Apple tells U.S. judge 'impossible' to unlock new iPhones
reuters.com
reuters.com
Finger unlock is nice when you're in a non-hostile environment, but now with a 100ms finger brush, the entire phone opens up wide and says "take all my data!"
I wish iPhones had a feature like "if dropped on the floor (or after any 'significant' impact), remove session key to disable finger print auth and require password again." Then when you gotta cheese it, you just throw and go.
There's no emergency evac situation. You either have basically no protection from hostile action or you avoid finger auth.
as far as "international spy," we have national level security directors storing secrets in AOL accounts. We can't protect people from themselves, so we have to make systems better for everybody.
But, trying to revoke the finger auth key in an emergency (less than 5 seconds) is difficult. Your only option is to try and quickly power off the device, but you're at the mercy of the "press and hold sleep/wake button for 5 seconds, then slide to turn off" delay timer.
Of course if ever you have an opportunity in an arrest you should shut down the iPhone... Unlock would require passcode.
1: https://securityledger.com/2013/09/iphone-touchid-falls-to-w...
Being DA 101
[0] http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
Similar to the idea of having a second PIN on your credit card that allows access but indicates acting-under-duress to the bank.
Is there a reason that they couldn't employ this countermeasure for your suggested security?
Sounds like you are alluding to being able to use a reverse version of your PIN on an ATM when in duress?
It's a trope [0].
> It's a trope
If it's debuked on Snopes, it's an urban legend or a myth. Trope means something different.just like it needs passcodes that do that same, if not more. a passcode to let you in, one to CALL the cops, and another to thwart them
I have no idea how this works in regard to the encryption. It isn't likely anyone else here does either. They are just speculating.
I hope that it is good, but I don't trust it. No one should trust it.
I would look, but I don't own an iPhone.
I don't mean this as a claim that the iPhone is a secure device, since it obviously isn't in several different ways, but rather just that I can't reproduce this specific behavior.
Not sure if it's been fixed yet or not, but you can just turn off Siri from the lock screen.
1: http://lifehacker.com/ios-9-lock-screen-exploit-gives-evildo...
Impossible is a very strong word in this context. Let me take the opportunity to remind everyone that an iPhone is a very complicated device running nearly 100% closed source hardware and software, include all sorts of opaque cryptographic hardware and a known-to-be-compromised secondary baseband computer, such that the security of the device's entire stack, top-to-bottom, could not possibly be verified by a third party in principle, let alone in practice.
In light of that fact, security claims by Apple could be regarded as changing (reducing?) the probability of the law getting your data by technical means or collusion with Cupertino, but certainly not as insuring that the probability = 0.
Edit: This is not an indictment of Apple per se, since the same is true of literally every smartphone ever constructed, but at least e.g. Blackberry isn't out there claiming that they're unable to compromise your data, full stop.
I was merely skipping the caveats (back doors, implementation error, leaky behavior, etc) and giving benefit of the doubt with regards to honesty of intentions.
Not sure if anyone noticed but this article is like a continuation of the story from days ago [1] when the judge in the case "questioned the government’s authority to compel Apple to unlock a seized mobile device using the All Writs Act" [2] and "called on Apple to weigh in about whether it is even capable of bypassing the lock screen in this case" [2].
Guess Apple has weighed in now as to its technical feasibility. Now it's up to the judge to decide whether it is an unreasonable burden on Apple, and whether it violates the Constitution, as to whether to compel Apple to help in the Justice Department's investigation.
In this one single case, the iPhone has an older iOS, so maybe it's not an "unreasonable burden".
But if it was iOS 8 or later, it might be deemed an unreasonable burden to compel Apple to brute force or otherwise crack the password, even if it was somehow technically possible. And "forcing Apple to push backdoored updates would constitute 'compelled speech' in violation of the First Amendment" [2].
So it does look as if Apple thought it through, and made iOS 8 so that they legally and practically cannot "betray their customers' trust" as you say.
[1] https://news.ycombinator.com/item?id=10383253
[2] https://www.eff.org/deeplinks/2015/10/judge-doj-not-all-writ...
