8 ms·
I was under the impression that decrypting storage actually requires the passcode of the phone, but this bug makes it look like the device is able to decrypt it
by sunaurus 4y ago
I was under the impression that decrypting storage actually requires the passcode of the phone, but this bug makes it look like the device is able to decrypt itself without any external input.
Does anybody know more context about this? What's the point of encryption if the device can just essentially backdoor decrypt itself?
- deleted 4y ago[deleted]
- dgl 4y agoIn the write-up search for the bit that says "and one time I forgot to reboot the phone". tl;dr: It's not an encryption bypass, it bypasses the lock screen once the phone has been unlocked once.
- perlgeek 4y agoIt seems to me this bug appears when a phone is booted, unlocked (and decrypted) once, and then locked again, but the decryption key still stays in memory.
- Gilboboy 4y agoThis is virtually always the case with these kinds of vulnerabilities on smartphones. Security researchers often say whether an attack or vulnerability is possible "before/after first unlock" in reference to the fact that the security is a totally different story if the phone has been unlocked/decrypted since last boot.
- tyingq 4y agoIt didn't work on a fresh reboot, so presumably, it functioned like you're describing. But, when he swapped the sim live, without the reboot, the phone was already running with the key in memory.
- gcr 4y agoOn iPhone, keys are evicted from memory when the device is locked. Apps running behind the Lock Screen can only write files to special file inboxes (this is why the camera lets you take pictures while locked but doesn’t display earlier pictures, for example) You’re telling me that android keeps keys in memory for its entire uptime?
- foobarian 4y agoOf course we won’t see analogous bug fixes on the Apple side so we can’t compare too closely. Unless you worked on this codebase :-)
- klausa 4y agoThat's not exactly true. There is a data protection class that is like what you're describing, but it is not used super-widely, the one most commonly used is exactly what is being described and makes data available after first unlock. https://developer.apple.com/documentation/security/ksecattraccessibleafterfirstunlock?language=objc https://developer.apple.com/documentation/security/ksecattra...
- Twisell 4y agoMaybe but this should be limited to application data scope. What baffles me is that lock-screen is a system wide critical application and should in no way rely on this method. iOS lock screen in theory shouldn't only respond to cryptographic validation from the secure enclave.
- gcr 4y agooh huh! thanks for the correction!
- 4y ago
- chrisfosterelli 4y agoThe passcode is required to get access to anything the first time you start the phone, for the reason you mention, and after that the password is retained in the trusted execution environment. This way apps can continue to function in the background while the phone is locked and you can unlock with alternative methods like fingerprints or face recognition.
- ngm___ 4y agoIt was a fresh boot, and instead of the usual lock icon, the fingerprint icon was showing. It accepted my finger, which should not happen, since after a reboot, you must enter the lock screen PIN or password at least once to decrypt the device. i was surprised to read this part too. assuming that the author's version of the events are accurate here, my best guess is that the device had not fully powered down, and was in either a low-power/hibernate or find-my-phone mode, where portions of the security subsystem were still powered, hence the device-unlock PIN was still cached. i don't otherwise see how else a fingerprint alone would allow for the device to be unlocked on cold boot. of course this detail doesn't take away from the rest of the report - great find xdavidhu!
- tech234a 4y agoDoesn’t seem like a full unlock, see the next paragraph: “After accepting my finger, it got stuck on a weird “Pixel is starting…” message, and stayed there until I rebooted it again.”