Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone
latimes.com
latimes.com
First, it's Apple sticking it to the FBI by making a stand for privacy and receiving public accolades doing so as a champion of privacy. The FBI is the bad guy trying to invade our privacy.
Now, it's the FBI sending a giant "screw you" to Apple by not only letting them know they were able to hack into the phone without Apple's help but at the same time, making a mockery of Apple's entire security claims. And now, Apple is in panic mode, slowly realizing that they went from being the hero of privacy in the modern age to the company that wasn't able to secure its phone from the FBI. From the FBI. Of all things.
No wonder they are freaking out and they want to know how the FBI did it.
Except that if I were them, I certainly wouldn't ask that publicly, I would at least pretend I know how the FBI did it and claim that it's already fixed in the next version of the OS.
Which still means that tens of millions of iPhones are at risk today and will be for months, but at least, you get to pretend that you're ahead of the FBI while right now, it's pretty obvious that Apple has been outsmarted by a government agency.
The bottom line is that in this line of work, it pays to be discreet and humble.
Sure, from Apple's side, it would have been better had it gone to court and been established that the government isn't allowed to do what it was trying to do, but... I don't see the FBI trying the same tactic again, and, here's the kicker—if they can't establish the authority to force Apple to unlock phones on non-secure enclave machines, then when they need a secure enclave equipped phone unlocked, it's going to be a lot harder to use the All Writs Act to force Apple's hand.
Right now, I'd say they are looking pretty good: they hacked into the phone of a terrorist without breaking any laws.
By the way, since the FBI said this phone will allow arresting other terrorists... did we find anything relevant on the phone?
They've probably spent six to seven figures on hiring a 3rd party for a bespoke service just to find what any analyst could've assumed - nothing.
That said given the severity of the situation even a 1 in a 1000 chance to get some additional information would'be been worth the kings ransom they must have had to pay to get it unlocked. At the end think what you want of the FBI but that's exactly what their duty should entail, forcing Apple to unlock it is a murky business but investing resources in unlock the phone themselves is perfectly within their right and even obligation to do.
I don't understand why people are going apeshit about this no one would bat an eye when the FBI picks a lock or breaks into a safe how is an iPhone different?
Because it was not about that one iPhone but the planned precedent with immense effects: using the court-order to "write" the new laws, and FBI started the whole thing exactly with that goal:
http://9to5mac.com/2016/02/26/fbi-apple-iphone-precedent-pol...
The vast majority of safes also have a backup lock or code.
In short; lock-makers continue to make exploitable locks just fine, because they sell just fine. The moment they stop selling is the moment they'll fix the issues. Nobody is going to skip the next iPhone because the FBI allegedly managed to crack one, security is not one of the features people care about (in general).
I have no problem with the FBI breaking into one phone that they have both a warrant for and have in their physical possession. That is how it's supposed to work.
I did, however, have problems with several other issues around this case (none of these have really gone away, only been postponed for now):
1. The FBI potentially being able to force a company to assist and do work for an investigation, as well as betray the privacy of its users
2. The government moving, partially based on this case, to force vendors to create back doors for everything, weakening security and privacy for everyone
3. The slippery slope that all of this would create
What proof do you have that the FBI hacked the phone? The only piece of evidence we have is that the FBI withdrew the case. That could be either 1.) They were able to crack the phone (unsubstantiated TMK) 2.) They realize they lost the debate regarding encryption but didn't want to risk setting precedent
Everyone knew they could do this and they only tried to use this whole thing to get easy access to all phones from Apple.
Wow, lying doesn't really look like the best course of action for a public traded company, I guess.
>Which still means that tens of millions of iPhones are at risk today and will be for months, but at least, you get to pretend that you're ahead of the FBI while right now, it's pretty obvious that Apple has been outsmarted by a government agency.
It's extremely probable that users are not in danger. If it's true that the FBI used Cellebrite's services, they might have used a slightly upgraded version of the company's solution that enabled the hacking of 32-bit devices (i.e. no secure enclave). The commercial solution touted publicly by Cellebrite is used by law enforcement all over the world to unlock iOS 8.x iPhones and iPads in a matter of 24h. There was a recent case in Milan, where the Court expert was able to unlock an iPhone 5 in 2 days and retrieve data thanks to the services of Cellebrite's offices in Munich.
So: 32-bit devices with iOS 9, no secure enclave, implication of a company known for providing solutions to break into iPhones since forever.
Icing on the cake: they might as well have used a system like the one suggested by ACLU and other experts: NVRAM cloning. That's a solution that's extremely phone specific and doesn't require to exploit any big scary bug to be carried out.