An Apple officer making a sworn statement that Apple has no technical ability to extract data from an uncooperative customer's phone is significant, even if it applies only to the present, not to the past or future.
Of course, Apple could be implementing things differently from as described but the whitepaper lays out what is and is not possible in the described system.
The key section I think most people really should take a look at is "iCloud Backup" starting on page 42. Almost everything you do with your device will end up in an iCloud Backup if you have enabled that, and while the data is encrypted for transport, note well the following;
The backup set is stored in the user’s iCloud account and consists of a copy of the
user’s files, and the iCloud Backup keybag. The iCloud Backup keybag is protected by
a random key, which is also stored with the backup set. (The user’s iCloud password
is not utilized for encryption so that changing the iCloud password won’t invalidate
existing backups.)
In plain English, if you have enabled iCloud Backup, everything but your keychain itself is accessible in plaintext to Apple, and can be restored, without your password, to any new device that [you / the Feds] may provide.I would very much love for Apple to provide an opt-in where the iCloud backup key is tied to the account password with extremely aggressive key-stretching. I would take the risk of losing my iCloud Backup over the trade-off of having my backups accessible to Apple and anyone they can be compelled to share them with. But I do appreciate for the average user, it's not uncommon for iCloud Backup to be immediately preceded by a password reset (just look down-thread for an example).
Note, Apple says that they use a combination of S3 and Azure to actually store the iCloud data, but that they have an additional layer of encryption over the data before sending it out. So while backups technically reside on Amazon/Microsoft servers, it's a black box to them.
At a minimum, if the police get access to your email account, they can force a Apple ID password reset and then restore your data onto a new device without needing permission from you or Apple.
Note however it is still possible to backup your iphone locally using iTunes and Apple now supports encrypted local backups. If you are worried about this threat vector, encrypted local backups provides a large degree of the same usability with significantly stronger security guarantees.
That's an interesting assertion. I mean, yes, sure, they could do that, but it's an interesting question of whether they are legally allowed to do that. Effectively they'd be misrepresenting themselves to your email provider and to Apple as if they were you. Is that acceptable 'undercover policing'? Can they reset your banking password too? Can they do this only while they have you under arrest?
It's a broad, overarching, and highly vague statement that amounts to, in many cases, "I decided you do, so therefore I have the right to act as if you do".
iTunes has supported encrypted local backups since the beginning of iOS.
restore your data onto a new device without needing permission from you or Apple.
and that's a great reason to verify your iCloud backup is always disabled on all devices (if you care about privacy). You just have to be vigilant about not accidentally enabling it during any setup process since iOS wants you to enable the feature, but it's easy to disable everywhere.
In the future they will use shady FinFisher iTunes and other exploits to grab the data then seize the phone.
https://9to5mac.files.wordpress.com/2013/07/screen-shot-2013...
Note the "slide to unlock" message at the bottom. If you asked most users what it means to unlock a phone, this is what they would think of, as they see it every day.
[citation needed]
"Unlocked phone" is not limited to experts. More than half a million hits on google: https://www.google.com/search?q=%22unlocked+phone%22&oq=%22u...
I really don't know what "most users" would think of.
Edit: I understand your point and agree that unlocking a device would not mean exactly the same thing to all people. I just don't agree that the parent needed an additional citation.
BUT on the other hand with proper use of crypto it is now possible to engage in secure communication at a distance that can never be decrypted without our consent and (if certain protocols and method are used) allow anonymity at both ends of the link (e.g. Tor hidden services). It is also possible to securely send money to others using Bitcoin without knowing their identity... ever.
Very interesting times... it's both a panopticon and an unprecedented age for anonymity and privacy.
I'm just astonished by the breadth of vulnerability in modern smartphones, particularly with Googles handling of Android security. We haven't even gotten into baseband vulnerabilities yet because the whole applications processor security thing is just an entirely crumbling piece of cardboard.
What worries me is that this will lead to laws being passed that will criminalize refusal to hand over passwords and encryption keys.
