4 ms·
Huh, I found this interesting, "Because the agents couldn’t bypass Malik’s password, they sent the phone to a forensics lab, which extracted all the phone’s dat
by b8 2y ago
Huh, I found this interesting, "Because the agents couldn’t bypass Malik’s password, they sent the phone to a forensics lab, which extracted all the phone’s data.", I wonder how they bypassed his password unless it wasn't fully encrypted. Well AFAIU my Pixel 6A is extractable even withe encryption and a long password via a cellebrite device now. Unsure if GrapheneOS would help prevent extraction.
- protimewaster 2y agoIt depends on a variety of factors, including whether the device has previously been unlocked after the most recent boot (AFU: after first unlock) or not (BFU: before first unlock). AFAIK, almost every device is more secure BFU.
- fph 2y agoIn their capabilities page, Cellebrite says they can't break into GrapheneOS.
- wkat4242 2y agoWow why would they give GrapheneOS such a marketing boost? I don't think they're lying, after all if they did they'd lie about much more common mobile OSes too. But personally I wouldn't inform the public of my weaknesses if I were a 'security/forensics' company.
- rfoo 2y agoBecause they want to advertise that they CAN break into phones loaded with GrapheneOS. Just not the latest version. Likewise they "announce" that they can't unlock BFU iPhone-s running latest iOS, and the real message is "we can unlock just slightly older iPhone-s and you may expect us to be able to unlock current version after few months".
- wkat4242 2y agoAh makes sense thanks!
- odo1242 2y agoSpecifically, they can only break into GrapheneOS if it’s missing a certain 2022 security patch
- prmoustache 2y agoSince most apps are syncing with something behind cloudflare, an AWS, Azure or GCP endpoint doing MiTM, I am pretty sure all they need is get a warrant and ask those companies to get a valid certificate, poison DNS and wait for the smartphone to give out its credentials to the forensic lab. People should never use apps that sync to something else than their own servers.
- chneu 2y agoHow would apps grant access to all the phones data though? Sure, they could intercept Google or Facebook or Microsoft, but I don't see how theyd get full access to the phone without an OEM helping them. Apps are sandboxed. I don't see how it's possible.
- jjav 2y ago> Apps are sandboxed. I don't see how it's possible. How many phone apps there are these days that are strictly local storage and don't communicate externally to anywhere? It's all cloud cloud cloud, which means it is most likely passing through one or more MITM points.
- odo1242 2y agoIf your phone has fingerprint unlock support, there’s usually a second chip (TPM, Secure Enclave, equivalents) that is in charge of providing the phone with its encryption key when the fingerprint lock is used. Finding a vulnerability in this chip can often be a way to get access. Also if the phone is on and was unlocked at least once, the encryption key is in memory somewhere and is vulnerable to regular old software exploits. (Both of the above can be prevented by shutting down the phone before the search attempt) Finally, if there’s a vulnerability that lets you reset the number of passcode attempts (which has to be loaded in memory somewhere, meaning a bootrom or kernel exploit could be used to modify it) and your passcode isn’t super long (4-digit PIN, some 6-digit PINs, pattern lock), it’s possible to make what is effectively a password guesser and use it to break the password lock within an hour or so.
- ratatoskrt 2y agoAFAIK most devices wipe the key from memory after a certain for this reason. My iPhone regularly forces me to enter my passcode instead of allowing me to use FaceID.
- OutOfHere 2y agoIt's not worth a gamble in case the key has not been wiped yet.
- odo1242 2y agoiPhone added this feature very recently (just a few months ago, it basically just randomly restarts the phone if it is unused and not connected to a network for over 24-48 hours - phones connected to a network can be erased via iCloud). Android doesn’t have it at all. There is a shortcut, however, on iOS to secretly put an iPhone into BFU mode - quick tapping the power button 5 times will lock the phone and erase the aforementioned in-memory keys so that it needs a password to unlock. (EDIT: it does not actually put the iPhone into BFU mode. It just disables biometrics.)
- OutOfHere 2y agoTo be clear, one can and probably should restart the phone after shutting it down, just so long as one doesn't login with the correct password. It might even be useful to enter the wrong password twice to further reset any memory imprints.