iPhone encryption broken


Recommended Posts

AN INSECURITY EXPERT has warned that the Iphone's built-in encryption software, which has helped to make the posy device so popular with businesses, is about as useful as a chocolate teapot.

"I don't think any of us have ever seen encryption implemented so poorly before," Iphone developer and data recovery expert Jonathan Zdziarski told Wired.

Zdziarski reckons the encryption feature on the Iphone 3GS is simply "broken" and makes it easier to extract personal data from an Iphone 3GS than it was to obtain from its two predecessors which had no encryption utility.

Live data can be extracted in two minutes from a 3GS, and a full disk image can be transferred to a PC within about 45 minutes by installing a custom kernel on the phone using readily downloadable tools such as Purple Ra1n or Red Sn0w.

The remote kill feature can be circumvented simply by removing the SIM card to prevent the signal from being received.

The news will probably come as a shock to the many businesses that have been seduced into buying the pretty toy thinking it was safe for corporate applications.

When Apple's upbeat results were announced last Tuesday, Apple's chief operating officer, Tim Cook, was bragging that millions of Iphones have been bought by Fortune 100 companies, US Government departments and universities.

Perhaps they would like to form an orderly queue outside One Infinite Loop to ask for their money back. ?

http://www.theinquirer.net/inquirer/news/1...cryption-broken

Link to comment
https://www.neowin.net/forum/topic/801384-iphone-encryption-broken/
Share on other sites

The encryption isn't "broken" per se - just it can be bypassed using the regular jailbreaking techniques to replace the kernel, then SSH'ing in to dump a copy of the phone's memory.

if you can get someones data that was supose to be "encrypted" then it's technically broken

What exactly does the encryption on the 3GS do? Just because they can jailbreak and ssh in and copy data doesn't mean anything if the data is actually encrypted?

I have to concur with this. If the data has been encrypted, I fail to see how someone will be able to access the content of the data.

I am assuming even if one knows the Encryption algorithm, accessing the Key without the Users Login details via the Kernel (or finding the Database entry) will be impossible.

If however the hacker is claiming the mechanism in which the Encryption key is stored and accessed can be circumvented to learn the key without the Login Details, or using a new Kernel (maybe the iPhone kernel does something unwise at some point storing something in clear text and a new custom kernel can read that) to get the login details without the original user present, thus eventually learning the Decryption key for the phones data. That would be something I would consider broken. However, if he/she is only getting a dump of the memory, this is less broken more obvious someone would be able to do it at one point or another. After all, it is all stored in memory, which can be read.

So a nameless cracker from an article posted on the inquirer now gets treated as fact? LOL, if it's broken Apple will fix it, non-event.

Um, he's not some nameless hacker / cracker... he's one of the first people to hack the iPhone and even wrote a book on how to write apps for it even before there was an SDK for it (non-web apps)

http://www.oreillynet.com/pub/au/1861

Um, he's not some nameless hacker / cracker... he's one of the first people to hack the iPhone and even wrote a book on how to write apps for it even before there was an SDK for it (non-web apps)

http://www.oreillynet.com/pub/au/1861

Well I stand corrected, but my point stands, it's only an issue is Apple doesn't correct it.

Um, he's not some nameless hacker / cracker... he's one of the first people to hack the iPhone and even wrote a book on how to write apps for it even before there was an SDK for it (non-web apps)

http://www.oreillynet.com/pub/au/1861

Funny how that guy does something illegal, yet is also helping law enforcement. Kinda hypocritical of himself and law enforcement for having anything to do with him. But then again this world is full of hypocrites.

There had to have been some backdoor, bug, or something for his "hack". You don't crack encryption in 2 minutes.

I read the original article the Inquirer is linking to. That article says the following:

Wondering where the encryption comes into play? It doesn’t. Strangely, once one begins extracting data from an iPhone 3GS, the iPhone begins to decrypt the data on its own, he said.

Watch the first video and it is exactly what he says.

The problem is not the encryption that is being used, it's all about how it's being used. That's a software problem and can be fixed by Apple (in the video the guy calls it a operating system design flaw, which it is).

The article itself is quite lame. The mentioned security problems/risk are not something that is limited to the iPhone. Mobile devices like the iPhone or a laptop are always a security risk! If the data is sensitive you do not let people take it with them, period. That's why a lot of companies forbid the use of any mobile device like a smartphone, laptop and even the usb sticks. Also, the encryption on something like the iPhone can be useless even if it works properly. Why? Because the service itself can be hacked (like email). If you want security you need to think bigger than just the mobile device and encrypting it. That also means thinking about how not to get it stolen in the first place, as well as securing the service you use on the mobile device (like mail, im, etc.). In other words: the warning on the end of the first video doesn't count for the iPhone, it counts for every mobile device!

