iPhone encryption broken


Recommended Posts

AN INSECURITY EXPERT has warned that the Iphone's built-in encryption software, which has helped to make the posy device so popular with businesses, is about as useful as a chocolate teapot.

"I don't think any of us have ever seen encryption implemented so poorly before," Iphone developer and data recovery expert Jonathan Zdziarski told Wired.

Zdziarski reckons the encryption feature on the Iphone 3GS is simply "broken" and makes it easier to extract personal data from an Iphone 3GS than it was to obtain from its two predecessors which had no encryption utility.

Live data can be extracted in two minutes from a 3GS, and a full disk image can be transferred to a PC within about 45 minutes by installing a custom kernel on the phone using readily downloadable tools such as Purple Ra1n or Red Sn0w.

The remote kill feature can be circumvented simply by removing the SIM card to prevent the signal from being received.

The news will probably come as a shock to the many businesses that have been seduced into buying the pretty toy thinking it was safe for corporate applications.

When Apple's upbeat results were announced last Tuesday, Apple's chief operating officer, Tim Cook, was bragging that millions of Iphones have been bought by Fortune 100 companies, US Government departments and universities.

Perhaps they would like to form an orderly queue outside One Infinite Loop to ask for their money back. ?

http://www.theinquirer.net/inquirer/news/1...cryption-broken

Link to comment
https://www.neowin.net/forum/topic/801384-iphone-encryption-broken/
Share on other sites

The encryption isn't "broken" per se - just it can be bypassed using the regular jailbreaking techniques to replace the kernel, then SSH'ing in to dump a copy of the phone's memory.

if you can get someones data that was supose to be "encrypted" then it's technically broken

What exactly does the encryption on the 3GS do? Just because they can jailbreak and ssh in and copy data doesn't mean anything if the data is actually encrypted?

I have to concur with this. If the data has been encrypted, I fail to see how someone will be able to access the content of the data.

I am assuming even if one knows the Encryption algorithm, accessing the Key without the Users Login details via the Kernel (or finding the Database entry) will be impossible.

If however the hacker is claiming the mechanism in which the Encryption key is stored and accessed can be circumvented to learn the key without the Login Details, or using a new Kernel (maybe the iPhone kernel does something unwise at some point storing something in clear text and a new custom kernel can read that) to get the login details without the original user present, thus eventually learning the Decryption key for the phones data. That would be something I would consider broken. However, if he/she is only getting a dump of the memory, this is less broken more obvious someone would be able to do it at one point or another. After all, it is all stored in memory, which can be read.

So a nameless cracker from an article posted on the inquirer now gets treated as fact? LOL, if it's broken Apple will fix it, non-event.

Um, he's not some nameless hacker / cracker... he's one of the first people to hack the iPhone and even wrote a book on how to write apps for it even before there was an SDK for it (non-web apps)

http://www.oreillynet.com/pub/au/1861

Um, he's not some nameless hacker / cracker... he's one of the first people to hack the iPhone and even wrote a book on how to write apps for it even before there was an SDK for it (non-web apps)

http://www.oreillynet.com/pub/au/1861

Well I stand corrected, but my point stands, it's only an issue is Apple doesn't correct it.

Um, he's not some nameless hacker / cracker... he's one of the first people to hack the iPhone and even wrote a book on how to write apps for it even before there was an SDK for it (non-web apps)

http://www.oreillynet.com/pub/au/1861

Funny how that guy does something illegal, yet is also helping law enforcement. Kinda hypocritical of himself and law enforcement for having anything to do with him. But then again this world is full of hypocrites.

There had to have been some backdoor, bug, or something for his "hack". You don't crack encryption in 2 minutes.

I read the original article the Inquirer is linking to. That article says the following:

Wondering where the encryption comes into play? It doesn’t. Strangely, once one begins extracting data from an iPhone 3GS, the iPhone begins to decrypt the data on its own, he said.

Watch the first video and it is exactly what he says.

The problem is not the encryption that is being used, it's all about how it's being used. That's a software problem and can be fixed by Apple (in the video the guy calls it a operating system design flaw, which it is).

The article itself is quite lame. The mentioned security problems/risk are not something that is limited to the iPhone. Mobile devices like the iPhone or a laptop are always a security risk! If the data is sensitive you do not let people take it with them, period. That's why a lot of companies forbid the use of any mobile device like a smartphone, laptop and even the usb sticks. Also, the encryption on something like the iPhone can be useless even if it works properly. Why? Because the service itself can be hacked (like email). If you want security you need to think bigger than just the mobile device and encrypting it. That also means thinking about how not to get it stolen in the first place, as well as securing the service you use on the mobile device (like mail, im, etc.). In other words: the warning on the end of the first video doesn't count for the iPhone, it counts for every mobile device!

The other problem I have with the demonstration: the same device with the same useraccount and the same iTunes is being used. That's not a good way of showing the problem. That would mean the thief would need to steal your iPhone and the machine you sync your iPhone to and hack that machine to hack the iPhone. Yeah..that makes sense... It would have been better if he used a completely different machine because that would really proof his point: the thief steals the iPhone and uses his own machine to hack it. Now he makes it completely unlikely this is a huge security risk since you need to steal a lot more than just the iPhone.

