Trump shooter used Android phone from Samsung; cracked by Cellebrite in 40 min
9to5mac.com
9to5mac.com
https://x.com/SEJeff/status/1813079033430876433
As much as it makes folks reel, this is working as intended. If you don't want them to crack your phones, consider setting a 10+ digit alphanumeric passcode instead of a numeric PIN.
Also, do not enable the biometrics such as FaceID. I'm very much of this opinion[1] that biometrics are usernames, not passwords.
[1] https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...
The first thing the police will do is connect it to power battery packs
https://www.unimelb.edu.au/newsroom/news/2019/august/myki-pr...
I'm just thinking of all the other weak security systems like garage door keypads where the code is derived from the more worn buttons. Or cleaning/dusting an ATM keypad before someone enters their code and then carefully examining the buttons afterwards.
But who knows — perhaps people have completely munged up their displays making fingerprinting useless.
Update: ChatGPT says 12 tries total to get it right, so that makes it ~10% success ratio?
I'd really like to see the ability to set a specific fingerprint to lock down the phone, requiring a different, more secure credential from the regular lockscreen to unlock. A long passphrase would probably be the right credential for most people.
After all, it would be annoying if FaceID failed just because I haven’t shaved today. So the algorithm has to account for that. As such, the entropy of the input is reduced.
Can't emphasize this enough. If you're going to use a phone, set a long strong password. Nothing else will do. Yes, it's a bit more inconvenient. There is no workaround.
https://www.livescience.com/62393-dead-fingerprint-unlock-ph...
At that point, it's probably easier to just clone the fingerprint and drape it over a purpose built prosthetic.
Looks pretty easy to me
I'm not surprised, there was a recent report that showed that Cellebrite can unlock any phone except for recent iOS and GrapheneOS. I'm just confused who "the people" that are being quoted everywhere are supposed to be.
The better publications will have policies on when anonymous sources can be used and may have those policies or an explainer of same available to readers. Eg here's Wapo's write-up on it: https://www.washingtonpost.com/policies-and-standards/#sourc...
They have a few charts listed. There’s still the several other companies with support documents that haven’t leaked.
I'm guessing this was a brute force attack or side channel attack of some kind, in concert with a packaged zero-day.
1. Set a sufficiently strong alphanumeric password for your lock screen.
2. Remember to reboot your phone weekly to reset any non-root malware.
3. Disable multimedia in the SMS messaging app as it's a vector for Pegasus style malware.
4. If using Signal, go to Settings, Privacy, Phone number, and set everything to Nobody. This again blocks messages from unknown users that could be a vector for Pegasus style malware.
I wish there was a system-wide permission to audit and/or disable screenshots, but there isn't.
But we don't know what version of Android his phone had, or what "newer Samsung model" means.
There's nothing surprising about state actors being able to quickly unlock the phone of a [failed] presidential assassin.
If they can crack his phone they can crack your phone.
But that's an unreasonable expectation because software is universally such garbage. Some is just less garbage than others.
State actors have the resources to find the holes in anything that isn't utterly perfect.
And not just them, anyone with access (legal or otherwise) to these tools can.
The only strategy that might work is to make it expensive or unviable to crack every single device. But in the case of something like this, an assassination attempt, then it’s a given that all stops are going to be pulled to crack it.
Those generic statements are great and all until you realise that every year, dozens (hundreds, thousands???) people disappear without a hint of a trace and the government is powerless to do anything about it and can't find them.
Or when a large, wealthy company commits crimes (or just government officials sometimes), all they have to say is "we lost the data" and suddenly, there is nothing that can be done about it, it's lost to the ether for ever without any possibility to find out anything about it.
In those cases that people get way with crimes, it is much more likely that there is no political motivation to go after them for whatever reason du jour. I don't think it's because the technology is so strong that they can't.
Saddam/Osama
Can't even get emails on my phone. I can however post comments on hacker news. FBI can have this comment for its data.