Showing posts with label Apple. Show all posts
Showing posts with label Apple. Show all posts

Sunday, October 29, 2017

Face Recognition

Following Apple's Face ID launch this is one of those hot topics at the moment. This technology is not without its sceptics and questions still remain whether it can become full proof. In today's world, that is a big ask.

I have collected some bits and pieces worth reading.

Apple's September 2017 paper on face ID and security - [https://images.apple.com/business/docs/FaceID_Security_Guide.pdf]

Kairos produce a useful comparison chart of facial recognition services[https://www.kairos.com/blog/face-recognition-kairos-vs-microsoft-vs-google-vs-amazon-vs-opencv]

The Guardian Newspaper published an article of Samsung's flawed Iris scanner - [https://www.theguardian.com/technology/2017/may/23/samsung-galaxy-s8-iris-scanner-german-hackers-biometric-security]

New research proposal just out 'Bypassing 3D Facial Recognition Authentication on Mobile Devices' - [https://www.os3.nl/_media/2017-2018/courses/ssn/projects/ssn_proposal_01.pdf]

Tuesday, July 25, 2017

New IPhone 7 passcode unlock tool



Obviously this is causing a bit of excitement. 

I have been keeping an eye on two websites selling this product but yet to find any customer feedback. Enquiries so far have drawn a blank response.

http://www.vipprogrammer.com/unlock-passcode-on-iphone-77-plus-crack-the-forgotten-screen-password-programmer-3638

http://myicloud.info/unlock-iphone7-plus-passcode-tool/

Interesting to see what Apple will have to say on this access method?

Friday, September 02, 2016

Apple iPhone connected devices

Proliferation of mobile devices and computers associated with cybercrimes and legal disputes grow on a daily basis. I thought perhaps readers might find this 2015 document a useful and helpful reminder. DEFT Practice Notice J10702015.pdf
 

Saturday, March 26, 2016

iMessage shown to have encryption flaw

Discussion article here:  https://www.washingtonpost.com/world/national-security/johns-hopkins-researchers-discovered-encryption-flaw-in-apples-imessage/2016/03/20/a323f9a0-eca7-11e5-a6f3-21ccdbc5f74e_story.html

Apparently, the research has found:

"It took a few months, but they succeeded, targeting phones that were not using the latest operating system on iMessage, which launched in 2011.

"To intercept a file, the researchers wrote software to mimic an Apple server. The encrypted transmission they targeted contained a link to the photo stored in Apple’s iCloud server as well as a 64-digit key to decrypt the photo.

"Although the students could not see the key’s digits, they guessed at them by a repetitive process of changing a digit or a letter in the key and sending it back to the target phone. Each time they guessed a digit correctly, the phone accepted it. They probed the phone in this way thousands of times.

“And we kept doing that,” Green said, “until we had the key.

"With the key, the team was able to retrieve the photo from Apple’s server. If it had been a true attack, the user would not have known.

"To prevent the attack from working, users should update their devices to iOS 9.3. Otherwise, their phones and laptops could still be vulnerable, Green said."

The research report is here: https://isi.jhu.edu/~mgreen/imessage.pdf

Saturday, March 19, 2016

Emergency Cases - Smartphone Examination


Capturing the target subject's smartphone activities is not as easy as is thought, as we are all finding out with the current Apple and law enforcement debacle.  The Apple case though is not the norm as the two opposing sides are fighting about the "right to access". The public are engaged with this story that continues to unfold as to what "Privacy" actual means, should terrorism enjoy the comfort of privacy and so on. However, there is a sub-text going on here (as well) concerning examination procedures for smartphones and methodology in emergency cases. Having been involved with mobile phone evidence in criminal and civil proceedings for over 30-years I can tell you it isn't as easy at all.

