FBI Gains Access to Suspected Trump Shooter’s Password Locked Phone
404media.co
404media.co
Anyone know about GrayKey? Curious how it works.
Their website (https://www.magnetforensics.com/products/magnet-graykey/) claims “ Magnet Graykey can provide same-day access to the latest iOS and Android devices – often in under one hour.”
It used to be, years ago, that the limit was a purely software function. For many years this limit has been enforced in firmware/hardware.
The paths between memory, storage, and CPU are now protected by the Secure Enclave hardware which is responsible for enforcing passcode entry attempt limits. These limits can only be configured after a mandatory passcode prompt (or via MDM).
It is certainly possible that certain elements of the U.S. government have developed more advanced exploits beyond what GreyKey could have done, that they aren’t going to publicize.
[1] https://www.fbi.gov/news/press-releases/update-on-the-fbi-in...
A) make a copy of the memory and hard drive (encrypted with a pin).
B) try a few pins until you’re locked out.
C) revert back to the copy you made in step A.
D) Try a few pins until you’re locked out.
E) Then after a day or two after all pins have been automatically tried and it has been unlocked, you’re in.
I bet they have faster and more efficient methods than this via some secret unpatched vulnerabilities or exploits but if they ever run out of them, this tried and true method works too.If you could brute-force memory, you don't need (C), because it would be easier to automate than doing on-device.
Modern "secure enclaves" found in nearly every phone and computer should be impossible to brute-force or leak secrets.
Unless, of course, the phone allowed fingerprint / face-id and the corpse was used. I believe on Android, you still have to use a PIN with every restart. Presumably, Apple is the same. Unsure if time since last unlock is also a factor.
1. Face-id / touch-id was still available to be used
2. Old phone without modern security measures (can brute force offline)
3. Someone else knew the pin/passphrase
...
∞. They bypassed a modern/certified secure enclave
> If you have an iPhone, iPad or Apple Vision Pro with the latest version of iOS, iPadOS or visionOS and two-factor authentication turned on for your Apple ID, you can change the Apple ID password for a child account in your Family Sharing group.
> Tap Settings > Family > your child's account.
> Tap Apple ID & Password.
> Tap Change [Child’s Name] Password.
> Enter your device passcode and follow the onscreen instructions.
Given that, there’s a decent chance the phone’s password is 1234 or some day of the year that’s relevant for the phone owner.
No, it cannot be, which is what I'm saying in my comment.
You cannot clone "secure enclaves." They are hardware mechanisms, not software.
Additionally, things like secure-enclaves have made pin length/commonality being a significant risk factor largely a thing of the past. If you only have ten tries, you will likely miss the correct pin, no matter the statistical likelihood you might find it.
Yes, good luck breaking a 256-bit or similar key. I'll see you and your quantum computer in 2.29*10^32 years
If you're interested in the crypto(graphy) used, Apple has a white paper, among other resources that makes this "too good to be true" anything but.
Glossary entry:
>Unique ID (UID) A 256-bit AES key that’s burned into each processor at manufacture. It can’t be read by firmware or software, and is used only by the T2 chip’s hardware AES engine. To obtain the actual key, an attacker would have to mount a highly sophisticated and expensive physical attack against the processor’s silicon. The UID isn’t related to any other identifier on the device including, but not limited to, the UDID.
Directly contradicts
>Because the UID is unique to each device and is generated wholly within the Secure Enclave rather than in a manufacturing system outside of the device, the UID key isn’t available for access or storage by Apple or any Apple suppliers.
on page 5.
In cases of ambiguity, I always assume the case least favorable to the end consumer, which is the case whereby there is a database somewhere someone is not willing/able to admit to for fear of burning all the muggle goodwill to ground.
Tis much easier to lie and force someone else to prove you wrong as long as you don't show the strength you have without having a plausible alternative explanation; it's one of the oldest techniques in the King's Game. We also know this by another name: parallel construction. That old turkey shows up in DEA training materials; no need to even reach as far as the Intelligence Community/Military Industrial Complex.
[0]https://www.apple.com/mideast/mac/docs/Apple_T2_Security_Chi...
But a "lone kidiot" narrative would be near-useless for meeting a whole lot of burning psychological, political, institutional, and financial needs.
And emotionally-charged belief in counterfactuals is "normal" behavior in modern America.
The FBI made a note that they accessed the phone, posted by NYT etc, https://www.fbi.gov/news/press-releases/update-on-the-fbi-in... , there isn't any other information.