10 ms·
Some U.S. law enforcement agencies are using GrayKey to bypass iPhone encryption
- xevb3k 8y agoFrom the article, it seems to be a passcode bruteforcing tool. They state in the article 3 days or longer for a 6 digit passcode. Which I assume means 3 days for a 4 digit code. That’s about 26 seconds per guess. So if you care about securing against this, use a longer passcode (and alphanumeric) is the message I guess.
- hardwaresofton 8y agoIsn't there a setting for wiping the device if the wrong password is entered X times?
- deleted 8y ago[deleted]
- mantas 8y agoI guess they copy something off the phone, validate passcode attempts against that piece and the phone gets correct passcode only.
- nielsbot 8y agoMaybe.. but I think the system is designed so that isn't possible. There is a secret device key inside the secure enclave used to salt your passcode... I bet they're bypassing the limit on number of password guesses.
- mantas 8y agoOn the other hand, is it possible to programatically enter the passcode? From the picture, it looks like it's unlocked via lightning cable. It's not emulating unlocking via touchscreen. I wonder how much security would it add to require input via screen.
- vegardx 8y agoI bet they just connect (or rather, emulate) a physical keyboard connected via Lightning/USB, and use it as an input device.
- monochromatic 8y agoYes, I wonder if this device has a way to bypass that.
- manicdee 8y agoThis device pranks the hardware to allow unlimited attempts at guessing the password. I don’t know the details: is it as simple as grounding the “password entered incorrectly” pin? Or is it about injecting so much noise on a signal line that the message to increment the PIN attempt count never gets through? I don’t know. So use a passphrase, not a PIN.
- hardwaresofton 8y agoWith all the work that I've heard went into secure enclave (IIRC that's apples hardware+software security latest-and-greatest), does that mean someone (or an entire team) at Apple is absolutely sweating bullets/thinking frantically right now? Security and a focus on user privacy protection (from other entities, at least) is definitely a differentiator for apple devices
- wool_gather 8y agoLast year someone demonstrated the possibility of dumping and restoring the state of the security hardware in between entry attempts, so that the phone always thought you were on your first try. I assume this is the technique being used by the GreyKey. EDIT: Pretty sure this is the one I'm thinking of: https://www.digitaltrends.com/mobile/cambridge-researcher-hacks-iphone-security-off-the-shelf-equipment/ https://www.digitaltrends.com/mobile/cambridge-researcher-ha... I guess it was two years ago.
- Cenk 8y agoYep! And with these guessing speeds, the amazing device can wipe an entire iPhone in less than a second!
- deleted 8y ago[deleted]
- onetimemanytime 8y ago>>So if you care about securing against this, use a longer passcode (and alphanumeric) is the message I guess. Yeah but "normal" people don't think that cops will have a reason to look at their phone. Until it's too late. Cat and mouse game, let's hope Apple does something. Typing 10 characters a gazillion times a day can become frustrating
- dewey 8y agoWhy do you have to type it that often? I usually have to type mine once per day and the rest is with fingerprint or faceID
- outworlder 8y agoIf you are using fingerprint or faceID, then they do not even have to use this tool.
- jeeyoungk 8y agoboth touchID and faceID are ephemeral and expires after 24 hours (configurable, i think). Unless the device was obtained from the person immediately any hardware hack to bypass them won't work.
- outworlder 8y agoTrue. It is still a 24h block (let's use the default) where the device is vulnerable. In many countries there are no protections against pressing your finger on the phone, or worse yet, turning it to face you.
- fredsir 8y agoIt works fine for every day use, and if I ever find myself in a situation where I could conceive a higher than normal risk of getting arrested, I would reboot the device so the password is required to unlock it. This can be done with one hand in the pocket in a matter of seconds.
- Anechoic 8y agoDoes anyone have a guess as to whether pair-locking an iPhone will prevent this exploit?
- willstrafach 8y agoYou are correct.
- rwbt 8y ago> Grayshift has been shopping its iPhone cracking technology to police forces. The firm, which includes an ex-Apple security engineer on its staff, provided demonstrations to potential customers, according to one email. Wow. That's very sleazy.
- hardwaresofton 8y agoIs it? Maybe I'm morally bankrupt, but if you think that's sleazy the world is a literal (figurative) ball of mud. A thing that can be cracked will be cracked. If someone's good at something, they will probably look to sell their skills. If it is within the law for police to perform this kind of thing (it probably definitely shouldn't be), they're gonna use whatever contractor can do it best (if they can't do it themselves). It just seems like the natural progression -- outside of the oddity of police being allowed to "break into" (in a sense) private property. I think this argument devolves into the does-tech-hurt-people (guns, security research) argument, and maybe I'm just way off base, but I don't knock the iphone cracking people in this instance... I mean I wouldn't necessarily do it but this isn't bad enough to pass muster in my book as sleaze.
