Siri - inconsistent...
 
Notifications
Clear all

Siri - inconsistent statements

6 Posts
3 Users
0 Likes
653 Views
RolfGutmann
(@rolfgutmann)
Posts: 1185
Noble Member
Topic starter
 

Apple in 2013 stated that they keep Siri data for two years on their servers

https://www.wired.com/2013/04/siri-two-years/

Out of the keynote at WWDC '17 they stated that Siri data will remain on user's devices intersynced.

https://www.youtube.com/watch?v=1HSKSlU0Ncs see at 15500 - 15800

If Siri data remains on the device/s forensics should be able to bring out. Am I wrong?

 
Posted : 09/06/2017 12:05 am
(@badgerau)
Posts: 96
Trusted Member
 

Unless it is encrypted, like Apple Mail, which the tools cant extract.

 
Posted : 09/06/2017 2:06 am
RolfGutmann
(@rolfgutmann)
Posts: 1185
Noble Member
Topic starter
 

In iOS 11 Siri is End-to-End encrypted. But which end to wich end (e.g. device)?

 
Posted : 09/06/2017 2:30 am
(@badgerau)
Posts: 96
Trusted Member
 

Apple Mail, notes etc is encrypted on the device. I suspect Siri data would be encrypted on the device too. Although i have not tested this, it should be easy enough to do.

 
Posted : 09/06/2017 2:52 am
RolfGutmann
(@rolfgutmann)
Posts: 1185
Noble Member
Topic starter
 

Siri is based on several patents hold by Apple. I actually work on an overview but not ready now. Here is US 2016/0335532 A1 Pub. Date Nov. 17, 2016 Filed May. 15, 2015

https://patentimages.storage.googleapis.com/pdfs/381d172c93405475a4d4/US20160335532A1.pdf

So Siri goes out the Apple web servers. Encryption on iOS always gets its keys from the Secure Enclave and there the Secure Element. A question rises if Siri dialogues are part of iCloud backup?

 
Posted : 09/06/2017 12:42 pm
CopyRight
(@copyright)
Posts: 184
Estimable Member
 

Apple Mail, notes etc is encrypted on the device. I suspect Siri data would be encrypted on the device too. Although i have not tested this, it should be easy enough to do.

There's a great chance pulling out notes, and notifications of email titles if the backup taken from iTunes was encrypted. UFED uses this method it encrypts the iTunes backup to force the iOS to give out extra information such as user credentials, notes, some deleted data etc… and then it decrypts it while parsing.

It would be a interesting topic for me to search for Siri artefacts though.

 
Posted : 11/06/2017 2:47 pm
Share: