3 ms·
Does that even make sense from a technical perspective? They are talking about a PIN code to unlock the phone to access the data on the phone. Could they not ju
by berndi 7y ago
Does that even make sense from a technical perspective?
They are talking about a PIN code to unlock the phone to access the data on the phone. Could they not just remove the memory chip and access it directly? Even if the data on it is encrypted using a 6-digit PIN, brute-forcing that should be a trivial task.
- mikeash 7y agoIf it’s an iPhone, the data is encrypted with a key derived from the PIN and a random key that is baked into the phone’s CPU. The CPU has instructions for encrypting and decrypting with this secret key but no instruction for reading the key directly. Short of decapping the chip and going in with an electron microscope to figure out what this key is, your only option is to brute force on the phone’s own CPU. But that CPU won’t run software that isn’t signed by the manufacturer, and that software imposes ever-increasing timeouts when unlock attempts fail.
- nradov 7y agoSo why don't they decap the chip and go in with an electron microscope? Has that type of exploit ever been successfully used against modern devices, or is it only a theoretical vulnerability?
- Faark 7y agoUsually, you don't want to work with the original, only on copies. Here we are talking about a one shot attempt to get info by destroying the hardware... I can see those people searching for any other way first.
- dogma1138 7y agoBecause it’s highly unlikely to work in the first place, not to mention likely cost as much as their annual operating budget.
- kube-system 7y agoMostly the former. There’s nothing expensive about decapping a chip and tossing it under an electron microscope.
- mikeash 7y agoHow much time and effort would it take to go from a chip under an electron microscope to the embedded crypto key, though? Seems like a substantial reverse engineering effort. (Although only for the first time you do a particular type of chip.)
- dogma1138 7y agoAn electron microscope alone won’t work not to mention you have a high likelihood of damaging to chip as the voltage of the electrons deposited on the sample can exceed what the IC can tolerate. You need a cryo probing station of some sort I’m not sure if these even exist for 12/10/7nm logic yet.
- dogma1138 7y agoA it’s not just an electron microscope but a cryo probing stations for sub 22nm lithography are insanely expensive. You can’t simply decap and image a multi layer chip it’s not 80’s era masked rom.
- egorfine 7y agoIt's a perfectly feasible exploit to extract 64, 256 or 512GB of strongly encrypted data.
- nradov 7y agoIs there documentation for someone having actually done this on a modern iPhone?
- deleted 7y ago[deleted]