Live data from Hacker News

The Feds Can Now Probably Unlock Every iPhone Model

forbes.com

81–90 of 162 posts

Re: The Feds Can Now Probably Unlock Every iPhone Model

#81
post #26
post #7

Earlier quoted context omitted.

>The story I hear is that Cellebrite hires ex-Apple engineers and moves them to countries where Apple can't prosecute them under the DMCA or its equivalents. Crazy if true. Doesn't this also create a weird incentive problem where the FBI (or any other law enforcement agency) who would normally be tasked with helping Apple with this doesn't actually want to?

So Israel is like a high tech Guantanamo where our government goes when those pesky laws get in the way.

The DMCA is applicable in Israel via the bilateral trade agreement with the US.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#82

Earlier quoted context omitted.

Relative to the size of its population, Israel has a highly developed electronics engineering related industry. Part of it related to their state support of domestic defense contractors like IAI and their avionics/radar/C4I equipment. Aside from Cellbrite, companies like Ceragon, Alvarion, Radwin, ECI, Telrad, Elbit. Second hand knowledge: Within international organizations that have worked extensively in the Israel-…

> Relative to the size of its population, Israel has a highly developed electronics engineering related industry. Part of it related to their state support of domestic defense contractors ... It's not due only to Israeli resources. Much of Israel's defense budget comes from the U.S., plus there is much more support, including technology transfer, that isn't provided in cash.

According to Businessweek [1] in 2012, the Israeli defence budget was approx. $15 billion per year and US military aid was $3.07 billion per year.

[1] http://www.businessinsider.com/heres-how-much-america-really...

Re: The Feds Can Now Probably Unlock Every iPhone Model

#83
post #52

Earlier quoted context omitted.

> after pointing this out. What would you say, exactly? If you said: "your honor, breathalyzers can be tampered with to provide false readings" It seems quite easy for anyone to respond with "how so?". Do you refer to "this one time in New Jersey"?

i have an expert that can explain various methods. Also, please release the device for the defenses inspection.

The prosecution will present calibration logs and security tampering prevention information to show that the device was independently verified as working correctly and demonstrably unchanged from that inspection date. A lot of people's careers rely on those records being correct, up to including a perjury charge if they're falsified.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#84

https://xkcd.com/538 All I want is my every day encryption to be a big enough pain in the butt to crack that the feds can't break it without spending a medium amount of money. ===Edit HN: Apologies this was lost in my subtlety, but consider the game theory aspects. Your best bet is to _just enough_ of a pain in the butt it's difficult to reach you, but you certainly don't want to be singled out on a national stage ei…

I'm not even on the Fed's radar. I don't want a mugger to send my stolen iDevice up the food chain to a Russian syndicate and have them able to in my Lastpass, internet banking app, live bitcoin wallet until I've had enough time to change all the credentials.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#85

This might be a good scenario for Apple. Apple doesn't have to build a backdoor, which is good for PR, and the Feds got what they want to they'll stop bothering Apple. Which is the position Android/Google was in all along.

So the tinfoil hat theory here is that Apple itself leaks the cracking tech to Cellobrite to ease the fed pressure, and keep reputation intact? Sorry, I don't buy it.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#86
post #23

How is chain of custody maintained if the process is a secret? Couldn't a person argue that the data obtained was planted?

>How is chain of custody maintained if the process is a secret? Couldn't a person argue that the data obtained was planted?

Well this is a more general issue (I mean not limited to this case or to sending a device to Cellebrite or to another external laboratory) once a chain of custody is formally valid, it has as much integrity as the integrity of the people that had physical access to or worked on the device.

Still - thankfully - "planting" evidence on a modern file system and OS (provided that the end result is an actual physical extraction) is not as easy as it may seem.

Definitely possible, but extremely difficult to achieve without leaving any trace behind.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#87

I'm too lazy to find a link for it, but last time I read about Cellebrite, they were cloning the data and simply trying unlock codes in sequence until one worked. They could restore the cloned data before each try, or possibly do it on custom hardware or an emulator, and start with a fresh copy each time, so they never triggered "erase after 10 failures". It's a pretty straightforward approach, but it doesn't scale w…

Doesn't scale well? Are you assuming you cannot run this parallel?

Re: The Feds Can Now Probably Unlock Every iPhone Model

#88

Earlier quoted context omitted.

Breathalyzers will tell you what's up right on the spot, unless you've come across some that require the cops to collect a jar of your breath for processing at some remote discrete location?

Breathalyzers are easily tampered with by police to provide false readings. One case of this in New Jersey could have potentially thrown out 20,000 DWI cases. But breathalyzer results in cases today are not thrown out after pointing this out.

That why where I live if you trigger the drink driving limit on a breathalyzer you're driven to the station where a medical professional will take your blood and send it to an independent lab.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#89
post #9

I'm too lazy to find a link for it, but last time I read about Cellebrite, they were cloning the data and simply trying unlock codes in sequence until one worked. They could restore the cloned data before each try, or possibly do it on custom hardware or an emulator, and start with a fresh copy each time, so they never triggered "erase after 10 failures". It's a pretty straightforward approach, but it doesn't scale w…

This is not true. You cannot just clone the data and run passcodes against it, because the data is not encrypted by your passcode. Instead, each file on iOS 11 is encrypted with a different AES 256-bit key, and cracking even one 256-bit key through exhaustive search is thought to be out of reach of humankind ( https://security.stackexchange.com/questions/6141/amount-of-... ). The file keys are wrapped by, among other…

> because the data is not encrypted by your passcode

You enter the correct code, your data gets decrypted. So your 256-bit key is derived from a 4-6 digit number somehow, which reduces your search space to that 4-6 digit number space.

Not sure how FaceID works, but that's probably even easier to break, people have done it with masks.

Re: The Feds Can Now Probably Unlock Every iPhone Model

#90
post #17

Earlier quoted context omitted.

No. An example would be automatically erase if the device has not been unlocked in 3 days.

This would be inconvenient at times.

-To most users, probably. But if you are a high-ish profile target, the (potential) inconvenience is probably worth the effort for the added peace of mind.

After all, when was the last time you spent three days without fondling your phone?

Post reply on HN