- paulsutter 8y agoIf they need to break the law to collect the data (the far over-reaching CFAA), what should they need? a search warrant? (honest question about civil liberties, I really am curious)
- hardwaresofton 8y agoI'm definitely not the person to ask -- I don't particularly live in this space, and I'm fairly sure other people here do and could answer more completely, but: If you see modern society in a democratic environment with the (somewhat naive) outlook that a large enough group of people have consented to be governed by the laws of the land, then it's really up to the law on when this is allowed/disallowed. It's more of a reflection of the people (or.. who's making the laws), and what they've decided -- if people decide that personal privacy is protected under law then so be it. If people decide police are allowed to break the law (at all) then so be it. If people decide that police are somehow above what would normally be a law when they have certain piece of paper (search warrant) signed by the local wiseman (judge) who is likely looking out for the best interests of the community and country at large, so be it. Things get blurry really quickly, and this is a gross oversimplification of how any of these systems work, but it's how I tend to think about it. I sometimes think that it can't be any other way -- once a bunch of humans attempt to work together, there are some fundamental problems that just end up best solved this way (in terms of efficiency and other factors).
- forapurpose 8y agoMost key bits are below; there's much more in the article and in the article's links. > GrayKey can unlock an iPhone in around two hours, or three days or longer for 6 digit passcodes > 'GrayKey' ... can break into iPhones, including the iPhone X running the latest operating system iOS 11. > The device comes in two versions: a $15,000 one which requires online connectivity and allows 300 unlocks (or $50 per phone), and and an offline, $30,000 version which can crack as many iPhones as the customer wants.
- zanedb 8y ago> Malwarebytes’ post says GrayKey can unlock an iPhone in around two hours, or three days or longer for 6 digit passcodes. So couldn't you avoid this by, say, having a longer PIN? Maybe even a password?
- mikeytown2 8y agoYeah I’m curious about how this would work with a longer pin. I have one that’s over 6 and you need to press ok after punching in the pin; making it much harder to crack I’d imagine.
- SomewhatLikely 8y agoAnd couldn't Apple defend against this by using an exponentially increasing wait period between guesses? Probably after some number of guesses with no delay, say 10 guesses.
- nielsbot 8y agoThey already do that--but this box somehow bypasses that security measure.
- deleted 8y ago[deleted]
- moomin 8y agoAbsent this whole article is the fact that there are good reasons for criminals to want to crack your phone. These developments just make it more likely your personal information and, frankly, cash can be stolen by anyone who swipes your phone.
- kafquaesque 8y agoThis is one of the best points I have read. Without the community knowing how he is doing it—it can be used maliciously. There are extremely good reasons for police officers to want access to an iPhone (which could be time dependent). At the same time there’s a lot of potential for misuse of the ability to gain access by agencies or malicious actors. It’s a trade-off. I err on the privacy side of the issue because things can be misconstrued in a legal setting. I can see why some people don’t have the same viewpoint and lean the other way.
- outworlder 8y agoThat 15k(or 30k) box looks like it is slightly more polished than an arduino case straight from the likes of DigiKey. It wouldn't look out of place in the 80's. The LEDs in particular would fit right in. I would not be surprised to find an actual $1 micro controller driving this. Or to find that out the box wasn't really required at all – and that during development the software ran in a normal laptop, but they needed a physical product to charge the big bucks...
- sterlind 8y agoGPS, 2-factor auth and probably additional tamper-proofing is packaged in the enclosure. GrayKey's value drops to zero the moment the exploit is unearthed; I suspect the black box mostly provides safeguarding. Though, one wonders whether a simple tap on the lightning cable couldn't spill the device's secrets.
- outworlder 8y agoGood observation, I had not considered the actual safeguarding of the exploit.
- nikanj 8y agoIt's somewhat amusing that their business model, i.e. "we break software protections", is 100% dependent on their own software protections working.
- userbinator 8y agoI would not be surprised if this was mainly developed by the Chinese, who have a history of making things like the *Box series, primarily for repair purposes. If anyone can extract keys from the actual secure enclave processor, it would be them.
- throwaway100000 8y agoAn i.MX6 SoM more like, running Linux. Uses an Apple Lighting to USB3 camera adapter to connect to the iPhone.
