From the Apple Platform Security document:
> After the TrueDepth camera confirms the presence of an attentive face, it projects and reads thousands of infrared dots to form a depth map of the face along with a 2D infrared image. This data is used to create a sequence of 2D images and depth maps which are digitally signed and sent to the Secure Enclave. To counter both digital and physical spoofs, the TrueDepth camera randomises the sequence of 2D images and depth map captures and projects a device-specific random pattern. A portion of the Secure Neural Engine — protected within the Secure Enclave — transforms this data into a mathematical representation and compares that representation with the enrolled facial data. This enrolled facial data is itself a mathematical representation of the user’s face captured across a variety of poses.
https://support.apple.com/en-gb/guide/security/sec067eb0c9e/...
My point is, I personally can't be sure there is no mechanism, legal or illegal, via which the NSA can just compel them to hand over the keys. Who knows, maybe there exists a FOOBAR law that compells them to build backdoors into their products. Maybe they're doing it voluntarily outside of the law. I would assume everything can be trivially hacked nowadays, and a large portion of intelligence analysts spend their time on parallel construction (i.e. creating alternative stories about how they gatheried their evidence, without giving away their abilities).
I'm not saying that Apple does this. I simply don't know.
Are you sure? Last I heard the NSA is in the intelligence gathering business... I absolutely would not put it past them that they acquired those keys somehow.
Even if they do not have the keys, bribing an employee and/or installing your own NSA person as an employee in an Apple-authorized repair shop seems like a rather easy thing to do. Or just backdoor the computer that is used to communicate with apple to perform the re-signing stuff. There are thousands of authorized repair shops around the world and you only need to compromise one (or compromise a few so that any "abnormal patterns of repairs" cannot be easily detected by Apple, if it even audits repair logs for suspicious activity at all).
I am sure the NSA has something figured out by now. And not just them.
Are you sure there isn't a teapot in orbit around Mars?
The NSA can't magically break into people's HSMs and steal the keys. We have a pretty good idea of what the NSA's capabilities are. If Apple's system is correctly designed, it will only allow components with certificates installed at manufacturing time to be paired together, and the pairing server will use a HSM to hold the private key to do so.
Can the NSA still backdoor your phone? Sure, that's possible by physical definition. They could extract a specific camera unit's private key via FIB analysis, then manufacture a backdoored replacement, insert that key into it, then bribe or otherwise backdoor themselves into some Apple authorized repair shop and run through a re-pairing with it when they swap it into your phone. But that's a lot harder and less likely to happen (i.e. only in extremely high-value cases, if at all) than the silly "oh it's the NSA, they definitely have the keys" nonsense that people throw around here without any supporting evidence.
On the other hand, the NSA certainly has a motive to obtain Apple's keys. And while I doubt we really have a good idea of what the NSA's capabilities are, the capabilities we do know about are sufficient.
The Snowden leaks gave us a very good idea about what the NSA does. Tap fibre. Backdoor products in transit. Develop and use remote exploits (nothing particularly amazing about them, it's on the same level of RE/exploitation/polishing work as what I've done for game console homebrew in the past). That one time they actually did something novel with modern crypto and figured out how to efficiently break 1024-bit DH for fixed parameter sets. These are all practical, reasonable things that are a far cry from the magical abilities people like to ascribe to them.
The NSA could waltz into the plant manufacturing the HSM. Or they could waltz into Apple and make sure Apple uses the right HSM with keys already known to the NSA, e.g. by replacing the shipment of the HSMs Apple ordered. (This would require the NSA knowing in advance when Apple buys HSMs for what purpose and from what vendor, but again, intelligence gathering business).
>These systems are designed to be robust even against physical access attacks.
They are designed by humans trying to make those things "robust" against attacks. "Robust" is a "best effort" word.
Assuming that the thing that got shipped to you actually is the thing you think and not just some nice NSA chip with the name of a popular HSM vendor printed on top. You cannot really open up the chip and look inside as, if this is a properly designed HSM, this it is supposed to be destro if you tamper with the enclosure or any other vital parts of it.
I'd be surprised if the NSA does not spend resources on research into breaking HSMs, and if it do esnot spend resources on designing "fakes". The level of their success is unknown until the next Snowden shows up. But if they did break some HSMs, they wouldn't be alone [0].
So, there is a chance the NSA can waltz into Apple and break into their HSM and steal their keys.
This assumes Apple uses HSMs for this kind of stuff and uses them correctly.
Since authorized third-party repair shops can replace components and repair the hardware with some help from Apple, as I said before, it's not even necessary to compromise Apple or their HSMs, it's sufficient to compromise those repair shops, whether third party of have a few NSA Geniuses around.
But either swapping out HSMs pre-installation or breaking ones with design flaws is certainly in the realm of possibility too.
>The Snowden leaks gave us a very good idea about what the NSA does.
No, Snowden showed what they did in 2013 and before, because that's when he went public.
Snowden does not know what they did 2014, let alone what they are doing now in 2021. That's about 8 years of most recent NSA R&D that we do not know about.
>Backdoor products in transit.
HSM is a "product", last I heard ;)
>These are all practical, reasonable things that are a far cry from the magical abilities people like to ascribe to them.
Magical? Nothing magical in what I said I believe the NSA could reasonably achieve.
We're talking about abusing design flaws in HSMs and/or supply chain attacks not creating "a GUI interface using VisualBasic to track the killers IP address".
I don't think the parent was advocating for anything related to the NSA, just reminding us of the current state.
The rule of law is significantly weaker and they have already shown that they will go after even mild dissidents e.g. journalists not just mass-terrorists or other more serious threats.
So sure US may have the keys. But unlikely every country does.
This is more petty Apple bullshit.
> After the TrueDepth camera confirms the presence of an attentive face, it projects and reads thousands of infrared dots to form a depth map of the face along with a 2D infrared image. This data is used to create a sequence of 2D images and depth maps which are digitally signed and sent to the Secure Enclave. To counter both digital and physical spoofs, the TrueDepth camera randomises the sequence of 2D images and depth map captures and projects a device-specific random pattern. A portion of the Secure Neural Engine — protected within the Secure Enclave — transforms this data into a mathematical representation and compares that representation with the enrolled facial data. This enrolled facial data is itself a mathematical representation of the user’s face captured across a variety of poses.
https://support.apple.com/en-gb/guide/security/sec067eb0c9e/...
I know a lot of the other phone manufacturers do stuff like this and think it's ok, but Apple knows what it's doing.