What Is the Secure Enclave?
mikeash.com
mikeash.com
This is the exact same asymmetry embodied in openness/privacy/surveillance. When governments and corporations have unfettered access to people's private information, this is very bad for human rights and an open democratic society. On the other hand, when individuals have open access to information from government organizations and corporations, this is generally good for human rights and an open democratic society.
Organizations using trusted execution technologies against individuals has been a disaster for individual rights. However, empowering individuals to use such technologies to protect them against corporations would have tremendous benefits for individuals.
Here's some material from a flash memory manufacturer with more details: https://www.spansion.com/Support/Application%20Notes/X-ray_i...
Anyway, it's just different than software. You can't sha sum your hardware to verify its what you expected.
I'm not sure, maybe an x-ray could see inside. Not unlike how binary blobs can be examined, but usually that's not considered open.
I'd wager that we can have open hardware, and that its correct manufacture can be verified to a satisfactory degree by a combination of auditing and testing without running into limits of the laws of physics or inherent design requirements.
I've been reading Friday Q&A for years and the posts never cease to amaze. He doesn't politicize or whine about anything. It's always thoughts from a teacher, a master.
I wish there was more in the tech world like him. Thanks Mike!
I do actually whine a lot, I just try real hard to keep it off my blog. Complaining is fun, but it's not helpful.
I suspect the iPhone's Secure Enclave is designed to self-destruct in a similar way.
Yeah, so how, exactly, do they wipe their data? Is it a firmware process? What if they are unpowered as they are tampered?
Or is the media attached in such a way that physically removing it would damage it physically?
http://www.microsemi.com/document-portal/doc_view/132857-ove... : see page 5. That's Microsemi but the general approach of Apple/TSMC/Samsung is likely to be the same.
This is also speculation, but perhaps this is why you have to enter the passcode on device reboot. This may be simply a software protection (see talk about being compelled to provide a fingerprint), but it may actually be a necessary step for the secure enclave to boot as well.
I also suspect that Tim Cook's announcement doesn't mean to imply that such a theoretical attack currently exists, but rather than one may exist in the future that Apple could be compelled to comply with.
But that doesn't meet the FBI's actual needs. The FBI's ACTUAL needs are to have a case with a lot of public sympathy in which they can force a major tech company to very publicly comply with their order to add a backdoor to a phone (without calling it that) in order to influence the legal and legislative systems (and perhaps public opinion, if the FBI even cares about that).
http://www.nytimes.com/2016/02/19/opinion/why-apple-is-right...
Source: http://www.politico.com/story/2016/02/apple-iphone-privacy-j...
On the other hand, if the FBI had some lead time, all of the above could be circumvented without Apple's cooperation.
Also, are you saying that even the machines manufacturing them do not know what they are doing ("... secure enclave manufacturing process is done is such a way that even the manufacturer does not know what the key is.")? Sounds a lot like a PR campaign... I would be curious to know how this manufacturing process really works.
Even so, if they do have the UID that greatly reduces the security of the encryption - especially if you are using a short passcode.
That's not a problem if your want to, say, extract secret keys once from one device that you own in order to break DRM.
But it makes it completely impractical if your aim is to extract crypto keys from smartphones to decrypt peoples data.
Obviously not practical for mass surveillance, but it would work to read one particular person's phone, which is the issue at hand.
Eh. I mean, yes, if the issue at hand were ACTUALLY read this one particular person's phone, that would probably be a valid avenue of attack.
But the actual issue at hand here is "establish precedent that you can use the All Writ's Act to get a judge to hand you an ex parte order that lets you walk in to a tech company and order them to build you (and, crucially, cryptographically sign) the tools you want so that you can get whatever data your heart desires".
Once that precedent is in place for this "just this one phone we swear" order, nothing's stopping them from walking into Apple or Google or whoever with an order to build and sign a custom OS version that, say, copies all data to an FBI server and push it as an OTA update to a target.
Once All Writs has been expanded to mean "you have to build us signed, custom versions of your software to get us data we want", all bets are off.
This is pretty far outside my area of expertise, so that may be a very dumb question.
>The first possibility is that the Secure Enclave uses the same sort of software update mechanism as the rest of the device. That is, updates must be signed by Apple, but can be freely applied. This would make the Secure Enclave useless against an attack by Apple itself, since Apple could just create new Secure Enclave software that removes the limitations. The Secure Enclave would still be a useful feature, helping to protect the user if the main OS is exploited by a third party, but it would be irrelevant to the question whether Apple can break into its own devices.
If we assume this is the case, it might explain what McAfee meant when he mentioned social engineering.