Mining iPhones and iCloud For Data With Forensic Tools
SternisheFan points out an article that walks us through the process of using forensic tools to grab data from iPhones and iCloud using forensic tools thought to have been employed in the recent celebrity photo leak. There are a number of ways to break into these devices and services depending on what kind of weakness an attacker has found. For example, if the attacked has possession of a target's iPhone, a simple command-line toolkit from Elcomsoft uses a jailbreak to bypass the iPhone's security. A different tool can extract iCloud data with access to a computer that has a local backup of a phone's data, or access to a computer that simply has stored credentials.
The discusses also details a method for spoofing device identification to convince iCloud to restore data to a device mimicking the target's phone. The author concludes, "Apple could go a long way toward protecting customer privacy just by adding a second credential to encrypt stored iCloud data. An encryption password could be used to decrypt the backup when downloaded to iTunes or to the device, or it could be used to decrypt the data as it is read by iCloud to stream down to the device."
The discusses also details a method for spoofing device identification to convince iCloud to restore data to a device mimicking the target's phone. The author concludes, "Apple could go a long way toward protecting customer privacy just by adding a second credential to encrypt stored iCloud data. An encryption password could be used to decrypt the backup when downloaded to iTunes or to the device, or it could be used to decrypt the data as it is read by iCloud to stream down to the device."
In my experience most iPhone user's don't even know their main account passwords. They have assistant's for stuff like that. Or kids.
The simple fact that any good encryption system would negate the ability to recover a lost account password is the entire reason why this will never happen.
No no no... none of this is true. Apple has assured me that this was all a result of bad choices for passwords.
The last link (about spoofing device identification) is really just a generic warning about man in the middle attacks.
Are there published ways to use a man-in-the-middle against iCloud?
Also normally the backups only activate when the device is plugged in...
"There is more worth loving than we have strength to love." - Brian Jay Stanley
You mean, I would have to spoof twice? Ah well, may as well give up then.
“He’s not deformed, he’s just drunk!”
""Apple could go a long way toward protecting customer privacy just by adding a second credential to encrypt stored iCloud data. An encryption password could be used to decrypt the backup when downloaded to iTunes or to the device, or it could be used to decrypt the data as it is read by iCloud to stream down to the device."
I'm sorry, but this smells a lot like common sense and good security practice.
In other words, it doesn't stand a chance getting past the don't-bother-me-with-security collective we like to call "smart" phone users.
Apple could go a long way toward protecting customer privacy just by adding a second credential to encrypt stored iCloud data. An encryption password could be used to decrypt the backup when downloaded to iTunes or to the device, or it could be used to decrypt the data as it is read by iCloud to stream down to the device.
I forgot my iPhone password, and those lousy Apple folks refused to reset it for me. They just said some kind of technobabble about encryption and security. Why did they make iPhones harder to use? Isn't Apple supposed to be easy to figure out?
You can't have it both ways. I encrypt all my sensitive data that I back up to the cloud, but I also keep copies of the key in safe places so that when my house burns down I don't lose access to my offsite backups along with it. I wouldn't expect the average iCloud user to appreciate the need for this, and neither does Apple, so their backups aren't encrypted.
... would end up being the same as the account password. Or just add a one. Not the answer.
like not trashing their users icloud accounts and forcing all their data to be deleted.
Or stop forcing me to use the same Itunes account as my teenage daughter without extraordinary measures.
How about they stop "updating" the OS so key software, or even a new computer doesn't have to be repurchased?
I thought once Jobs died that would be the end of it, but that homo Cook seems to be hanging in there.
The discusses also details a method for spoofing device identification to convince iCloud to restore data to a device mimicking the target's phone.
I checked the link, and it does no such thing. The article is about fake Wifi hotspots. Such a fake Wifi hotspot could of course cause all kinds of trouble (basically it can read WiFi traffic that you thought was encrypted), but it doesn't allow anyone to convince iCloud of anything.
Take the Elcomsoft tool mentioned. It requires for example "The targetâ(TM)s iCloud passwordâ"by them volunteering it, through a phishing attack, or by gaining access through other social engineering.".
These tools don't do anything cryptographically clever. If you have a victim's iCloud password, they are cracked. All this tool does is to make it easy to download all the data and to examine the data, once the account is cracked. It doesn't do anything about the cracking.
All that crazy encryption and locked down garbage yet it seems to be only protecting Apple's property.
Jailbreak a phone and they quickly patch the exploit away. Security is to enforce their rights over your device.
Obviously when the government or law enforcement comes along though all that security just vanishes. Yet the device was sold to you boasting of it's security.
