11 ms·
Securing a travel iPhone
- joshavant 10y agoI thought I once read that, since Touch ID relies on fingerprints, a US court order can compel you to provide those, thus forcing you to unlock an iPhone in question. This, as opposed to a passcode-only configuration, which a court order cannot compel you to give (I believe since this would fall in the category of 'forcing you to testify against yourself'). If that is indeed the case, I imagine it would make better sense to leave Touch ID disabled, unlike what this article suggests.
- Esau 10y agoYeah, fuck Touch ID. In my opinion, a computer security feature that works when you are unconscious is not a computer security feature.
- rimantas 10y agoTalk about throwing out the baby with bathwater. Being unconscious ir a very rare use case for iPhone. In other cases having protection provided by Touch ID beats passcode which is to inconvenient so many would skip and left without ANY protection. Touch ID is basically transparent and provides adequate protection for common scenarios.
- Esau 10y agoI would rather have no passcode than use Touch ID.
- johncolanduoni 10y agoInstead of being vulnerable in some specific scenarios, you want to be vulnerable in a lot of common scenarios as well as the original ones?
- Esau 10y agoCorrect. I feel that Touch ID is security snake oil.
- Jtsummers 10y agohttp://blogs.wsj.com/digits/2014/10/31/judge-rules-suspect-can-be-required-to-unlock-phone-with-fingerprint/ http://blogs.wsj.com/digits/2014/10/31/judge-rules-suspect-c... Court decision from 2014. http://www.theatlantic.com/technology/archive/2016/05/iphone-fingerprint-search-warrant/480861/ http://www.theatlantic.com/technology/archive/2016/05/iphone... First known application since then.
- ThatGeoGuy 10y agoKeep in mind this is strictly relevant to US jurisdiction. In Canada, I recall that you can be compelled by a court to give up a password, or be held in contempt. That being said, something like TouchID is irrelevant if the password is going to be forced out of you anyways.
- toomuchtodo 10y agoI would like two passwords. One that unlocks the phone, and one that wipes the entire device immediately.
- ThatGeoGuy 10y agoThis would be useful if you had information that would put you in jail for the rest of your life, and certainly should be something offered for users who need it. However, being put in contempt of the court is not joke, and I can't imagine this would go over well if you tried it when compelled to unlock the phone. Hidden containers similar to what TrueCrypt could do might take you farther in this regard. Self-destructing a hidden container should ideally not expose what you wish to protect and at least provide plausible deniability.
- jxcl 10y agoThis makes sense if you tell them that you know the password and refuse to give it, but what if you claim not to remember the password? Or claim never to have known it? What burden of proof is required then in order to be held in contempt?
- mikeash 10y agoI leave it enabled, then power the phone off before interacting with The Man, like when going through customs. Touch ID is disabled on a fresh boot until you enter your passcode, so that basically turns it off temporarily. This is briefly mentioned in the article. Another thing you could do is set it up with an unusual finger, like the middle-finger of your non-dominant hand. After five failed tries, Touch ID is disabled until you enter your passcode, so you can use the wrong finger five times when they ask you, and disable it that way. Say you're sweating too much or something (a common cause for real Touch ID failures for me). It all depends on just how paranoid you are and what you want to defend against.
- lostlogin 10y agoHaving got sick of damp fingers blocking Touch ID I added my nose as one of the options. No more lockout during dish washing.
- overcast 10y agoThis works? Genius!
- gamegoblin 10y agoI did this so I can unlock my phone with my snowboarding gloves on. I can unlock with the nose and then press the texting app button with my nose to read tests.
- elithrar 10y ago> If that is indeed the case, I imagine it would make better sense to leave Touch ID disabled, unlike what this article suggests. It entirely depends on your threat model. If you are at hacker or tech conferences, TouchID is far better as it can't be shoulder surfed. If your threat model is nation-states, then you would take a different approach. As TFA says: > Turn the phone off before entering any situation that might lead to you being coerced to use your fingerprint to unlock the phone.
