iOS 11 Horror Story: The Rise and Fall of iOS Security
blog.elcomsoft.com
blog.elcomsoft.com
I wonder if this is an attempt to fix that gone wrong.
1: https://9to5mac.com/2017/10/10/psa-apple-id-phishing-attempt...
See also NOOP, NOPR, etc.
Basically, if you press the home button; nothing happens.
1: https://twitter.com/marcoarment/status/841359803192561665
1: https://www.reddit.com/r/privacy/comments/51wqhd/dropbox_fak...
I don't think the issue went away with iOS 11. It's still happening in iOS 11 for myself on an iPhone X as well as some of my colleagues.
I honestly think this is a reasonable security model, as every other 'forgot password' workflow that I see services use is already vulnerable to my phone and passcode being in the wrong hands.
Think about the common options here. Apple could send out a rest link via email, but bad guy already has my email. They could send a verification code via SMS - oh wait, this is MY PHONE we're talking about. How about they send a push notification to... nevermind.
About 3 seconds worth of thought brings one to the conclusion that with my phone and pin/passcode, a bad actor could reset the passwords for pretty much every service I use - it's not just iCloud.
So someone explain to me in non hand-wavy terms how you'd expect this to be any different/better?
From the article:
Any attempt to change or remove that password must pass through iOS, which would require to provide the old password first. Forgot the original password? There’s no going back, you’re stuck with what you have unless you are willing to factory reset the device and lose all data in the process.
Apparently, there was no password recovery. Now there is, and as a convenience it even skips the whole email step. This has implications for accessing the data present on the device, which is the whole point of the article.
If you lose your phone, you can change your email password.
I don't entirely agree with this - if my iPhone PIN is compromised, I do not want my 2FA iCloud account to be compromised.
There are some alternatives that are absolutely more secure. Now the trade off might not what you want, but the iPhone and iOS isn't the most secure smart phone available.
https://www.silentcircle.com/products-and-solutions/devices/
Probably, but silent circle isn’t one of them. Silent circle is just a generic Chinese android phone without carrier bloatware. Instead, they ship a bunch of their own bloatware. They haven’t really made any fundamental improvements to security over what you can get with any other rootable android phone.
iOS has a generally much stronger hardware security model than Android, although it’s not perfect either, especially given that it’s closed source and not auditable.
I’m hopeful that Purism’s librem 5 cell phone will represent a substantive improvement in smartphone security. Runs standard Linux, isolated baseband, hardware kill switches, etc.
Things have not gotten better. So no, there are not alternatives that are “absolutely more secure.”
I think the phone is silly for other reasons, but that link is nonsense and largely unrelated to the discussion at hand.
https://www.bittium.com/BittiumToughMobile
It also comes with its own Secure Suite MDM and is not tied to any unwanted third party. It's quite expensive, though, and I have no first-hand experience of it. Just talked with some Bittium guys recently. Lots of former Nokians working there.
I wonder if Apple changed its mind on blocking law enforcement from decrypting iPhones. It seems they were the ones to reach out to law enforcement when the Las Vegas attack happened.
I for one think it's completely ridiculous that every time such an attack happens it's encryption that gets most of the blame, rather than say the guns that were the actual tools that killed all of those people.
So one unhealthy individual can go and get an assault weapon, hundreds of bullets, no questions asked, but it's when he starts talking on his iPhone is when we should be getting worried and monitoring his conversationss?
Plus, such attacks are probably kept private, not shared with their best friends before they happen. The whole logic process seems so backwards. It's a little late to be reading the contents of the shooter's iPhone after he's already killed 20 people, no?
A cowardly mass attack devoid of value for human life can occur using nearly anything (pressure cookers, fertilizer, vehicles, chemicals under your sink, etc, etc, etc). While certain individuals certainly should not be allowed to possess firearms (those with mental or criminal behavioral events/patterns - there is already a federal background check that occurs in obtaining firearms) it is near impossible to prevent someone from obtaining something they are dead set on obtaining unless you lock them up until their death.
