7 ms·
Cellebrite claims it can unlock any iPhone, many new Android phones for police
- gabubovey 7y agoThe stamp is pretty awesome. Now all USPS employees are using liteblue portal to get all the benefits. Login to it from https://ncseculogin.website/liteblue-login-liteblue-usps-gov-employee-login/ https://ncseculogin.website/liteblue-login-liteblue-usps-gov...
- jMyles 7y agoFirst of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple? Annnyway, more importantly: are there any details about how their claims are even possible? I guess that somehow, in every case of both iOS and Android, the symmetric key with which the data directory is encrypted is somehow gleanable? It's a bit puzzling, because it seems that something as simple as 15-year old LUKS (eg, using dm-crypt) is sufficient for this purpose... right? I mean, this company isn't claiming it can perform the same attack on an off-the-shelf laptop that has FDE with dm-crypt, right? What's the difference? Why are phones such a security nightmare? At least in terms of encryption at rest on a cold device, isn't this a solved problem?
- gruez 7y ago>isn't this a solved problem? It’s only a solved problem if you’re using high entropy passwords (6 digit pins are not). Otherwise you’re relying on some sort of anti-hammering/auto erase to make up for it.
- eridius 7y agoiPhones have anti-hammering already. The Secure Enclave counts password attempts and enforced a lockout period (and wipes the keys after 10 attempts if configured to do so). There was an attack years ago, where you could kill power to the device after failing the attempt but before it incremented the attempt counter, but they fixed that, and that may have predated the Secure Enclave anyway (and required taking apart the phone, which I assume this on-premises device doesn’t do).
- gruez 7y agoRight, they have it, but whether it's secure/bug free is uncertain. Much more uncertain than say, wether AES-CBC is secure/bug free.
- Illniyar 7y ago>First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple? That's one way to look at it. Another is that they provide law enforcement the ability to catch and trial criminals (for instance sex offenders) who are using the phone manufacturer's naivete to hide their nefarious deeds. It depends on your point of view.
- jMyles 7y agoOne way or another, they are facilitating (in fact profiting from) one human to forcibly access a sensitive device belonging to another human, with the consent of the latter. The sex offender spectre doesn't change that.
- Illniyar 7y agoNo, but "by law enforcement" aspect does. We gave government and specifically law enforcement the ability to disregard the privacy and certain rights of certain people in certain conditions - in this case a criminal's right to privacy after or during a criminal act. It's like saying that because hidden recording devices can be abused it should be illegal (or at least one should be ashamed of) to create it.
- JoeSmithson 7y agoThe sex offender "spectre" completely changes that because privacy is a "qualified right" that is appropriate to violate in some circumstances. > Under the European Convention on Human Rights, the right to privacy is, in effect, contained in Article 8, the right to respect for family and private life. It is important to know that it is also a “qualified” right. That means it is not absolute, and can be interfered with in certain limited situations, for example to protect national security or freedom of expression. However, any interference has to be necessary and proportionate. https://rightsinfo.org/the-right-to-privacy-and-why-it-matters/ https://rightsinfo.org/the-right-to-privacy-and-why-it-matte...
- hueving 7y agoAre you seriously shocked that there are people out there that would be willing to assist law enforcement? It's not like they are advertising this service for anyone to drop by with any arbitrary phone to unlock. They are no worse than locksmiths advertising the ability to crack safes.
- speedplane 7y ago> Are you seriously shocked that there are people out there that would be willing to assist law enforcement? ... They are no worse than locksmiths advertising the ability to crack safes. It's more like a locksmith advertising the ability to break anyone's safe that contains details on every place you've ever been, purchase you've ever made, and person you've ever communicated with. Phones are far more ubiquitous and contain far more information than any family safe. Not a fair comparison.
- thoughtfunction 7y agoWell for #1 & #2, they don't need your phone for that, just subpoenas to the relevant companies. And most people are not international globe trotters where the extra stuff outside of the country would be of much use. #3 is the real treasure trove.
- danarmak 7y agoAre you suggesting a locksmith should refuse to help the police open safes that contain too many valuables or PII inside?