Consider the current Apple case (and the articles still keep coming) and mistakes that are said to have occurred. The - TECH INSIDER - reported (http://www.techinsider.io/apple-the-fbi-screwed-up-san-bernardino-investigation-2016-2)

"The fact that the password was reset means that Apple was unable to retrieve info from the iPhone's unencrypted iCloud backup like it has for past investigations, according to reporters Apple spoke with. If the password hadn't somehow been reset while in law enforcement custody, the FBI likely wouldn't need Apple to create a tool that lets it brute force hack the iPhone's lock screen passcode and gain access to the device's encrypted contents."

It is the words "password hadn't somehow" that has significance for me because in those words it doesn't take account of the intense situation people are operating under, speed of investigation operations, timescales, prevention for potential further attacks and pressure to resolve the case etc.  So the sub-text here is learning from adverse outcomes in emergency cases. Put on hold demands for back-door access as the golden cure because, in itself, it is not. There can be a plethora of superlative elements that will be sifted, considered and discarded where found not  to be relevant. For elements that may be relevant they still need to be sifted, considered and conceptualised.

From a range of materials I use in my training courses I use the following which I originated back in 2006 (and I published it back in 2010).


Primer(C now) = Point in time and Space (which is a constant reference point) in the present tense when the examiner is contacted for an investigation and from which the examiner uses to look back in time at and into the future regarding mobile telephone evidence.
.
(T) = Time is the timeline, limited by how far the examiner can see into the past and future based upon discovery.
.
(S) = Space is the space line that is used as a constant reference point from which all other events occurring in space can be considered based upon discovery (seizure of device, chain of custody of an exhibit etc)
.
(F) = Future relates to things that have yet to happen (future events). This is based upon things that maybe discovered from the time the examiner is contacted
.
(F d) = F d represents, as far as possible, thus not set to a specific period of time, how far into the future the examiner can identify events beyond which no further discovery is possible.
.
(PU usage) = Past User usage (below Blue line represents past recorded events, and below the red dotted line events unfolding during and after investigation)
.
(PR usage) = Past Record usage (below Blue line represents past recorded events, and below the red dotted line events unfolding during and after investigation)

The proposition in Smith Diag 1 is intended to represent, by use of visualization, how mobile telephone usage can be investigated. The diagram tests your powers of observation and, more importantly, your depth of knowledge. So do not be fooled by what you believe to be my poor graphics skills. I deliberately intended that (PU usage) area to be shown larger than the (PR usage) area in order to suggest more data may be found in the mobile telephone than maybe obtained from the network records. That is because not all activity on a mobile telephone leads to activity in the radio and fixed mobile network. Network records are not limited to billing records therefore issues associated with cell site analysis also need to be considered. It does not automatically follow there shall be parity between data obtained from the mobile telephone and the network records and vice versa. The diagram below (Smith Diag 2) represents a number of suggested data elements commonly arising during an investigation.


The third diagram (Smith Diag 3) uses the classic representation of Time (T) and Space (S). Use of a Time line may be obvious but the Space line may not be so obvious. The point of using Space is as a determinate for e.g. the seized exhibit in the examiner's possession. Let's say the examiner receives the mobile telephone exhibit on the 30th March 2008 at 3.00pm. The exhibit was seized 10th March 2008 at 11.00am. So, the examiner has two facts to work with (a) the exhibit in the laboratory (in time and space) and (b) the exhibit seized at a location from premises or person (in time and space).. So at the point the examiner has initial Contact (C now) with the exhibit then past events can now start to be determined. By way of illustration, following examination let’s say the examiner finds that the data recovered from the device reveals activity not connected with Space where the mobile telephone was seized at (b). Space would therefore be highly relevant, because (i) the examiner would need to demonstrate that as a fact and (ii) to demonstrate the separation in Space between each of the locations (a) laboratory, (b) the seizure, and the intervening factor between (a) and (b). This may be supported, for instance, by the last location and frequency details stored on the SIM card or may be the handset has GPS or one of the smartphone mapping system that might be set to automatic logging.


Have a go at designing one of these diagrams and show how you would handle the Apple phone (in this case) - the seizure and examination procedure. Just as a heads up F d is intended to represent a text message in the future that has been sent but not yet delivered to the target's handset. So how would you know if a text message is pending and who would you have to cooperate with to get that information (and the text content too)?

Hope this helps.

Friday, February 19, 2016

Moral Ethics of Backdoor iPhone 5C

Backdoor iPhone 5C

The discussion below is entirely hypothetical and is not intended to make or shift people into making decisions, legally or morally, nor create detriment at all.

There has been a huge amount of press regarding the balance between lawful investigation / national security versus Apple's company policy not to backdoor their products precisely for privacy and security reasons. It is laudable stand-off Apple have created because they ask where is the demarcation between full access and privacy and security. I cannot say this is David and Goliath being played out because Apple are far too big to be labelled a minnow (unjustly facing might versus right).

However, are Apple's arguments being raised legal ones or moral ones or both. Is Apple your moral barometer in life? Does Apple think for you and make/take your moral decisions for you? Only you can answer these. Apple appear to have made a good fist of standing by their publicised policy for legal reasons and, in fairness, it is understandable, they could have a fear of being accused of misleading statements to suddenly confirm there was always a backdoor into their product. They have done well and spoken in their statement that they never tried to make one in the first place.

[u][b]Apple's Open Letter[/b][/u]
https://www.apple.com/customer-letter/
"But now the U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create. They have asked us to build a backdoor to the iPhone."

The public statement was made following a US Judge's Order:
https://assets.documentcloud.org/documents/2714001/SB-Shooter-Order-Compelling-Apple-Asst-iPhone.pdf

There is a point at which peoples' morals are woven in the fabric of their country's constitution where those moral become tenets that become doctrines for the society in which they wish to live. These can lead these morals being inextricably linked (not easy to disentangle) in the decision making process where an organisation like Apple might bend and could say for example "Okay, hands up, we have stood by our customers and promises we made to them but a greater good needs our help. If customers wish us to assist law enforcement and national security carefully set down by a strict and specific set of criteria allowing Apple to (firstly) build the access and (secondly) to deploy it, then we need customers' support to loosen are obligations?"  That statement is hypothetical only created for the following question to ask what would criteria do Apple customers morally consider should release Apple to allow access and deployment (backdooring)?

Below is a short list of graduated crimes against society. It is accepted straightaway that some may not figure in your moral domain (but then create one for yourself and see how you feel about it?). Put the list in order so that you create a moral demarcation where you believe Apple could (not should) allow backdooring on a single make/model of smartphone. The stage is now yours, and yours alone, as this is about you and not me, national security, law enforcement or Apple for that matter. Where do you think you feel and stand on this matter.

Place in your order of importance the below and highlight at what stage you would expect Apple to concede and backdoor their device for the greater good?

10....................backdoor device to find a burglary/car thief
9....................backdoor device to find local cannabis supplier
8..................backdoor device to find IIoC photo distributor/procurer
7................backdoor device to find people trafficker
6..............backdoor device to find arms smuggler
5...........backdoor device to find LE or civilian murderer
4.........backdoor device to find agent spreading bacterial warfare
3.......backdoor device to find murderer of national president
2.....backdoor device to find kidnapper of 30 babies from hospital
1...backdoor device to find where nuclear device placed before explodes

Remember more is less and less is more.  

Wednesday, October 29, 2014

Apple's New Nano-SIM Card

Should make examinations interesting. Apparently, an open-ended SIM that can be either postpaid or prepaid account without the need to change SIMs but still switch between carriers. Either Apple intend to go for their own IMSI (thus become an operator) or the IMSI will need to be updated OTA...hmmmm

"If you are among the millions who will purchase one of the 4G versions of the new iPad Air 2 or iPad mini 3 tablets from Apple in the next few months, and you live in the US or UK, then when you switch the tablet on for the first time, you will find a nano-SIM card already installed in the SIM card slot."


..............

"What Apple envisions with its SIM is that users will be able to quickly and easily switch between different carriers to take advantage of the best short-term deals available at any given time - without having to go through the hassle of getting a new SIM card.

