Does anyone know how much of a black box these cellebrite (or competitor) systems are?
Like if we could get some into the hands of the best reverse engineers in software and hardware, how difficult might it be to figure out the methods by which they gain access (aside from standard brute force and the like)? Are these unreleased zero day software exploits? Or something that anyone with enough knowledge of of the hardware system could implement with say a few million dollars and a small team of capable people? How are updates delivered? Do we know that the devices don't provide remote access to the vendor themselves?
I don't imagine they are super hard, if they require wifi or usb or JTAG access, you can just dump it and figure out what it is doing, its not going to be any harder than reversing any other explotiation technique.
There would be thousands, if not tens of thousands of people in the world who can do it. Its much harder to create the exploit than to reverse it.
It's a pity that we (likely including the journalist) don't know more about how the cops got access to the iPhone beyond cloud backups: the one thing I'm taking away from this article is that passcodes can still be brute forced.
I think that bruteforcing the passcode is an unlikely attack vector, if they do "brute force it" it likely wont be with apples OS running, it would be some kind of custom attack.
That's the point of the Secure Enclave, where the password keys are stored. It's designed to be impossible to image. Early attacks relied on pulling the power to the chip after it sent a failure message but before it updated the attempt counter, this is fixed on newer revisions to happen the other way around.
Are you a hardware engineer at apple speaking in official capacity? Not that I would believe that even you were. Of course the government can read their surveillance device.
Yes but with the controller built in and hardware hardening.
They are designed precisely to prevent this kind of attack.
I bet most of the exploits used by these boxes have nothing to do with the secure element but just bypass security using exploits in standard system or USB code. Most phones will be captured with the OS running but just the UI locked, with all encrypted volumes already mounted.
True but only if the user actually uses iCloud backup of course. I never did when I had an iPhone, for that reason, I don't want all my personal stuff in the cloud.
But this is not how cellebrite boxes work anyway. They focus on the device.
Along with this, the ISPs, phones and services online all have a close relationship with those requesting access from law enforcement. Rarely would most put up a fight for you or anyone else if your information was requested.
There are numerous ways for LE to view and manipulate your online experiences. Your phone can be viewed remotely like remote desktop over your cell connection without your knowledge. Defeating all end to end encryption in the process.
LE is given access to your application APIs and can control the results you get from job searches, your YouTube recommended videos and even the advertisements you are served.
Now you may think there are protections and they need a warrant. They do not in many cases. Most important to understand is that LE only has to follow the law and the rules if they want to use information they collect against you in court. Most requests do not go this far. So it is wide open for your information.
Even getting your phone and getting into it is easier than ever. However once you get here odds are it will face scrutiny in court.
I am hopeful a lot of this will continue coming out and being verified more officially. We live in a surveillance state and most people need to be educated about it.
This is very interesting. Would you be able to point to sources where we can learn more about these capabilities? A friend who is usually quite rational has lately been insisting this is happening to them (remote monitoring, harassment via search results and anything with an algorithmic feed). They haven't done anything wrong, but may have gotten on the wrong side of well-connected people, and are now concerned things could escalate (e.g. framing). If there were any indicators on their devices or elsewhere that they could look for, it could be helpful.
Is there any info yet on what kind of a phone the attacker had?
I still cannot find any article about this incident explicitly mentioning not even a specific model, but just whether it was Android or iOS at all.
While most of them keep referencing that old San Bernardino story where the attackers had an iPhone with an outdated security model even for the time of the incident (it was iPhone 5c iirc).
Don't know Apple, but Androids can be put into Bootloader and Recovery without password or pin. Most Recovery[s] give you access to the file system (if not, Bootloader can be used to install your own Recovery). Extract the files and run through whatever software you have for decryption.
Nexus 6 (late 2014), as well as rare Nexus 5X (2015), where owner enabled "OEM unlock" option.
Obscure Chinese brands made such android phones for few more years.
All Google Pixels (2016 and later), and virtually any android phone made after circa 2018 are safe from naive bootloader attack: user data is encrypted, plus you have to "OEM unlock" to even get the recovery to run.
Like if we could get some into the hands of the best reverse engineers in software and hardware, how difficult might it be to figure out the methods by which they gain access (aside from standard brute force and the like)? Are these unreleased zero day software exploits? Or something that anyone with enough knowledge of of the hardware system could implement with say a few million dollars and a small team of capable people? How are updates delivered? Do we know that the devices don't provide remote access to the vendor themselves?