Cellebrite claims it can unlock any iPhone, many new Android phones for police
wired.com
wired.com
If they are not doing that one of the only other options i can see is if they can clone the phone and perform a offline brute force against the pin code but my understanding is that the secure enclave is meant to prevent attacks like that.
And yeah, you can’t clone an iPhone and get anything usable. The pin is entangled with a secret that never leaves the Secure Enclave, so an offline attack would be an attack on the full encryption key, not on the pin.
For example, how can a radio interface have "enough" access to facilitate decryption of an encrypted volume?
Get code execution on the radio chip, use that to harvest the decryption keys from RAM and the rest is pretty trivial.
> To protect the device from vulnerabilities in network processor firmware, network interfaces including Wi-Fi and baseband have limited access to application processor memory. When USB or SDIO is used to interface with the network processor, the network processor can’t initiate Direct Memory Access (DMA) transactions to the application processor. When PCIe is used, each network processor is on its own isolated PCIe bus. An IOMMU on each PCIe bus limits the network processor’s DMA access to pages of memory containing its network packets or control structures.
Of course there's always the chance that there's a bug in one of these interfaces
And on Android: ¯\_(ツ)_/¯ Even for the Google Pixel I can't find a security whitepaper, just a blog post with a couple of vague bullet points.
From there they would likely have to exploit a number of other bugs to get into the position that they want to be in.
Most mobile phones allow the baseband to have full access to the entire device, which is why an exploit of the baseband can turn into a full device compromise, but AIUI iPhones don't do this and keep the baseband as a separate unprivileged component, specifically to defend against this attack vector. So a baseband compromise might get you access to any data going over the baseband (e.g. phone calls, unencrypted data traffic, etc) but shouldn't get you access to the rest of the device.
I think what makes this statement interesting is that Apple recently introduced anti-replay counters into their A12 SOC to defeat replay attacks that just reset the memory after each attempt.
I think this might represent a new generation of attacks that either have found a bug in the secure enclave OS itself or some kind of local timing/side channel attack.
The secure enclave has been getting more complex (things like neural net for FaceID) and I have no idea if it has modern mitigations like ASLR so there is reasonable chance people can get execution there. Really just another local privilege escalation.
The side-channel idea is also really interesting because a lot of the row-hammer and SPECTRE style attacks seem far-fetched in real scenarios but attacking a different ring of your own chip with full kernel access makes any kind of hardware attack seem much more reasonable.
And that's what scared me into changing my relationship with my phone. I try to treat it as an ephemeral, disposable data terminal in which I have minimal trust.
Every few weeks I back it up to the LAN and purge it. If I lose it I revoke its login certificates so that it can't access the mail and chat servers, and block the PAYG SIM.
Yet more and more services want me to regard it as a secure token endowd with ultimate trust. The latest is one of my banks ( Halifax ) which demands that I install their app to authorise any online payment.
For example, what's the degree of entropy for a non-trivial 6x6 pattern? (And why is my search fu not availing me of the answer to this question? :-) )
Oracle created the DeWitt Clause that forbids researchers from publishinging benchmarks for their products, and this apparently stands up in court. I have to imagine Apple could forbid researching and building exploit tools just as easily.
The Boston bomber had a years old iphone that they eventually got cellebrite to decrypt.
It comes across as LE access by stealth rather than transparently handing over data upon request.
Was this "DeWitt Clause" ever challenged specifically in a trial? If yes, can you give us some details, e.g., date, the name of the opposing party, the venue, etc.?
If it has never been challenged specifically, and gone through litigation all the way to a trial, can we honestly say "it stands up in court"?
It might be possible to require a publication delay as a condition to a license, but an outright ban on publication might not be enforceable. The only way to know for sure is a lawsuit that goes to trial. Of course, even if we never actually find out because it never actually is the basis of any litigation that goes to trial, inclusion of a "DeWitt Clause" in a license could still intimidate licensees and effectively discourage publication.
The 2002 story linked on the Wikipedia page for "DeWitt Clause" mentions a telephone call to DeWitt's employer asking for him to be terminated. However it says nothing about a lawsuit based on breach of this particular "DeWitt Clause".
Consider whether a company such as https://www.blackbagtech.com/ (specifically products like MacQuisition) can exist without active support from Apple.
https://www.law.cornell.edu/uscode/text/17/1201
> (A) No person shall circumvent a technological measure that effectively controls access to a work protected under this title
Annnyway, more importantly: are there any details about how their claims are even possible? I guess that somehow, in every case of both iOS and Android, the symmetric key with which the data directory is encrypted is somehow gleanable?
It's a bit puzzling, because it seems that something as simple as 15-year old LUKS (eg, using dm-crypt) is sufficient for this purpose... right?
I mean, this company isn't claiming it can perform the same attack on an off-the-shelf laptop that has FDE with dm-crypt, right?
What's the difference? Why are phones such a security nightmare? At least in terms of encryption at rest on a cold device, isn't this a solved problem?
It’s only a solved problem if you’re using high entropy passwords (6 digit pins are not). Otherwise you’re relying on some sort of anti-hammering/auto erase to make up for it.
There was an attack years ago, where you could kill power to the device after failing the attempt but before it incremented the attempt counter, but they fixed that, and that may have predated the Secure Enclave anyway (and required taking apart the phone, which I assume this on-premises device doesn’t do).
That's one way to look at it. Another is that they provide law enforcement the ability to catch and trial criminals (for instance sex offenders) who are using the phone manufacturer's naivete to hide their nefarious deeds.
It depends on your point of view.
The sex offender spectre doesn't change that.
It's like saying that because hidden recording devices can be abused it should be illegal (or at least one should be ashamed of) to create it.
> Under the European Convention on Human Rights, the right to privacy is, in effect, contained in Article 8, the right to respect for family and private life. It is important to know that it is also a “qualified” right. That means it is not absolute, and can be interfered with in certain limited situations, for example to protect national security or freedom of expression. However, any interference has to be necessary and proportionate.
https://rightsinfo.org/the-right-to-privacy-and-why-it-matte...
They are no worse than locksmiths advertising the ability to crack safes.
It's more like a locksmith advertising the ability to break anyone's safe that contains details on every place you've ever been, purchase you've ever made, and person you've ever communicated with. Phones are far more ubiquitous and contain far more information than any family safe. Not a fair comparison.
#3 is the real treasure trove.
Is it acceptable for this company to sell it to Saudi Arabian police where it's a crime for a woman to run away from home?
https://www.businessinsider.com/saudi-arabia-imei-track-runa...
Or how about Australia raiding journalists for whistleblowing on abuses conducted by their arm forces in war: https://www.bbc.com/news/world-australia-48522729
Perhaps you agree or perhaps you don't. But the issue is more complex than saying that "everyone should help the police"
Yes, a lot of the effect is harmful, including in helping police do harm. But an argument that no-one should help the police is basically an argument the police shouldn't exist.
I'd argue that nobody should help the police as they exist in many modern implementations, because the police as they exist now are often bad actors. But it's not hard to imagine a police force that's held to a higher standard such that they actually are trustworthy. The argument doesn't have to be "police shouldn't exist"--it could be "police should be better".
My previous post was responding to your claim "But an argument that no-one should help the police is basically an argument the police shouldn't exist", which is incorrect. The two are very different arguments.
I take "not helping" to mean not just not developing specialized products that only police can legally use, but also not calling the police in case of crime, not helping them with investigations as witnesses. Where the law permits, not selling them generic products and services (eg food). And where personal circumstances permit, not working for a company that does business with them, deplatforming them, etc.
Many reasonable people do indeed take the position that the recent development of a paramilitary force, professionally tasked with keeping domestic peace, has been a bad way to achieve law and order.
So sure, I'll make an argument that today's police - and the private companies who enable them to perform end-arounds on quintessential rights - are contrary to the western common-law tradition and that society will be better when we end this short experiment and move on to a different approach.
No, as I said, it's the flaunting it that surprises me.
Flaunting this is great advertising for them - and most importantly free advertising for them. Not saying it’s right, but this is how they get customers when direct word of mouth is too slow.
Why shouldn't they be able to access their data?
Probably.
I've met a lot of people who argue against the right to privacy. Most of those people are in positions where they profit from trampling people's privacy in some way: social media integrations, profiting from advertising, law enforcement/spying, or simply deprioritizing security. Lots of those folks are on Hacker News.
One horribly annoying decision of Android is that the encryption passphrase cannot be different from the unlock pin, leaving users with two choices:
- Have a long, secure password that actually makes Android's encryption worth a damn. They then have to enter this password every time they want to unlock their phone. I don't think many people go for this option.
- Have a short usable password so you can painlessly unlock your phone. However, then encryption only provides a marginal benefit
(- I decided to use a long password with fingerprint unlock as a compromise, which creates its own security problems.)
It seems that they ignore that a powered off devices could easily provide much stronger protection by allowing a separate encryption password. And if the device is powered on, limiting unlock attempts might be somewhat useful to frustrate attacks against short lock screen passwords.
I think this only works for an attacker model that excludes reasonably sophisticated attackers. I expect this to thwart pickpockets or muggers, but not the police or anyone more sophisticated than that.
If you ask around I'm sure most people think LE should be able to do this for security reasons. Not saying I agree or disagree but that's the way it is.
For many, I bet the answer is yes. Plus I bet they sleep at night justifying their actions as helping to hunt down criminals and terrorists, (which I think some of them may be thinking of as having a close experience with).
Of course these are all post-hoc justifications for the primary motivator, money.
I'm sure a technical deep dive on these vulnerabilities would be an exciting read.
We talk about how we want to abolish the CFAA so we can't (morally) turn around and use it when it suits us.
EULA is not the law. Terms of service is not the law. It is absurd to say that Apple should have the legal authority to (in a practical sense) legislate. Yes, theoretically speaking we don't need an iPhone to stay alive but still. You could have argued we didn't need Carnegie steel to stay alive either.