"Obviously, if you have signed up to a two-year contract you won't be switching deals that often, but if you are on a pay-as-you-go deal, then this could be a real money-saver......."


Quotes from:
http://www.ibtimes.co.uk/apple-sim-how-does-it-work-end-sim-cards-1471065

Tuesday, December 11, 2012

A European Focused Mobile Consumer Survey

A European Focused Mobile Consumer Survey

Informa Telecom and Media have published the results of their Smartphone Usage and Behaviour Survey 2012 conducting the survey in four european countries UK, Spain, Germany and the Netherlands http://www.informatandm.com/mobile-consumer-survey/ .

The results for the UK identified the brand of mobile phone owned in particular age groups.













The responses to the survey confirm that the smartphone market in the UK is segmented and therefore mobile operators attempting to forecast device usage and data/services activity may require enabling customers the selection and choice of a range of platforms to sink their teeth into optimising any consumer initiative to enable the growth of smartphones to continue.

For examiners the survey illustrates that predominantly the smartphones to be examined fall into a fairly small category, which could be quite useful for forecasting future examinations and, in particular, the expenditure on tools etc.

Friday, June 22, 2012

iPhone changing to 19-pin port?

iPhone changing to 19-pin port?

Screen Shot 2012-06-20 at 5.13.55 PM
Image courtesy of Tech Crunch

This could be an interesting twist in the marketplace relating to Apple's campaign to continue separating iPhone innovation from other handsets in the marketplace, not only through the use of distinctive design, but distinctive access to the phone. According to Tech Crunch  (the popular online tech gadget news website) they have verified that iPhone is to have changes made to the pin port swapping out the 30-pin port for a 19-pin port - http://techcrunch.com/2012/06/20/confirmed-the-new-iphone-will-have-a-19-pin-mini-connector/?goback=.gde_1794802_member_126527789

Some handset manufacturers have taken the route adopting the miniUSB. See USB research reference materials (below), but other handset manufacturers still retain specialists plugs in order to gain access.

http://en.wikipedia.org/wiki/USB
http://en.wikipedia.org/wiki/Enhanced_mini-USB
http://en.wikipedia.org/wiki/File:Types-usb_new.svg

Tech Crunch's news suggests Apple are not yet ready to take the USB route. I am more intrigued though whether there is any connection between the 19-pin port intro and Apple's adoption of the 4FF-uicc size which they have been successful in gaining agreement and approval for inclusion into the ETSI standard?

4FF-uicc research reference material
http://trewmte.blogspot.co.uk/2012/06/etsi-release-details-of-new-4ff-uicc.html
http://trewmte.blogspot.co.uk/2012/06/sim-card-new-4ff-form-factor-size.html

The implications could be wider for the handset examination market as new standards, and tools ranging from plugs to STKs to newer software upgardes, should be expected from such a development.

Saturday, July 23, 2011

Mobile Markets: Nokia 'Mobile Man'...it tells of a story

Mobile Markets: Nokia 'Mobile Man'...it tells of a story

This excellent construction, made up entirely of mobile phones, is Nokia's collaborative project with Beijing postal service to encourage recycling of mobile phones that can be handed in at post offices, according to the news article at news.cnet.com.   


It's great to see projects like, which tend to draw promotions using creative and talented ideas demonstrating the evolving and transforming world of mobile phones and its market places. Back in 2007 I posted on another creative work cellphone-transformer, which, yet again, shows a design that captures the imagination displaying the versatile uses to which a mobile phone might be put.

