3 ms·
Not really, no, because it turns out cops aren't actually stupid. When they arrest you and take your phone (or anything electronic, really) the first thing the
by tsotha 11y ago
Not really, no, because it turns out cops aren't actually stupid. When they arrest you and take your phone (or anything electronic, really) the first thing they do is clone the memory. You might succeed in wiping out a copy by giving them the alternate password, but that's just going to add to your charge list.
There was a case a few years back (discussed on HN) where a gang had software installed on everyone's phone that caused a remote wipe when activated. The cops did a big raid, and even though they took everyone's phone someone they hadn't caught yet was able to wipe them.
The cops changed their SOP so that when they get ahold of your phone the first thing they do is yank the battery.
- nadams 11y ago> When they arrest you and take your phone (or anything electronic, really) the first thing they do is clone the memory Depends on the situation. If it's a raid due to software piracy - then probably. If they pulled you over for speeding and arresting you - they probably won't or even know what to look for. And I really can't think of a way to clone a device like an Android device without unlocking it. ADB now a days requires your explicit permission from a prompt. And if you are like "oh they have ways" I would be very interested in that because that sounds like whatever they are doing are using an exploit or some sort of back door.
- tsotha 11y ago>And I really can't think of a way to clone a device like an Android device without unlocking it. ADB now a days requires your explicit permission from a prompt. And if you are like "oh they have ways" I would be very interested in that because that sounds like whatever they are doing are using an exploit or some sort of back door. No, they don't need to use any kind of exploit. They have hardware that allows them to clone the the device's memory. I doubt it has to be on at all. There's no way to secure a device if the attacker has physical access. The best you can do is secure the data with encryption.
- cvwright 11y agoBehold the Samsung Anyway Jig: http://forum.xda-developers.com/showthread.php?t=1629359 http://forum.xda-developers.com/showthread.php?t=1629359 The link is a few years old. No idea if there is a current version that works on modern phones, but it seems reasonable to assume there would be.
- nadams 11y agoI found this article [1] and I'm already suspect of FUD. The first part talks about bluetooth pairing with the device - which requires unlocking. The second page talks about unlocking an iPhone with plist files from a synced computer. So it's not a matter of some magical device that can backdoor a phone - but rather using interfaces that already exist. I found this company [2] and it has the usual marketing ploy - but a quick google search doesn't reveal any actual reviews of people using it. I can paragraphs of marketing spin but no one actually saying "we used this to get into cell phones that were password protected". I'm not saying it's not possible - I just find it hard to believe without it making modifications to the underlying software (ie flashing a ZIP on android that zeros out the pin password or something). [1] http://arstechnica.com/tech-policy/2011/04/michigan-state-police-we-only-grab-your-cellphone-data-with-a-warrant/ http://arstechnica.com/tech-policy/2011/04/michigan-state-po... [2] http://www.cellebrite.com/Mobile-Forensics/Products/ufed-touch http://www.cellebrite.com/Mobile-Forensics/Products/ufed-tou...
- MichaelGG 11y agoHow do you yank the battery and clone memory on an iPhone?
- tsotha 11y agoWhat I meant is they yank the battery as soon as they get the phone. I believe you can clone the memory without powering the device if you have the right hardware. If not they could always disconnect the antenna before powering up.
- funwithjustin 11y agoThe question stands. How do you quickly yank a battery from an iPhone?
- tsotha 11y agoI'm pretty sure there's a lead you can cut.
- funwithjustin 11y agoI'm pretty sure you just made that up.
- tsotha 11y agoI'm a little confused here. Are you trying to say there's no way you can disconnect the battery of an iPhone even if you don't care whether or not it works when you're done? Really? I begin to doubt your fitness for this conversation.
- Crito 11y agoIn fact, I wager that you could find a spot on any phone model that you could hit with a narrow drillbit to disconnect the power. You could make a jig that you put the phone into and guides the drillbit into just the right spot. It would only take seconds to use, but you would need to be prepared for the specific phone model. Maybe you could even have a CNC machine preloaded with the data for a wide variety of phone models. You put the phone down on the work surface, key in the model, and the CNC machine deftly cuts through the right power lead. Less portable, but would require less precise planning.
- nickodell 11y agoWhen you say 'memory,' are you talking about volatile or nonvolatile memory?
- tsotha 11y agoNonvolatile, of course.
- nickodell 11y agoI was under the impression that you couldn't run a bruteforcer against these phones because the key is kept inside of a hardware security module. Couldn't the duress code just wipe the key in the HSM? If they can copy the HSM, that wouldn't help, but in that case, it doesn't really seem like they need your help getting the PIN in the first place.
- tsotha 11y ago>I was under the impression that you couldn't run a bruteforcer against these phones because the key is kept inside of a hardware security module. Couldn't the duress code just wipe the key in the HSM? That's something I hadn't considered. Is it set up that you can create and destroy the keys but never get access to them?