Live data from Hacker News

GrayKey iPhone unlocker poses serious security concerns

blog.malwarebytes.com

51–60 of 97 posts

Re: GrayKey iPhone unlocker poses serious security concerns

#51

This seems at odds with Apple’s claims about holding the device encryption keys in a secure coprocessor that only releases them in response to a valid passcode, and self-destructs the keys if too many passcodes are tried.

It’s not at odds with it - it’s pretty obviously using a vulnerability to run a crack against the passcode. Once the passcode is found, that is used to unlock the phone and this the Secure Enclave.

I agree it’s not at odds with it, but it’s not even that simple - the passcode is enforced by the Secure Enclave itself. It’s not a case of “try passcodes until you find the right one then tell the SEP” - it has to be exploiting a vulnerability in the SEP itself, assuming what we know of the design and attack is true.

Re: GrayKey iPhone unlocker poses serious security concerns

#52
post #32

Earlier quoted context omitted.

It's a realistic point though. Illegal industrial espionage definitely happens and with the resources of a huge multinational corporation it becomes easier to conceal behind a wall of secrecy and misdirection. I doubt Apple would do it, but it also wouldn't surprise me and they definitely could . All they have to do is discretely obtain the device in question and have a few good engineers quietly pick it apart for a…

Is this not automatically illegal under the DMCA? Well, assuming the company in question is based in the US.

The DMCA specifically criminalises the circumvention of copyright protection methods, not all access controls.

Re: GrayKey iPhone unlocker poses serious security concerns

#53

This seems at odds with Apple’s claims about holding the device encryption keys in a secure coprocessor that only releases them in response to a valid passcode, and self-destructs the keys if too many passcodes are tried.

Nah, I don’t think so, but if true it would hint at a vulnerability in the implementation of the Secure Enclave.

Re: GrayKey iPhone unlocker poses serious security concerns

#54
post #47
post #37

Earlier quoted context omitted.

Time delays only provide a false sense of security. In theory I could always cut open the casing and just plug wires straight into the EMMC or whatever you have in there. Your time delay UI is useless if I just bypass your UI and wire straight into the hardware. Of course that's non-trivial EE work, but the point is it's possible, for someone with enough money and the right equipment. What would make it intractable i…

You misunderstand the SEP. It contains an externally unreadable private key baked in at manufacturing time that encrypts protected data. Your "wires" would read garbage. The iOS security white paper is worth a read. Perhaps a nation-state actor could shave down the processor and read that key with a SEM or some crazy thing, but that's literally how far the design is supposed to have pushed iOS security. Which is what…

SEMs are not that expensive. The cheap ones on eBay are $12-14K. The more expensive Chinese ones are closer to $200K.

A security company can easily afford either.

Re: GrayKey iPhone unlocker poses serious security concerns

#55
post #47

Earlier quoted context omitted.

You misunderstand the SEP. It contains an externally unreadable private key baked in at manufacturing time that encrypts protected data. Your "wires" would read garbage. The iOS security white paper is worth a read. Perhaps a nation-state actor could shave down the processor and read that key with a SEM or some crazy thing, but that's literally how far the design is supposed to have pushed iOS security. Which is what…

SEMs are not that expensive. The cheap ones on eBay are $12-14K. The more expensive Chinese ones are closer to $200K. A security company can easily afford either.

I don't think the acquisition of a SEM is the barrier to performing this kind of attack. It's still extremely hard

Re: GrayKey iPhone unlocker poses serious security concerns

#56
I thought iPhone were electronically secure, it seems they are not. I thought the FBI had to just do some Xray of some chip to read some ROM thing.

Sometimes I wonder if real security is really and theoretically possible, or if it's just engineers who never manage to achieve it because designers want things to be usable for consumers.

What ever happens it doesn't seem really secure, consumer oriented device do exist. I wonder if there are android devices who do a good job at that, and what's the status of the security of android device in general, I would guess it's not better.

Re: GrayKey iPhone unlocker poses serious security concerns

#57

Earlier quoted context omitted.

Is this not automatically illegal under the DMCA? Well, assuming the company in question is based in the US.

The DMCA specifically criminalises the circumvention of copyright protection methods , not all access controls.

I’m not a lawyer, but quoting from the Wikipedia article the DMCA “also criminalizes the act of circumventing an access control, whether or not there is actual infringement of copyright itself.” You could argue that you hold copyright on for example a photo you’ve taken, and the passcode is the access control method.

Re: GrayKey iPhone unlocker poses serious security concerns

#58

Earlier quoted context omitted.

Is this not automatically illegal under the DMCA? Well, assuming the company in question is based in the US.

The DMCA specifically criminalises the circumvention of copyright protection methods , not all access controls.

[deleted]

Re: GrayKey iPhone unlocker poses serious security concerns

#59
Humans being abysmal PIN and password generators, a decent fraction of phones can probably be unlocked within 5 attempts by just trying 123456, 123123, 111111, 654321, 000000. Unless/until the phone forces the user to learn rather than select a PIN that's probably going to remain the biggest vuln.

Re: GrayKey iPhone unlocker poses serious security concerns

#60
post #21

If this actually works there has to be some huge, embarrassing vuln in Apple's Secure Enclave Processor on par with the "CTS Labs" AMD secure coprocessor hoopla that hit the news just this week.[1][2] The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper sa…

It seems like they don't have the exponential delays, but they do have delays. Why else would it take 3 days to unlock the phone if it has a 6-digit passcode?

Apple's security paper says it would take more than 50 years to brute-force an alphanumeric 6-digit passcode at 80ms per iteration. I suspect that's still correct here (if “3 days or more” is for 6 numeric digits).

Post reply on HN