The business and ecomonic philosophy that resides behind these creative images equally tells of a story of growth and success. If recycling is happening then, perhaps, that is as a likely consequence of mobile ubiquity taking hold. That is a nice statement, but can I back it up?  I don't have my finger on every financial and market research pulse, but, apart from anecdotal references, there are various stats out there from the market research firms. Indeed, back in 2008 I blogged (staggering-figures-for-mobile-phone) on the state of the mobile data market when the economic downturn (which appears to have started in 2007 so we are led to believe) had got a firmer grip on global markets. In 2010 the stats still showed extraordinary figures (text.it), although the exact detail where all this activity occurs to generate such figures may not be obvious. It may be compelling to want to know how many consumers send text and mms messages (see OFCOM website for stats), but that is not the full picture. There are the other data markets in business to consider, such as the M2M market place (winwin) and comments by industry pundits on the mobile payments market (cellular-news).

It is useful to see how industry people collate information and bring amassed facts together in order to express their views and vision on what all the facts mean to them in aggregrate. An example of this can be seen in Tomi Ahonen's enthusiastic commentary found in Insiders Guide To Mobile (lulu) with references to trillion dollar market, over 4 billion users and the segmented factors when drawn together identified to him what is forecast for mobile. A view of one segment of the mobile phone market, apps, is simply a further illustration of information to be sourced to underpin market trends (windows-phone-apps-reach-new-market), another is sales and market penetration, such as Apple's iPhone outrageously outstanding sales growth.

If I removed from the context of the above commentary discussion about modern technology, and simply focussed on what an image might communicate, I could have been talking about social, cultural and economic life that might have been depicted by way of an 18th/19th century painting (irrespective of whether the painting is by an impressionist or not). Whilst the image above may not be an old master piece, the image still has a story to explicitly convey and that, in forensic terms, requires understanding all or part of any implicit subtext the image can also communicate.

My forensic skills, acquired over the years, meant that my reaction to seeing this image (even though photo/art imagery is not my subject), was to look at it as evidence and then set out to see what I could deduce from there. In reality we do this everyday in our work. We see a SIM card. We then want to know what it is and what is inside. In order to know what we are dealing with we need to know how it works and what can be held inside and whether all or part thereof can be revealed. Moreover, we need to know what amounts to 'conformance' and within that framework which conforming element is 'mandatory' and which is 'optional'. Once we have that background we can then begin to understand what is 'non-conforming' and/or 'unusual'. This path can equally be taken when dealing with mobile phones and RF investigations.

In conclusion, the subtext of this discussion can be revealed. However mobile phones maybe presented to the world, it is our job in forensics not to change that messsage, but to break down the presentation into its various building block elements in order that we know how each piece works and then how the pieces fit together and work and cooperate together.  This is because a true forensic standard requires of the individual to obtain knowledge by way of commentary, appropriate training, standards, specs and investigation, that includes examination and testing (trial and error), which is one side of the coin. The other side of this coin is knowing what the 'thing' in its final state is intended to do, which requiries understanding of the market place it which the 'thing' is to be adopted.  Using skills and techniques like these provide for a rich source of experience, too. Essentially, learning to bring all the pieces that are needed into play and being able to demonstrate that identifies the forensic examiner working with a well hone, self-principled approach of high standard.

For MTEB students, the summer recess is now here. Sure, have a great time and relax and enjoy the break, but don't waste valuable time. Great people strive in life because they want to go beyond what has already been achieved. Take time out from relaxing to bring together the exposure you have had to mobile knowledge and experience you have acquired, thus far. Select a particular line of investigative enquiry and see how far you get with it. I have identified some links above to illustrate a way forward or choose a different subject matter; remember to be able to demonstrate the primary basics of 'bush' methodology.

Thursday, May 19, 2011

Aggregated SIM

Aggregated SIM

Interesting news story out of  Reuters that has been posted by many website that states that Apple has proposed a standardized SIM card smaller than those it currently uses in the iPhone and iPAD in order to be able to produce thinner devices, an Orange executive told Reuters on Tuesday. The news story also mentions Apple having gone along the Standards path and approached ETSI (European Telecommunications Standards Institute) and a hint that something could be seen as early as next year.

http://www.reuters.com/article/2011/05/17/us-summit-orange-apple-idUSTRE74G4WY20110517