Let's not forget that the only time the US has been invaded (technically not yet the US, I know) was when armed private civilians rose together and defeated the preeminent military power in the world. Had those people not been armed the US would not exist. Think how many potential conflicts on US soil the armed population may have deterred since then when you compare it's history with nearly any other country in the world over the last 250 years.
Oh, and WWII: Aleutian Islands, even a small group of German spies.
So I'm very skeptical about any correlation between firearms ownership and homeland defense.
And Canadians are still invading my sunny state every winter, they wear smiles and friendly greetings as their uniforms, and use loonies as ammunition.
Their entire claim of a horror story relies on having physical access and the passcode, which would be game over on basically any device anyway.
It does point out a problem with most sms and app based 2fa systems in that all accounts that are protected as such essentially rely on your devices passcode to keep those accounts safe.
In iOS 11 it changes, now you can for example access all passwords in the keystore. So you know my 4 digit pin for my phone, not to mention my Google password, Apple iCloud password, etc. Those should not be accessible with just the access code.
The way I go is have a long 10-14 digit code, and Face ID/Touch ID saves me the trouble of having to key it in all the time.
You can do that in iOS 10 as well.
Apple made your passcode is equivalent to your root password on a Mac.
I think they were trying to make it easy for less tech savvy users to use the device. I agree that there has to some mechanism to change what kind of password you want to apply to access certain functionality on your phone
Does a prompt for TouchID/FaceID affect usability?
If i understand correctly, prior to 11, you needed to know the iCloud password to, say, remove Activation Lock. Now, you don't need iCloud password, just device password (and physical access of course).
It's a significant drop in security, and not just in a theoretical sense ,if only because people enter their device passcodes a lot more than they do their icloud passwords (which makes them tend to be easier to guess and easier to capture).
The issue here is actually deeper. With the physical access to your device, they get access and ownership of your other devices, too.
Say, you lose your iPhone on a trip and an attacker recovers your passcode for that phone (say you're not a HN'er, but an average joe who uses a 0000 passcode for convenience). Now the attacker can overtake your apple ID, go into the Find My iDevice app and _lock_ your iPad and your MacBook that are still in your possession. And now you've got two more bricks on your hand, which presumably display a Bitcoin address with a ransom.
With iOS's 2FA system : I've had to click buttons on other devices. Enter codes on other devices. Enter codes from other devices. Click links in emails. Type my passcode on other devices. I just ... don't have a grasp on it at all.
That's not good.
With regards to the backup issues outlined in the article, it's hard to say if the backup leak is a major issue.
Take the casual user: They won't be making iTunes backups. Most casual users are probably just doing iCloud backups. In fact, they don't do backups at all; iCloud backups are automatic so they don't think about it (it just works).
Take the security hard user: They'll have a password instead of a passcode on the device. So adversaries probably won't get access anyway. Of course, it's possible they shoulder-skim your password, whereas they probably won't be able to ever shoulder-skim your backup password. So certainly Apple's change here _does_ objectively make the system weaker.
It's hard to say if what Apple did here was the right thing. Like I said, I don't think most casual users are doing iTunes backups, so why even bother making iTunes backups more user friendly?
Regardless, it could certainly be improved. Maybe require 2FA to reset backup password?
The issue where you can reset the iCloud password is certainly troubling. It's a hard issue to balance, as Apple doesn't want to set up a system where the average user gets locked out of their account because they forgot their password. But it really shouldn't be possible to take a single iDevice and password and take over a user's iCloud account.
If what you’re saying is true (resetting an EXISTING recovery key to an attacker controlled recovery key requires only device passcode), that is a major security flaw.
Fundamentally, iOS has made the trade off that most people should default to being able to recover their data if they forget their password. Technical or famous people can and should opt IN to the high security recovery key model.
In other words: if you have set a recovery key, you shouldn’t be able to reset your iCloud password or recovery key without BOTH possession of a secondary logged in Apple device AND the current iCloud password. Alternately, you can of course control the whole shebang with a recovery key, that’s what it’s for.