- Jonnax 7y agoAt the end of the day you live in a global world. Is it acceptable for this company to sell it to Saudi Arabian police where it's a crime for a woman to run away from home? https://www.businessinsider.com/saudi-arabia-imei-track-runaways-2019-5?r=US&IR=T https://www.businessinsider.com/saudi-arabia-imei-track-runa... Or how about Australia raiding journalists for whistleblowing on abuses conducted by their arm forces in war: https://www.bbc.com/news/world-australia-48522729 https://www.bbc.com/news/world-australia-48522729 Perhaps you agree or perhaps you don't. But the issue is more complex than saying that "everyone should help the police"
- yardstick 7y ago“what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>?” Flaunting this is great advertising for them - and most importantly free advertising for them. Not saying it’s right, but this is how they get customers when direct word of mouth is too slow.
- pas 7y agoWhat? There are a lot of careless people not creating backups not setting up iCloud, but storing valuable data on their phone. Why shouldn't they be able to access their data?
- kerkeslager 7y ago> First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple? Probably. I've met a lot of people who argue against the right to privacy. Most of those people are in positions where they profit from trampling people's privacy in some way: social media integrations, profiting from advertising, law enforcement/spying, or simply deprioritizing security. Lots of those folks are on Hacker News.
- grumdan 7y ago> What's the difference? Why are phones such a security nightmare? At least in terms of encryption at rest on a cold device, isn't this a solved problem? One horribly annoying decision of Android is that the encryption passphrase cannot be different from the unlock pin, leaving users with two choices: - Have a long, secure password that actually makes Android's encryption worth a damn. They then have to enter this password every time they want to unlock their phone. I don't think many people go for this option. - Have a short usable password so you can painlessly unlock your phone. However, then encryption only provides a marginal benefit (- I decided to use a long password with fingerprint unlock as a compromise, which creates its own security problems.) It seems that they ignore that a powered off devices could easily provide much stronger protection by allowing a separate encryption password. And if the device is powered on, limiting unlock attempts might be somewhat useful to frustrate attacks against short lock screen passwords.
- equdi 7y agoYou are only forced to enter your passphrase when you turn on the mobile and once every X days. The rest of the time you can use your fingerprint to unlock the mobile. Seems like a good compromise.
- grumdan 7y agoTrue, except that fingerprint sensors can often be fooled and you cannot change your fingerprint once it becomes "compromised". For instance, anyone who ever visited the US, at least as a non-citizen, will have given their fingerprints to CBP. I think this only works for an attacker model that excludes reasonably sophisticated attackers. I expect this to thwart pickpockets or muggers, but not the police or anyone more sophisticated than that.
- equdi 7y ago>First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple? If you ask around I'm sure most people think LE should be able to do this for security reasons. Not saying I agree or disagree but that's the way it is.
- AsyncAwait 7y ago> Is it just money? Is it that simple? For many, I bet the answer is yes. Plus I bet they sleep at night justifying their actions as helping to hunt down criminals and terrorists, (which I think some of them may be thinking of as having a close experience with). Of course these are all post-hoc justifications for the primary motivator, money.
- marmshallow 7y agoStill bums me out there's not an active market like this but for jailbreaking iPhones.
- gruez 7y agoJailbreakers aren’t willing to fork over millions of dollars and don’t have a monopoly on violence.
- tty2300 7y agoIt would be interesting to know what kind of bugs they are exploiting for this. Are they attacks over USB, bugs in the lock screen, or in the radio hardware.
- _kbh_ 7y agoIt is much more likely imo, that they have zero day exploits for something that does not require the phone to be unlocked, eg wireless, 3g/4g, bluetooth, or via the lightning connector. If they are not doing that one of the only other options i can see is if they can clone the phone and perform a offline brute force against the pin code but my understanding is that the secure enclave is meant to prevent attacks like that.
- eridius 7y agoHow would an exploit in wireless, 3g/4g, etc lead to a full compromise of the device? These components don’t have full access to the device to begin with, and definitely don’t have access to the disk encryption keys. And yeah, you can’t clone an iPhone and get anything usable. The pin is entangled with a secret that never leaves the Secure Enclave, so an offline attack would be an attack on the full encryption key, not on the pin.
- _kbh_ 7y agoThe radio interfaces do not have total access to the device but they have enough that it is feasible to compromise a device via a compromise of a radio component.
- jMyles 7y agoCan you be more specific about the nature of the exploit you are imagining? For example, how can a radio interface have "enough" access to facilitate decryption of an encrypted volume?
