💎 Fed’s first rate cut since 2020 set to trigger market. Find undervalued gems with Fair ValueSee Undervalued Stocks

Apple to undercut popular law-enforcement tool for cracking iPhones

Published 06/13/2018, 05:04 PM
© Reuters. FILE PHOTO: A customer views the new iPhone 7 smartphone inside an Apple Inc. store in Los Angeles
AAPL
-

By Joseph Menn

SAN FRANCISCO (Reuters) - Apple Inc (O:AAPL) said on Wednesday it will change its iPhone settings to undercut the most popular means for law enforcement to break into the devices.

The company told Reuters it was aiming to protect all customers, especially in countries where phones are readily obtained by police or by criminals with extensive resources, and to head off further spread of the attack technique.

The privacy standard-bearer of the tech industry said it will change default settings in the iPhone operating system to cut off communication through the USB port when the phone has not been unlocked in the past hour.

That port is how machines made by forensic companies GrayShift, Cellebrite and others connect and get around the security provisions that limit how many password guesses can be made before the device freezes them out or erases data. Now they will be unable to run code on the devices after the hour is up.

These companies have marketed their machines to law enforcement in multiple countries this year, offering the machines themselves for thousands of dollars but also per-phone pricing as low as $50.

Apple representatives said the change in settings will protect customers in countries where law enforcement seizes and tries to crack phones with fewer legal restrictions than under U.S. law. They also noted that criminals, spies and unscrupulous people often use the same techniques. Even some of the methods most prized by intelligence agencies have been leaked on the internet.

“We’re constantly strengthening the security protections in every Apple product to help customers defend against hackers, identity thieves and intrusions into their personal data,” Apple said in a prepared statement. “We have the greatest respect for law enforcement, and we don’t design our security improvements to frustrate their efforts to do their jobs."

Apple began working on the USB issue before learning it was a favorite of law enforcement.

The setting switch had been documented in beta versions of iOS 11.4.1 and iOS12, and Apple told Reuters it will be made permanent in a forthcoming general release.

Apple said that after it learned of the techniques, it reviewed the iPhone operating system code and improved security. It decided to simply alter the setting, a cruder way of preventing most of the potential access by unfriendly parties.

With the changes, police or hackers will typically have an hour or less to get a phone to a cracking machine. That could cut access by as much as 90 percent, security researchers estimated.

This also could spur sales of cracking devices, as law enforcement looks to get more forensic machines closer to where seizures occur. Undoubtedly, researchers and police vendors will find new ways to break into phones, and Apple will then look to patch those vulnerabilities.

The setting change could also draw criticism from U.S. law enforcement officials who have been engaged in an on-again, off-again campaign for legislation or other ways to force technology companies to maintain access to users’ communications.

Apple has been the most prominent opponent of those demands. In 2016, it went to court to fight an order that it break into an iPhone 5c used by a killer in San Bernardino.

Then-FBI Director James Comey told Congress that without compelling Apple to write new software to facilitate the digital break-in, there would be no way to learn if the shooter’s device contained evidence of a conspiracy. The FBI ultimately found a contractor that broke into the phone without Apple's cooperation.

Apple and most private security experts argue that government contractors and others can usually find means of cracking devices. They also say that weakening encryption by design would lead to more hacking by those outside of government.

© Reuters. FILE PHOTO: A customer views the new iPhone 7 smartphone inside an Apple Inc. store in Los Angeles

Until recently, current FBI Director Christopher Wray repeatedly claimed that the Bureau had been unable to get into more than 7,000 phones in 2017. Last month, the Washington Post reported that the true number was less than a third as high. The FBI blamed "programing errors." https://wapo.st/2lbOiUd

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.