10 ms·
Apple can comply with the FBI court order
- citizensixteen 11y agoThis is so far the clearest and easiest to understand explanation of the Apple/FBI case I have come across. Great read.
- jeffehobbs 11y agoGreat piece. Get thee to a "Secure Enclave" supported device, everyone.
- venomsnake 11y agoOr any rooted android. Good luck in defeating LUKS. No custom firmwares will help them.
- feld 11y agoa rooted android is probably easiest to own over the air with a push notification, so yeah, that's a great idea! NOT
- venomsnake 11y agoA powered down device rarely has that vulnerability.
- paraxisi 11y agoA powered down device isn't exactly terribly useful.
- 16bytes 11y agoYou can't send a powered down phone a push notification for post-hoc analysis. You would have had to know the target and push a vulnerability beforehand, which wouldn't have helped in this case.
- feld 11y agoSo power it on? It will still boot with encryption. Isn't Android encryption is an extension of ext4 and only protects some data. It's not full disk / LUKS last I knew.
- TACIXAT 11y agoCould you expand a little on what you're referring to? Is this a specific vulnerability?
- scintill76 11y agoMake sure you set high enough LUKS master key iteration counts, and/or very complex password, so that they can't image the LUKS header and brute-force your passphrase off-device.
- st3v3r 11y agoA rooted android is even less secure.
- venomsnake 11y agoIf you say so https://blog.torproject.org/blog/mission-impossible-hardening-android-security-and-privacy https://blog.torproject.org/blog/mission-impossible-hardenin...
- HillRat 11y agoJohn Kelley (@johnhedge), former Apple security engineer, says that Secure Enclave isn't protected against that kind of tampering, so that's not a solution, either. Until manufacturers start going to embedded HSMs, anyway.
- markyc 11y agoFBiOS :)
- nindalf 11y agoIndeed, this is precisely why Apple is writing an open letter. If this was an iPhone 6, they would have simply told the judge "no" and that would have been the end of the story. But since its a 5C, it is possible and Apple doesn't want to do it to avoid setting a precedent. If they cooperate with law enforcement to backdoor this phone, then they would face much more pressure to comply with any future laws that require backdoors be built-in.
- ikeboy 11y ago>Apple has allegedly cooperated with law enforcement in the past by using a custom firmware image that bypassed the passcode lock screen. If true, precedent has already been set.
- jk563 11y ago> This simple UI hack was sufficient in earlier versions of iOS since most files were unencrypted It probably wouldn't apply as precedent as it previously had nothing to do with encryption.
- cubano 11y agoIn the end, they will have no choice but to comply. Do people think this a game? Apple doesn't run things, the federal government does, and will, in the end, use it's full power to get what it desires.
- leereeves 11y agoI like to imagine that in the end the people run things. (I know, I know.) Apple may have to comply with this order (after appeals), but this also helps muster the troops for the battle against universal backdoors.
- matwood 11y agoAnd if they do have to comply this time, it would be nice if Apple were very vocal about continuing to make it impossible to comply in the future with newer iPhones.
- caf 11y agoMakes you wonder why the FBI bothered with the bit about submitting PIN guesses electronically, and didn't just ask for a firmware that looped over all 10,000 PINs until it found the right one.
- bryanlarsen 11y agoPerhaps the phone in question has a 6 digit PIN, so it's useful to try it non-sequentially.
- jkxyz 11y agoWould setting this precedent to enable brute-forcing the PIN on a less secure model really be that dangerous, then? This isn't a request to circumvent encryption on all models. It would be worrying if the government were asking for a backdoor into the Secure Enclave feature to retrieve the encryption keys, but that's nowhere near what this request is actually detailing. I still remain opposed to any kind of circumvention that reduces security, which this definitely does. Just questioning whether it's something to be so shocked about since it's not exactly far removed from the kind of requests that they have conformed to in the past.
- retube 11y agoThe FBI's position seems entirely defensible. The phone data may yield important information - accomplices, contacts etc. It also seems pretty disingenuous/hypocritical for Apple to plead "customer privacy" when the ENITRE BUSINESS MODEL of much of the smart phone and app industry (from which Apple directly benefit with a 30% commission) is predicated on abusing customer privacy.
- jonknee 11y ago> It also seems pretty disingenuous/hypocritical for Apple to plead "customer privacy" when the ENITRE BUSINESS MODEL of most of the smart phone and app industry is predicated on abusing customer privacy. Apple uses privacy as a major selling point. Apple has also proven very bad at abusing customer privacy for profit, they have even shuttered their own advertising service.
