Live data from Hacker News

Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

latimes.com

41–50 of 129 posts

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#41
post #9

I really find this whole thing hilarious. First, it's Apple sticking it to the FBI by making a stand for privacy and receiving public accolades doing so as a champion of privacy. The FBI is the bad guy trying to invade our privacy. Now, it's the FBI sending a giant "screw you" to Apple by not only letting them know they were able to hack into the phone without Apple's help but at the same time, making a mockery of Ap…

>Except that if I were them, I certainly wouldn't ask that publicly, I would at least pretend I know how the FBI did it and claim that it's already fixed in the next version of the OS

Wow, lying doesn't really look like the best course of action for a public traded company, I guess.

>Which still means that tens of millions of iPhones are at risk today and will be for months, but at least, you get to pretend that you're ahead of the FBI while right now, it's pretty obvious that Apple has been outsmarted by a government agency.

It's extremely probable that users are not in danger. If it's true that the FBI used Cellebrite's services, they might have used a slightly upgraded version of the company's solution that enabled the hacking of 32-bit devices (i.e. no secure enclave). The commercial solution touted publicly by Cellebrite is used by law enforcement all over the world to unlock iOS 8.x iPhones and iPads in a matter of 24h. There was a recent case in Milan, where the Court expert was able to unlock an iPhone 5 in 2 days and retrieve data thanks to the services of Cellebrite's offices in Munich.

So: 32-bit devices with iOS 9, no secure enclave, implication of a company known for providing solutions to break into iPhones since forever.

Icing on the cake: they might as well have used a system like the one suggested by ACLU and other experts: NVRAM cloning. That's a solution that's extremely phone specific and doesn't require to exploit any big scary bug to be carried out.

Most probable outcome: Apple will keep on hardening iOS security and it's own cloud security even more. In the end the common user wins.

The FBI is STILL the bad guy, acting like criminals who won't disclose a potential vulnerability (which might as well not exists) to the manufacturer.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#42
post #18
post #4

Ask these guys, not the feds: http://www.cellebrite.com/Pages/cellebrite-solution-for-lock... You are welcome Apple.

The San Bernadino phone was running iOS 9. (It's reasonable to assume that if there was a vulnerability in 8.x, Apple would want to have fixed it in 9.)

Cellebrite is a multinational with lots of resources. I would expect they already had some solution for iOS 9 devices in the pipeline, which was not ready to be made into a public product yet. Nonetheless they were more than happy to field test it with the San Bernardino terrorist's phone. DISCLAIMER: That's my speculation, based on my own coverage of the whole Apple-FBI thing.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#43
post #38

Earlier quoted context omitted.

Cellebrite's full portfolio is not public what you see on their site are very basic turn-key solutions. They have a bespoke service called CAIS as well as few other unlisted services which they do not advertise openly given their sensitive nature. Their turn-key forensic solutions are tailored for general law enforcement and the public sector (private investigators, corporate security, law firms etc.), CAIS is usuall…

> Cellebrite's full portfolio is not public So, basically their own collection of zero-days and techniques? Do they come up with them themselves, or do they buy them on the exploit market?

Probably both, not necessarily "zero-days" at least not in the traditional sense but various attacks and services that they might not want to advertise publicly for various reasons (don't forget that as an Israeli company their exports are controlled by the Israeli Defense Ministry).

In some cases they might also offer a bring your own exploit type of service where they integrate client provided exploits with their existing platforms and solutions.

Some of their products are also hardware focused, their "Chinese SOC" attacks are mostly OS agnostic (Mediatek chipsets for example are attacked via some generic DMA exploit) and are designed specifically to assist LEA's to breaking into cheap disposable phone. http://www.cellebrite.com/Media/Default/Files/Forensics/Data...

But like any company these days it pretty much depends on what you want to buy for them they'll offer you a wide range of services from idiot proof turn key solutions to bespoke consulting like services, if they do have the ability to break into iOS9 or a more generic way to attack Apple SOC's they will not advertise it openly, at least not initially from previous experience with them it can take months and even years between them actually have an initial capability to it being integrated into their open commercial products.