- ericabiz 10y agoIf you never want Touch ID to work, you can just replace the home button in the phone. It's a security feature from Apple--a new home button will never work with Touch ID again. It's not too difficult to swap a home button yourself with the right tools, or most stores will do it for ~$49 to $59 (depending on your iPhone model.) If you have a store do it, definitely ask for your original home button back in case you change your mind later or sell your phone.
- st3fan 10y agoJust don't setup Touch ID?
- ericabiz 10y agoObviously, but if you're as security-minded as this article author is, I'd trust a hardware solution over a software solution. It's the difference between turning off your camera and actually unplugging your camera (for instance.)
- mynameisvlad 10y agoExcept, it's really not. If you've never set up Touch ID on the device, then there's no fingerprint for it to even compare to; it'd be impossible for it to authenticate.
- fhood 10y agoI would put extra emphasis on don't use wifi. Preferably ever.
- linkregister 10y agoI think it's acceptable to trust the cryptography used in a well-used VPN, such as OpenVPN.
- dylz 10y agoI wonder how many people don't bother preloading CA/certs onto the .ovpn config and just allow whatever though..
- ape4 10y agoI would have thought a rooted Android or Ubuntu phone would more secure (done right).
- JonathonW 10y agoGiven that rooting an Android phone frequently involves turning off security features (for example, rooting a Nexus device entails unlocking the bootloader to accept an unsigned boot image), you're probably better off running a stock, unrooted firmware to make it easier to tell if things have been modified. That's in addition to the added attack surface that the root itself provides once the phone's up and running. Yes, the SU app on the phone (whatever that is nowadays) is supposed to prompt for permission before granting an app root access, but are you sure that code's bug free? Or free of intentional backdoors?
- ape4 10y agoYou'd use your root access to make the changes you want. eg uninstall factory apps. Then, day-to-day, run as a non-privileged user.
- ThatGeoGuy 10y agoNot that I disagree with what you've outlined, but to play devil's advocate: Some security settings that pertain particularly to Android devices only (such as ADB, internal SSH server) can only be disabled if you use apps that require root [0]. Maybe if you assume you have a targeted attacker, and they have physical access, root seems like a very bad target. If you install malware that gains root access, doubly so. But if the user is intelligent enough to not install random, non-vetted apps, and to turn auto-updates off, then rooting may actually provide a security benefit here, because you can at least avoid blind network attacks. I'll also say that if you choose to unroot after using SecDroid [0], then you may find it difficult if not impossible to root the phone again, as you won't be able to use ADB anymore. In any case, there's a lot of vulnerabilities in mobile phones, and you really have to pick and choose to see which ones you think will most likely affect you. [0] https://github.com/x942/secdroid https://github.com/x942/secdroid
- 10y ago
- Razengan 10y agoAs someone in a country with a serious mugging problem and having lost an iPhone already, one of the biggest security flaws I see is being able to power it off without providing any authentication. What is even the point of Find my Phone and all that if anyone can just instantly switch off all the tracking?? You can't even ring your own number after that, and even law enforcement cannot look up the cell tower logs to see where it's been. There should be an option to require a passcode for power-off, and another option to periodically send Find my Phone tracking even when "powered off," via any available network, until the battery dies. EDIT: I agree they can just take out the SIM and we need to be able to force-power-off anyway.. but what can be done to increase the recoverability of these expensive items?
- pavel_lishin 10y agoWouldn't that be trivially defeated with a small packet of tin foil?
- Jtsummers 10y agoAnd removing the SIM card.
- rolodato 10y agoThe problem is that there has to be a way to forcefully power off the phone in case it freezes. If the OS depends on software to power off and the software is not reponsive, there's no way to shut it down without exhausting/removing the battery.
- gnashville 10y agoI think that's what sleep/wake+home button is for. Holding sleep/wake still requires 'slide to power off' (which i assume wouldn't respond when iOS locks up.) sleep/wake+home button restarts iOS but ultimately reconnects to the device to the web.
- wyager 10y agoIf the phone is locked, they can't do anything but part it out anyway. They might as well remove the battery.