If you actually care about security, use a long alphanumeric password. It's not a big hassle when you have Touch ID. If you are ever in trouble, try turning the iPhone off immediately or quickly touch your fingerprint reader a few times with a wrong finger or enter the passcode wrong five times (so that Secure Enclave discards the cached decryption key and no longer accepts fingerprints). Also, use Apple Configurator tool to make your iPhone "Supervised" and don't let it pair with any new computer. And disable iCloud backup entirely.
Of course, there is the potential that Secure Enclave could be updated with new microcode (I have no idea if that is actually possible).
* Wipe after 10 unsuccesful PIN attempts
* Be configured with a 6 digit numeric PIN code
* Be configured with an unlimited alphanumeric password
* Exponentially increase delay between PIN attempts after
unsuccessful entry - for example 3 attempts in 3 seconds,
next attempt after 10 seconds, next attempt after 60
seconds, next attempt after 4 hours, next attempt after
24 hours, next attempt after a week, next attempt in a
year (making up numbers to prove a point)Yep, it was patched: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451
That HSM is still just a physical machine, and it can be, with difficulty, modified or copied.
To be impossible it would have to be mathematically impossible (or at least not within human time scales).
"Disassemble phone, desolder security module, dissolve the outer layers in hydrochloric acid, cut the silicon into 16nm slices, scan each layer with an electron microscope" impractical.
From a cold boot user data is not loaded into memory until a correct pin has been entered once, and since A5 nobody has managed to compromise their bootchain it is not really viable to exploit either.
http://blog.cryptographyengineering.com/2014/10/why-cant-app...
To break such a system is not impossible, but would require some heroic effort, even nation states would probably resort to some side channel or the proverbial five dollar wrench.
I'm not sure you understand what an HSM is. It doesn't help to "emulate" one. An HSM performs cryptographic operations under certain conditions (such as correct PIN entry) using internally stored keys. The whole point is that you can't get the keys out, only use them. If you had another HSM, or a logical model of one, it wouldn't contain the right keys.
Certainly as engineered systems, it's possible for HSMs to contain vulnerabilities, but getting the key out of an HSM is a much more sophisticated task than cracking a keyspace of just 10,000 possibilities. Possible, maybe.
[0]http://www.apple.com/business/docs/iOS_Security_Guide.pdf
It's actually really impressive.
And I don't know for sure, but I feel like that one was fixed at some point.
Edit: Yep, superuser2 links to the CVE: https://news.ycombinator.com/item?id=10423257, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451
Seems more of a mechanical setup, rather than this guy's video. Like put a kill switch ON THE PATH (i.e. before signals reach) the "Okay iPhone, register this failed attempt" destination.
Other commentors have pointed out that the PIN/crypto stuff is handled by dedicated hardware designed to resist tampering, probably pretty much state-of-the-art. The issue before was a software issue. Now that it's fixed it's very hard to completely hack the hardware and would have to be done to each phone individually: https://news.ycombinator.com/item?id=10424439 I'm not an expert, but I imagine intercepting the signal would be just as hard, as the signal is contained within one tiny chip and it might not even be possible to reliably modify a circuit on that scale. You can't just replace the chip with a no-PIN version either, because it contains a unique crypto key to the data you presumably want from the phone. This also makes modifying the chip difficult, because if you screw up you could lose the key.
[0] https://www.mdsec.co.uk/2015/03/apple-ios-hardware-assisted-... [1] http://forum.gsmhosting.com/vbb/10720367-post1.html
Unless Apple already inserted a secret backdoor that allows for forced updates, you don't have to update the phone when it prompts you. The closest I've seen it get is a reminder that asks you if you'd like to schedule an update for 2:00 AM or some such time, and then asks for your passcode to do so. You still need to type it for the explicit purpose of updating for it to go through.
I know that recent updates download automatically on Wi-Fi, perhaps that was what you're thinking of?
The 5th protects you from being compelled to be a witness at your own trial, it does not however protects from destroying evidence, interfering with a police investigation or hindering justice.
