<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Extracting the File System from iPhone/iPad/iPod Touch Devices</title>
	<atom:link href="http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/</link>
	<description>«...This blog is about &#60;a href=&#34;/?s=password+recovery&#34;&#62;cracking passwords&#60;/a&#62;, &#60;a href=&#34;/?s=forensic&#34;&#62;forensics solutions&#60;/a&#62;,&#60;br&#62;&#60;a href=&#34;/?s=security&#34;&#62;computer and network security&#60;/a&#62;, &#60;a href=&#34;/?s=system+recovery&#34;&#62;system recovery&#60;/a&#62; and other things...»</description>
	<lastBuildDate>Fri, 26 Apr 2013 14:47:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Faye</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-29804</link>
		<dc:creator>Faye</dc:creator>
		<pubDate>Tue, 29 May 2012 19:55:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-29804</guid>
		<description><![CDATA[Hi just wondering if u can advise in best product to buy? I made a backup of my iPhone 4 on my windows 7 pc, I need a password and told that there will be a file called keychain which has it?]]></description>
		<content:encoded><![CDATA[<p>Hi just wondering if u can advise in best product to buy? I made a backup of my iPhone 4 on my windows 7 pc, I need a password and told that there will be a file called keychain which has it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jezza</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-25334</link>
		<dc:creator>Jezza</dc:creator>
		<pubDate>Sat, 19 Nov 2011 16:03:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-25334</guid>
		<description><![CDATA[Does this mean that: as long as you can neither break the passcode nor the backup encryption password, the data is safe (both on device and/or computer)?

(i.e. from a user point of view a strong passcode and strong backup encryption password is enough to avoid having the data protection cracked?)

Any point in further encrypting the actual sync folder used by the iTunes?]]></description>
		<content:encoded><![CDATA[<p>Does this mean that: as long as you can neither break the passcode nor the backup encryption password, the data is safe (both on device and/or computer)?</p>
<p>(i.e. from a user point of view a strong passcode and strong backup encryption password is enough to avoid having the data protection cracked?)</p>
<p>Any point in further encrypting the actual sync folder used by the iTunes?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrey Belenko</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-25123</link>
		<dc:creator>Andrey Belenko</dc:creator>
		<pubDate>Sat, 12 Nov 2011 10:50:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-25123</guid>
		<description><![CDATA[Yes, a little: more files are protected with the passcode and escrow keybag can&#039;t be used instead of the passcode for decryption.]]></description>
		<content:encoded><![CDATA[<p>Yes, a little: more files are protected with the passcode and escrow keybag can&#8217;t be used instead of the passcode for decryption.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JK</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-25043</link>
		<dc:creator>JK</dc:creator>
		<pubDate>Wed, 09 Nov 2011 13:39:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-25043</guid>
		<description><![CDATA[Does iOS 5 mitigate any of this?]]></description>
		<content:encoded><![CDATA[<p>Does iOS 5 mitigate any of this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrey Belenko</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-24880</link>
		<dc:creator>Andrey Belenko</dc:creator>
		<pubDate>Fri, 04 Nov 2011 06:56:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-24880</guid>
		<description><![CDATA[1. What you are saying is generally true when getting data from the device itself and not from the backup. Keychain items protected with classes above the kSecAttrAccessibleAlways are impossible to decrypt without the passcode (or the escrow keys in iOS 4). EPPB, however, works only with the backups and the story is slightly different there.
If backup is encrypted and backup password is known then all keychain items from the backup can be decrypted (except for those with ...ThisDeviceOnly protection classes). Device passcode protection does not matter here.

