5 ms·
Specifically, Apple says it can extract active user-generated data from native apps on passcode-locked iOS such as SMS, photos, videos, contacts, audio recordin
by sprite 12y ago
Specifically, Apple says it can extract active user-generated data from native apps on passcode-locked iOS such as SMS, photos, videos, contacts, audio recording, and call history.
Are they talking remotely or with device in hand?
- pilif 12y agoAccording to http://www.apple.com/legal/more-resources/law-enforcement/ http://www.apple.com/legal/more-resources/law-enforcement/ > The data extraction process can only be performed at Apple’s Cupertino, CA headquarters for devices that are in good working order. this can't be done remotely. Still. Why do they go through all the trouble with their encryption when they leave themselves a backdoor. Once a backdoor is in there, it'll be abused. Either by disgruntled employees or by everybody when it leaks.
- sprite 12y agoThanks!
- deleted 12y ago[deleted]
- Osmium 12y ago> Why do they go through all the trouble with their encryption when they leave themselves a backdoor. I am no means an expert on this, so someone else please correct me if I'm wrong, but I seem to remember reading that it's not so much a backdoor as much as there are only 9999 possible 4-digit passcodes (and most people only use 4-digit passcodes). The iPhone hardware rate-limits attempts to prevent you from brute-forcing it, but Apple can reflash the firmware to get around this, thus allowing them to be able to bruteforce the PIN. Whether this counts as a "backdoor" or not, I'm not sure. If that is true, then I imagine there'd be nothing they could do if you used a longer (random) password instead of a simple PIN.
- ghshephard 12y agoThere is nothing Apple can do if you use something other than a 4 digit passcode beyond trying to crack your password.
- nanofortnight 12y ago> Specifically, the user generated active files on an iOS device that are contained in Apple’s native apps and for which the data is not encrypted using the passcode (“user generated active files”), can be extracted and provided to law enforcement on external media. The keywords are "data [which] is not encrypted using the passcode".
- matthewmacleod 12y agoI think you're misinterpreting the guidelines; specifically: Upon receipt of a valid search warrant, Apple can extract certain categories of active data from passcode locked iOS devices. Specifically, the user generated active files on an iOS device that are contained in Apple’s native apps and for which the data is not encrypted using the passcode (“user generated active files”), can be extracted and provided to law enforcement on external media. In other words, the only data which can be extracted is data which is not encrypted on the device using the passcode. So I don't really think this qualifies as a backdoor; it's just that physical access to the device allows them to retrieve unencrypted data.
- pilif 12y agoI was of the opinion that iOS uses full disk encryption, throwing away the key when the device is locked. This is further substantiated by the fact that a full reset is now instantaneous whereas it took a while in the old days. In that case I wonder how some data can both be instantaneously be wiped but not be encrypted. Which is why I believe there to be a backdoor for the full disc encryption on the device. That's the only way how to reliably get access to the device when it's full disk encrypted and the key is not in memory any more.
- matthewmacleod 12y agoYou don't need to rely on an opinion; there's a fairly in-depth description of iOS security available direct from Apple: https://www.apple.com/ipad/business/docs/iOS_Security_Oct12.pdf https://www.apple.com/ipad/business/docs/iOS_Security_Oct12.... My understanding is that files under iOS are grouped into various classes with different levels of protection. Some data is under a class for which the key is discarded when the device is locked; this requires the passcode to be entered again before access can be gained. Some data doesn't have full protection applied to it - for example, the phone must be able to display the name of a caller even when locked, so it's intuitively obvious that contact names/numbers can't have this applied. I'm not sure exactly what the scope of each class is, but Apple do claim to be enable to retrieve things like mail, and if the implementation is as they describe then I see a limited scope for backdoored encryption - obviously it's always possible, but none of the information they've released about capabilities is contradictory.
- r00fus 12y ago> Why do they go through all the trouble with their encryption when they leave themselves a backdoor. Is it mandated by the government? I wouldn't be surprised if so.