Apple And The FBI: Intended And Unintended Consequences Of An iPhone Backdoor

A federal judge ordered Apple to comply with the FBI’s request for technical assistance in the recovery of data from the San Bernardino gunman’s iPhone 5C. The FBI wants Apple to create a custom backdoored firmware for the iPhone 5C that will disable some security features such as the PIN rate limiters and the feature that auto-erases after 10 failed attempts. Then, it wants Apple to push that update to certain phones so the FBI can brute-force them in minutes or hours. This sort of request has both intended (by the FBI) and unintended consequences.

Latest Videos FromTom's Hardware
TOPICS
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • g-unit1111
    This is why I will never use a phone pay system, or buy a car that has an app to start it from your phone. I do stand with Apple and FFTF on this one.
    Reply
  • LORD_ORION
    Remember when the US used to make fun of these commie totalitarian behaviors in cartoons? There would be a sweet little girl reading a letter from her pen pal, except the voice over was some burly hairy goon speaking in a Slavic accent.

    Reply
  • TwoDigital
    I thought the FBI was supposed to be this super-smart group of cyber-criminal trackers. If they HAVE the phone, why can't they just read data right from the memory chip and then brute-force it in an environment that doesn't have a 10-chances-and-it-blows-up keycode? Also, if they google this, they can buy this: https://www.intego.com/mac-security-blog/iphone-pin-pass-code/ ... just saying.
    Reply
  • DeadlyDays
    probably because this isn't about cracking the phone, it is about the FBI, amongst other US groups, to establish a prerogative for companies to comply with requests to break/decrypt secured devices.

    I would be incredibly surprised if they didn't have the technology to clone the device virtually and run dozens if not hundreds of instances to break into it bruteforce style. Like it says in the article, if there is a precedent than a judge unfamiliar with technology may misunderstand it and the fbi and others could use it to force companies to do this for situations where it is much, much harder/nearly impossible to break in via bruteforce.
    Reply
  • chicofehr
    I think what they want is for apple to circumvent the 10 attempts limit which in itself would reduce the value of encryption. of course like others said, cloning the memory chip itself and cracking it in a virtual environment would make more sense.
    Reply
  • InvalidError
    17519645 said:
    Also, if they google this, they can buy this: https://www.intego.com/mac-security-blog/iphone-pin-pass-code/ ... just saying.
    When the FBI wants to access a device, they usually do not want to wait several hours or days to get in - that's assuming the data self-destruct does not get triggered in the meantime.

    For devices with Secure Enclave backed encryption and equivalents, duplicating the eMMC does you no good since the non-readable UID code hidden inside the Secure Enclave used to generate encryption keys is not externally accessible - Apple claims the hardware lacks any ability for the software/firmware to read the UID back after it is written. That limits you to having to go through the Secure Enclave's 80ms key generation latency for each password guess attempt or directly brute-forcing the 128+ bits file/block encryption.
    Reply
  • d_kuhn
    I thought the FBI was supposed to be this super-smart group of cyber-criminal trackers. If they HAVE the phone, why can't they just read data right from the memory chip and then brute-force it in an environment that doesn't have a 10-chances-and-it-blows-up keycode? Also, if they google this, they can buy this: https://www.intego.com/mac-security-blog/iphone-pin-pass-code/ ... just saying.

    I'm sure they can do just that on older phones... but they're also cheap and lazy... right now they have to REALLY want that data in order to pay what it would cost to disassemble the phone and manually extract the stored data. This law gives them a cheap way to do the same thing and makes it easy to distribute that capability to other agencies and use in less serious situations. I'm sure the goal of this move is not to get the data on that particular phone (I'd be surprised if they don't already have it) but rather to weaken phones to cheap/wide access from government agencies.
    Reply
  • bloodroses75
    What I don't get about this whole thing is that it is illegal to internationally travel between some countries with encrypted electronic devices. So, does this mean that every person that has an iPhone is breaking the law if they internationally travel with their phone?

    https://www.princeton.edu/itsecurity/encryption/encryption-and-internatio/
    (one of many links about the subject)
    Reply
  • none12345
    I rarely get to say kudos to apple. But stick to your guns apple, don't cave to that BS.

    Destroying personal liberty/security in the name of protecting you against terrorism, means the terrorists have already won.
    Reply
  • targetdrone
    I think what they want is for apple to circumvent the 10 attempts limit which in itself would reduce the value of encryption. of course like others said, cloning the memory chip itself and cracking it in a virtual environment would make more sense.
    I think what they want is for apple to circumvent the 10 attempts limit which in itself would reduce the value of encryption. of course like others said, cloning the memory chip itself and cracking it in a virtual environment would make more sense.

    We are talking about a government agency here. Making sense is against the rules.
    Reply