Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Workaround: hold iPhone in front of owner's face.

That won’t work on my 6s
[doublepost=1529032171][/doublepost]
They sell to "law enforcement only" and they sure will do their best so that Apple doesn't get their hands on one...

There are a lot of tools that are suppose to be sold to Law Enforcement only that still end up in the hands of criminals and others who are not in law enforcement.
 
  • Like
Reactions: FeliApple
How does that even make sense? It's not like some agency paying for a box is just going to "take their word for it" on a five figure purchase. Pretty sure they are going to require proof.

Hey, it's just taxpayer money. And, something like this might even be federally funded, along with tanks and all that other kind of police gear.

There are a lot of tools that are suppose to be sold to Law Enforcement only that still end up in the hands of criminals and others who are not in law enforcement.

Yeah, considering the police lose nearly 200k guns each year in the US, I'm guessing one of these boxes could get lost too.
 
  • Like
Reactions: centauratlas
If I had to guess then I would say that DFU mode is still available. There still needs to be a way to restore the device if someone forgets their password. They may simply have an exploit that starts with the phone in DFU mode, which enables the port for data mode again, and then uses some method to crack the password on the device.
I seem to recall some jailbreaks that started with putting the phone in DFU mode. Apple will for sure work to plug whatever holes are being used.


The OS is not running in DFU so the iPhone won't ask for a password therefor it can't be unlocked, AFAIK the data on the iPhone is encrypted so what you suggest won't work.
 
They sell to "law enforcement only" and they sure will do their best so that Apple doesn't get their hands on one...

If you think Apple doesn’t have contacts in law enforcement, you’re a little naive. Everyone has a price and Apple can afford every price.
 
Everything has a price and Apple is definitely not short on cash I think they will get their hands on one. Of these boxes if the haven't already
Exactly. You think some cop making $30k a year isn't going to jump to snatch one of these up and sell it to Apple? lol.
[doublepost=1529063244][/doublepost]
Why are you assuming such?
Because Apple has like $300,000,000,000 to play with.
 
Sure. Like a government agency hell bent on opening your phone wouldn't make you open your eyes. :rolleyes:
Well if you're going to bring force or torture into the equation then we're no longer talking about a convenient security feature.
 
Some have said Grayshift is just saying they defeated the security measures to sell products. While I agree companies are motivated to stretch the truth I’d also point out that in this case it would fraud. They either can or cannot defeat the security measure. Saying you can when you can’t would be fraud.
 
  • Like
Reactions: fairuz
Everything has a price? That same saying can be used against Apple. Someone can pay an apple employee to steal Apple's digital signing keys. Ultimate back door right there.
Except Apple go to great length to make sure that can not happen
[doublepost=1529070269][/doublepost]
How does that even make sense? It's not like some agency paying for a box is just going to "take their word for it" on a five figure purchase. Pretty sure they are going to require proof.


CurrentC morphed into Walmart Pay and I think Target is coming out with a version too. It didn't die at all.
We are talking about law enforcement so yeah they pretty much would just take their word for it. If law enforcement were clever and not just a bunch of corrupt sods they would not need to hack peoples phones
 
Regardless if this is true, or just brinkmanship, one of the underlying truths of security is that physical access makes it easier to gain logical access. The fact that LEO's have physical access means that if a hack is available... they will be able to use it.
 
If they were smart, they would've waited until iOS 12 was in the GM stage to announce this. Now Apple can look into fixing their bypass. :D

Which makes me think this is a marketing bluff to reassure their customers and have a reason to say they couldn’t do it when the GM rolls around.
 
Except as soon as Apple becomes aware of that theft, they can change them. Greykey cannot change hardware/firmware/software so easily, especially on boxes already out there.
Is that a speculation? I don't know why you think that what apple can do, greykey can't do? Hardware, if greykey can't update the hardware, so can't apple. Worst is apple has millions of iPhone spread across the world. Firmware.. I don't know how frequqnfre apple updates the firmware of iPhone. But greykey may post the new firmware on their website, so that box can download and update it. Same applies to the software. So...
 
You’ve committed a crime or been under investigation and had your phone cracked by one of these? If not, “our” is not the correct word to use.
There is nothing to stop the government from doing this to you. There is nothing to stop a criminal using the exact same exploit from doing this to your phone. "Ours" is EXACTLY what I meant. Did I stutter?
 
Everything has a price? That same saying can be used against Apple. Someone can pay an apple employee to steal Apple's digital signing keys. Ultimate back door right there.

So split the signing key into chunks and make it so no single person ever knows it in its entirety.
[doublepost=1529078215][/doublepost]
I'm guessing you'd have to go on the presumption Grayshift's code isn't encrypted.

They can obfuscate the code, but at some point, the device has to interact with Apple's code. As for encrypting the code, they'd need to ship it with a decryption key; otherwise, it would would have a hard time running.
 
  • Like
Reactions: fairuz
I wonder if it's the idea of fooling the phone's clock. Anyway, there's no final patch for this other than requiring a stronger password. They'll always find a way to rip the memory off the phone then crack the weak 5-6 numeric password.

Also, where's that guy who usually comments and says he works for an iPhone hacking company? He was saying last time that he was working on a workaround.
 
Which makes me think this is a marketing bluff to reassure their customers and have a reason to say they couldn’t do it when the GM rolls around.
Maybe, but it seems a bad idea to lie in your advertising about something you are trying to sell to law enforcement.
 
Except as soon as Apple becomes aware of that theft, they can change them. Greykey cannot change hardware/firmware/software so easily, especially on boxes already out there.
If it's software/firmware, they issue an update to the very few entities that have a box, vs Apple who's trying to give out patches to millions of users. If it's hardware, they do the same except charge money that they know people will pay.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.