Most probable outcome: Apple will keep on hardening iOS security and it's own cloud security even more. In the end the common user wins.
The FBI is STILL the bad guy, acting like criminals who won't disclose a potential vulnerability (which might as well not exists) to the manufacturer.
There is no obligation to disclose vulnerabilities. You are free to sell them to the highest bidder, including the government. The government has some damn good uses for them, see Stuxnet.
Of course, big tech companies would love it to be required to disclose vulnerabilities. That way they get the whole security community's labor for free and don't have to pay bug bounties.
Anything about successful / unsuccessful / advanced / trivial solution is just speculation at this point as far as I know. The only thing that FBI said is that they got the data they wanted - and that could be done in thousands of ways. And it doesn't even have to be something that can be prevented or fixed by Apple (what if they found a CCTV recording of the owner tapping the code in?)
The FBI asked for access, Apple said no (because they knew the case was about precedent rather than capabilities). Apple knows the older phones had vulnerabilities (see this faux-apple computer - https://youtu.be/zsjZ2r9Ygzw?t=15m50s commercial).
This is the follow-up from Apple saying "oh, you needed our help to crack it huh? How did you suddenly find a way to do it on your own without us as soon as you realized public perception wasn't proceeding as you hoped?
EFF seems to think that the FBI is legally required to disclose the method (https://www.eff.org/deeplinks/2016/03/fbi-breaks-iphone-and-...) due to their VEP process.
If anything, the question is whether the US Government is morally obliged to reveal the vulnerability, given that the risk of not doing so is much higher than the value the government gets from exploiting it as a tool against terrorism. That, I believe, is the EFF's strategy – getting public support and appealing to the government's moral obligation to protect its people.
It may be the wrong opinion, but it's the popular opinion among many people I've spoken to. Namely, they think Apple has egg on its face and isn't as good at security as they claimed to be. Right and wrong don't always matter in the court of public opinion.
>it's pretty obvious that Apple has been outsmarted by a government agency.
I disagree with this assessment. It's not very surprising that the FBI was able to hack into a particular iPhone by focusing all available resources on the task. Given their previous duplicity, I would not even believe the claim without real evidence. Furthermore, I would not be surprised if they'd already hacked into it weeks ago. After all, their objective here was never to hack into the phone, but to establish a legal precedent that would force companies like Apple to comply with their future wishes. Apple has well and truly won, and the FBI is at this point trying (and succeeding, sadly) to save face.
I would speculate that Apple are asking them about it publicly because they know that the FBI will not comply with such a demand, thus making the FBI look bad, since it is now (purportedly) putting the security of millions of consumer devices at stake. They may also suspect that the FBI has not legitimately hacked into the phone, which remains a possibility. Or, as is more likely, that the FBI's method required large resources and could not be applied to many iphones at once, for instance.
As an iPhone user, I presume I have standing and could argue some form of damages. Now, is there a lawyer out there interested in discussing whether there is really any merit to bringing a suit forward?
Would / could this be a class action, or in this case, is it better to seek an individual out come?
Hypothetically speaking, of course, until there are proven grounds to stand on.
Ianal, but isn't the US government (via the FBI's court proceedings) publicly stating they have access to / have used a vulnerability actionable in some way?
If this were done in private that would be one thing, but they've now gone on the record as saying a usable vulnerability exists.
The fact that it's the government also adds in the great deference that the courts give the government on national security issues. And it would be with good reason in this case. Vulnerabilities are used to craft attacks against our country's enemies (see Stuxnet).
Some applications that I cracked, yghm illegally, had TOS or EULA with something like 'you're not allowed to RE our app" or "if you find a vulnerability you must let us know about it in the first order". Doesn't Apple have something like that for their software? That would make it easier for them to legally force FBI to reveal the method. If, FBI, does not lie, which can be the case, they got data from different source and iOS is still safe.
And look like a lying fool when details eventually come out and reveal that it's a hardware security flaw, not something that can be patched by OS.
Well, ask the agent what they set and/or read their logs. This isn't rocket surgery.
They come off looking like complete fools at best, since their huge public spectacle was based on "only Apple can do this," and now that it turns out they could have done it themselves, it just looks like they're incompetent.