- feld 11y agoApple does not use customer data as part of their business model. This is a unique Google/Android feature.
- CaptSpify 11y agoWe don't actually know that. The best we can say is that don't seem to use customer data. I'm not saying they do, but, we can't demonstrably say they don't either.
- ogezi 11y agoit's a slippery slope.
- jlebrech 11y agowhy can't they just use a pin code robot https://www.youtube.com/watch?v=k_n5W69OdKM https://www.youtube.com/watch?v=k_n5W69OdKM
- feld 11y agoit would take forever. there's a timeout penalty for entering the wrong code.
- LordKano 11y agoBecause they don't want to spend the time. After too many incorrect pins, there's a time delay before another attempt can be made. The FBI is also thinking about the next time. They want to be able to take a phone, plug it in and brute force the PIN to gain access.
- centizen 11y agoI have a feeling it's more about setting the precedent, as others have said. There are strategies that can bypass the timeout periods and automatic wiping while bruteforcing, and I'd be surprised if the FBI didn't have at least one rig set up to do it.
- RandomBK 11y agoThere is a setting that makes the phone wipe all data after 10 failed attempts. While off by default, the FBI is worried that the setting is turned on.
- StreamBright 11y agoI am wondering if there is no other way to get in. There are lots of security researchers out there who can hack in to iOS or any other mobile os. Would not be it simpler to hire somebody who could do it? There are probably many ways to get access to this device other than guessing the pin. Update: In the meantime I was talking to my security engineer peers and it is not feasible to carry out an attack this way. The user partitions remains un-mounted until the PIN is provided after the boot.
- jonknee 11y ago> There are probably many ways to get access to this device other than guessing the pin. It's encrypted data using the PIN (and a key embedded in the phone). There's not another way in.
- StreamBright 11y agoThe problem is that you are thinking of offline access when encryption is relevant, what I am thinking about is online access, for example let the device boot, connect it to a familiar wifi access point that is modified to redirect the normal iOS traffic to a site that infects the phone with a malware that opens it to unauthorized access. I am not sure if it is feasible though.
- jonknee 11y agoThe phone can't decrypt itself, it literally doesn't know how.
- j_jochem 11y agoSo I've been wondering, since the PIN is obviously not a strong cryptographic secret, the way the encryption works is basically security by obscurity. All an attacker would have to to was clone the contents of the the device's SSD and somehow read the secret key that is embedded somewhere else. I'm not sure how feasible the latter part is, but surely this shouldn't be beyond the capabilities of US three-letter-agencies?
- pilif 11y agoI know my opinion is probably not popular, but if there was a way for Apple to physically install a firmware on a single device to allow for brute-forcing and if Apple did that in response to a direct court order, then this is probably the best compromise we can get. I really believe that there should be a way for law-enforcement to get access to specific devices in response to a court order as long as the solution doesn't involve weakening the encryption for everybody else. I'm absolutely against backdoors, secret* keys or similar crap. But physically access a single device in order to make brute-forcing it possible, that seems acceptable to me as that won't affect any other device. That would be similar to a court order allowing law enforcement to enter your premises and take out the safe in order to pry it open at some other location where specialised equipment is available. If this is all law enforcement wants, then maybe it's time to hand this over before law enforcement wants even more which will doubtless pave the way for mass surveillance of devices. * until they leak. Then everybody has access.
- Spoom 11y agoThe FBI's backup in this case to Apple agreeing to work with them might just be to force Apple to disclose their signing key for iOS disk images, which could potentially be worse since it would enable the FBI and not Apple to control on which device(s) the image was installed. From a PR standpoint, that might be better for Apple since they could argue that they did not cooperate in creating a bypass, but from a technical perspective, it would be much worse. Were I in Apple's position, I would probably do what Apple is doing here... but it's a harder question than just "should we cooperate?" They have to ask, "what if we don't?"
- pilif 11y agoI was of the opinion that apple is actually signing individual OS installs (using https://en.wikipedia.org/wiki/SHSH_blob https://en.wikipedia.org/wiki/SHSH_blob), so ultimately, apple would still be very much aware, if not totally in control of what firmware is installed where.