This isn't only done for secrecy reasons this is also pragmatic some attacks might be very case dependent, expensive, or even potentially destructive and so wont be offered with their normal forensic services (that have to comply to very strict forensic standards, including being able to openly explain how access was achieved to ensure that the data has actually been extracted correctly and chain of custody maintained) so quite often what they are offered under their more bespoke services are capabilities that are not (yet) commercially viable for general forensic use.

In this case the FBI or any other agency is quite likely not to care about presenting the information as evidence in court, and their risk appetite might also be considerably greater.

Your local police/DA on the other hand must be able to present the evidence and defend how it was obtained in court so the tool has to be certified (NIST in case of US courts) and the extraction method has to be defensible in court.

However if we are talking about zero-days then those also cannot be offered as part of their commercial turn key solutions (court defensibility aside) because the solutions they provide have to be reliable and consistent.

Zero-days for the most part are likely to be fixed quicker than their products can be shipped yet alone certified so anything which is that volatile will only be offered via their "consulting service" and the clients will be quite aware that they are paying for something that might be a one off solution only.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#45
Is it legally acceptable that FBI knows about a criminal activity and do not act to stop it? A security vulnerability like this will sooner or later be used by criminals, and the FBI are in the authoritative position to prevent it. Could future victims sue the government for allowing the crime to occur? There have been many lawsuits where an ISP has been found guilty for knowingly host a copyright infringer on their network and not acting to prevent it, so it should not be too implausible that a government agency responsible to prevent crime is held to equal or higher standard.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#46
post #45

Is it legally acceptable that FBI knows about a criminal activity and do not act to stop it? A security vulnerability like this will sooner or later be used by criminals, and the FBI are in the authoritative position to prevent it. Could future victims sue the government for allowing the crime to occur? There have been many lawsuits where an ISP has been found guilty for knowingly host a copyright infringer on their…

That's a strange standard to hold the FBI up to.

Should police, upon seeing an unlocked car, promptly find the owner and inform them? Of course that's a nice thing to do as people, but it's not really a legal obligation.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#47
post #9

I really find this whole thing hilarious. First, it's Apple sticking it to the FBI by making a stand for privacy and receiving public accolades doing so as a champion of privacy. The FBI is the bad guy trying to invade our privacy. Now, it's the FBI sending a giant "screw you" to Apple by not only letting them know they were able to hack into the phone without Apple's help but at the same time, making a mockery of Ap…

>Except that if I were them, I certainly wouldn't ask that publicly, I would at least pretend I know how the FBI did it and claim that it's already fixed in the next version of the OS Wow, lying doesn't really look like the best course of action for a public traded company, I guess. >Which still means that tens of millions of iPhones are at risk today and will be for months, but at least, you get to pretend that you'…

What's the objective behind Apple wanting to know the method then? It sounds like any of these could be possible, so it's not like there's a big mystery (especially given the Cellebrite Purchase Order found on some government website).

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#49

Earlier quoted context omitted.

If you were a lock or safe maker, wouldn't you want to know how people were able to crack your product so you could improve it in the next version? Or would you just keep trying to sell a version of the thing that people buy to keep their stuff safe with a known exploit? Good luck.

I wouldn't consider lock makers as a good example on one hand they ask for feedback from locksmiths to improve their designs and on the other actually train licensed locksmiths how to break locks. The vast majority of safes also have a backup lock or code.

Then why did you use locks and safes as an example in the first place?

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#50
post #47

Earlier quoted context omitted.

>Except that if I were them, I certainly wouldn't ask that publicly, I would at least pretend I know how the FBI did it and claim that it's already fixed in the next version of the OS Wow, lying doesn't really look like the best course of action for a public traded company, I guess. >Which still means that tens of millions of iPhones are at risk today and will be for months, but at least, you get to pretend that you'…

What's the objective behind Apple wanting to know the method then? It sounds like any of these could be possible, so it's not like there's a big mystery (especially given the Cellebrite Purchase Order found on some government website).

It could be something else. That’s the problem. Apple doesn’t know for sure and they would like to.
Post reply on HN