3 ms·
> Nation states almost certainly have the ability to extract the private keys out of an image sensor and SEP. Outside of superpowers even if you're willing to d
by alwillis 15d ago
> Nation states almost certainly have the ability to extract the private keys out of an image sensor and SEP. Outside of superpowers even if you're willing to do it destructively. They can then sign their own fraudulent images.
That's not how this works.
Let's pretend they're able to extract the sensor key and the SEP key. Then what?
An attacker won't have the ECDSA P-256 over SHA-256 signed timestamp token from the Apple Push Notification Service.
When Reference mode starts, the operating system supplies a SHA-256 digest to be embedded at a fixed location in the captured frame’s metadata. The digest is computed from the most recent secure timestamp, the device manifest, and the device's secure boot manifest.
More encryption and checking happens until the secure digital negative is sent to Private Cloud Compute:
PCC recomputes the digest embedded in the frame and verifies the
sensor's signature over the pixels and that digest, verifying the
certificate chain back to the sensor CA. PCC also verifies the SEP
signature and chains it to the BAA CA, and it verifies the signature
on the device manifest and chains it to the CA that signs device
manifests at the factory. It then confirms that the sensor and SEP
named in those chains belong to the same device. Only if all these
checks pass does processing continue.
Only PCC can create an Apple Reference Image; an attacker having the image and sensor private keys doesn't enable them to create a reference image.
- monocasa 15d ago> An attacker won't have the ECDSA P-256 over SHA-256 signed timestamp token from the Apple Push Notification Service. Sure they can, they have everything needed to prove to Apple's servers that they're a real iPhone since pulling the keys means they have the cryptographic root of trust, and Apple's servers will happily be a signature oracle for them in that case. > When Reference mode starts, the operating system supplies a SHA-256 digest to be embedded at a fixed location in the captured frame’s metadata. The digest is computed from the most recent secure timestamp, the device manifest, and the device's secure boot manifest. And when you know what is measured into those manifests and the keys at the root of trust you can manufacture those too. The entire scheme is dependent on not being able to extract device specific keys. At the end of the day, those are almost certainly efuses burnt based on a on-chip HRNG as a manufacturing step which is intended to never leave the device, but instead only signatures and associated public keys. But when you have chip development hardware of the kind you'd have at a decent fabless semiconductor company, you can very clearly see burnt efuses.
- alwillis 15d agoI made a flow chart of the Apple Reference Image process; hopefully it clears up some misconceptions [1]. [1]: "How pixels become an Apple Reference Image" - https://news.ycombinator.com/item?id=49735284 https://news.ycombinator.com/item?id=49735284
- monocasa 14d agoThat matches what I said.