5 ms·
I would like to see some clarification on point #5. The only other option I see for the FBI is to continue manually bruteforcing PINs, the arduousness of such a
by ayyghost 11y ago
I would like to see some clarification on point #5. The only other option I see for the FBI is to continue manually bruteforcing PINs, the arduousness of such a task being why they requested Apple's help in the first place. Is he talking about 0days?
- gpm 11y agoManually bruteforcing PINs is actually not a way to get in here, the phone will wipe the keys that the pin protects after 10 attempts. I'm not sure what method Snowden has in mind for decrypting this device without going through Apple. It seems like it must be a 0day.
- nxzero 11y agoDepending on the device/iOS versions, you're able to bypass the count limits.
- Crito 11y agoThe FBI is asking that Apple provide them the ability to bypass the PIN timeout limits. In modern iphones, those limits are handled by the secure enclave. However on the 5C in question, the limits are done in iOS and can be disabled by flashing a custom version of iOS. That's what the FBI is requesting.
- ap3 11y agoThe phone "may" wipe the keys after 10 failed attempts. That is a configuration option. Can't that be changed by the remote configuration management software?
- jdiez17 11y agoJust one way I can think of would be to dump the contents of ROM chip, bruteforcing the encryption key by checking all possible PINs and comparing the decrypted data against some known plaintext that would be present on all iOS devices. (this would require the FBI to know what key derivation algorithm is used on pre-secure-enclave devices, but that's not outside the realm of possibility).
- abalone 11y agoIt's not that simple. The encryption key is not just the PIN. It's the PIN combined with a very strong unique key that is burned into the hardware, making hat particular brute force attack unfeasible.
- jdiez17 11y agoThat's true for devices with a Secure Enclave, which the iPhone 5C does not have. As far as I know the key derivation is done entirely in software on older iPhones, but even if there was device-specific keying material it would be possible to dump that as well.
- uxp 11y agoThe CPU contains both the UID and GID on all iPhones (old and new). The Secure Enclave, if available, contains it's own UID for it's own key derivation. https://mikeash.com/pyblog/friday-qa-2016-02-19-what-is-the-secure-enclave.html https://mikeash.com/pyblog/friday-qa-2016-02-19-what-is-the-...
- droithomme 11y agoThe machine id of the phone appears to be already known: https://www.eff.org/deeplinks/2016/02/technical-perspective-apple-iphone-case https://www.eff.org/deeplinks/2016/02/technical-perspective-... > From a technical standpoint, it would be possible to craft the cracking software to only run on Farook's phone by checking its hardware ID. The court order was actually quite specific that this is all that is being requested. Note that the court's order presupposes that the hardware ID is already available through some means. The court's order was crafted after a period of inquiry regarding actually technically feasible work. It's not certain how the machine id of a particular phone is known without being able to query it, but the case assumes it is known. The keyphrase is combined with the machine id and a hash is generated and compared against the stored hash to allow access. The stored password hash is stored on the flash drive and is readable since it's ordinary flash memory that can be directly read if one has physical access. So the hash and the machine id are available, and it is likely Apple uses a known and vetted secure hashing algorithm rather than roll their own. From this, one can do a brute force search using external computers to determine what the keyphrase is.
- abalone 11y agoThey can hack the chip hardware itself: https://www.technologyreview.com/s/519201/tamper-proof-chips-with-some-work-might-give-up-their-secrets/ https://www.technologyreview.com/s/519201/tamper-proof-chips... (Thanks to tzs for posting this on another thread.)
- muddi900 11y agoI was just going through Apple's Security White paper and according to it, there's no way to enter the passcode electronically.
- pmh 11y agoNot that this fully addresses point #5, but automated mechanical means to enter the PIN do exist: http://www.blackhat.com/us-13/arsenal.html#Engler http://www.blackhat.com/us-13/arsenal.html#Engler As gpm pointed out in a sibling comment, the issue is that they can't brute force the PIN without wiping the phone.
- muddi900 11y agoMechanical entry would take time as well if it is a alphanumeric code.
- TheSpiceIsLife 11y agoIs there's a way to connect a device to where the digitiser connects to the logic board that would mimic pressing the screen?
- muddi900 11y agoI am guessing the JTAG points are fused. FBI does not need Apple to try that.
- blazespin 11y agoIt's a version of iOS without the trusted execution environment. It can be hacked.