5 ms·
Apple’s Secure Enclave Processor (SEP) Firmware Decrypted
- LeoPanthera 9y agoAugust 18, 2017 Also, don't be mislead by the headline. To quote a comment on the article: "Imagine the Secure Enclave as a vault. Apple hung a big, dark curtain over it to prevent anyone from even seeing the vault. Now, that curtain has been opened and people can see the vault. The vault, however, is still locked as securely as ever."
- wonderous 9y agoMaybe for a casual reader, but nothing is misleading about the headline unless you don’t understand how Apple’s Secure Enclave Processor (SEP) works. For more on that, as mentioned in the linked page, there’s the “Demystifying the Secure Enclave Processor” talk from Blackhat: https://www.youtube.com/watch?v=7UNeUT_sRos https://www.youtube.com/watch?v=7UNeUT_sRos Or here’s the PDF: https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-De...
- rubyfan 9y ago> unless you don’t understand how Apple’s Secure Enclave Processor (SEP) works. So basically it’s only misleading to 99.9999% of people?
- CapacitorSet 9y agoNot on HN, where I expect most readers to understand what is firmware and what happens when you have its binaries and/or source code.
- askafriend 9y agoI think you’re a bit out of touch in that regard. I think that 99.99% applies to even HN and it certainly applies to me.
- kbenson 9y agoI think the best you can hope for, even here, is that the majority says "from the headline I'm not sure what that means in practice, so I'll reserve judgment until I look into this." And even that's a tall order.
- geofft 9y agoEven if you understand firmware (which I wouldn't expect of most readers, just some; the reason we develop abstractions is so our fellow hackers can hack on new things instead of studying the same things we already studied and hacked), it's extremely common for companies that keep security software secret to rely on that secrecy for security. You need to understand the Secure Enclave in particular and believe that the Apple folks are both talented and honest enough to implement what they say they're implementing to know that, in this case, that's not what's happening.
- floatingatoll 9y agoBack when this was first posted, the headline on HN from an article was “Secure Enclave decrypted”, which couldn’t be further from the truth. The more nuanced “Secure Enclave firmware decrypted” replaced it, and is vastly more accurate. Both headlines fail a general public test IMO, but at least the “firmware” is factually true!
- slim 9y agoActually the sentence you've chosen is misleading. This is the essential step towards breaking the iPhone open. The next steps will be less news worthy, til we get a jail break
- c22 9y agoIsn't it more like getting the plans to the vault?
- runeks 9y agoIt’s more like acquiring knowledge of the mechanics of a safe dial lock: if the mechanism exposes a safe interface, it doesn’t matter. Only if there’s a flaw in the inner workings of the lock, that an attacker can exploit from the outside, does it pose a problem.
- QAPereo 9y agoIsn’t there always a flaw?
- nateberkopec 9y agoThe link makes it sound like SEP only handles TouchID - is this true, or does the SEP also deal with passcodes?
- iancarroll 9y agoThe SEP also deals with passcodes, yes. It is integral to preventing the passcode from being brute forced.
- ikawe 9y agoIt does more than that. From the [ios security guide]: > The Secure Enclave provides all cryptographic operations for Data Protection key management and maintains the integrity of Data Protection even if the kernel has been compromised. e.g. you can encrypt and decrypt, referencing a key by id, but without having the private key ever leave the enclave, even if the app or iOS kernel gets compromised. [ios security guide] https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf The Secure Enclave section is pretty short and the entire document is very approachable.
- DennisP 9y agoSounds like basically what a cryptocurrency hardware wallet does. Several months ago I saw a project making wallet software that used the enclave. I forget who they were but I think they'll have a hard sell; everyone just reflexively assumed it was insecure because it was on a phone.
- ikawe 9y agoAnd yet you’d be hard pressed to do worse than any mainstream desktop OS.
- iancarroll 9y agoIndeed, cryptocurrency hardware wallets and the SEP are basically just HSMs (hardware security modules). It's unfortunate people would draw negative connotations from it being on a mobile device. The security architecture of iOS and the SEP combined with the relatively wide deployment of iPhones makes for a great number of use cases.
- abalone 9y ago> It’s a black box that we’re not supposed to know anything about Nope. Apple published a whitepaper that details how the SEP works.[1] Decrypting the firmware does help researchers look for vulnerabilities in the implementation, but it's not like Apple is relying on it being a black box. [1] https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- Cyph0n 9y agoCan you point out the section in that whitepaper that describes SEP in detail? Because all I see is a high-level marketing document.
- abalone 9y agoSays the PhD candidate in hardware security. You may want more low-level details but it's inaccurate characterize it as "marketing". That's just snark. It presents numerous details on the implementation of the SEP throughout the document.
- Cyph0n 9y agoThe article claimed that SEP is a black box, which you strongly denied based on the contents of the security whitepaper. But when confronted, you failed to present which part of the document presents how SEP is implemented in detail. If you would like to avoid such replies in the future, try to avoid making strong, absolute statements. When I talk about topics I am unfamiliar with, I tend to use phrases like "I think" and "I believe" quite sparingly. > Says the PhD candidate in hardware security. Again, the fact of the matter is that the Apple security whitepaper is a marketing document. I'm not sure what my background has to do with that though.
- johneth 9y agoThere's a video of a presentation by Ivan Krstic (head of security engineering, Apple) at Black Hat from 2016 about iOS security: https://www.youtube.com/watch?v=BLGFriOKz6U https://www.youtube.com/watch?v=BLGFriOKz6U
- log78 9y agoThis article is extremely misleading to most people
- runesoerensen 9y agoPreviously discussed here https://news.ycombinator.com/item?id=15039460 https://news.ycombinator.com/item?id=15039460
- kbos87 9y agoTLDR - The writer is a shitty marketer masquerading as a clever engineer behind a thinly veiled headline.
- runeks 9y agoThis is interesting. I hope Apple has some hefty bug bounties on SEP vulnerabilities. I also hope Apple has chosen a sensibly safe language for the SEP firmware code, since correctness is of essential importance here.
- tyingq 9y agoSee this blackhat paper for some detail. https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-De...
- LeonM 9y agoHow does one find such a key? It's my understanding the brute forcing such key would take billions of years on a regular CPU, so can anyone here explain how this was (probably) achieved?
- hendersoon 9y agoThis was actually cracked back in August, and sites quoted Apple as saying they have no plans to fix it, presumably because obscurity is not security and they originally encrypted it because well, why _not_? Ultimately there will be some exposure from this, and they'll address each exploit as it comes just like the rest of the system.