back

by Obscurity4340·3y ago·view on hn ↗
I'm pretty sure they do the same thing as a manual iTunes backup. A lot of the older phones with chips before A13 also seem to be variably vulnerable to being jailbroken with CheckRa1n where they can gain root access. It seems likely that Cellebrite uses CheckRa1n for a lot of older phones. There's also the issue of protection levels where if your phone has been unlocked once since boot (AFU), various keys are kept (possibly transparently) in RAM where they can be dumped somehow.

Also, iCloud backup and several other dangerous "features" like iMessage are enabled by default whenever you sign in to iCloud so there's a few backdoors already standard to anyone who uses iCloud. If you sign in in settings, it automatically signs/opts you into iCloud, even if you don't want it.

1 comments
true, imessage and facetime have a long history of indecency and it's somewhat unfounded to assume they're safe now.

cloud backups are also very problematic because they contain a lot of sensitive information and are not safely encrypted.

This isn’t the case if you enable advanced data protection

> If you choose to enable Advanced Data Protection, the majority of your iCloud data — including iCloud Backup, Photos, Notes, and more — is protected using end-to-end encryption. No one else can access your end-to-end encrypted data, not even Apple, and this data remains secure even in the case of a data breach in the cloud.

Which requires you first setup 2fa, which itself requires 2 keys.

https://support.apple.com/en-us/HT212520

I’d be more worried about these ota security patches they can send out whenever and how easily it is to MITM that process and send down exploited security patches. I’m sure it’s already happening in the wild

The fineprint for ADP is that all the filenames and checksums/hashes, and various manipulation dates are all StandardDataProtection meaning Apple retains access. Think of ADP like a safe made of bulletproof but highly transparent glass. So an enormous amount of (meta)data is still available to Apple or anyone who can hack or compel cooperation.
Here we go with the metadata again. Viewing metadata means nothing as it can be easily changed by the user while retaining the actual data. Rename the file, change the creation date. Instead of naming the folder “classified military pics” you name it “Susan’s 5th birthday party”.

Metadata means nothing.

There's an option in Configurator to disable OTA PKI updates. Is that the same thing?