Are you saying you were able to reset an established recovery key without needing to enter your iCloud password OR 2FA acknowledgement on a secondary device?
Bummer.
I have an "RK-" recovery key in my backup from when I set it up a couple of years ago. However today I see no reference to recovery codes whatsoever, either on my account or during attempts to recover my password. I just now stripped two-factor auth entirely, and set it up again from scratch. There is absolutely no reference to a recovery key anywhere[1].
It must depend on which devices and/or OS versions one is running. I've got a 2013 MacBook Pro on High Sierra and an iPhone 6 on iOS 11 (latest software on both). I also have a confirmed phone number. I no longer have the option for a recovery code with two-factor auth[1].
"Remember, if you lose your recovery key, you might be locked out of your Apple ID account permanently."
If you lost your recovery key, you are basically screw yourself out your own account, permanently, period.Recovery keys are gone. You must either have a 2nd device, or be able to receive a text or phone call to a verified phone number. Failing these, the last resort is now an "account recovery" process that takes a few days to reset via what looks like verification by email and confirmation of personal details.
I'd rather have retained the recovery key option, but I imagine this system was removed because the majority of consumers weren't actually storing the key. Of people who at least stored the key, far too many probably only put it on their Apple device(s), which is of course useless.
If you don't have an iPhone it gets even weirder -- I've had it pop up auth codes on the same laptop on which I'm logging into iCloud.
Pet-peeve, but I wouldn't say ridiculous. It's like how there's no Kerberos compatibility for web apps.
YMMV, I guess.
I assume it is because the iPhone is decrypting the backup, but it's just that it is doing it very slowly for some reason.
they need to add a "keep going anyways" button, or a prompt to plug in like the watch has
I know this is bad, but for me it is awesome right now.
> The password you entered to protect your iPhone backup could not be set. Please try again.
What happens then is: the password i set is actually active, becuse to back up i have to enter that password - but as soon as i unplug the iPhone and plug it back in, I can/have to set e new password.
I updated iTunes to the newest version, restarted the iPhone, reset the iPhone settings multiple times, but I cannot encrypt the backup anymore. Weird.
edit: (the solutions to this problem that google offers did not solve the problem)
"Forgot the original password? There’s no going back, you’re stuck with what you have unless you are willing to factory reset the device and lose all data in the process. If you ask me, this was a perfect and carefully thought through solution."
I'm not sure how you can consider it a perfect solution that users are losing their backups and hammering Apple for support about the issue. The suggestion to make another backup via iCloud is not terribly useful to those who have lost their phone.
So, the only scope left is if you have your device in hand, in which case having the option to back stuff up to iCloud even if you lost the local backup password is pretty legitimate if you want to migrate devices. And useful even for resetting the said password: you back up to iCloud, reset your device to reset the password and then restore an iCloud backup. The only catch is that you'd need to buy some iCloud space from Apple, but a) they're gonna be happy to charge you for it, and b) it's quite cheap as the backup size is quite smaller than the amount of storage taken on your phone (my phone backup is 15 GB when 80 GB was used on the phone), and is a one-month purchase.
I don't care much about the phone backups on some secondary devices. I do care whether those devices can hijack my icloud account with just that phone's pin.
That seems terribly broken, to be able to change icloud without having the password or without 2FA.
I am certain that one cannot consider it a perfect solution that Apple can read a user's data.
Like with Mozilla's crippling of Firefox's end-user security, any protocol which allows an unauthorised party to read data will eventually ensure an unauthorised party to read data.
——————-
I don’t really get their point it’s like if someone told us « Linux have weakened their threat assessment level, if you got the password of a sudoer user you can access evrything on the system »
The only difference being that it extend to what you putted in the cloud. But loosing the passcode on iOS was always the equivalent of giving full admin right on the machine.
That’s the whole point of TouchID/FaceID/SecureEnclave teach user to have a strong passcode while keeping a smooth UX because they don’t have to type them regularly.
So yes this is a single point of failure which come with pros and cons.