It all appears to be a carefully thought out plan to get people to trust their phones enough to do things with them that they wouldn't do if they didn't think it was secure. It's all a big plan to draw out your secrets into the open by masquerading as a locked diary.
Wish some of that security was there for the end user......
"using forensic tools to grab data from iPhones and iCloud using forensic tools"
I just double checked and the same old attack still works on iCloud. If you forget your password, you can reset it in either of two ways. Either they can email you a new password, or you can answer the challenge questions. So let's get into Miley Cyrus's account.
https://www.google.com/?q=mile...
Her mother's maiden name is Finley
https://www.google.com/?q=mile...
Her first pet was named Cocoa.
There you go, now we can reset her iCloud password and Miley's naked pictures. [voice style="ben-stein"]Wow[/voice]
I don't understand the icloud backup option. The cost of the apple icloud data plan is really large and recurring, so backing up my phone would use 32GB for each backup. I don't want to pay apple for that. The lack of security makes it even worse -- mental note... don't copy the iphone backup to box or dropbox ;)
There you go, now we can reset her iCloud password and Miley's naked pictures
maybe we can reset her password and prevent HER from posting naked miley pictures instead?
If you want security get a Black Phone. It is brought to us by Phil Zimmerman, the author of PGP.
https://www.blackphone.ch/ - And it costs less than an iPhone6!
I feel like the age of the security question is slowly become more obsolete due to the sheer amount of facts of our lives that are made public (also any question that revolves around your favorite x is subject to change, making it incredibly difficult to answer these questions if the configuration was done a few years in the past). Either that or they have to become more obscure/tricky. Like in the way that pub quizzes have had to become more clever to prevent people cheating with their smart phones. Which would again, make it even more challenging for even the right person to answer the question.
to the fact that items thought deleted were showing up in the backups. That, to me, is the most disturbing part of this story. Yes, I READ BOTH articles. The second one, as others noted, was focused on WiFi spoofing. The first detailed the use of forensic tools to access the information in the backups.
Of course, to gain access to any of this information, the author had to have physical access to the phone and jailbreak the device as well as a knowing the iCloud password. And, the exploits he discussed were against older hardware and the obsolete iOS 5.1 He had no success against against iOS 7 on the iPhone 5s.
As I stated earlier, knowing that so much still existed AFTER supposedly deleting it (such as mailboxes, pictures, call history) is a real issue and one that needs to be publicly addressed by Apple.
goto fail;
goto fail;
"If any question why we died, Tell them because our fathers lied."
People were doing that in the late '80/early '90s with analog cell phones, so nothing new here. Once you have physical access it's mostly game over...
But why didn't FindMyiphone timeout after let's says, 3 or 5 attempts? that's just sloppy...
I've got better things to do tonight than die.
a losing battle; non-fulcking-existant. I have a life to
Once your data leaves your direct physical possession, it's no longer yours.
You either better hope that you're not interesting or any encryption lasts for the lifetime of the data, neither of which is forever.
What was the saying a decade or so ago? "Don't publish it if you don't want to see it on the front page of tomorrows' newspaper."
(For you youngsters: "Newspaper", noun: a massively printed and delivered blog written by multiple people that other people paid for.)
If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
using forensic tools.
The IRS is the one organization that you don't want to fuck with. Remember, these are the guys who took down Al Capone.
Talk about your low hanging fruit.
I know it's a theoretical excercise but getting naked pictures of Miley Cyrus is more easily achieved by just hanging around Miley Cyrus with a camera. Or letting people that ready hang around Miley do that.
Please choose a better example.
That is the only reason why last year I went to the 5S. I was thinking Apple would let apps use it as an authentication tool.
iOS8 provides for exactly that.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
The arstechnica article is rubbish.
They used a 4 year old iphone4 running 3 year old iOS5 and installed a jailbreak on the phone while it was already unlocked after putting in the 4 digit passcode.
Then they used some software to brute force a hash for a 7 character dictionary password.
Absolute trash article. Surprised to see it here on slashdot.
The only valid point they make in the massive 4,000 word article is that if you trust a PC when connecting your phone - that PC gets keys that can be used to talk to your phone. So you need to make sure that the PC is encrypted and/or not stolen by attackers.
Except now when you try that MLC gets an email saying someone is requesting her password to be recovered, and can just change it.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
One night, I change her password. I log into her account, and download everything. She's twerking while I do this. I can either parlay this to email access or run the same attack against gmail. I use the access to her email to reset every other password she hhas - Facebook, etc. If I want to, I can use her icloud credentials to lock her out of her phone for a while. The next morning, she reads her email and finds out that I reset her password- but only if I haven't deleted that email,while I was setting her account to forward a copy of all future emails to me.
Cool