- bjacobel 11y ago> maybe it's time to hand this over before law enforcement wants even more which will doubtless pave the way for mass surveillance of devices. The FBI is already paving that way with this case. They don't overly care about access to this particular iPhone. They're taking this case through the courts so that they can establish a precedent that allows them to force manufacturer cooperation to unlock any phone. Edit: If they really cared about access to this individual phone, they wouldn't be going through the courts to get it; they'd be talking to the NSA TAO or other LEO with advanced forensic capability. As several people have pointed out, this iPhone 5C does not have a Secure Enclave and probably does not present a significant challenge to forensically analyze, to people that know what they're doing. They're going through the courts on this so they can get carte blanche to access iPhones 5S and above, which no LEO currently has capabilities to inspect. Further edit: This is Farook's work phone. His main, personal phone was found destroyed in a dumpster near the site of the attacks. I find it incredibly unlikely the FBI really cares much about the contents of this individual phone, they just want a high-profile test case to expand their surveillance capabilities.
- populacesoho 11y agoAgreed.
- exabrial 11y agoWe need to create devices that RESIST (warrantless,unconstitutional) mass surveillance and hide all of our data and metadata from everyone. Obama set a terrible precedent by warrantlessly scanning 'metadata' about who we contact. We're innocent by default, period. I agree with the first post. We need to be creative and find a way to resist government surveillance, and the piece where the engineering seems impossible is allowing an occasional breach of security for extreme circumstances. What's extreme? Well first, physical possession of the device should be required. Second, it should take resources only a nation-state would be able to afford. Want to decrypt an iPhone? It's going to cost > $5million in processing power. Any criminal would move on.
- sandycheeks 11y agoThe part that I find most interesting as a former enterprise systems administrator from the 90's is that the employer owns the device but does not have a pass code for it. Is this the normal IT policy for these kinds of devices?
- SSLy 11y agoMaybe? I work in 50-100k people software corporation, employer owns the phone and PC i use, but does not know phone pin or LUKS password.
- crystalmeph 11y agoIt's bad security to tell your manager your passcode/passwords, even for accounts they can get into through admin channels. The risk isn't the manager, the risk is that someone overhears you telling them the password, finds the piece of paper it's written on, etc.
- tkinom 11y agoWhat would happen when other governments, their court, their agencies make similar demand? The Pandora's box is opened?
- deleted 11y ago[deleted]
- zaroth 11y agoCrucially, this is software which doesn't currently exist in the world and which Apple has no intention of voluntarily writing. There is no specific law or regulation (like CALEA) which requires Apple to provide this functionality. What the FBI is attempting is to use 'All Writs Act' from 1789 which authorizes Federal courts to issue "all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law." Are there limits to what a judge can order a person, or a company, to provide? A warrant describes "the place to be searched, and the persons or things to be seized." I would not expect a judge can draft a warrant for something which doesn't actually exist, and then force someone to create it. This is not about providing physical access, or about producing documents which are in your possession. This is whether the government can usurp your workforce to make you create something that only you are capable of creating, against your will, not because there's actually a law which says you have to provide that capability, but simply because some investigator has probable cause that given such a tool they could use it to find evidence of a crime! If 'All Writs' somehow does give the government the ability to enslave software developers to creating this particular backdoor, what is there to legally differentiate this request from, for example, one that would function over WiFi or LTE remotely? There's been a lot of discussion about the 'secure enclave' and how this particular attack isn't possible on the iPhone 6. I think that's missing the point.... If 'All Writs' can force Apple to open a black-hat lab responsible for developing backdoor firmware for the 5C, then it can do the same for the 6. For example, why not force Apple to provide remote access to a suspect's device over LTE while the device is unlocked / in use? While we're at it, the iPhone has perfectly good cameras and microphones, let's force Apple to provide real-time feeds. Think about the sheer quantity of networked devices which exist (or will exist) in an average home which could be used in the course of an investigation. If they can force Apple to create a 5C backdoor, I can't see any reason they can't apply the same logic to WiFi cameras, Xbox Kinects, or even your cars OnStar. Heck, even TV remotes come with microphones and bluetooth now... And don't get me started on Amazon Echo! Fundamentally, the question is can you force a device manufacturer to implement backdoors into their products to be used against their own customers? Notably, service providers have already lost that battle, they are required to architect their systems to be able to spy on their users and provide that data to law enforcement, often through specially design real-time dashboards. At least in that case it is based on duly enacted legislation with that specific intent. But this is something really quite shocking -- can investigators, simply through obtaining a warrant, force companies to re-design the personal devices that we own and keep with us almost every moment of the day to spy on us? I truly hope not.