Meanwhile Apple comes off as fully committed to their customers' privacy even when it means standing up to the US government. The fact that the FBI was able to get into this phone doesn't really change much; the mere fact that Apple could have gotten into it already means that security was lacking on it, but it seems to me that everybody understood that this was an older model and newer ones are better. Which is funny, because I'm pretty sure both the FBI's proposed attack from Apple and whatever the FBI did themselves would work on the latest hardware too, but just about everyone is convinced that the Secure Enclave would prevent it. And then in September Apple will announce the iPhone 7 with Even Better Security, further demonstrating their commitment in this area.
My conspiracy theory instincts tell me that this is a play to fool us into thinking that Apple is fighting for our privacy, in order to make us trust Apple unconditionally and in the meantime not develop new ways of hiding our communications. In reality I think the government always gets what it wants.
No one ever doubted that there was some vulnerability that exists that could be used without Apple's help. There is almost always a vulnerability. The hard part is discovering it. As soon as a third-party told them about it, they paused the case against Apple. The new information changed the facts of the case and made compelling Apple unnecessary. For the FBI to do anything else would have been perjury of the highest order.
Yes, I expect the FBI to "know everything" when it comes to techniques available to do their job. No, I don't expect the FBI to "know everything" when it comes to the contents of my private messages. There's no conflict.
They just hacked into an iPhone, something Apple has been claiming for a long time was impossible. Even Apple has no clue how they did it.
Incompetent they are not.
You're looking at political theater, that's it. But there's little incompetence flying around.
Apple looks bad because they claimed that if they produced this software for the FBI it would eventually get in the hands of international criminals and put their users at risk (this before the FBI tried compelling them so it would not have set court precedent). So the FBI did an about run and got someone to come up with a method to achieve the same aim, and so the end result to Apple users is the same, except Apple are in the dark as to what the vuln is. That's a position they'd like to not be in.
On the other hand, the FBI coming in and trying to compel Apple, after an initial rebuff, looks like it was unnecessary and makes them look less competent.
Now, given it took a third party to do this, the FBI can't very well disclose the third party's trade secret.
Lose-lose for both.
This should be titled "The iPhone was never as secure as we wanted to think it was"
> No wonder they are freaking out and they want to know how the FBI did it.
Not really sure how you reached that conclusion, as there wasn't even a single quote from an Apple employee or legal representative in the article. The only quote even related to the FBI giving the exploit method to Apple is from the product counsel at AVG Technologies.
So how exactly is Apple "freaking out"?
The author, on Twitter, said that "last week" Apple said they wanted to know what the exploit was, but the announcement about a successful exploit was only two days ago.
http://www.loopinsight.com/2016/03/28/apples-statement-on-go...
(I couldn't find this statement on apple.com, but it has been relayed by many news sources so I believe it is indeed official.)
It won't work on newer phones. The whole discussion is possible right now mainly because it's an iPhone 5c without a secure enclave. With (I believe) 6 and up the protection checking lives inside of an equivalent of PC's TPM. You can tell it "here's data and key, decode it" or "validate these bytes", but not "give me the internal key" - it doesn't support this on hardware level. (apologies to anyone annoyed at the simplification)
If the FBI cracked the phone, then Apple can smack them with it when this comes around again. If the FBI didn't crack the phone, then Apple can smack them with it for dropping the lawsuit.
This is just Apple saying "Fuck you, FBI, for bringing this lawsuit and then dropping it when things went badly. You're gonna sweat some more before you get off the hook."
And considering that the according to polling data only about 30% of the people say that Apple should not unlock the phone and 50% saying they should the public opinion doesn't really works for them currently.
The FBI might be playing the long game, they'll unlock a couple of phones (or pretend to do so), even cooperate with Apple and when the time comes go back to court saying that Apple fixed any potential flaw, and that the FBI might've even assisted them in doing so and now they hit a wall and need Apple's help.
There are sensible reasons not to report vulns, like utter incompetence of the system's owners or the system's security standing in the way of your perfectly legal activities.
I mean, for heaven's sake, "in Syria, militias armed by the Pentagon fight those armed by the CIA"[1]. And that's just the latest incarnation of this tired old worn out story.
Governments are nothing but the criminals we've decided we'd be better paying off than let run loose, whatever good it's done us. That's why governments are, ostensibly, so against 'organised crime', just a turf war really.
The only question left, then, is: What major bit of dumbshittery will government agency XZY slap itself in the face with next and get away with it.
1. http://www.latimes.com/world/middleeast/la-fg-cia-pentagon-i...
Should police, upon seeing an unlocked car, promptly find the owner and inform them? Of course that's a nice thing to do as people, but it's not really a legal obligation.
