4 ms·
We don't have to speculate how Apple could possibly handle account recovery without entirely sacrificing security, because it's spelled out in their iOS securit
by voidmain 9y ago
We don't have to speculate how Apple could possibly handle account recovery without entirely sacrificing security, because it's spelled out in their iOS security whitepaper: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
TL;DR: Keychain recovery relies on a cluster of hardware security modules to enforce the recovery policy. After 10 tries to guess your PIN, the HSM will destroy the keys. Apple support gates all but the first few of these tries. The paper also implies that you can use a high entropy recovery secret as an alternative, though I can't figure out how you would enable that.
This seems like a pretty reasonable point in design space to me. Of course, you are relying on Apple's trustworthiness and competence to implement this design. But that is true without recovery, since the client software is also implemented by Apple.
- dsacco 9y agoThat's a good point, but the question is not just how to maintain security and usability without account recovery, but how to do so without device redundancy. There's no speculation about how to maintain true E2EE with a network of trusted key pairs, but without multiple devices the user is very vulnerable to permanently losing access. I think the recovery key is a clue. As I speculated elsewhere in this thread, I think they're going to do it with multiple recovery keys ostensibly written down by the user and never transferred directly to Apple, which each then redundantly encrypt all user data before transmitting respective copies to iCloud. That would pull it off, and it basically just shifts the trusted device redundancy problem to a trusted key redundancy problem. The only remaining usability obstacle is to make sure the user has safely recorded all recovery keys.
- voidmain 9y agoThe "HSM cluster" serves as a redundant "device" which is in Apple's possession rather than yours, but which you must trust to withstand tampering, even by Apple. The option to record the keys yourself is also described in the whitepaper: "If the user decided to accept a cryptographically random security code, instead of specifying their own or using a four-digit value, no escrow record is necessary. Instead, the iCloud Security Code is used to wrap the random key directly. " As I said, I can't actually find this option in my iOS settings. Maybe you have to disable Keychain first?
- learntofly 9y agoI think this relates to a time before 2 Factor Authentication, when Apple used 2 Step Verification. You could st that time (if you were using iOS 6 to iOS 8) chose various recovery options. I'm no expert but this is my recollection. In the scenario where you have 2 devices, one is iOS 9/10 and have migrated from 2SV to 2FA, the other is iOS 6/7/8, you can still access the recovery menus on the iOS 8 device, but it does weird things to the keychain if you mess about with it.