Live data from Hacker News

GrayKey iPhone unlocker poses serious security concerns

blog.malwarebytes.com

31–40 of 97 posts

Re: GrayKey iPhone unlocker poses serious security concerns

#31
> An iPhone typically contains all manner of sensitive information: account credentials, names and phone numbers, email messages, text messages, banking account information, even credit card numbers or social security numbers. All of this information, even the most seemingly innocuous, has value on the black market

My phone has no banking information, credit card information, Social Security numbers, or email accounts that can be used to recover or reset access to any online service. Why? Because I don't trust my phone.

But aside from all that, all that information is already on the black market. There have been so many breaches, Equifax just to name one, to think otherwise.

Re: GrayKey iPhone unlocker poses serious security concerns

#32
post #23

Earlier quoted context omitted.

You would obviously just refrain from discussing the manner in which the device was acquired.

The cops have never heard that one before.

It's a realistic point though. Illegal industrial espionage definitely happens and with the resources of a huge multinational corporation it becomes easier to conceal behind a wall of secrecy and misdirection. I doubt Apple would do it, but it also wouldn't surprise me and they definitely could.

All they have to do is discretely obtain the device in question and have a few good engineers quietly pick it apart for a few weeks to figure out how it works. They then patch the vulnerability in a regular update claiming they discovered it as part of normal procedure and nobody takes notice.

Edit: the legality of the device itself is kinda interesting to me. Like, even if it is doing something illegal (like using stolen code or something), how would Apple prove it as long as it was only sold to law enforcement? If the police aren't asking too many questions and Apple can't legally acquire one, how do they prove it? I suppose they'd have to gather enough circumstantial evidence to get a judge to issue a subpoena, but things get a bit dark and fuzzy.

Re: GrayKey iPhone unlocker poses serious security concerns

#33

I hate this stuff. I want to secure my device and not have the govt or companies steal it, I want to control my device. Still, it's fascinating to learn about. Did no one think, when they take someone's phone for 5 minutes at the border, they could be doing this to your phone.

Well, as the article makes it clear it takes from hours to days to crack, no - they’re not doing this in 5 minutes at the border.

From the article:

>>It can take up to three days or longer for six-digit passcodes, according to Grayshift documents, and the time needed for longer passphrases is not mentioned.

So yeah, up to three days for six-digit passcodes. If you have a longer passcode with letters and special characters, you could wait a long, long time.

Re: GrayKey iPhone unlocker poses serious security concerns

#34

However, it does mean that an iPhone’s security cannot be ensured if it falls into a third party’s hands. That was and will always continue to be true. Even secure cryptoprocessors of the type used in smartcards and HSMs can be cracked with enough determination and time. There are companies in China who will read and clone them for surprisingly little money. It has always amused me somewhat how scared (or the impress…

the fact the methods of accessing the device are so secret seems very prone to a court rules of evidence challenge.

The accused has a right to know exactly how evidence was obtained, and if the chain of custody was broken, just hiding behind an NDA isnt going to cut it.

Re: GrayKey iPhone unlocker poses serious security concerns

#35
post #21

If this actually works there has to be some huge, embarrassing vuln in Apple's Secure Enclave Processor on par with the "CTS Labs" AMD secure coprocessor hoopla that hit the news just this week.[1][2] The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper sa…

It's worse, since this attack doesn't require root privileges to run!

Re: GrayKey iPhone unlocker poses serious security concerns

#36
post #21

If this actually works there has to be some huge, embarrassing vuln in Apple's Secure Enclave Processor on par with the "CTS Labs" AMD secure coprocessor hoopla that hit the news just this week.[1][2] The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper sa…

It's worse, since this attack doesn't require root privileges to run!

sure, but it does require physical access for at least a couple hours, up to multiple days, if you don't use a predictable pincode. And from what I gather it doesn't even threaten a passphrase.

Re: GrayKey iPhone unlocker poses serious security concerns

#37
post #21

If this actually works there has to be some huge, embarrassing vuln in Apple's Secure Enclave Processor on par with the "CTS Labs" AMD secure coprocessor hoopla that hit the news just this week.[1][2] The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper sa…

Time delays only provide a false sense of security. In theory I could always cut open the casing and just plug wires straight into the EMMC or whatever you have in there. Your time delay UI is useless if I just bypass your UI and wire straight into the hardware.

Of course that's non-trivial EE work, but the point is it's possible, for someone with enough money and the right equipment. What would make it intractable is to ditch the idea that a 4 digit pin is protecting you from anything. There's simply not enough entropy in that.

Time delays are useful protection when over a network. But not when the attacker has physical console access, e.g. to a phone. At that point proper cryptography and mathematics is the only good protection.

Re: GrayKey iPhone unlocker poses serious security concerns

#39
I bet there is lawsuit in works by Apple et al!

I mean if they truly broke and iPhone lock, then it means they had to be tampering with a true Apple device (not a dummy) in order to make their device work. Therefore, they violate Apple TOS that I am sure forbids any sort of backdooring. I doubt they will go after a rouge chinese jailbreaker sitting in moms basement and trying to make a name for him/herself, but here we have example of a for-profit incorporated business that makes 100% of their money by breaking Apple's devices.

On the other hand, if this is all just some sort of marketing gimmick, or that device never been truly tested on iPhone, then I am sure they can go after them for attempting to shame iOS/iPhone for users to think their devices are less secure than they actually are, which could hit their bottom line.

Re: GrayKey iPhone unlocker poses serious security concerns

#40
post #17
post #10

Is it just me or does the price point seem extremely low? They have a device that should be in high demand globally, and maybe one competitor. And they are charging 15-30k, for basically unlimited usage?? You can't tell me federal law enforcement wouldn't pay at minimum ten times that amount for metered usage...

I bet they realize the lifespan of this device is very short and are trying to maximize ROI short-term.

True. If Apple or a security firm get a hold of one of these devices, surely they'd be able to reverse engineer it and patch the vulnerabilities.
Post reply on HN