikipedia article. It lists probabilities for all the different variants of the MHP. Your scenario is referred to as the Monty Fall or Ignorant Monty variant.

https://en.wikipedia.org/wiki/Monty_Hall_problem#Other_host_...

    "Monty Fall" or "Ignorant Monty": The host does not know
    what lies behind the doors, and opens one at random that
    happens not to reveal the car
    (Granberg and Brown, 1995:712) (Rosenthal, 2005a) (Rosenthal, 2005b).
    Switching wins the car half of the time.

Re: Your iPhone just got less secure. Blame the FBI

#248
post #55

Earlier quoted context omitted.

I agree with you, and I think this will eventually lead to a world where governments are unable to exert meaningful influence on large corporations. We're already starting to get there; I have a feeling that if the supreme court had forced Apple to write a custom version of iOS that things could have gotten really messy very quickly -- there were rumors that Apple's entire iOS engineering team was ready to resign if…

> It's plausible to see a scenario where Apple says "You know what? Fuck it, we're based in Ireland now." Maybe, but I think you're putting the cart before the horse. We're not at that stage right now. Right now we can turn the tables on the FBI and demand they contribute back to our own ability to secure ourselves. It's not too tough to describe the issue to the general public. The FBI would ordinarily help business…

> the FBI is refusing to cooperate with the general public who own iPhones.

Which I think is a perfectly rational thing for the FBI to do in the absence of a law stating that they must do so. I don't think it's the best thing for democracy, but if I were a senior-level FBI official, I'm trying to give my organization as many tools as I can get to do their job. He's a man with a small, narrowly defined scope: investigate crimes as effectively as possible. It's not his job to think of the repurcussions.

Which is why our current decade-long legislative deadlock is fucking killing us. The world today is nearly unrecognizable from the one in 2006 - and in the lack of leadership by Congress, the executive branch (which includes the FBI and most other non-military law enforcement agencies) has to step in and take control.

Really, the problem is that a lack of leadership from congress has created a power vacuum that Obama has been publicly very reluctant to fill. But the gap exists, and people in the executive branch under Obama have had no such qualms expanding their power into areas that Congress just hasn't addressed because they're too buy trying to defund Obamacare or ban abortions.

Our legislative process at work, folks.

Re: Your iPhone just got less secure. Blame the FBI

#249

Earlier quoted context omitted.

Now see if you can work it out if your friend told you this beforehand: Between pregnancies, I had an accident that resulted in an odd medical condition. The doctors said that after it happened, 50% of boy fetuses that otherwise would have resulted in pregnancy would simply fail to implant, and I wouldn't even know about it. Now there's an all new ambiguity. How do you decide whether your friend was planning on havin…

Here's an epistemological head-scratcher: do the odds still change if you don't hear the daughter's name accurately? Why?

Remember, those odds are the level of certainty you have that a given statement may be true based only on what you already know. You can also assign a level of certainty to the facts you think you know.

Given the number of ways to mishear "Mary" and the dialectical variant in pronunciation characterized by the Mary-marry-merry merger, I'd tentatively assign the following values:

  25% One child is a girl.  (Heard correctly)
  25% One child is a boy.   (Heard incorrectly)
  50% No new information.   (Incomprehensible or ambiguous)

  In the first case P(A and B|A) = P(A and B|B) = 1/2
  In the second, P(A and B|!A) = P(A and B|!B) = 0
  In the third, P(A and B|A or B) = 1/3
In any case, you're just guessing at the probability you might mishear something, so there's no definitive answer. The mere possibility that I might have heard a boy's name means that the overall probability could be anywhere between 0 and 1/2. By the above, my new odds are 5/12.

So the odds do change, based on your confidence in what you heard (and your confidence that your friend isn't the kind of parent to name her son "Meriadoc" or something similar).

Re: Your iPhone just got less secure. Blame the FBI

#250
post #20

I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it. The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in questio…

Schneier has tended toward more high-level and pragmatic assessments over time. Maybe because of his "security evangelism" efforts he's trained to think more like the pragmatic layperson.

Obviously all phones technically have the same vulnerability both before and after the FBI decision. But now there is a larger pragmatic chance of it being exploited. That is the point AFAIK.

Post reply on HN