I know that in some places, the courts has ruled a police officer do not have a legal duty to protect citizens from harm or prevent crimes. Strangely, in places where citizens that witness a crime has a legal duty to report it, its unclear if the police has the same requirement.
But this is the FBI, so shouldn't they be held to a higher standard?
The FBI does not understand that no government will ever be able to force all encrypted software to do key escrow with them. That misunderstanding is costing a heap of tax payer dollars and risking public safety.
The NSA and the FBI are very different in their understanding of tech. Former NSA director Hayden already said he thinks the FBI's plan is no good. He also said he understands why Comey is pursuing this path. He did not say Comey is lying.
They lied about the motivation for the case, and they lied about a software update from Apple being the only means of recovering the data.
It'd be nice if they realized this future is coming very soon. We pay the FBI to be good at maintaining public safety.
On top of that, the polls about this issue showed there is somewhere between 40 and 50 percent of the public who sides with the FBI in the SB case. If backdoor legislation is introduced following a terrorist attack, there is a chance it could pass. We're better off educating the public now about how encryption works and where it is used.
The people we want to convince already trust the government. They will not listen if you include "the FBI lied about everything" in your argument. I think they could understand that backdoor-less encryption tech is better for our safety than backdoored encryption, given some explanation that one weakness exposes all devices. And, I think they could understand the impracticalities of enforcing what the government wants, given some discussion about how encryption is used in both commercial and free and open source messaging apps.
My luck--it will go down.
(I am curious if someone they really did hack it.)
I guess the biggest problem really is that they don't know if this vulnerability exists in current versions or if it was already fixed. I don't know that they would normally bother to fix old vulnerabilities but they do need to work on identifying this one at least.
There's some irony in here somewhere...
https://www.schneier.com/blog/archives/2008/08/dmca_does_not_a.htmlThis whole circle jerk was about the govt compelling Apple to bypass its own security so that they can do it in every other case to come after.
You are welcome Apple.
They have a bespoke service called CAIS as well as few other unlisted services which they do not advertise openly given their sensitive nature.
Their turn-key forensic solutions are tailored for general law enforcement and the public sector (private investigators, corporate security, law firms etc.), CAIS is usually offered to state security agencies and they have other services which are tailored towards intelligence and national security agencies.
So, basically their own collection of zero-days and techniques? Do they come up with them themselves, or do they buy them on the exploit market?
In some cases they might also offer a bring your own exploit type of service where they integrate client provided exploits with their existing platforms and solutions.
Some of their products are also hardware focused, their "Chinese SOC" attacks are mostly OS agnostic (Mediatek chipsets for example are attacked via some generic DMA exploit) and are designed specifically to assist LEA's to breaking into cheap disposable phone. http://www.cellebrite.com/Media/Default/Files/Forensics/Data...
But like any company these days it pretty much depends on what you want to buy for them they'll offer you a wide range of services from idiot proof turn key solutions to bespoke consulting like services, if they do have the ability to break into iOS9 or a more generic way to attack Apple SOC's they will not advertise it openly, at least not initially from previous experience with them it can take months and even years between them actually have an initial capability to it being integrated into their open commercial products.
This isn't only done for secrecy reasons this is also pragmatic some attacks might be very case dependent, expensive, or even potentially destructive and so wont be offered with their normal forensic services (that have to comply to very strict forensic standards, including being able to openly explain how access was achieved to ensure that the data has actually been extracted correctly and chain of custody maintained) so quite often what they are offered under their more bespoke services are capabilities that are not (yet) commercially viable for general forensic use.
In this case the FBI or any other agency is quite likely not to care about presenting the information as evidence in court, and their risk appetite might also be considerably greater.
Your local police/DA on the other hand must be able to present the evidence and defend how it was obtained in court so the tool has to be certified (NIST in case of US courts) and the extraction method has to be defensible in court.
However if we are talking about zero-days then those also cannot be offered as part of their commercial turn key solutions (court defensibility aside) because the solutions they provide have to be reliable and consistent.
Zero-days for the most part are likely to be fixed quicker than their products can be shipped yet alone certified so anything which is that volatile will only be offered via their "consulting service" and the clients will be quite aware that they are paying for something that might be a one off solution only.
> Apple already knows, and you can be sure the engineers already knew the mechanism that can be exploited. They hired an Israel firm to remove the nand flash, clone it, and brute force the pin code by trying each combination until valid data was readable from the nand flash (combined with the hardware encryption key located on a second chip). It's not particularly difficult with the right tools and engineers.
Source: https://www.reddit.com/r/worldnews/comments/4cj2pd/apple_wan...