7 days till end - U...
 
Notifications
Clear all

7 days till end - USB RM iOS 11.4

10 Posts
5 Users
0 Reactions
708 Views
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

7 days is a short period of time. Not sure how we will handle this in-lab?

https://blog.elcomsoft.com/2018/05/ios-11-4-to-disable-usb-port-after-7-days-what-it-means-for-mobile-forensics/#more-4802

USB Restricted Mode (RM) can come within days not weeks. How to prepare?


   
Quote
passcodeunlock
(@passcodeunlock)
Prominent Member
Joined: 9 years ago
Posts: 792
 

USB RM or not, there will be always ways to go around.

They make it (Apple), we'll brake it - sooner or later )


   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

Who has a C-level friend at GrayKey to get in touch with?


   
ReplyQuote
passcodeunlock
(@passcodeunlock)
Prominent Member
Joined: 9 years ago
Posts: 792
 

What is C-level meaning here ?!


   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

C-Level means all managers with C as the first of its abbreviations like CEO, CISO, CIO, CFO or simple a manager who knows Power Delivery PD specs of USB-C -)


   
ReplyQuote
(@randomaccess)
Reputable Member
Joined: 14 years ago
Posts: 385
 

Apparently this feature was also in a previous beta, and wasn't in production; so no guarantee we'll see it in 11.4.
Probably eventually though.

In terms of Graykey, my understanding is they arent distributing outside of North America atm, and even then only to LE.


   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

Apple manytimes tested features in Beta 1-3 before rolling-out to market. But there is reason they want to block access by USB RM.

What solution do you have if in USB RM mode?


   
ReplyQuote
benfindlay
(@benfindlay)
Estimable Member
Joined: 16 years ago
Posts: 142
 

What solution do you have if in USB RM mode?

I think the answer to that question is very much dependent upon who you are/who you work for.

For instance, I can foresee police changing the way they work to prioritise imaging of such devices to be carried out inside the 7-day window, greater emphasis on obtaining PIN codes at point of arrest/interview etc.

Failing a co-operative suspect, conversion of tenprint/custody photos into usable 3D-printed models to defeat Touch-ID/Face-ID respectively should also be an option that's considered.

Basically if you can shift priorities to getting into the device inside the 7-day period, and make an image, it can go back to sitting in the queue to be examined at a later point in time.

And for those organisations who do DF investigations but sit outside the judicial systems, I think waterboarding might also be an option… 😯

Ben


   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

The authentication layer gets more and more locked shifting towards biometrics. Not so an easy task to overcome Face ID by a 'living' 3D-model. Face ID shifts to micro-living elements on the face and will get a thermal micro-lens in the future.


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

And for those organisations who do DF investigations but sit outside the judicial systems, I think waterboarding might also be an option… 😯

… particularly for odious crimes such as Parking Crimes that are reportedly on the rise
https://www.forensicfocus.com/Forums/viewtopic/t=16625/

jaclaz


   
ReplyQuote
Share: