FBI unlocked iPhone 11 Pro via GrayKey, raising more doubts about Pensacola case
ww.9to5mac.com
ww.9to5mac.com
https://www.forbes.com/sites/thomasbrewster/2020/01/15/the-f...
(to be clear: if Forbes handled their ads on their own or used ad networks that invest in the security of their platform, I'd actually probably bite the bullet, but if I visit the site on mobile and end up being redirected to another "your phone is infected!" ad exploiting their current provider... I'll keep steering clear without ublock enabled.)
Image copy of the article for the interested.
So basically bad actors are hijacking the ad network that Forbes is using because it's a poorly secured ad network.
I didn't realize that was what was going on but that explains a great deal.
Six ones, or up and down the middle column, that sort of thing.
[0]: https://techpinions.com/apples-penchant-for-consumer-securit...
And the "long been used" is IMHO a tad bit exaggerated, it came out in the first months of 2018, and - set aside the FBI and whatever other US three or four letter government agencies, it is not likely that US$ 15,000 or US$ 30,000 is something that any police department has in a drawer and can spend instantly, more probably it has taken at least a few months for everyone to get the expense authorized:
https://www.forbes.com/sites/thomasbrewster/2018/03/05/apple...
No idea on volumes of sale or how many departments got one, in either the "online" or "offline" version, but by now - if it was "widely" used - I presume we would have a lot of evidence based on unlocked iPhones in trials.
I don't know, I simply have no idea of the number of device units of the Gray thingy sold, and how much they could have been used, and as well I have no idea on how many crimes involve the access to a (password protected) iPhone, but unless (yet another piece of data I have no idea about) all suspects either use an Android (or however non-iPhone) or give to the police access to the device without need to "crack" the access code, they should be non-trivial amounts.
I mean, I understand that it is a fraction (going to trial) of a fraction (criminal cases involving a phone) of a fraction (suspects not providing access to the device) of a fraction (suspects using specifically an iPhone), still the ubiquity of iPhones and the large number of criminal cases should anyway result in tens or hundreds, while we have AFAICT none or maybe a few actually documented/published about.
The declining of local reporting may be indeed another factor, but there would certainly be lawyers making a fuss (right or wrong) about this or that right violated through the use of this or similar tool.
The contract with ICE:
https://www.forbes.com/sites/thomasbrewster/2019/05/08/immig...
is likely to produce no public court records, just like many national agencies, still the sheer fact that not a single actual court record of its use can be found (at least by me) could mean that the device is not used that much by local police, a few cases should have been brought to the attention of the public.
I wish that were true. Police in any small town in America could start at lunchtime and have that amount by nightfall. Let me introduce you to "civil asset forfeiture" ( https://www.heritage.org/research/reports/2014/03/civil-asse... )
There are state and federal version of this, and a "sharing" program to share the loot. It's pure corruption in blatant violation of the US Constitution, but it's good for government/police business (e.g. buys a lot of helicopters, tactical/swat equipment, training, etc.) so it persists.
"The idea that the State originated to serve any kind of social purpose is completely unhistorical. It originated in conquest and confiscation - that is to say, in crime. It originated for the purpose of maintaining the division of society into an owning-and-exploiting class and a propertyless dependent class - that is, for a criminal purpose." -- Albert J. Nock
If they do, why would they reveal it for something as 'basic' as a single attacker? Or they may have broken it, and simply 'reverse engineered' the path to evidence with public means:
* https://en.wikipedia.org/wiki/Parallel_construction
Agencies don't want to reveal means and methods if they don't have to.
So you would need to break open the co-processor without destroying its contents and read the secure enclave key before any brute forcing could happen directly on the encrypted data.
And no you can't just try to brute force it by sending decryption requests to the secure enclave. The secure enclave itself implements a exponentially increasing lockout time and won't respond to decryption requests during it. [0]
[0] https://www.apple.com/in/business-docs/iOS_Security_Guide.pd...
> To further discourage brute-force passcode attacks, there are escalating time delays after the entry of an invalid passcode at the Lock screen. ...On devices with Secure Enclave, the delays are enforced by the Secure Enclave coprocessor. If the device is restarted during a timed delay, the delay is still enforced, with the timer starting over for the current period.
https://www.apple.com/in/business-docs/iOS_Security_Guide.pd...
Does this mean. There's a new unpatched exploit out there that greykey is using?
[1] https://blog.elcomsoft.com/2019/09/usb-restricted-mode-in-io...
Let’s not sing the requiem for their security team just yet.
I wouldn't blame them for any lack of success. Perhaps instead blame them for suggesting to the user physical security is possible at all.
If you assume the device is off and the user chose a strong password, it's pretty easy to defend. You simply encrypt the data with a key which is encrypted with the user's password.
If you want to protect devices that are on, or want to protect devices with less than stellar passwords, then it becomes harder.
I suppose if you assume the user never puts data on the device, it also becomes easier.
It is often more secure to generate a random, high-entropy key and storing it in secure storage, which is what the iPhone does.
There are 2 ways to slow down the attacks: key stretching and secure storage. Key stretching is a good idea.
I recommend not relying fully on secure storage, because I've heard of tons of hardware vulnerabilities (side channel attacks, undervoltage, electron microscopes, buggy implementation). I trust math more than a physical object. In fact it seems impossible to me to build fully secure storage, because if someone has a delicate enough measurement tool to measure the atoms inside the storage, the data inside can be extracted. If you store the password (or hashed password) as well as the key in the secure storage, and have it only return the key if the input password is correct, you run the risk of someone finding a bug in the storage to extract the key without the password. Then you're compromised.
But you build a system so that the secure storage is no worse than regular crypto. You do the encryption using a combination of the user's password and the output of the secure storage. That way even if the secure storage is fully compromised, the password is still needed.
To be usable, phones need to allow relatively weak passwords.
12 characters gives 62 bits of entropy. That's plenty if proper key strengthening is in place.
Linus Sebastian says that when his phone got slower to open up, he got happier, because it caused him to use his phone less, cutting out the useless stuff. https://youtu.be/WGZh-xP-q7A?t=305
When was the last time a regular person turned their phone off? Not counting reboots or out of battery incidents I'm going to guess not since it was purchased.
Apple has chosen to run a ton of code inside the secure enclave, and bugs from that are on them.
This is potentially a quite difficult problem IMO
But if that does happen then the system of timeouts will prevent you from using up all the attempts.
None of that gets in the way of resetting the counter only when the user succeeds.
The only way would be to physically decap the chip which would most probably destroy it.
Yep, and if it gets hacked, then all you need to do is change your fingerprints.
Until the next round of FBI tools, where they extract the fingerprints to their database as part of their unlocking process.
If you do a little bit of reading about the topic, too, note how well-designed biometric systems require more than a simple fingerprint or photograph — e.g. Apple's FaceID has liveness checks for eye motion and uses a 3D scan. None of these are impossible for a well-resourced attacker but that's true of the alternatives as well. This is why you need to think in terms of threat models — e.g. the attacker who can get a high-resolution 3d scan of your face can also watch you type your passcode in so the latter isn't more secure in practice.
If an attacker watched you type in your passcode, what would you do about it?
This is covered in the Apple Platform Security Guide.
https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app... (I believe this link can change when the guide gets updated)
The hard part is trying to defend a physical device in the hands of an attacker while using a simple 6-digit passcode.
>GrayKey is not for everyone. We kindly request that you tell us a bit about yourself and your organization.
This feels like its begging for DMCA litigation, but its likely Apple already knows how and why GrayKey works. Keeping GrayKey around serves apple as law enforcement has (for now) an easy means of hacking some iphones at an entry cost, while permitting Apple to continue insisting their phones are just too secure to help hack.
How? If the FBI can get into someone's iPhone with their magic box and you can read about it in the news, how can Apple convince people that the iPhone is "too secure"?
It can't do anything for FaceID, TouchID or alphanumeric passcodes.
Apparently GrayKey can't crack long passwords, since it's essentially brute-forcing, but almost everyone I know uses a four-digit code.
Also, this is troublesome because in the US, we're told that cops can force you to hand over your fingerprint but not your passcode. It's a bit problematic if those passcodes are easy to crack.
Even 4 digits could be enough, given that iOS enforces (very long) delays after a few failed attempts.
This is, apparently, the thing that GrayKey is able to bypass.
It's not settled law that you can't be compelled to provide a passcode. In general, the 5th Amendment prohibits compelled testimony that is incriminating. Disclosing a password to your own phone is usually not per se incriminating. Contrast that with disclosing a password to a device you're accused of hacking, where showing knowledge of the password is evidence of guilt. Many (most?) courts haven't yet been prepared to defend such a fine distinction, and seem to be more comfortable with a simpler rule that prohibits compelling password disclosure, period. But that could easily change, especially at the Supreme Court.
I anal but isn’t this basically slavery/forced indenture? Could a court of law compel Apple to write some software? If so, can a court of law require George RR Martin to write a novel and send him to prison if he declines?
Conceptually I agree with you, the law is not as clear.
I'd imagine neither of your examples could or would happen given the power Apple and Martin's representatives have, and how absurd forcing someone to write a book as part of a court decision would be, but I'm fairly sure you could find examples of relatively similar things. I could certainly see something like a contract-related case being resolved by essentially legally compelling someone to write a book that they said they'd write, or else be fined/imprisoned.
Again, I anal so I don't know the law but contracts sound like a strictly civilian (not government vs not government) court case where there should be no possibility of imprisonment. If there is it sounds like a bug to me and we ought to amend the laws so that it is not possible.
The whole notion of Miranda rights is still highly contentious, especially among conservative jurists, and that's why an increasingly conservative Supreme Court has narrowed and carved out exception to Miranda rights. Because of the conservative exceptions, you should never just remain silent. You should politely ask for an attorney whenever a question is asked, but even then you might still get dinged for refusing to answer some types of questions. For example, if you're not yet in custody, or for simple questions like your name. It's complicated, which is precisely what the original Miranda rights were intended to safeguard against.
The irony is the right against self-incrimination, and many other rights copied from English law and enshrined in the constitution, were originally judge-made rules. By creating Miranda rights the "liberal" Supreme Court was following in the footsteps of traditional Anglo-American legal practice, and exercising their inherent powers. Courts have inherent, constitutionally protected authority to control what is and is not allowed to be presented in court. (Though it overlaps with legislative powers to control court procedures.) Almost all the rules for doing so were crafted by the English courts over nearly a millennium. It's not at all out of sorts for the highest court in the land to craft a new rule instructing lower courts that testimony is presumptively compelled if given before a Miranda warning and to reject it at trial.
To be fair, the conservative counter argument is that in England the highest court in the land was the House of Lords, which was also a House of Parliament, which was and remains the seat of legislative power. Procedural protections didn't always arise in the House of Lords, but the closer you get to 1776 the fewer instances there were of lower courts making such procedural rules. So similar to the Second Amendment, you can pick and choose a window of time that best support a claim to historical precedent.
That's why my passcode is always "I murdered her, officer".
https://appleinsider.com/articles/18/04/16/researcher-estima...
4 digit = less than 15 minutes 6 digit = less than 24 hours 8 digit = less than 92 days
Besides those estimates, other sources talk of 4 digit = a couple of hours 6 digit = some three days
https://blog.malwarebytes.com/security-world/2018/03/graykey...
even if those could be "lucky" events.
The "clever" bit, according to reports is that the procedure "frees the device", i.e.:
1) you connect the iPhone to the Graykey
2) Graykey does something in a few minutes
3) you disconnect the iPhone and it is the phone itself that in due time unlocks itself
Which plainly means that several devices can be processed per hour (and then kept on a shelf, connected to a power supply as long as it is needed).
It’s probably using some kind of exploit to upload a custom ramdisk (similar to jailbreaks). Except, unlike jailbreaks, it doesn’t jailbreak the device, but instead tests the passwords.
What’s also interesting is that the Secure Enclave (which holds the encryption key) is supposed to enforce the 10 password limit, so they’re doing something really clever here.