- qume 8y agoI thought the iphone has a delay after a few attempts at the secure enclave level? I wonder if this is doing some sort of timing or voltage related validation of the code without needing to actually submit it. Ie the equivalent of 1234,backspace,5,backspace,6 etc without sending whatever is the equivalent of 'submit'
- fredsir 8y agoI for one am glad I started using 25 character passwords 3-4 years ago. I just wonder how long it will be before that is not good enough either. Surely in my life time. And what's next? 50 character passwords? One hundred characters? 10-factor authentication?
- caf 8y agoI wonder if Grayshift have joined the MFi program to license the patents to the Lightning connector...
- Operyl 8y agoSome more fun information here: https://blog.malwarebytes.com/security-world/2018/03/graykey-iphone-unlocker-poses-serious-security-concerns/ https://blog.malwarebytes.com/security-world/2018/03/graykey... It looks like it runs third party code on the device. Only needs to be connected to the black box for two minutes and then unplugged for the remainder of the process.
- emilfihlman 8y agoIt's probably in Apples best interested to let this firm operate. It might be even a long term strategy for them. It relieves pressure from them and keeps law enforcement happy.
- iainmerrick 8y agoI wonder if they have any process in place to prevent Apple buying one of these and figuring out how it works. I would guess Apple already has one. But if they’ve tried to get one, and been foiled somehow, there must be a fascinating cloak-and-dagger story there that we’ll probably never hear...
- Shivetya 8y agowell I am curious what the break time on longer passwords is? They made claims against four and six character passcodes but my employer already requires longer if we are to receive corporate mail.
- haZard_OS 8y agoI have never worked for a company that requires less than 8 characters for a password. Most have required 10 characters (or more), with at least one numeral, one special character, one uppercase letter, and one lowercase letter.
- dre85 8y agoI've always wondered about the legalities of such things. How is it okay for a company to legally sell a hack of another company's technology? Is it because they only sell to the police? If this is okay, then where is the actual limit? Can they sell hacked access to a company's servers for example?
- tinus_hn 8y agoThis isn’t really a hack, it’s just a tool for brute forcing pin codes. It doesn’t work if you have an alphanumeric code or a very long pin code.
- briffle 8y agoBut doesn't that still violate the DMCA that prohibits working around access control technology?
- IshKebab 8y agoIt is a hack. It shouldn't be possible to test pins via a lightning connection. If it weren't exploiting a bug you would have to enter the PIN via the screen, and then you only get a few attempts. It seems likely that Apple could just buy one of these, find the bug and fix it. Unless it is using some very low level exploit which I suppose is possible and might explain why it is hardware rather than software (though that might also be to justify its cost and prevent piracy).
- 8y ago
- micro-ram 8y agoWhat about the requirement to run signed code from power on?
- 1024core 8y ago> FBI Director Christopher Wray recently said that law enforcement agencies are “increasingly unable to access” evidence stored on encrypted devices. > Wray is not telling the whole truth. I wish there was some punishment for Government officials for lying to the public. You can be prosecuted for lying to the FBI, so why shouldn't they be prosecuted for lying to you (the voter, who is supposed to have the power in a democracy)
- stronglikedan 8y agoI would guess it's to reduce the amount of frivolous accusations by people who only think they were lied to or simply disagree. I would imagine that most government officials would spend their day fighting off these accusations, with no time for their official duties.
- acct1771 8y agoI'd rather their time be taken up by explaining shit in court as opposed to making backdoor deals.
- scrupulusalbion 8y agoI see two issues here: (1) Whether LE agencies are actually finding it more-and-more difficult to access devices that employ encryption. I think this is plausibly true, simply because there are more such devices being sold than ever before (from the perspective of senior LEOs). (2) Which LE agencies is he talking about? If he is refering to all agencies, then he might be right. Many LE agencies have very limited budgets. However, if he is talking about the more well-funded and competent agencies, then he is probably wrong >I wish there was some punishment for Government officials for lying to the public. You can be prosecuted for lying to the FBI, so why shouldn't they be prosecuted for lying to you Get rid of the punishment for lying to LEOs and it is all fair and equal. They lie to us and we lie to them, both without punishment. It would still be illegal to lie to judges. >(the voter, who is supposed to have the power in a democracy) The purpose of democracy is to use elections to legitimize a limited group of persons to use the power of the State. The power of voters is limited to selecting who will be in that group. The rest of the power of the State is in the power of the hands of those who were selected.