Hi to you all and thank you for this very interesting web site.
After reading many posts,
I have question
I understood that the locked screen 4S that I have to extract is not possible for now
(my lab owns CELLEBRITE SOFT), but would it be possible to
extract the memory chip physically and read it ?
But Where is this chip ? Witch one ?
Is it possible ?
Thanks a lot for your help
Alex
I have question
I understood that the locked screen 4S that I have to extract is not possible for now
(my lab owns CELLEBRITE SOFT), but would it be possible to
extract the memory chip physically and read it ?
But Where is this chip ? Witch one ?
alexfromparis
Here is some info that may help your research
Toshiba THGVX1G7D2GLA08 16 GB NAND Flash Memory
http//
However, if you read the webpage (link below) it will tell you iPhone 4S has a Hynix NAND flash
http//
Hynix NAND flash - http//
Here are a few other links about tearsdown, chip removal etc
http//
http//
http//
http//
There is a course coming to the UK - http//www.forensicfocus.com/Forums/viewtopic/p=6560881/
A Det. Bob Elder - VICPD who uses the forensic focus forum handle "sideshow018" is involved with this course.
Dear trewmte,
thank you so much for your time and links.
Reading at first look, I understand that it is doable, but sounds a long process
to success.
I'm going to study that!
Thanks again !
Alex
I think a password protected 4S actually has the encryption on the chip, bypassing the lock to go straight to the chip therefore, doesn't work in this case
Bigjon is correct on this as far as our research and development has indicated. It is believed that the data on the chip is encrypted and the key to decrypt this data is not found within the two NAND type memory chips described by my colleague Trewmte. It is believed to be on another chip that will require reading in order to decrypt the data, possible a TPM type chip or other onboard hardware device. Working on it and I know of one other entity that is working it hard as well….hopefully soon!
I agree with bigjon and sideshow018 regarding the encryption and encryption keys. Indeed search forensic focus there have been discussions on this over the last year. You will note that my post makes no mention of encryption but references discussion and location of the nand chip.