It's much more likely that a marketing-driven product development culture would lie to its customers than it is that Grayshift engineers have compromised the SEP itself. Researchers have been "compromising" HSMs by standing on its external signaling implementation rather than the chip itself for decades, now.
That's just a guess though, it could be far more complex than that
in other words: the encryption/wipe code may be a function of the password screen, but the phone may accept a hashed key as a valid unlock attempt through a different interface that does not contribute to the failed attempts limit.
The most obvious possibility is that Apple can one day succeed and iPhone will be uncrackable by these tools.
Can it be that Greykey is just a relabeled Chinese unlock box made to crack the lock screen?
doesn't mean Apple has to accommodate
Lots of things are illegal without a warrant or without some other legal requirement.
The FBI breaking encryption in a legal investigation is not illegal.
isn't it the other way around?
I can probably think of hundreds of places you can still do it and it's not illegal. Some examples: in school classes to learn, at home for practice, researchers attacking each others new algorithms, estate clearance to get dead person assets released, for interoperability in may cases, for archiving old things in many cases, and on and on.
In fact, almost any place I can think of where I might break encryption (which I have done both as a hobby and professionally and as while a PhD student) is perfectly legal. It becomes illegal when used to do something else illegal, like violating copyright, or stealing things.
So no, breaking encryption is not illegal as a whole.
Here, break this: Lbh qvqa'g oernx gur ynj.
Right that was what I meant, that the specific "list" I could think of is actually of exemptions. Irrelevant nitpick really, sorry.
Just because the FBI pay $$$$ per unlock, doesn't mean the marginal cost to the supplier is $$$$, that could just be GrayKey trying to cover the $$$$$$$ they paid for an exploit, and make some profit.
With an iPhone, any storage you can access with physical access is going to be encrypted. The encryption key lives in the secure enclave, which you do not have access to even with physical access, barring drastic measure like trying to take chips apart and scanning their contents, which may or may not be feasible at all.
What still may be possible is bugs and exploits, but that's up to whether you are lucky enough to have one that works against a particular phone and firmware.
If I wanted to hide an important piece of information, I guess I'd find a physically obscure and secured playce, like a hidden safe or whatnot. But I wouldn't trust crypto, no matter if the key were placed in a "secure enclave" (haha), or not.
Every phone ever sold can have its internal data read, it's not a case of if but when. This also applies to every HDD, SDD and any encryption software you may be using, it will be cracked eventually.
So, not realistically viable in 99.99% of attack scenarios.
The idea of a Secure Enclave has existed for years in the form of Chip-and-PIN bank cards. Before that HSMs are built on the same principle (a bank card I just a tiny HSM).
Of this works on the principle that it’s very hard to reverse engineer silicon, and that you can make it harder by creating silicon designs that deliberately obfuscate their purpose.
End result is a piece of hardware that very difficult to take apart with irreversible damaging it, and destroying the data in the process. The attack itself would also require an extremely high level of skill.
Ultimately no security is perfect, it’s not meant to be. Security is just meant to skew the effort-reward equation enough that no one can be bothered to break into your thing.
Citation needed.
> If I wanted to hide an important piece of information, I guess I'd find a physically obscure and secured playce [sic], like a hidden safe or whatnot.
That's just basic threat assessment. Obviously if you have a chunk of data that's really sensitive, it would be best to "air gap" it from the internet.
> But I wouldn't trust crypto, no matter if the key were placed in a "secure enclave" (haha), or not.
Please review Apple's "Apple Platform Security" document before continuing to comment. [1]
[1] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...
Right now they are using USB to gain access to the device. There is nothing stopping an attacker from actually prying open the device and fitting alternative components that can bypass security. Consoles are cited as an example of an unhackable device, which is not true. Consoles were designed to be unhackable by cheap mass-market methods but a determined hacker can still do it, just that he will have to spend more to do it than the cost of a new console. The hacker in this scenario is FBI with a lot of money and resources with the physical device in their custody. I doubt if FBI is going to lose the ability to hack devices anytime soon.