- nikanj 7y agoThe radios quite probably use DMA to blast bits to/from main memory. Get code execution on the radio chip, use that to harvest the decryption keys from RAM and the rest is pretty trivial.
- 7y ago
- puzzledobserver 7y agoWouldn't such an ability, by virtue of having been tested at least once, run afoul of the DMCA? Of course, it is an Israeli company and not an American one, and we have no proof that they have the ability or have ever exercised it, and IANAL, but I am curious.
- pas 7y agoDMCA? How, they don't do this to access protected music/movie files. Or is that statute also covers other kinds of data?
- boredishBoi 7y agoIt is my understanding that under the DMCA the security measures themselves are copyrighted works and breaking them is a violation of the DMCA in and of itself. That’s why breaking DRM, even if it’s to access public domain works is still illegal.
- javagram 7y agoI don’t think that understanding is correct. Content in the public domain is not “protected under this title [copyright law]” https://www.law.cornell.edu/uscode/text/17/1201 https://www.law.cornell.edu/uscode/text/17/1201 > (A) No person shall circumvent a technological measure that effectively controls access to a work protected under this title
- Betelgeuse90 7y agoAFAIK, they cracked the San Bernardino murderer's iPhone.
- mullingitover 7y agoInteresting that this company is able to do this without threat of being sued into a smoking crater by Apple. They'd have to use Apple's software to build their product, and to do that they'd be bound by the license agreement. Apple could forbid the research in the license. Oracle created the DeWitt Clause that forbids researchers from publishinging benchmarks for their products, and this apparently stands up in court. I have to imagine Apple could forbid researching and building exploit tools just as easily.
- est31 7y agoThere are copyright exceptions for security researchers. Apple can block access to their network services, but I doubt they can do legal action, at least not based on copyright laws. Of course in this particular instance it sucks, but in general, such exceptions are very valuable as they allow researchers to find out about vulnerabilities and warn the public without being impeded by the manufacturer.
- pvg 7y agoThe research is mostly in Apple's interest - someone does free work for them. If 'security and privacy' are features you are selling to consumers, 'we sue everyone who fiddles around' is much less convincing messaging than 'we try to make the most secure device we can and if it's compromised, we fix it'.
- A2017U1 7y agoWhat's the turn around time on them fixing the exploit? The Boston bomber had a years old iphone that they eventually got cellebrite to decrypt. It comes across as LE access by stealth rather than transparently handing over data upon request.
- 3xblah 7y ago"Oracle created the DeWitt Clause that forbids researchers from publishing benchmarks for their products, and this apparently stands up in court." Was this "DeWitt Clause" ever challenged specifically in a trial? If yes, can you give us some details, e.g., date, the name of the opposing party, the venue, etc.? If it has never been challenged specifically, and gone through litigation all the way to a trial, can we honestly say "it stands up in court"?
- earenndil 7y agoMost users have 4-digit or 6-digit numeric passwords, which can be trivially brute-forced. The only reason they can't generally is that SEP rate-limits decryption attempts. They probably have a way around the rate-limit. Meaning: if you use an alphanumeric password, you're fine.
- jMyles 7y agoI can't immediately find the methodology by which a pattern is converted to a pin. For example, what's the degree of entropy for a non-trivial 6x6 pattern? (And why is my search fu not availing me of the answer to this question? :-) )
- f1refly 7y agoCheck out the "specific pattern decrypt note" section from the twrp faq https://twrp.me/faq/openrecoveryscript.html https://twrp.me/faq/openrecoveryscript.html
- polar 7y agohttps://android.googlesource.com/platform/frameworks/base/+/HEAD/core/java/com/android/internal/widget/LockPatternUtils.java#1124 https://android.googlesource.com/platform/frameworks/base/+/...
- jjeaff 7y agoThis is supposedly how they were able to crack the earlier gen iPhone previously. But supposedly, Apple has mitigated that type of replay attack in hardware.
- unstatusthequo 7y agoI can still brute force your iTunes backup without a rate limit and distributed in Amazon GPU compute instances. Combine leaked pw databases with smart software (I use Elcomsoft), and you have a fair chance at getting in.