- walterbell 10y agoThe OP has responded to questions on Twitter, including TouchID criticism, https://twitter.com/FiloSottile/status/750273921568485377 https://twitter.com/FiloSottile/status/750273921568485377
- r00fus 10y agoDoes any of this avoid the pitfall of a stingray device[1]? Is there any way to prevent 2G? [1] https://epic.org/foia/fbi/stingray/ https://epic.org/foia/fbi/stingray/
- linkregister 10y agoYou can mitigate a downgrade to 2G by using a VPN and a VOIP app like Whatsapp or Viber. Call quality would be abysmal on EDGE. I haven't seen any stock configuration of iOS that permits you to disable 2G. Using 3G or LTE wouldn't help someone trying to evade a state or higher law enforcement organization, since all they need to do is use the cellular provider's Lawful Intercept capability somewhere in the packet core, such as the GGSN (for metadata) or at a tower's next IP router (for call content). I think the purpose of this guide was primarily for border crossings. Filippo almost certainly gets hassled at borders, as many security professionals do. His comment about the Great Firewall was more likely about accessing an unrestricted internet, and less as an phone call anti-surveillance measure.
- rdslw 10y agoIt's also an ultimate checklist of potential vector attacks.
- st3fan 10y agoI also like to power off/on my phone at airports. So that it will be on (which you have to show sometimes) but requires the passcode to unlock.
- spraak 10y agoRelated, are there any guides for securing a laptop for travel?
- spdustin 10y agoI think two security related changes could be made to iOS that would benefit many people. 1) PIN/TouchID locking of contacts, like you can do with notes. Don't allow messages and emails to and from the contact to be decrypted from the encrypted store without authenticating, like you can now do with notes. Would help with securing communications with legal counsel or other privileged parties from being captured. 2) A "duress" PIN/TouchID registration; if I unlock my phone with a duress code or imprint my duress-coded fingerprint, reboot the phone (to look like it was a glitch-induced reboot) and present the PIN prompt again. Auto-wipe the phone if the duress code is given again this second time.
- duaneb 10y agoSeems pretty niche for a luxury phone.
- spdustin 10y agoAsk anyone leaving or entering the US (or, indeed, any of several countries who may choose to screen phones upon entry/exit) if it's niche. I'd also submit that the iPhone is hardly a luxury item. I know that's a relative term - feature phones are luxury items in some regions of the world - but it's no yacht or Maserati or other such "luxury" item. Many, in fact, got their iPhone for free.
- Johnny555 10y agoif I unlock my phone with a duress code or imprint my duress-coded fingerprint, reboot the phone (to look like it was a glitch-induced reboot) and present the PIN prompt again. Auto-wipe the phone if the duress code is given again this second time. If such a feature was commonplace, criminals would know about it and wouldn't be happy when they saw you activate it with your middle finger (I mean, who wouldn't use their middle finger to activate such a function!?) after they just threatened you enough to make you attempt to unlock your phone.
- spdustin 10y agoSo you'd use the PIN. Then they get the metaphorical middle finger without seeing you use the real one. Besides, no criminal cares about your phone being unlocked. They just want the phone. Well, I guess there are circumstances where a criminal wants information, but if they're the ones compelling you, you have other pressing issues that go beyond protecting information from unauthorized parties. I'm talking about being compelled to unlock your phone by someone seeking information on it, either depriving you of due process or your civil liberties.
- FiloSottile 10y agoHey, author here. Happy to answer questions. There's also a big Twitter thread here https://twitter.com/FiloSottile/status/750273921568485377 https://twitter.com/FiloSottile/status/750273921568485377 To frame the post and the conversation, I am targeting a loose but not universal threat model. If threat of deadly force is higher up in your risk scale than shoulder-surfing, or Apple cooperation is a given, then you might want to make very different choices, but more importantly, you probably need better advice than a blog post. The only things I want to add are pair-locking, maybe a forced VPN profile, and a correction on how to check the Whatsapp fingerprint. You can find all these things in the Twitter thread.
