Live data from Hacker News

Cellebrite claims it can unlock any iPhone, many new Android phones for police

wired.com

81–90 of 90 posts

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#81
If such a device were used in the course of an investigation, wouldn't the defense have the right to examine the device and cross-examine the responsible engineers to ascertain how it works and to ensure that the recovered information has not been tampered-with?

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#82

Most users have 4-digit or 6-digit numeric passwords, which can be trivially brute-forced. The only reason they can't generally is that SEP rate-limits decryption attempts. They probably have a way around the rate-limit. Meaning: if you use an alphanumeric password, you're fine.

I can still brute force your iTunes backup without a rate limit and distributed in Amazon GPU compute instances. Combine leaked pw databases with smart software (I use Elcomsoft), and you have a fair chance at getting in.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#83
post #81

If such a device were used in the course of an investigation, wouldn't the defense have the right to examine the device and cross-examine the responsible engineers to ascertain how it works and to ensure that the recovered information has not been tampered-with?

Not if they use parallel construction

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#84
post #77

Earlier quoted context omitted.

It's supposed to. We don't even know for sure that there's a flaw in it; they might have just bypassed it, found a way to read the flash memory directly.

The memory used by the SEP is encrypted.

With a key. Which is stored in SEP hardware. Which could, in theory, be extracted.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#85

Wouldn't such an ability, by virtue of having been tested at least once, run afoul of the DMCA? Of course, it is an Israeli company and not an American one, and we have no proof that they have the ability or have ever exercised it, and IANAL, but I am curious.

AFAIK, they cracked the San Bernardino murderer's iPhone.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#86
post #8

It is much more likely imo, that they have zero day exploits for something that does not require the phone to be unlocked, eg wireless, 3g/4g, bluetooth, or via the lightning connector. If they are not doing that one of the only other options i can see is if they can clone the phone and perform a offline brute force against the pin code but my understanding is that the secure enclave is meant to prevent attacks like…

this was meant to be a reply to earenndils comment at https://news.ycombinator.com/item?id=20194224 i hope this makes more sense.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#87

Earlier quoted context omitted.

But since we lack an individually actionable way of making the police better, doesn't the argument reduce to "we should not help the police as they are now"?

Yes, tautologically, "no-one should help the police" means "we should not help the police as they are now", but given that's obvious, I suspect that's not what you intend to say. My previous post was responding to your claim "But an argument that no-one should help the police is basically an argument the police shouldn't exist", which is incorrect. The two are very different arguments.

The police could not exist if most people refused to help them. Arguing for people not to help the police is therefore arguing for the police to stop existing or to become less powerful or less effective.

I take "not helping" to mean not just not developing specialized products that only police can legally use, but also not calling the police in case of crime, not helping them with investigations as witnesses. Where the law permits, not selling them generic products and services (eg food). And where personal circumstances permit, not working for a company that does business with them, deplatforming them, etc.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#88
post #77

Earlier quoted context omitted.

The memory used by the SEP is encrypted.

With a key. Which is stored in SEP hardware. Which could, in theory, be extracted.

I'm not saying extraction is technically impossible, just that you can't simply bypass the SEP and read its flash the way hardware reversers do with other embedded systems.

Re: Cellebrite claims it can unlock any iPhone, many new Android phones for police

#89

Most users have 4-digit or 6-digit numeric passwords, which can be trivially brute-forced. The only reason they can't generally is that SEP rate-limits decryption attempts. They probably have a way around the rate-limit. Meaning: if you use an alphanumeric password, you're fine.

I can still brute force your iTunes backup without a rate limit and distributed in Amazon GPU compute instances. Combine leaked pw databases with smart software (I use Elcomsoft), and you have a fair chance at getting in.

Do many people still perform iTunes backups? I haven’t since iCloud first offered them.
Post reply on HN