Live data from Hacker News

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

404media.co

241–250 of 565 posts

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#241

Sadly, they still got to her Signal on her Desktop – her sources might still be compromised. It's sadly inherent to desktop applications, but I'm sad that a lot more people don't know that Signal for Desktop is much, much less secure against adversaries with your laptop.

Did she have Bitlocker or FileVault or other disk encryption that was breeched? (Or they took the system booted as TLAs seek to do?)

[deleted]

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#242

Earlier quoted context omitted.

It does mean that. You can't be forced to divulge information in your head, as that would be testimonial. But if there are papers, records, or other evidentiary materials that are e.g. locked in a safe you can be compelled to open it with a warrant, and refusal would be contempt.

They need to prove that those materials exist on the device first. You can't be held in contempt for a fishing expedition.

You need "probable cause to believe" which is not as strong as "prove" but yes, it can't be a pure fishing expedition.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#243

Sadly, they still got to her Signal on her Desktop – her sources might still be compromised. It's sadly inherent to desktop applications, but I'm sad that a lot more people don't know that Signal for Desktop is much, much less secure against adversaries with your laptop.

Did she have Bitlocker or FileVault or other disk encryption that was breeched? (Or they took the system booted as TLAs seek to do?)

breached

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#244
post #97

Earlier quoted context omitted.

Forget OS updates. The biggest obstacle to exploit persistence: a good old hard system reboot. Modern iOS has an incredibly tight secure chain-of-trust bootloader. If you shut your device to a known-off state (using the hardware key sequence), on power on, you can be 99.999% certain only Apple-signed code will run all the way from secureROM to iOS userland. The exception is if the secureROM is somehow compromised and…

It's why I keep my old iPhone XR on 15.x for jail breaking reasons. I purchased an a new phone specially for the later versions and online banking. Apple bought out all the jail breakers as Denuvo did for the game crackers.

> Apple bought out all the jail breakers > Denuvo did for the game crackers

Do you have sources for these statements?

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#245
post #4

[flagged]

Indeed, likely as secure as the VPNs run by intelligence contractors. 1. iOS has well-known poorly documented zero-click exploits 2. Firms are required to retain your activity logs for 3 months 3. It is illegal for a firm to deny or disclose sealed warrants on US soil, and it is up to 1 judge whether to rummage through your trash. If I recall it was around 8 out of 18000 searches were rejected. It is only about $23 t…

> 1. iOS has well-known poorly documented zero-click exploits

PoC || GTFO, to use the vernacular.

If you're talking about historical bugs, don't forget the update adoption curves.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#246

It seems unfortunate that enhanced protection against physically attached devices requires enabling a mode that is much broader, and sounds like it has a noticeable impact on device functionality. I never attach my iPhone to anything that's not a power source. I would totally enable an "enhanced protection for external accessories" mode. But I'm not going to enable a general "Lockdown mode" that Apple tells me means…

It isn’t. Settings > Privacy & Security > Wired Accessories Set to ask for new accessories or always ask.

I have to warn you, it does get annoying when you plug in your power-only cable and it still nags you with the question. But it does work as intended!

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#247
post #7

> Natanson said she does not use biometrics for her devices, but after investigators told her to try, “when she applied her index finger to the fingerprint reader, the laptop unlocked.” Curious.

Probably enabled it at some point and forgot. Perhaps even during setup when the computer was new.

I want to say that is generous of her, but one thing that is weird is if I didn’t want someone to go into my laptop and they tried to force me to use my fingerprint to unlock it, I definitely wouldn’t use the finger I use to unlock it on the first try. Hopefully, Apple locks it out and forces a password if you use the wrong finger “accidentally” a couple of times.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#248

Earlier quoted context omitted.

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

> Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. > What’s so hard to make 2-3 pins and each to access different logged in apps and files. Besides the technical challenges, I think there's a pretty killer human challenge: it's going to be really hard for the user to create an alternate account that looks real to someone who's paying attention. Su…

Background agent in the decoy identity that periodically browses the web, retrieves email from a banal account etc.?

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#249

Earlier quoted context omitted.

Multi-user has been solved for decades. Multi-user that plausibly looks like single-user to three letter agencies? Not even close.

Doesn't having standard multi-user functionality automatically create the plausible deniability? If they tried so hard to create an artificial plausible deniability that would be more suspicious than normal functionality that just gets used sometimes.

What needs to be plausibly denied is the existence of a second user account, because you're not going to be able to plausibly deny that the account belongs to you when it resides on the phone found in your pocket.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#250
I find it so frustrating that Lockdown Mode is so all-or-nothing.

I want some of the lockdown stuff (No facetime and message attachments from strangers, no link previews, no device connections), but like half of the other ones I don't want.

Why can't I just toggle an iMessage setting for "no link preview, no attachments", or a general setting for "no automatic device connection to untrusted computers while locked"? Why can't I turn off "random dickpicks from strangers on iMessage" without also turning off my browser's javascript JIT and a bunch of other random crap?

Sure, leave the "Lockdown mode" toggle so people who just want "give me all the security" can get it, but split out individual options too.

Just to go through the features I don't want:

* Lockdown Mode disables javascript JIT in the browser - I want fast javascript, I use some websites and apps that cannot function without it, and non-JIT js drains battery more

* Shared photo albums - I'm okay viewing shared photo albums from friends, but lockdown mode prevents you from even viewing them

* Configuration profiles - I need this to install custom fonts

Apple's refusal to split out more granular options here hurts my security.

Post reply on HN