- The bad news is that if you give your passcode you can loose everything
- The good news is that the only way to crack your device is to guess in ten attempts what is the passcode from 1000000 possibilities by default (maybe less cause you can’t decently use some combination like 123456)
But in the end I was able to remove the password and keep the keychain data all in place and instill a new iTunes Backup Password which I knew.
So what’s actually changed other than not having to go through the whole iCloud Backup/Wipe/Restore in order to reset the iTunes Backup Password?
Maybe I am misremembering and it didn’t actually restore my keychain back onto the same device when I did the restore?
Prior to iOS 11, to get access to a backup of an iDevice (and that backup allows you to view all data on the device, keychain etc):
1) iCloud Backup
2) Wipe
3) Restore [requires iCloud password]
4) Perform iTunes Backup
Now under iOS 11 it's (according to the article): 1) Reset Settings [requires pin code]
2) Perform iTunes Backup
So the difference is that now you don't need the iCloud password.If you disable iCloud Keychain, sign out of an iCloud account and then log into a different iCloud account on the same iPhone — what happens to the local keychain data?
What happens when I turn off iCloud Keychain on a device?
When you turn off iCloud Keychain for a device, you're asked to keep or delete the passwords and credit card information that you saved. If you choose to keep the data, it isn't deleted or updated when you make changes on other devices.
And then...
When you turn on iCloud Keychain, any previously-saved website usernames and passwords, Wi-Fi networks, and Internet accounts are automatically included in iCloud Keychain.
In exchange for letting people reset their encrypted backup password without losing data.
How is that a "horror story"?
Settings > Accounts & Passwords > App & Website Passwords
Settings > Safari > Autofill > Saved Credit Cards
To nitpick, there is more data in the keychain than passwords and credit cards. But I think having all your passwords and credit cards exposed is probably bad enough.
The security experts or the people who lost everything because they lost their passcodes?
If you carry your fortune in your wallet is it okay to blame the wallet manufacturer for your financial crisis when you misplace it?
You are right though, those people are the loudest to complain. :)
I can find no mention of this feature in the article. It would seem that it would mitigate the core problem described by preventing someone in possession of your phone and passcode (but not the recovery key) from taking over your iCloud account.
Settings --> user thing at top --> password and security
Perhaps I'm in the wrong place.
I guess the only consolation is that eventually the phone will logout, so the attack would have to be done soon after getting the phone?
Update: It's much worse than that. I just got a login notification on my ipad for my apple id. So I'm not signed in. But, I went to reset the password, and it said I can do it with a passcode since I'm signed in to icloud.
So icloud signin lasts far longer than apple ID signin for the app store.
This seems like a serious vulnerability. Makes me rethink having multiple idevices, or putting anything in icloud keychain. Any one of them gives access to everything.
I am not a security expert though, so take this with a grain of salt.
[1] https://itunes.apple.com/us/app/apple-configurator-2/id10371...
It doesn't mention what type of phone they're talking about in this case (or go into much technical detail at all, of course) but I'm very curious just what "advancements" enable law enforcement to bypass the encryption that is, by now, enabled by default on most phones, AFAIK.
I'd be even more interested if this was an iPhone, as that's what I have. This wouldn't have been iOS 11, however, as the original event (the setting of a passcode) occurred on 2015-11-02.
Regardless, these "advancements" discussed in this article sound more like "regressions" to me.
[0]: http://fox59.com/2017/11/30/technology-advancements-lead-to-...
I will admit though the data available to access in a backup is far deeper than I had expected, and definitely far deeper than you can get through iOS alone. I'm not a security nut, but I'm surprised I didn't know about this option (again, probably because I don't use iTunes).
The other security relaxation allows you to change your Apple ID's password without knowing what the old one was. To me, that's a much larger problem.
So my question is (having never gone through that flow with Apple ID), what was the "Forgot Password" flow in iOS 10? If the answer is it sends you an email, how does that work for people that use icloud.com mail (because, if they don't know their password, they can't get their mail)?