The other problem I have with the demonstration: the same device with the same useraccount and the same iTunes is being used. That's not a good way of showing the problem. That would mean the thief would need to steal your iPhone and the machine you sync your iPhone to and hack that machine to hack the iPhone. Yeah..that makes sense... It would have been better if he used a completely different machine because that would really proof his point: the thief steals the iPhone and uses his own machine to hack it. Now he makes it completely unlikely this is a huge security risk since you need to steal a lot more than just the iPhone.

Edited by dyn
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The limited imaginations and business acumen of non-dominant players is simply that: the abject lack of creative business acumen. Businesses often want to operate in a financially-rewarding marketplace (free market economics) and/or exit/cash-out at maximal financial recompense. Money is their incentive; regulations are both their obstacles and their tools; politics is their means of influencing the marketplace. Google, in this story's example, is crying that AWS and Azure are "too dominant" -- cuz Google Cloud is not printing as much money as Alphabet wants (although it is still dramatically more than they actually need). The EU DMA should truly follow-the-money and treat the EU as its own sovereign nation in order to protect European market players: Domestic entities are exempt from market-influence regulations until absolute monopoly is achieved; Foreign (non-EU/non-Euro) entities are all regulated via stricter DMA measures whereby regulated partnership with independent domestic entity becomes the only way for foreign entities to 'tip the scale' for favorable financial remunerations. Basically create a dual-track aligning with China's foreign investment models. In my eyes, this is the only way to properly protect the European marketplace beyond the current dot-com/ai-bubble/social-media crazes.
    • I have a fire n ice theme w my bedroom laptops. one is a red lenovo gaming laptop (fire) and the precision is ice
    • Adobe Acrobat Reader DC 2026.001.21691 by Razvan Serea Adobe Acrobat Reader DC software is the free, trusted standard for viewing, printing, signing, and annotating PDFs. Its the only PDF viewer that can open and interact with all types of PDF content – including forms and multimedia. It’s connected to Adobe Document Cloud – so you can work with PDFs on computers and mobile devices. Adobe Document Cloud is a revolutionary, modern and efficient way to get work done with documents in the office, at home or on-the-go. At the heart of Document Cloud is the all-new Adobe Acrobat DC, which will take e-signatures mainstream by delivering free e-signing with every individual subscription. Document Cloud includes a set of integrated services that use a consistent online profile and personal document hub. With Adobe Document Cloud, people will be able to create, review, approve, sign and track documents whether on a desktop or mobile device. Businesses will be able to take advantage of Document Cloud for enterprise which provides enterprise-class document services that integrate into systems of record such as CRM, HCM, CLM, and CMS, adding speed, efficiency and transparency to getting business done with documents. Adobe Acrobat Reader DC new feature highlights: Work with PDFs from anywhere with the new, free Acrobat DC mobile app for Android or iOS. Select functionality is also available on Windows Phone. Use the new Fill & Sign tool in your desktop software to complete PDF forms fast with smart autofill. Download the free Adobe Fill & Sign mobile app to add the same option to your iPad or Android tablet device. Save money on ink and toner when printing from your Windows PC. Store and access files in Adobe Document Cloud with 5GB of free storage. Get instant access to recent files across desktop, web, and mobile devices with Mobile Link. Sync your Fill & Sign autofill collection across desktop, web, and iPad devices. Adobe PDF Pack premium features includes: Convert documents and images to PDF files. Use your mobile device camera to take a picture of a paper document or form and convert it to PDF. Turn PDFs into editable Microsoft Word, Excel, PowerPoint, or RTF files. Combine multiple files into a single PDF (web only). Get signatures from others with a complete e-signature service. Send, track, and confirm delivery of documents electronically instead of using fax or overnight services (tracking not available on mobile). Store and access files online with 20GB of storage. Download: Adobe Acrobat Reader DC 64-bit | 719.0 MB (Freeware) Link: Adobe Acrobat Reader DC Home Page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Hello, Interesting. I suspect memory and storage costs have slowed the rollout of Windows 11-compatible hardware for some customers. Regards, Aryeh Goretsky
  • Recent Achievements

    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      404
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      131
    4. 4
      Xenon
      72
    5. 5
      Michael Scrip
      71
  • Tell a friend

    Love Neowin? Tell a friend!