So…. How Could The FBI Crack That iPhone Without Apple’s Help?

That’s the question of the day. And it is a safe bet that the FBI isn’t going to be too keen on telling the world how it was done. That leaves nothing but speculation to work with. I’ve thought about this overnight and I have a couple of theories that I’ll put out there. But if you’ve got any of you’re own, I’d love to hear them. And I bet, so would Apple.

NAND Mirroring Attack: The concern that the FBI had was that they could inadvertently wipe the contents of the phone if they simply tried to guess at the passcode that the phone used. So they had to find some way to ensure that they could somehow copy the contents of the phone so that if that did happen, they could restore it and try again. Jonathan Zdziarski who is a expert at iOS forensics and security has written about a type of attack called a NAND Mirroring Attack which involves removing the chips that store the data on the phone, copying them, putting the chips back in and then trying to brute force attack the phone by trying different combinations of the passcode until they hit the right one. If the phone erased the data, they simply popped the chips out and restored the data to try again. This high tech game of cat and mouse can go on indefinitely until they get what they want.

Exploiting A Software Flaw: It is possible that the FBI via their new best friends at Cellebrite could have exploited a flaw in iOS to get into the phone. The problem with this theory is that Apple and other look for these flaws and try to patch them, and they are rather aggressive about doing so. However, if the phone is running an older version of iOS that has some known flaw or flaws that they could exploit, it would be possible to unlock the phone. Thus this highlights why you should always keep the OS on your phone up to date.

In my mind, either theory is plausible. But like I said earlier, I don’t expect a blog post from the FBI telling the world how they pulled this off. But you can bet there’s a lot of people who are going to do their best to find out.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading