3 ms·
Border Control Agents have been issued with devices that can copy the entire contents of your cell phone in a few minutes - the entire contents, using JTAG, of
by primitur 13y ago
Border Control Agents have been issued with devices that can copy the entire contents of your cell phone in a few minutes - the entire contents, using JTAG, of every storage device onboard.
If you've got bits encrypted, great - but there's a lot of stuff you can't encrypt in iOS and Android, in general, unless you work really hard at it ..
- superuser2 13y agoDon't know why this was downvoted. http://www.cellebrite.com/mobile-forensic-products/ufed-touch-ultimate.html http://www.cellebrite.com/mobile-forensic-products/ufed-touc... This device, advertised to law enforcement agencies, plugs into the phone (or sometimes connects by Bluetooth), exploits it, recovers deleted data, and copies all your texts, contacts, browsing history, GPS history, etc. to a flash drive for the operator. If it's an iPhone it can't exploit, the operator can copy some plists from your iTunes library (which you'd also have with you at a border crossing) onto the device, bypassing the PIN. Locking your phone or deleting data is pretty much worthless if you're trying to hide from well-equipped law enforcement agency.
- throwaway99783 13y agoI've worke for a few companies that make these products. They largely depend on public exploits. If you have a fully up-to-date iOS device the odds are lower that someone using one of these kits can image it without a passcode. The companies that make these kits are really dumb and employ bottom-of-the-barrel developers that aren't really capable of writing good code, let alone finding jailbreak-type bugs in mobile stuff. They also don't have the money (or the contacts) to buy the bugs, so, stick to phones that can't be jailbroken and you're probably safe against these imagers...
- primitur 13y agoSorry, but no. You may be correct about the incompetent developers of these devices, but the truly competent developers simply use JTAG and do a block-by-block NAND/Flash transfer. There is no protection against this.
- throwaway99783 13y agothe iphone doesn't have a live jtag, does it? you can only use the jtag interface on hardware if the hardware is cooperating (by design) with you, it isn't a magic wand you can wave and get everything... additionally, ios does on-flash encryption of the data partition and you need the phone online to read it (or to get the key), so even if you could get some magical jtag port to give you up all the blocks that store user data, it would be encrypted...
- primitur 13y agoThere are debug pins exposed on the standard iOS connector, yes - they may not be 'full JTAG' but they are there for manufacturing and testing purposes, and accomplish pretty much the same thing as you would normally use JTAG. And yes, you can do a full block copy - with the cooperation of the OS - if you know the back door. A lot of these Border Patrol devices depend on it.
- superuser2 13y agoI should add that these aren't primarily border control devices. Legitimate use-case would be searching a phone seized in an arrest after obtaining a wiretap order for it. They police end up using them to read your entire digital life as long as an officer says that, in his judgement, you may have been texting while driving.
- ams6110 13y agoYeah doesn't really make a lot of sense at the border. Nobody is going to deliberately bring any device with incriminating content over the border, not when you can easily get a new phone and laptop at WalMart for a couple of hundred bucks.
- comex 13y agoAs someone who wrote multiple iOS jailbreaks, the above post is entirely incorrect. (1) It is almost certain that JTAG is not exposed on an iPhone, as this would be a massive and obvious error on Apple's part, though I do not actually have proof of this. (2) No type of debug interface is exposed via the dock connector, as this would also be a massive security hole. Rather, as previously stated, imaging software uses exploits, often for bugs previously found by jailbreakers and since patched. (Note that people have used the kernel debugger over the serial interface on some dock connector pins, but only as a convenience after exploiting the kernel to enable this functionality. It is normally disabled.) (3) A raw block copy of the NAND is useless, because the data is encrypted using the UID key hidden in the hardware AES engine. (4) Even if you get an exploit running, some information (sensitive information minus the information that's required for operation while locked) is encrypted with the passcode. You can bruteforce the passcode, the process of testing a particular passcode requires using the aforementioned UID key, which you can only ask the hardware AES engine to encrypt and decrypt things with, not actually retrieve. Therefore, without some really powerful hardware attacks, bruteforcing must be conducted at a fixed rate on the phone itself, rather than offline on a compute cluster. If you use a 4 digit passcode, this isn't much help, since it doesn't take long to try 10,000 possibilities, but a good password will take a long time to bruteforce. Not perfect - among other things, as previously mentioned, you're screwed if they also have the computer you sync the phone with - but not bad. See: http://images.apple.com/iphone/business/docs/iOS_Security_Oct12.pdf http://images.apple.com/iphone/business/docs/iOS_Security_Oc...