FileVault 2’s Apple ID Backdoor
mjtsai.com
mjtsai.com
What happens when a user tries to log in without Apple ID is the mac sends a request to Apple: "Is this password valid for this apple id?". If Apple replies positively, the login request is accepted and the user is allowed access to the system.
See how this doesn't work for Filevault? Since Filevault encrypts the encryption key with the users' password, and the password itself isn't known to Apple, this checkbox can't be used to decrypt the drive.
The main vulnerability here is that it can allow access to a Filevault-enabled system that still has the decryption key in memory -- as is the case by default for any mac that goes to sleep. Either the checkbox shouldn't disappear if you enable filevault, or they should make the decision to disable AppleID-based authentication when Filevault is enabled (which is probably what they tried to do).
If you want your system to really be secure, you need to disable the RAM-based sleep, so that the RAM contents are written to your Filevaulted disk before shutting down completely.
1) A malicious party with access to your Apple ID and password can access your FileVault2-encrypted computer when it has been put to sleep. It is not vulnerable if it has been turned off.
2) Mountain Lion automatically enables this feature and hides the option if you're using FileVault2, providing no way to disable it, when you upgrade.
Therefore, to be secure from Apple ID insecurity when using FileVault2, you must take one of the following actions:
1) Turn off your computer rather than putting it to sleep.
2) Decrypt FileVault (which makes the preference appear), deselect the checkbox, and re-encrypt.
tl;dr: Apple force-enabled user password recovery using Apple ID in Mountain Lion, meaning they can apparently also change your FileVault 2 passphrase and decrypt your disk.
I'm not convinced though. Has he tried this?
Normally the user has the same password as the passphrase used to decrypt the FileVault 2 volume. If Apple resets my password, does my passphrase get reset too? Sure? How does that work?
So, (again, I'm speculating), your AppleID and FileVault 2 passwords are completely independent things -- it's just that your additional recovery/backdoor key is stored in the iCloud, accessible with AppleID.
Here's the analysis of FileVault 2 http://eprint.iacr.org/2012/374.pdf
1. Apple nabs a copy of my FileVault 2 recovery key
2. Apple can reset my FileVault 2 passphrase
The article doesn't make it clear, and doesn't seem to test either.
In the linked analysis, the authors "reduced" the security of FileVault 2 to the entropy of 120-bit recovery key.
So we're talking about whether resetting an Apple ID will also reset a FileVault passphrase.
Here is how I understand it:
FileVault 2 uses a generated secret key for encryption ; It uses a table that contains for each account the encrypted key, encrypted in turn with a key derived from each user password. It also generates a "backdoor" key that can recover the encryption key which you can write down or if you want (!) store with Apple. The issue described here is not related to the actual full-disk encryption and the reason why the password reset does not work when cold-booting is not related at all to missing network drivers (as described in the article.) Rather it shows that the encrypted disk can't possibly decrypted by just reseting you Apple ID, because - if you have not agreed - FileVault has _not_ stored the backdoor key on Apple servers and it can't be used to recover the encryption key. Why does recovery work when the machine is sleeping? Well, because in that case the encryption key is stored in memory and _can_ be restored if the OS wishes to give it up. It is well known that full-disk encryption only really protects you if the machine has been fully shut down. A dedicated attacker can usually recover the key by removing the battery and cooling the RAM to keep it from losing data.
I agree that not being able to turn off the option is a bug that should be fixed, but the situation is not as bad as it may sound at first.
TL;DR: FileVault 2 is just as secure as everyone assumed and even Apple can not decrypt your disk if the computer has been shut down. If it is running Apple could always use a backdoor if they wanted and other attackers could always extract data from memory.
If the option is disabled, the encryption is as good as your encryption password, period.
The complaint was that this option is now enabled by default.
Not quite; it's more like "If you've enabled the Reset Password Via Apple-ID feature before turning on FileVault, you cannot disable it since that checkbox is hidden when FileVault is active".
I don't think it'd be possible to get far enough into the boto process to actually use the reset feature without having the FileVault password, though.
> Worryingly, this was enabled by default on my MacBook Air as soon as I upgraded from the copy of Lion it shipped with. I did not enable this feature.
So it looks like you don't have to enable it yourself manually. I can neither confirm nor deny this myself, just going off what the author has said.
In my case, I haven't enabled the "Reset via AppleID" feature, upgraded from Lion to Mountain Lion, and when I get the "Forgot password?" popup on the login screen, the only option to reset my password presented is to use my "master password", no mention of using Apple ID.
I did notice an unrelated bug, though: as can be seen in the screenshots, the upgrade appears to have enabled Guest User login.