Live data from Hacker News

Why can't Apple decrypt your iPhone?

blog.cryptographyengineering.com

81–90 of 132 posts

Re: Why can't Apple decrypt your iPhone?

#81
post #49

There's another technical surveillance method here that I feel more people should be talking about: monitoring iMessage communication. iMessage is extremely secure[1], except for the fact that Apple controls the device list for iCloud accounts. The method would simply be for Apple to silently add another device to a target's account which is under law enforcement's control. I say "silently" in that they would need to…

Whenever you add a device to your pool of iMessage devices, all of the other devices get a popup message telling them. This is the step where each of the other devices get the decryption key for that device.

My hunch is that Apple doesn't have a way to prevent the popup messages so if they were forced to add a law enforcement iPhone to an iMessage pool then the target would notice an extra device was added.

Re: Why can't Apple decrypt your iPhone?

#82
post #62

> (Apple pegs such cracking attempts at 5 1/2 years for a random 6-character password consisting of lowercase letters and numbers. PINs will obviously take much less time, sometimes as little as half an hour. Choose a good passphrase!) Do not use simple pin passwords on your phone. In particular, if you use fingerprint access, there is no reason not to have a long, complex password.

There is an argument against using the fingerprint access and that is that a user gives up the right of consent while in custody. If law enforcement gets a judicial order to forcibly press the prisoner's finger to the sensor to unlock the device, then he or she has little recourse as the right to remain silent is not implicated. One cannot be similarly physically compelled to disclose a code only held in his or her m…

If you have the ability to lawyer it enough, I think you'd have a few layers of court required to sort out whether this is allowed (assuming they don't have proof you have something on the phone). You are basically forcing self-incrimination, a violation of the Fifth Amendment.

I totally agree that, if you are really concerned about this, fingerprint is a bad idea, but the legal ramifications are interesting.

Not quite relatedly, does anybody know if there is a heat sensor? Or can I just cut somebody's finger off to use it? (We are obviously well outside of judicial channels here! :)

Re: Why can't Apple decrypt your iPhone?

#83

Earlier quoted context omitted.

Yes, currently iCloud backups are not encrypted so they can be extracted by law enforcement, but on the other hand they are not mandatory, as Apple also offers a full local backup solution through iTunes (albeit, admittedly, they could make it work automatically like Time Machine, instead of manually; I guess they'll get there, now that they're using privacy in marketing). On the other hand, it is perfectly possible…

> iCloud backups are not encrypted This is wrong. iCloud uses AES 128 and 256 encryption: http://support.apple.com/kb/HT4865?viewlocale=en_US&locale=e...

This doesn't really say much unless we also know how the AES key itself is derived.

If you don't have two-step authentication on, then Apple's password reset is based on asking some security questions and sending an e-mail challenge. Even if they actually derived the key from your security question answers (unlikely), that's the kind of thing law enforcement would have no trouble cracking. More likely, the whole authentication system simply returns true or false, and the key is stored in some separate place -- perhaps more secure than a random hard drive in the datacenter, but still somewhere where Apple can get it if forced.

If you do have two-step authentication enabled, Apple's docs imply that it is impossible to recover your account without at least two of:

* Your password.

* Your "recovery key" -- a secret that they give you and instruct you to print out and keep somewhere.

* Your phone (or some other device that can generate one-time codes).

They say that if you can't produce two of these then all your data is lost and you'll need to create a new Apple ID. This implies that they might indeed store your data encrypted by an AES key which is in turn stored encrypted in two different ways: once with your password, and once with your recovery key. Thus it would actually be impossible to recover your data without one of these, and Apple doesn't store either one on their servers, therefore Apple would not be able to produce your data for law enforcement.

That said, I would be very surprised (and impressed) if Apple actually does this. Consider that this would prevent their services from doing any offline processing of your data at all -- a compromise few product designers would be willing to make for a security guarantee that almost no user actually understands. More likely, the language in the documentation is a matter of policy -- Apple refuses to recover your account simply because that's the only way to guarantee that social engineering is impossible, not because they are technically incapable.

And anyway, even if your data is stored encrypted at rest with a key that is actually derived from your password, there's nothing stopping law enforcement from demanding that Apple intercept your password (or the key itself) next time you log in. That's basically what they did with Lavabit, after all.

(Things I think about while working on sandstorm.io...)

Re: Why can't Apple decrypt your iPhone?

#84
post #49

There's another technical surveillance method here that I feel more people should be talking about: monitoring iMessage communication. iMessage is extremely secure[1], except for the fact that Apple controls the device list for iCloud accounts. The method would simply be for Apple to silently add another device to a target's account which is under law enforcement's control. I say "silently" in that they would need to…

Whenever you add a device to your pool of iMessage devices, all of the other devices get a popup message telling them. This is the step where each of the other devices get the decryption key for that device. My hunch is that Apple doesn't have a way to prevent the popup messages so if they were forced to add a law enforcement iPhone to an iMessage pool then the target would notice an extra device was added.