This is SIM card developmental news and fascinating to watch as SIM and the microprocessor electronic card (ICC/UICC) that it uses takes further steps on its evolutionary journey.  We already know some of the form factors for ICC/UICC:

The integrated and non-integrated examples
Photobucket

A closer look at an integrated example
Photobucket

When SIM (subscriber identity module) cards were introduced for GSM (global systems for mobile) communication devices (handset/terminal devices) ETSI standardised the ID-1 format which was an ISO-size card as defined in the international standard ISO-7816 and commonly referred to as a 'credit card' size. A plug-in size (the size of a 'postage stamp') was also introduced and these designs are commonly seen in the standard GSM11.11. Distinctively, the shape, size and operational performance of the card means that the card, called an ICC- integrated circuit card (or Universal ICC following the introduction of 3G-WCDMA cellular radio) - should be distinguished from the SIM module, which is itself a programmable area on the card.   However, a further card size emerged and was defined in the 2004-03 ETSI standard TS 102.221 as "mini-UICC". It should be noted that where I have mentioned GSM11.11 this standard refers to the use of SIM cards with GSM technology and services. The lineage of GSM SIM and its standards are linked to ETSI standards including TS 102.221 and, of course, ISO standards. A similar path can be trod when dealing with U-ICC/U-SIM.

As for Apple's suggested development, what we don't know at this stage is what the aggregated SIM (but I think I might want to read that as form factor and size) will look like or its content for that matter. We can only guess at this stage.

Tuesday, November 16, 2010

iPhone - Evidence Handset Reader Tools

iPhone - Evidence Handset Reader Tools

Two questions:

1) How many 'evidence' handset reader tools can you name off the top of your head?
2) And how many of those tools extract and harvest data from iPhones?

In answer to question one we know we can at least identify thirteen (13) tools and the answer to question two is also at least thirteen (13) tools. The answers can be found in 'iPhone Forensics White Paper' published by viaForensics. The authors of the document are Andrew Hoog and Katie Strzempka.

The number of tools now available and sold into the marketplace is a bit of surprise because in most cases a large portion of the forensic community do not own one copy of each of these tools as it is not strictly necessary. It is quite useful, though, to see a report like this that brings together at least 13 tools so that there is a record of the existent of these tools and how they are viewed in relation to their usefulness.

What I like about this report is that it is produced entirely independent of any of the handset reader software manufacturers and the authors/publishers were not compensated in any way for the work and effort that went to researching and testing each tool.  I should also point out that I am not being compensated in anyway either for mentioning the researchers/publishers or this White Paper.

I wont spoil the fun for you of reproducing the findings and results recorded in the White Paper, but you can read about them for yourself at the weblink below:

http://viaforensics.com/education/white-papers/iphone-forensics/

Monday, August 23, 2010

Apple's Killer Patent for Jailbreakers

Apple's Killer Patent for Jailbreakers

Apple has used the route of a patent to institute a series of measures to protect its devices from Jailbreakers, thieves and unauthorised users.

http://forensicmobex.blogspot.com/2010/08/apples-killer-patent-for-jailbreakers.html

Tuesday, August 03, 2010

One-Size-Fits-All Power Charger

One-Size-Fits-All Power Charger

Manufacturers have agreed to create a single one-size-fits-all power charger, thus the expectation of a standard PSU interface will be used. The approach is being applied to data-enabled mobile phones for models to be distributed in 2011 according to the EU, as reported by Business Week:

http://www.businessweek.com/ap/financialnews/D9H9F7H00.htm?

Business Week identify the manufacturers as Apple, Emblaze Mobile, Huawei Technologies, LGE, Motorola, NEC, Nokia, Qualcomm, Research in Motion (RIM), Samsung, SonyEricsson, TCT Mobile, Texas Instruments.

The news of a single charger has been around for a while but is a useful reminder as apparently the 2011 handsets wont be supplied with charger according to the Business Week article.

Handsets with the new charger design could prove helpful when we are examining mobile phones where there is no charger supplied with the 'exhibit' or the customer's DFE.