The "always signed in" model of mobile computing means that once you have access to the device, you have the keys to the kingdom. Why are we concerned about a slightly smoother iCloud password reset flow when somebody with this level of access has enough information and capabilities to get into my bank account?
The same, apparently; I just tried it on this phone, which I haven't updated, and it didn't ask for anything but the passcode.
Perhaps the behavior of a completed reset differs; I'm not about to mess with it just for kicks. But the fact that everything up to that point is identical makes me doubt that somewhat.
How has this not been a bigger issue before? I’d imagine, iOS 11 or not, for those of us without iTunes, anyone with my iOS pass code has always been able to access my iCloud account.
Anyone who has your passcode and access to your device can takeover your iCloud account by resetting the account, lock your other devices, and access any passwords you have stored in iCloud keychain
If so, this seems like a massive security liabilty, and grounds for deleting all icloud keychain passwords.
Do you know how many people share that passcode with others, intentionally or unintentionally? Family members, spouses, etc. repair people who do screen replacements. Their buddy, who can text for them while they drive.
I’m sitting on a plane and saw the person next to me enter her passcode. It’s 258085.
That is not a secure 6 digit passcode, it’s a vertical Tetris shape. Humans are great at pattern recognition, particularly when it’s in a grid format and leaves finger smudges.
I could easily pick pocket this woman’s phone and ruin her weekend without much effort at all, just from reading this article.
But you say her 6 digit passcode is quite secure?
Settings > Passcode > Change Passcode > Passcode Options > Custom Alphanumeric Code
If you only use numerals, you can go longer than six digits and still use the numeric keypad to authenticate.
This is exactly why my google account password is the only one I do not keep saved anywhere. Not in keychain, not in 1password. It's a strong password, plus 2FA (not that 2FA matters if someone has my phone).
If something happened to me, I'd like a stranger to be able to access it. It's not particularly embarrassing information for people to see - for some people, yes. But there should be a way to make your health data unencrypted for those that prefer it very accessible.
Privacy by default should be the norm, not the other way around - lots to be inferred/exposed from even the smallest bit of info.
I don't see the relationship to mass spying.
I recall seeing it when Eric Schmidt at Google said something like “don’t have anything worth hiding, and then you won’t care if you are hacked”. Excuse my brevity, but you argument and his are dumb arguments. These devices are incredibly powerful, and allow us to interact with one another in ways pen, paper, snail mail, and landlines never could (let alone the security risks those mediums have, which cannot be mitigated).
Devices can be incredibly secure. Manufacturers and service providers should prioritize that over mindless convenience.
I would agree with you, however, that you should not put your entire life into any insecure device. And it seems the iPhone is not an insecure device (I’m frustrated, and I have a 20+ character keyboard passphrase! Let alone 4-6 digit code)
I understand that for many people this is problematic because they need these goodies for their day-to-day functioning. But so far I've managed to do without them and I don't feel particularly handicapped.
So: Inconvenience where there should be convenience, convenience where there should be inconvenience.
Do not interconnect services
Specifically, I:
1. don't use iCloud backup.
2. Backup to my own computer
3. Have a backup program to a different provider than Apple
4. Do not interconnect accounts with iPhone/Mac.
Only annoying thing is the iphone telling me that iCloud backup is full because I haven't upgraded.
https://ios.gadgethacks.com/how-to/enable-disable-two-factor...
More likely, Apple wants to ease user adoption.
Did you buy an iPhone X? It was awesome to setup. There was this nifty feature to use NFC/the cameras on my new phone to authenticate myself, and it was a breeze. Huge fan of this type of improvement and convenience.
You know what I’m not a fan of? My iPhone being a gateway to hijack the rest of my digital life. It’s a key to my little kingdom that didn’t exist before, and my only protection is (figuratively speaking) locking my phone to me like the Nuclear Football, and continuing to use a 20+ character passphrase with enough entropy I can’t be brute forced.
But I'm not really serious with this 'conspiracy theory', it's just some food for thought/shitpostin'.