2. For developers I&#039;d suggest to use standard system services for storing sensitive data (i.e. use Keychain and do not re-invent the &lt;del datetime=&quot;2011-11-04T09:05:41+00:00&quot;&gt;wheel&lt;/del&gt; crypto) and to use the most restrictive protection classes for both keychain items and application data files.
For users – use complex passcode, do not connect the device to third-party PCs, use backup encryption.]]></description>
		<content:encoded><![CDATA[<p>1. What you are saying is generally true when getting data from the device itself and not from the backup. Keychain items protected with classes above the kSecAttrAccessibleAlways are impossible to decrypt without the passcode (or the escrow keys in iOS 4). EPPB, however, works only with the backups and the story is slightly different there.<br />
If backup is encrypted and backup password is known then all keychain items from the backup can be decrypted (except for those with &#8230;ThisDeviceOnly protection classes). Device passcode protection does not matter here.</p>
<p>2. For developers I&#8217;d suggest to use standard system services for storing sensitive data (i.e. use Keychain and do not re-invent the <del datetime="2011-11-04T09:05:41+00:00">wheel</del> crypto) and to use the most restrictive protection classes for both keychain items and application data files.<br />
For users – use complex passcode, do not connect the device to third-party PCs, use backup encryption.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jerome</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-24864</link>
		<dc:creator>Jerome</dc:creator>
		<pubDate>Thu, 03 Nov 2011 05:38:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-24864</guid>
		<description><![CDATA[1) I would assume that if passcode is complex and if the application is storing credentials in keychain with adequate protection attributes (I would assume all attributes would do the job, except the kSecAttrAccessibleAlways), then this information is not accessible by your tool (EBBP). I am correct ?
2) If not, or more generally, do you have some best practices to follow for users AND developers to make sure the information (in keychain items, files, iTunes backup, etc) are well protected and not accessible by your tool ?]]></description>
		<content:encoded><![CDATA[<p>1) I would assume that if passcode is complex and if the application is storing credentials in keychain with adequate protection attributes (I would assume all attributes would do the job, except the kSecAttrAccessibleAlways), then this information is not accessible by your tool (EBBP). I am correct ?<br />
2) If not, or more generally, do you have some best practices to follow for users AND developers to make sure the information (in keychain items, files, iTunes backup, etc) are well protected and not accessible by your tool ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Devon</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-24183</link>
		<dc:creator>Devon</dc:creator>
		<pubDate>Sun, 11 Sep 2011 22:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-24183</guid>
		<description><![CDATA[Thanks for this useful information, I will be refering to it for my mobile forensics project. @bob the “wipe device after 10 failed passcode attempts” is useless as the device cracking will be performed in off-line mode if I&#039;m correct?]]></description>
		<content:encoded><![CDATA[<p>Thanks for this useful information, I will be refering to it for my mobile forensics project. @bob the “wipe device after 10 failed passcode attempts” is useless as the device cracking will be performed in off-line mode if I&#8217;m correct?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Creswici</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-23465</link>
		<dc:creator>Paul Creswici</dc:creator>
		<pubDate>Thu, 16 Jun 2011 22:05:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-23465</guid>
		<description><![CDATA[@Andrey,
It’s precisely that I have to enter the complex password many times a day that makes it workable – repetition of a complex string makes it memorable and practise makes it easy to enter rather than annoying.]]></description>
		<content:encoded><![CDATA[<p>@Andrey,<br />
It’s precisely that I have to enter the complex password many times a day that makes it workable – repetition of a complex string makes it memorable and practise makes it easy to enter rather than annoying.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrey Belenko</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-23358</link>
		<dc:creator>Andrey Belenko</dc:creator>
		<pubDate>Mon, 30 May 2011 19:26:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-23358</guid>
		<description><![CDATA[@Bob,
1) Escrow keybag is not required. Without both escrow keybag and the passcode we can decrypt almost every file and significant part of the Keychain. Let me say this again: having only the device and not knowing the passcode nor having escrow keybag we can decrypt very significant part of its device contents. FDE on your PC does not help.
2) Do you REALLY use complex alphanumeric passcode (passcode – and not backup password)? You have to enter it like dozens of times a day and I don&#039;t think many people are using something really complex. That quickly becomes annoying. Also, the &#039;wipe device after 10 attempts&#039; is irrelevant here, too, since we bypass all sort of such protections. And it is a &#039;game over&#039; for iOS 4 in some environments with certain security requirements.]]></description>
		<content:encoded><![CDATA[<p>@Bob,<br />
1) Escrow keybag is not required. Without both escrow keybag and the passcode we can decrypt almost every file and significant part of the Keychain. Let me say this again: having only the device and not knowing the passcode nor having escrow keybag we can decrypt very significant part of its device contents. FDE on your PC does not help.<br />
2) Do you REALLY use complex alphanumeric passcode (passcode – and not backup password)? You have to enter it like dozens of times a day and I don&#8217;t think many people are using something really complex. That quickly becomes annoying. Also, the &#8216;wipe device after 10 attempts&#8217; is irrelevant here, too, since we bypass all sort of such protections. And it is a &#8216;game over&#8217; for iOS 4 in some environments with certain security requirements.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Walder</title>
		<link>http://blog.crackpassword.com/2011/05/extracting-the-file-system-from-iphone-ipad-ipod-devices/comment-page-1/#comment-23357</link>
		<dc:creator>Bob Walder</dc:creator>
		<pubDate>Mon, 30 May 2011 18:31:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1637#comment-23357</guid>
		<description><![CDATA[They did NOT find the keys.... the toolkit relies on 1) Possession of the escrow keybag which is stored on any host PC which has sync&#039;d to the device via iTunes (good luck with that if I store my iTunes backups on an encrypted volume, BTW!) or 2) Brute force attack on the device to break the passcode. What they have done that is cool is shown that they can do this. HOWEVER, since any sensible user with data to protect will use a complex passcode consisting of a larger number of alphanumeric &amp; special characters and NOT a simple 4 digit passcode, then my guess is that on-device cracking of the passcode is not realistic. ALSO, if user has set &quot;wipe device after 10 failed passcode attempts&quot; then.... this stuff makes for good headlines but it is not &quot;game over&quot; for iOS 4 users by any stretch of the imagination]]></description>
		<content:encoded><![CDATA[<p>They did NOT find the keys&#8230;. the toolkit relies on 1) Possession of the escrow keybag which is stored on any host PC which has sync&#8217;d to the device via iTunes (good luck with that if I store my iTunes backups on an encrypted volume, BTW!) or 2) Brute force attack on the device to break the passcode. What they have done that is cool is shown that they can do this. HOWEVER, since any sensible user with data to protect will use a complex passcode consisting of a larger number of alphanumeric &amp; special characters and NOT a simple 4 digit passcode, then my guess is that on-device cracking of the passcode is not realistic. ALSO, if user has set &#8220;wipe device after 10 failed passcode attempts&#8221; then&#8230;. this stuff makes for good headlines but it is not &#8220;game over&#8221; for iOS 4 users by any stretch of the imagination</p>
]]></content:encoded>
	</item>
</channel>
</rss>