Maybe I don't understand the problem, but it seems to me that it would be very simple for apple to prevent the popup messages at their discretion, since they write and control the software that causes the popup to happen in the first place.

Re: Why can't Apple decrypt your iPhone?

#85

Earlier quoted context omitted.

I wrote myself a database that I use for passwords and the like. I get around this by masking text until I tap a button, and then waiting a random number of ticks before decrypting the value and progressively unmasking the text. It takes between ½ and two seconds. The problem I've yet to solve is hiding the text. Leaving it on-screen for, say 10 seconds before re-masking and encrypting is fine for now but sometimes t…

You should try 1Password: https://agilebits.com/onepassword It's the most recommended password manager on Hacker News.

Thanks, I'm aware of it but it doesn't work for me.

Beyond what I described above, I need something that works on Windows and Windows Phone, and I need it to securely sync between the two.

Re: Why can't Apple decrypt your iPhone?

#86
post #53
post #41

Earlier quoted context omitted.

Technically, this sounds about right (am mostly a n00b though) but the comments on this thread seem to me terrifyingly naive for a post-Snowden world. Apple has semi-convincingly denied the presence of a few, very specific attack vectors, and the article is speculating about the details of those denials, which is all well and good. But it is an absolute certainty that communications technologies built and operated by…

Yes, the NSA has boasted of having a surveillance "partnership" with U.S. companies, but those would be telecommunications carriers -- AT&T, Verizon, etc., not Silicon Valley firms: http://www.cnet.com/news/surveillance-partnership-between-ns... Also look at the sworn affidavit that EFF obtained from local SF bay area whistleblower Mark Klein -- an AT&T technician who revealed the existence of the NSA's fiber taps at…

[deleted]

Re: Why can't Apple decrypt your iPhone?

#87
post #31

Earlier quoted context omitted.

But if this is the case, why bother with bullet point 1. to 4. The chip is probably manufactured in China, why spend a thought about whether US law enforcement can somehow via Apple decrypt the data of my phone when the Chinese Government can do it anyways?

I fear the American government's totalitarian/police state leanings far more than I fear the PRoC. Though the Chinese government is undoubtedly an enthusiastic squasher of political dissent, and their secret police are surely quite brutal, and I hate commies with a passion, I am hardly ever likely to have a conflict with the Chinese state. An Unconstitutional American surveillance state is a far more immediate proble…

I agree with you, but I would add that: if any power has the key to your phone's backdoor, there is a chance of the key getting into the NSA's hands.

Re: Why can't Apple decrypt your iPhone?

#88
post #5
post #4

Earlier quoted context omitted.

I'm skeptical as well. Seems to me that so many things on your phone are talking to Apple (and other 3rd parties) anyways, that this might not even matter? Although the FBI seems to be not very happy about this (if it's not just "for show" that is)[1]. The FBI is using the age-old "Save/Protect the children" argument, literally. [1] http://www.washingtonpost.com/business/technology/2014/09/25...

Never mind that none of this matters if you have unlocked the phone and it's on (default protection policy is protect until first unlock, which happens right after turnup). That's gotta be 99.9% of cases. Once the police or apple have a locked phone, all bets are off. Apple can just install an app remotely that gets them past the lockscreen, and unless this is from a cold boot, you have access to all apps and all dat…

>> Apple says they don't have a specific backdoor anymore (!), and they won't let you audit anything.

Yes. Its amazing to me how eager some people are to take a corporation's spokepeople at their word.

Re: Why can't Apple decrypt your iPhone?

#89
post #62

> (Apple pegs such cracking attempts at 5 1/2 years for a random 6-character password consisting of lowercase letters and numbers. PINs will obviously take much less time, sometimes as little as half an hour. Choose a good passphrase!) Do not use simple pin passwords on your phone. In particular, if you use fingerprint access, there is no reason not to have a long, complex password.

There is an argument against using the fingerprint access and that is that a user gives up the right of consent while in custody. If law enforcement gets a judicial order to forcibly press the prisoner's finger to the sensor to unlock the device, then he or she has little recourse as the right to remain silent is not implicated. One cannot be similarly physically compelled to disclose a code only held in his or her m…

The obligatory xkcd reference had to be posted here. :)

http://xkcd.com/538/

"Drug him and hit him with this $5 wrench until he tells us the password."

Re: Why can't Apple decrypt your iPhone?

#90
post #84

Earlier quoted context omitted.

Whenever you add a device to your pool of iMessage devices, all of the other devices get a popup message telling them. This is the step where each of the other devices get the decryption key for that device. My hunch is that Apple doesn't have a way to prevent the popup messages so if they were forced to add a law enforcement iPhone to an iMessage pool then the target would notice an extra device was added.

Maybe I don't understand the problem, but it seems to me that it would be very simple for apple to prevent the popup messages at their discretion, since they write and control the software that causes the popup to happen in the first place.

They would have to update the OS on the device first. And that's definitely not something that can be done silently.

I'm assuming here that the OS already doesn't have the ability to suppress the popup, and I think that's a safe assumption because Apple doesn't want to have this ability.

Post reply on HN