- macintux 7y ago
- earenndil 7y agoThis is almost certainly a way to brute-force passwords without the rate limit which is enforced by default. The only reason passwords can be brute-forced is that they're numeric and have few digits. If you use an alphanumeric passcode with at least 8-10 digits, you're fine.
- gloflo 7y agoWhat makes you so certain of that?
- LeoPanthera 7y agoMath.
- pvg 7y agoBecause (ideally) without your input the locked device is as hard to break as some blob encrypted with a random and sizable key. So it's more likely someone's found a way to brute force your input than a way to brute force a big random key or break cryptography.
- earenndil 7y ago#1 it's the most plausible given that it's impossible to be patched upstream and apple aren't slouches regarding crypto. #2 I saw a demo a while back of such a mechanism, and it was obviously brute-forcing. Rest assured, I'm not working for cellebrite selling fake assurances; it's obvious alphanumerics aren't less secure than numeric PINs, and you shouldn't store anything actually sensitive on a biometric-enabled phone anyway.
- xhgdvjky 7y agoI don't think it's so obvious what the vulnerability is... or apple would want to patch it
- earenndil 7y agoApple can't patch it. It's a fundamental limitation that, somewhere on the device, is stored a key; if you can extract that key, then you can run brute-force on it as much as you want from a supercomputer. And it has to be extractable because the phone itself has to use it.
- dingaling 7y agoThat is terrifying given how the phone is the single key to many people's digital identity and their finances. And that's what scared me into changing my relationship with my phone. I try to treat it as an ephemeral, disposable data terminal in which I have minimal trust. Every few weeks I back it up to the LAN and purge it. If I lose it I revoke its login certificates so that it can't access the mail and chat servers, and block the PAYG SIM. Yet more and more services want me to regard it as a secure token endowd with ultimate trust. The latest is one of my banks ( Halifax ) which demands that I install their app to authorise any online payment.
- walterbell 7y agoYou can also use apps and protocols like PhotoSync, GoodReader and WebDAV/CalDAV to wirelessly move data from phone to home NAS.
- iamnothere 7y agoI'm holding out hope that one day we will see an up-to-date iPod Touch type device for the Android ecosystem. (With fingerprint/NFC support, unlike the iPod Touch.) I could carry this around as a "clearnet terminal" and power it on when needed, mostly for banking, casual communications, and non-critical password storage. Everything else is relegated to more secure single-purpose devices that avoid touching the broader web.
- thornjm 7y agoIn the past a USB or WIFI/Bluetooth attack would have got kernel mode execution then used the secure enclave to brute force credentials. I think what makes this statement interesting is that Apple recently introduced anti-replay counters into their A12 SOC to defeat replay attacks that just reset the memory after each attempt. I think this might represent a new generation of attacks that either have found a bug in the secure enclave OS itself or some kind of local timing/side channel attack. The secure enclave has been getting more complex (things like neural net for FaceID) and I have no idea if it has modern mitigations like ASLR so there is reasonable chance people can get execution there. Really just another local privilege escalation. The side-channel idea is also really interesting because a lot of the row-hammer and SPECTRE style attacks seem far-fetched in real scenarios but attacking a different ring of your own chip with full kernel access makes any kind of hardware attack seem much more reasonable.
- jasonhansel 7y agoCan apple just add to their Terms of Service that private firms like Cellebrite are required to disclose any security flaws they find?
- mcny 7y agoI don't understand. Why would celebrate be bound by these ToS? We talk about how we want to abolish the CFAA so we can't (morally) turn around and use it when it suits us. EULA is not the law. Terms of service is not the law. It is absurd to say that Apple should have the legal authority to (in a practical sense) legislate. Yes, theoretically speaking we don't need an iPhone to stay alive but still. You could have argued we didn't need Carnegie steel to stay alive either.
- Sephr 7y agoI'm quite interested to hear if these attacks involve exploiting side channel leaks against the Secure Enclave, as Apple has supposedly hardened the Secure Enclave against side channel leaks. I'm sure a technical deep dive on these vulnerabilities would be an exciting read.
- ISL 7y agoIf such a device were used in the course of an investigation, wouldn't the defense have the right to examine the device and cross-examine the responsible engineers to ascertain how it works and to ensure that the recovered information has not been tampered-with?
- gruez 7y agoNot if they use parallel construction
- stunt 7y agoThis is also a great advertisement to tell everyone we buy zero-days and information about backdoors!