- spdustin 11y agoI wonder about the relevance of the case styled "United States v. Hubbell" (530 U.S. 27)† Specifically (emphasis mine): > ...the Self-Incrimination Clause ... may be asserted only to resist compelled explicit or implicit disclosures of incriminating information. Historically, the privilege was intended to prevent the use of legal compulsion to extract from the accused a sworn communication of facts which would incriminate him. -and- > ...the act of producing documents in response to a subpoena may have a compelled testimonial aspect. We have held that “the act of production” itself may implicitly communicate “statements of fact.” By “producing documents in compliance with a subpoena, the witness would admit that the papers existed, were in his possession or control, and were authentic.” -and- > Compelled testimony that communicates information that may “lead to incriminating evidence” is privileged even if the information itself is not inculpatory. † https://www.law.cornell.edu/supct/html/99-166.ZO.html https://www.law.cornell.edu/supct/html/99-166.ZO.html EDIT: Wikipedia summary of the case here: https://en.wikipedia.org/wiki/United_States_v._Hubbell https://en.wikipedia.org/wiki/United_States_v._Hubbell
- riskable 11y agoThis is all well and good but the 5th amendment doesn't apply to corporations. So United States v. Hubbell is irrelevant.
- geographomics 11y agoIf Apple can update the firmware of the Secure Enclave, could they not also write one that leaks out all the data contained within it? Presumably this could then be used for offline attacks against the image dumped from the phone's flash memory.
- lowbloodsugar 11y agoOne would hope that the Secure Enclave only allows itself to be updated after the PIN has been entered successfully.
- Fando 11y agoObviously government should not be allowed such power. Simply because it cannot be trusted. Everyone knows it will use this backdoor against everyone without limit. And everyone knows the lengths to which the US will go to spy on their people and everyone else. The fact that this request is being made is further evidence of the government's intentional malevolence. This behavior should not come as a surprise anymore. I mean any reasonable person by now knows what to expect from US government.
- ericmuyser 11y agoTechnically feasible, sure. But with a higher risk of introducing security vulnerabilities than most features.
- eridius 11y agoDespite the assertion of this article, it doesn't actually give any evidence to support the claim that Apple is capable of writing this backdoor. The important question is whether it's possible for Apple to update the OS on the phone (or to load a program into memory that runs on the phone) via DFU mode or something similar without triggering a wipe of the phone. And this article doesn't even acknowledge that question, it makes the blind assumption that this is possible. But is it? As far as I know, nobody has ever updated an iPhone over DFU mode without erasing the phone. It's plausible that Apple has the know-how to do that, but it's also plausible that the device firmware may have been written to trigger a wipe the moment any modification is made via DFU mode. As a side note, the author mentions that Apple has updated the Secure Enclave with increased delays in the past without wiping data, though they state that only Apple knows how it really works. I just want to put forth the theory that maybe the Secure Enclave allows its firmware to be updated if and only if the user's passcode is provided at the time the OS tells the Secure Enclave to prepare for a firmware update. That would be a reasonable way to ensure the Secure Enclave can't be subverted.
- growlix 11y agoThe security architecture described here seems pretty clever. Is this degree of security unique across mobile devices? If the phone in question was from a different manufacturer or ran a different OS, would the FBI have to ask its creator for help?
- pas 11y agoChrome OS was already doing chain of trust booting when it was first announced/revealed/open-sourced, but with maybe a hardware switch to enable flashing other loaders. (Since then that has been probably removed.) There are Android full disk encryption schemes, and of course phones with signed bootloaders. https://nerdland.net/unstumping-the-internet/pattern-unlock-after-android-full-device-encryption/ https://nerdland.net/unstumping-the-internet/pattern-unlock-... http://www.extremetech.com/mobile/216560-android-6-0-marshmallow-makes-full-disk-encryption-mandatory-for-most-new-devices http://www.extremetech.com/mobile/216560-android-6-0-marshma... What Apple did that was so valuable is providing a very clear, almost abstract implementation, from scratch, hitting every point along the way (randomized device private keys, read and execute only Secure Enclave, signed loaders, proper AES(-XTS?) full disk encryption, probably also requiring strong a password too, full lock after ~48 hours - sure, it'd be good if this could be customized to something lower).
- PascLeRasc 11y agoWhat I don't understand is why Apple can't just unlock the phone the same way that they would for any typical customer that forgot their passcode. I've never owned an iphone, what is the recovery process like for a typical customer that can't get into their phone?