I read through the article - including the hand wavey "Apple has never been cracking your data conclusion" - but I don't understand what has changed since previous versions of iOS other than more data being encrypted. Apple claims they can't decrypt data, but, the article suggests that they can simply run the decryption on the local phone with custom firmware. Most people chose a 4 digit pin, and, @80 millisecond/gue…
Why can't Apple decrypt your iPhone?
91–100 of 132 posts
Re: Why can't Apple decrypt your iPhone?
#92There's another technical surveillance method here that I feel more people should be talking about: monitoring iMessage communication. iMessage is extremely secure[1], except for the fact that Apple controls the device list for iCloud accounts. The method would simply be for Apple to silently add another device to a target's account which is under law enforcement's control. I say "silently" in that they would need to…
Re: Why can't Apple decrypt your iPhone?
#93I read through the article - including the hand wavey "Apple has never been cracking your data conclusion" - but I don't understand what has changed since previous versions of iOS other than more data being encrypted. Apple claims they can't decrypt data, but, the article suggests that they can simply run the decryption on the local phone with custom firmware. Most people chose a 4 digit pin, and, @80 millisecond/gue…
The passcode and the pin is not the same thing, most people don't have a passcode.
On iOS I believe this is incorrect, the Passcode is another name for PIN on the iPhone.
http://support.apple.com/kb/ht4113
You can have complex or simple passcodes, but everybody I've ever seen who bothers to have a passcode (myself excepted), sets it to a 4 digit code (aka PIN). To make it worse, it's usually their ATM PIN.
Re: Why can't Apple decrypt your iPhone?
#94Earlier quoted context omitted.
Maybe I don't understand the problem, but it seems to me that it would be very simple for apple to prevent the popup messages at their discretion, since they write and control the software that causes the popup to happen in the first place.
They would have to update the OS on the device first. And that's definitely not something that can be done silently. I'm assuming here that the OS already doesn't have the ability to suppress the popup, and I think that's a safe assumption because Apple doesn't want to have this ability.
Can you link me to a technical analysis about this?
It would be one of the few phones where the baseband/SIM couldn't make changes to the system.
Re: Why can't Apple decrypt your iPhone?
#95> The Secure Enclave is designed to prevent exfiltration of the UID key. On earlier Apple devices this key lived in the application processor itself, and could (allegedly) be extracted if the device was jailbroken and kernel patched. Speaking as a jailbreaker, this is actually incorrect. At least as of previous revisions, the UID key lives in hardware - you can ask the hardware AES engine to encrypt or decrypt using…
Is jailbreaking becoming more difficult and would that be a sign of iOS/iPhone becoming more secure?
Re: Why can't Apple decrypt your iPhone?
#96Earlier quoted context omitted.
You should try 1Password: https://agilebits.com/onepassword It's the most recommended password manager on Hacker News.
Thanks, I'm aware of it but it doesn't work for me. Beyond what I described above, I need something that works on Windows and Windows Phone, and I need it to securely sync between the two.
https://discussions.agilebits.com/discussion/12133/1password...
Re: Why can't Apple decrypt your iPhone?
#97There's another technical surveillance method here that I feel more people should be talking about: monitoring iMessage communication. iMessage is extremely secure[1], except for the fact that Apple controls the device list for iCloud accounts. The method would simply be for Apple to silently add another device to a target's account which is under law enforcement's control. I say "silently" in that they would need to…
That would only catch messages sent to the target, not messages that the target sent itself. For example if I send a iMessage to a friend on my Mac, I won't see my sent message on my iPhone later.
Re: Why can't Apple decrypt your iPhone?
#98> (Apple pegs such cracking attempts at 5 1/2 years for a random 6-character password consisting of lowercase letters and numbers. PINs will obviously take much less time, sometimes as little as half an hour. Choose a good passphrase!) Do not use simple pin passwords on your phone. In particular, if you use fingerprint access, there is no reason not to have a long, complex password.
There is an argument against using the fingerprint access and that is that a user gives up the right of consent while in custody. If law enforcement gets a judicial order to forcibly press the prisoner's finger to the sensor to unlock the device, then he or she has little recourse as the right to remain silent is not implicated. One cannot be similarly physically compelled to disclose a code only held in his or her m…
Re: Why can't Apple decrypt your iPhone?
#99So the key is derived from passcode? isn't that 5 digits that are easy to brute force?
5 digits would be easy. It would take a little over an hour on average. However, passcodes are not limited to digits. Use upper and lower case letters and digits, and then a 5 character passcode would on average a little over a year. Make it 6 characters, and that's 72 years.
Even those who are super security conscious tend to just use numeric PINs. It's the very, very rare individual who enters an alphanumeric passcode.
Re: Why can't Apple decrypt your iPhone?
#100Earlier quoted context omitted.
It's very probably within the realms of possibility , yes. It's very probably not within the realms of practicality just yet, however.
Go check out some conference presentations by Christopher Tarnovsky. He's made a career out of it, and acquired some very expensive toys (focused ion-beam equipment doesn't come cheap), but there are lectures of his explaining how he broke the (iirc) STMicro TPM chips for fun . These sorts of devices have all sorts of countermeasures against direct invasive attacks like these, but with enough cash and bricked test ph…
"enough cash and bricked test phones" - the great thing about this, is you can just buy the $650 phones - you can get a thousand of them for less than a million dollars, which probably is under your typical line managers budget in the NSA techOps group.
And, lets be realistic, Apple isn't trying to defend against the NSA or Nation States, just your average hacker without access to $100mm+ in hardware.