Edited by dyn
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Stellarium 26.2 by Razvan Serea Stellarium is a free open source planetarium for your computer. It shows a realistic sky in 3D, just like what you see with the naked eye, binoculars or a telescope. It is being used in planetarium projectors. Just set your coordinates and go. Stellarium key features: Realistic simulation of the sky, sunrise and sunset Default catalogue of over 600,000 stars Downloadable additional catalogues for up to 210 million stars Catalog data for all New General Catalogue (NGC) objects Images of almost all Messier objects and the Milky Way Artistic illustrations for all 88 modern constellations More than a dozen different cultures with their constellations Solar and lunar eclipse simulation Photorealistic landscapes (more are available on the website) Scripting support with ECMAScript (a few demo scripts are included) Extendable with plug-ins: 8 plug-ins installed by default, including: artificial satellites plug-in (updated from an on-line TLE database) ocular simulation plug-in (shows how objects look like in a given ocular) Solar System editor plug-in (imports comet and asteroid data from the MPC) telescope control plug-in (Meade LX200 and Celestron NexStar compatible) The major changes of this version: Added new sky culture Added new plugin: Planes Many improvements in plugins Many improvements in Core and GUI Many updates in sky cultures. [full release notes] Download: Stellarium 26.2 (64-bit) | 456.0 MB (Open Source) View: Stellarium Home Page | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • NASA: This asteroid may not kill us but it probably won't be far off either by Sayan Sen Image by Zelch Csaba via Pexels New observations by NASA's James Webb Space Telescope have eliminated the last remaining impact threat posed by asteroid 2024 YR4, ruling out the possibility that the near-Earth object could strike the Moon in December 2032. NASA said observations collected by Webb on February 18 and 26, 2026, enabled scientists to refine the asteroid's orbit enough to "rule out a chance of lunar impact on Dec. 22, 2032." Instead, asteroid 2024 YR4 is now expected to pass the Moon at a distance of about 13,200 miles (21,200 km). The agency stressed that the update "reflects improved precision in our understanding of where the asteroid is expected to be in 2032 rather than a shift in its orbital path." The announcement closes a remarkable chapter in planetary defence that began in late 2024, when the approximately 60-metre-wide asteroid briefly became the most closely watched near-Earth object in the world. Discovered on December 27, 2024, by the ATLAS telescope in Chile, 2024 YR4 initially appeared to have a small chance of colliding with Earth on December 22, 2032. As astronomers gathered more observations, the impact probability briefly climbed to around 3%—the highest ever recorded for an asteroid of its size—before steadily falling as its orbit became better understood. By early 2025, international observations had ruled out any significant risk to Earth. However, astronomers were left with another possibility: a roughly 4% chance that the asteroid could instead strike the Moon. "The probability that asteroid 2024 YR4 will strike the Moon on 22 December 2032 is now approximately 4%," the European Space Agency (ESA) had said last year, noting that "there is a 96% chance that the asteroid will not impact the Moon." ESA said such an impact, while unlikely, would have presented an extraordinary scientific opportunity. "It is a very rare event for an asteroid this large to impact the Moon – and it is rarer still that we know about it in advance. The impact would likely be visible from Earth, and so scientists will be very excited by the prospect of observing and analysing it," said Richard Moissl, Head of ESA's Planetary Defence Office. "It would certainly leave a new crater on the surface. However, we wouldn't be able to accurately predict in advance how much material would be thrown into space, or whether any would reach Earth," he added. The asteroid also exposed an important blind spot in planetary defence. Because 2024 YR4 approached Earth from the direction of the Sun, it remained hidden from ground-based telescopes until after its closest approach. "We looked into how Neomir would have performed in this situation, and the simulations surprised even us," Moissl said. "Neomir would have detected asteroid 2024 YR4 about a month earlier than ground-based telescopes did. This would have given astronomers more time to study the asteroid's trajectory and allowed them to much sooner rule out any chance of Earth impact in 2032." He added, "As an infrared telescope, like Webb, Neomir would have also immediately given us a much better estimate for the asteroid's size, which is very important for assessing the significance of the hazard." The latest NASA observations underscore the value of space-based infrared telescopes in tracking faint asteroids. According to NASA, Webb made "among the faintest ever observations of an asteroid," extending the object's observational record by nearly eight months at a time when it had become too faint for other telescopes. That additional data allowed scientists to eliminate the remaining uncertainty surrounding its 2032 flyby. Although asteroid 2024 YR4 is now confirmed to pose no threat to either Earth or the Moon, scientists say its discovery remains one of the most significant real-world tests of the international planetary defence system, demonstrating how continued observations can rapidly transform an object once considered hazardous into one whose future path is known with high confidence. Source: NASA, ESA This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing.
    • Yup. Google is just scraping the entire internet for their own ad profits without sharing revenue with the sources. It's obviously stealing, but since these sites depend upon Google's search scraps to survive... As for me, I just stopped using Google for anything except Reddit searches. If Reddit's own search wasn't complete crapola, I'd never use Google search again.
  • Recent Achievements

    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
    • Apprentice
      daryld went up a rank
      Apprentice
    • Contributor
      Carltonbar went up a rank
      Contributor
    • One Month Later
      The_Focal_Point earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      418
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      130
    4. 4
      Xenon
      69
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!