Feeds

iOS 4 hardware encryption cracked

‘We don’t want this to fall into the wrong hands’

7 Elements of Radically Simple OS Migration

Russian security outfit ElcomSoft is shipping a toolset that cracks open the hardware encryption protecting iOS4-based iPhones – but it's only for spooks and law enforcement.

In an announcement that will have black-hats working to replicate its results, the company says its tool can “extract all relevant encryption keys from iPhones running iOS 4,” and can also use those keys to “decrypt iPhone file system dumps.”

Vladimir Katalov, ElcomSoft CEO, says the tool breaks “into the heart of iPhone data encryption”.

With access to the device (a prerequisite for ElcomSoft’s technique), the software uses its unique ID and escrow keys (which exist to allow remote devices to sync with the iPhone) to access data.

According to this H Online article, data can only be extracted from an iPhone that’s booted in Device Firmware Upgrade mode, which allows direct copying of data on the Flash drive. This breaks iOS’s protection of the keys themselves, which are not visible to applications running in normal mode.

However, breaking the keys is slow. When files are decrypted, two keys are required – the one generated by the user’s passcode, as well as the key created by iOS Data Protection. H Online said the demonstration given to it required 40 minutes to brute-force a four-digit passcode.

While it might also be feasible to brute-force the escrow key stored on a computer to which the iPhone syncs, that approach has both pros and cons: a PC offers a faster platform for guessing keys, but the escrow key is larger than a typical user’s passcode.

ElcomSoft promises to guard the tool closely, with Katalov saying “we made a firm decision to limit access to this functionality to law enforcement, forensic and intelligence organisations and select government agencies”.

ElcomSoft had already demonstrated password recovery from iPhone 4 devices, last year.

Whether or not you think the police are the ‘right hands’ for this technology probably depends on whether or not you’ve had a device wrongfully seized and presumably data-dumped by a plod suffering a rush of blood to his head. ®

Build a business case: developing custom apps

More from The Register

next story
Nice computers don’t need to go to the toilet, says Barclays
Bad computers might ask if you are Sarah Connor
4K video on terrestrial TV? Not if the WRC shares frequencies to mobiles
Have your say with Ofcom now, before Freeview becomes Feeview
PEAK LANDFILL: Why tablet gloom is good news for Windows users
Sinofsky's hybrid strategy looks dafter than ever
YES, iPhones ARE getting slower with each new release of iOS
Old hardware doesn't get any faster with new software
You didn't get the MeMO? Asus Pad 7 Android tab is ... not bad
Really, er, stands out among cheapie 7-inchers
Apple winks at parents: C'mon, get your kid a tweaked Macbook Pro
Cheapest models given new processors, more RAM
VMware builds product executables on 50 Mac Minis
And goes to the Genius Bar for support
Leaked Windows Phone 8.1 Update specs tease details of Nokia's next mobes
New screen sizes, dual SIMs, voice over LTE, and more
Microsoft stands on shore as tablet-laden boat sails away
Brit buyers still not falling for Windows' charms
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?