Live data from Hacker News

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

404media.co

441–450 of 565 posts

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#441
Depending on your jurisdiction faceid is safer than fingerprint, because faceid won’t unlock while your eyes are closed.

In many European countries forcing your finger on a scanner would be permissible under certain circumstances, forcing your eyes open so far has been deemed unacceptable.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#442

Earlier quoted context omitted.

[flagged]

Direct? No. That he was indicted for it? Yes [1]. (Clarification: I’m using the term colloquially. Whether Epstein had a mental condition is unclear.) [1] https://www.justice.gov/usao-sdny/press-release/file/1180481...

Unless I missed something, that's not pedophilia.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#443

Remember...they can make you use touch id...they can't make you give them your password. https://x.com/runasand/status/2017659019251343763?s=20 The FBI was able to access Washington Post reporter Hannah Natanson's Signal messages because she used Signal on her work laptop. The laptop accepted Touch ID for authentication, meaning the agents were allowed to require her to unlock it.

Also, using biometrics on a device, and your biometrics unlock said device, do wonders for proving to a jury that you owned and operated that device. So you're double screwed in that regard.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#444
post #324

Is there an implication here that they could get into an iPhone with lower security settings enabled? There's Advanced Data Protection, which E2EEs more of your data in iCloud. There's the FaceID unlock state, which US law enforcement can compel you to unlock; but penta-click the power button and you go into PIN unlock state, which they cannot compel you to unlock. My understanding of Lockdown Mode was that it babyif…

It's relatively well know that the NSO Group / Pegasus is what governments use to access locked phones.

This was known, in the past, but if its relying on zero-days Apple & Google are, adversarially, attempting to keep up with and patch, my assumption would not be that pegasus is, at any time, always able to breach a fully-updated iPhone. Rather, its a situation where maybe there are periods of a few months at a time where they have a working exploit, until Apple discovers it and patches it, repeat indefinitely.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#445

Earlier quoted context omitted.

Not on my Pixel phone, that just sets it to vibrate instead of ring. Holding down the power button retrieves a menu where you can select "Lockdown".

On my 9 you get a setting to choose if holding Power gets you the power menu or activates the assistant (I think it defaulted to assistant? I have it set to the power menu because I don't really ever use the assistant.)

Yes, that was the default for me, but I changed it in settings.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#446
post #282

Don't be idiots. The FBI may say that whether or not they can get in: 1. If they can get in, now people - including high-value targets like journalists - will use bad security. 2. If the FBI (or another agency) has an unknown capability, the FBI must say they can't get in or reveal their capabilities to all adversaries, including to even higher-profile targets such as counter-intelligence targets. Saying nothing also…

I would not recommend that one trust a secure enclave with full disk encryption (FDE). This is what you are doing when your password/PIN/fingerprint can't contain sufficient entropy to derive a secure encryption key. The problem with low entropy security measures arises due to the fact that this low entropy is used to instruct the secure enclave (TEE) to release/use the actual high entropy key. So the key must be sto…

[deleted]

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#447
post #374

Can't they just use Pegasus or Cellebrite???

It's unlikely that Pegasus would work since Apple patched the exploit it used.

I think it's unclear whether Cellebrite can or cannot get around Lockdown Mode as it would depend very heavily on whether the technique(s)/exploit(s) Cellebrite uses are suitable for whatever bugs/vulnerabilities remain exposed in Lockdown Mode.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#448

Earlier quoted context omitted.

She has to have set it up before. There is no way to divine a fingerprint any other way. I guess the only other way would be a faulty fingerprint sensor but that should default to a non-entry.

> faulty fingerprint sensor The fingerprint sensor does not make access control decisions, so the fault would have to be somewhere else (e.g. the software code branch structure that decides what to do with the response from the secure enclave).

If you're interested in this in more detail, check this out:

https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#449
post #347

Earlier quoted context omitted.

You can setup a separated account with a long password on MacOS and remove your user account from accounts that can unlock FileVault. Then you can change your account to use a short password. You can also change various settings regarding how long Mac has to sleep before requiring to unlock FileVault.

I didn’t understand how a user that cannot unlock FileVault helps. Can you please elaborate on this setup? Thanks.

With that setup on boot or after a long sleep one first must log in into an account with longer password. Then one logs out of that and switches to the primary account with a short password.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#450

Earlier quoted context omitted.

> It's close enough Not really, because tools like Cellbrite are more limited with BFU, hence the manual informing LEO to keep (locked) devices charged, amd the countermeasures being iOS forcefully rebooting devices that have been locked for too long.

There is a way now to force BFU from a phone that is turned on, I can't remember the sequence

Eh? BFU ("before first unlock") is, by definition, the state that a phone is in when it is turned on. There's no need to "force" it.

If you mean forcing an iOS device out of BFU, that's impossible. The device's storage is encrypted using a key derived from the user's passcode. That key is only available once the user has unlocked the device once, using their passcode.

Post reply on HN