If you intentionally destroy incriminating evidence that's a crime, if you prevent the police from executing a search warrant that's a crime too, a court can order you to present existing physical evidence including private diaries, recordings, or anything else and refusal to do so is a crime.
Now while you can say that a code is "speech" it's wouldn't be that hard to claim that it isn't, handing out a code isn't baring witness, this isn't speech in any sense, you can already be compelled to give DNA and fingerprints.
That code essentially is a device that serves only 1 purpose and it is to unlock your phone, if you build your house in a nuclear silo and refuse to give the police the keys when presented with a search warrant they'll lock you up, quite a few constitutional lawyers can argue that this example can also be applied to passwords, encryption keys, and other similar devices.
This isn't the same situation that Apple has; while I bet the motions would be filed under seal, I don't believe it would create significant liability for Apple to have a warrant canary, and then remove it after the canary 'dies'.
In fact, in 2014, Apple's canary did 'die', with no further comment, and no public disclosure that their were material difficulties with the canary. Apple seems to have been working to enhance security on their devices since then. I would take from this that they didn't receive giant, secret penalties from their canary.
I thought you were saying EFF's assumption that a court cannot compel a canary to be maintained, would also prevent a court from compelling a software update targeting a certain user. Anyway, I believe we can't trust either a canary or software, because either can probably be compelled.
[0] https://www.washingtonpost.com/posteverything/wp/2014/09/23/...
Whether it's a crime for the device owner is an entirely separate question; there's case law in both directions about whether you can be compelled to supply the passphrase or unlock the device. (That case law also varies by jurisdiction.)
There's an entirely separate question about whether the device vendor can be compelled to introduce a backdoor where none previously existed. And you could quite reasonably argue that even if the device owner could be compelled to unlock the device, the device vendor should not be compelled to produce a less secure device, any more than a safe manufacturer should be compelled to produce a backdoor combination that unlocks one of their safes.
And if you have the key to your nuclear silo in your hand but refuse to unlock the door, the police don't have to lock you up because they can take the key from you instead. But if the lock is a keypad then the scenario is identical to the iPhone and you're just assuming the conclusion. Your argument seems to distill into the idea that if the police can't read your iPhone without violating your constitutional rights then your constitutional rights have to give way.
http://www.cnet.com/news/obama-denies-that-us-spied-on-germa...!
"the United States is not monitoring and will not monitor the communications" means, "Was monitoring up until just now."
Here Apple says "We can't unlock new iPhones." Apple says nothing about their ability to restore iCloud backups or load software to capture evidence from a locked phone.
I'm not sure how easy it would be to fool the touch ID sensor on the phone. I think I remember a MythBusters episode where they made a silicone mould of a fingerprint to bypass a security system.
"Forcing Apple to extract data in this case, absent clear legal authority to do so, could threaten the trust between Apple and its customers and substantially tarnish the Apple brand"
This quote, granted taken without full context, seems to indicate a pretty clear stipulation of "clear legal authority". Not sure what to make of that, but I do think that in matters of privacy and surveillance the words are always chosen very carefully indeed.
Agree, but often impossibility claims have an expiration date. They also said it would be impossible to jailbreak iOS 9 with the new rootless security... It took few months for a Chinese team to completely by-pass Apple's new design.
http://www.forbes.com/sites/antonyleather/2015/10/18/how-to-...
Also, "child pornography" ...what if "child pornography" is involved? You wouldn't want THAT, right?
Another vector of attack is fingerprint scanner. After iPhone turned on, by default you can unlock it with fingerprint scanner. And turning iPhone off is not very quick, you need to push power button for a few seconds and then slide over screen. If police arresting you, then will get your phone from your hands and just force your finger to open it, no pincode needed.
So yes, while iPhone is probably safe when properly configured (ruling out possible vulnerabilities), the proper configuration is hard to use and is not default.
That's from the point of goverment attacker. If attacker is just some thieve or commercial espionage, probably iPhone is a good device even with default settings.
I do not think this is an attempt to sell newer iPhones to the small fraction of users they have running iPhones too old for iOS8.