- newman314 10y agoI'd avoid using TouchID to unlock your phone for legal reasons. Once the phone is unlocked, you can use TouchID as the phone is already open and you would not gain/lose anything from using TouchID in that scenario. But until the courts rule that you cannot be compelled to TouchID unlock your phone like a PIN, I think that is the safer route to take for now.
- mahyarm 10y agoIf you expect you can reliably turn off your phone (7 seconds) before you get in a search situation, then use a full password instead of a numeric pin, then touch ID is a great balance of convenience and security. TouchID also prevents shoulder surfing of your code. It's all about the threat model.
- watson 10y agoCorrect me if I'm wrong, but isn't it also possible to just use one of your fingers that you didn't register with touch ID for 5 or so consecutive unlock attempts and it will have the same effect as rebooting your phone?
- notjosh 10y agoThere is a slight difference. Keychain and NSFileManager have possible modes of "kSecAttrAccessibleAfterFirstUnlock" [0] and "NSFileProtectionCompleteUntilFirstUserAuthentication" [1] respectively that are (fittingly) in an open state within your app after you've unlocked the device. [0]: https://developer.apple.com/reference/security/ksecattraccessibleafterfirstunlock https://developer.apple.com/reference/security/ksecattracces... [1]: https://developer.apple.com/reference/foundation/nsfilemanager/1653059-file_protection_values https://developer.apple.com/reference/foundation/nsfilemanag...
- deleted 10y ago[deleted]
- sly010 10y agoI was once mugged for a crappy Nokia feature phone. I had a prepaid sim for a long time. Very hard to replace (in Hungary) without loosing the phone number. I managed to convince my muggers to let me take the SIM. Ironically they got caught and I got the phone back.
- xnzakg 10y agohttps://xkcd.com/538/ https://xkcd.com/538/ Well, at least it prevents the thieves from doing more damage if it's stolen.
- secfirstmd 10y agoNice guide. Just some other OPSEC stuff we have done for occasional problems in the field training human rights defenders and journalists (who needed specific solutions)... You can always use a call relay. So you can give people one phone number that relays to your own real number (for voice calls) - although an voice call is obviously more vulnerable than Signal call etc. Ditto, AFAIK there is the ability to setup a relay for SMS through an Android. I can't remember the app but basically people could SMS that number and it relays to you real number. Before people jump on me, yes I am aware of the weaknesses of both of the above but sometimes a specific type of threat model requires these two tricks. I recommend it unless you are aware of the trade offs.
- b15h0p 10y agoAbout turning off iCloud backup: You say that messages are being stored unencrypted. That may be true as we do not know what happens on Apple servers. But this is about securing the phone for traveling i.e. you would have to worry about the transport. And I would strongly guess that backup traffic would happen with http, probably with pinned certificates.
- smartbit 10y agoWhat I miss in this article in using MDM to harden an iOS devices in the first place. Eg. you can prevent the ability to make backups [0] diminishing that as a route to exfiltrate information. Secondly an always-on VPN [1] to a fixed IP address prevents network information leakage from the moment the device is turned on the first time. A quick search resulted in these two links but I didn't hit a comprehensive guide, other than Apples MDM docs, combining this travel guide combined with iOS MDM hardening. [0] https://community.rapid7.com/community/infosec/blog/2015/11/26/reduced-annoyances-and-increased-security-on-ios-9-a-win-win https://community.rapid7.com/community/infosec/blog/2015/11/... [1] http://www.howtogeek.com/218851/how-to-enable-always-on-vpn-on-an-iphone-or-ipad/ http://www.howtogeek.com/218851/how-to-enable-always-on-vpn-...
- mehrdada 10y agoA key step missing is to set up the iOS device as Supervised in Apple Configurator and prevent pairing with non-Configurator hosts. Additionally, you can install your own non-removable profile via Configurator on the device disabling a bunch of privacy-damaging features there.
- peteretep 10y agoNo VPN? I'm using Freedome and I like it.
- shurcooL 10y agoIf I may ask, in what circumstances would one want to go this far in securing their travel phone? Is this meant to be for a "general trip somewhere", or something more specific?