6 workarounds for accessing encrypted devices

 

Connecting state and local government leaders

A pair cybersecurity experts have published an essay that discusses the practical, technological and legal implications of encryption workarounds.

The story of Syed Farook’s iPhone is a perfect illustration of both the power of encryption on personal devices and the government’s frustration with such security when it hinders an investigation.

In the wake of the 2015 San Bernadino, Calif., shootings, investigators wanted access to Farook’s iPhone. The phone was encrypted, the FBI asked Apple to write software to give it access and Apple refused to comply. What ensued was a long battle that played out in courts and in public. In the end the government allegedly paid $1 million to third party to have the phone unlocked.

Access to encrypted information need not always be as difficult or expensive for investigators, however. Two cybersecurity experts have published an essay that discusses the practical, technological and legal implications of six encryption workarounds.

“Encryption raises a challenge for criminal investigators,” wrote Orin S. Kerr, director of the Cybersecurity Law Initiative at George Washington University Law School, and Bruce  Schneier, fellow at Harvard University’s Berkman Klein Center for Internet & Society and CTO at Resilient. When law enforcement attempts to access encrypted data, only ciphertext or  scrambled information can be seen, which is useless unless it can be decrypted. “For government investigators," Kerr & Schneider wrote, "encryption adds an extra step: They must figure out a way to access the plaintext form of a suspect’s encrypted data.”

The following workarounds have been used by investigators since messages have been encrypted – back to the time of Elizabeth I when decoded private letters revealed an assassination plot. Today, because encryption is so widespread, investigators come across it in routine cases, making ways to bypass encryption especially timely and relevant. 

1. Find the key. The most obvious of the six ways to get around encryption is finding the passwords, passcodes or passphrases required to get into a device. The key might be written down somewhere or stored on an accessible device.

2. Guess the key. Although encryption keys themselves are long and random, the passwords that protect them are usually easier to guess. Investigators have used a suspect’s date of birth as a password to access personal devices. Password-cracking software can try millions of passwords per second, but investigators can be limited by a device’s features that only allow a certain number of password tries before locking out the would-be user.

3. Compel the key. Merely asking, “What’s your password?” could get investigators the exact information they need, and authorities could legally compel device owners or others who know its password to provide it, the authors said. Both the Fourth and Fifth Amendments provide the device owners with some protection, but “considerable ambiguity remains about how much of a burden [these Amendments] impose” on investigators.

4. Exploit a flaw in the encryption scheme. This workaround requires finding a flaw in the encryption and using that weakness to gain access to the device. This technique, commonly used by hackers, “is analogous to breaking into a locked car by breaking a window instead of picking the lock,” the researchers said. The FBI likely gained access to the San Bernardino shooter’s phone this way, the authors said. The company helping the FBI may have found a flaw in an auto-erase function used on the phone to make it harder to guess passwords. “This approach relied on two workarounds in tandem: First, exploit the flaw; second, guess the key,” they said. 

5. Access plaintext when the device is in use. This workaround requires accessing a device while it is in use and its data has been decrypted, such as when a suspect using a device is arrested before the phone or computer can be shut down. Gaining remote access “is much more complicated than physically seizing the machine,” the two said. “First, hacking will require the government to have figured out a technical means to gain remote access to the device. Second, government hacking can raise complex legal questions under the Fourth Amendment and other laws. Dozens of federal courts are currently considering the legality.”

6. Locate a plaintext copy. Can’t get into the device? Find the information somewhere else. The information that investigators are looking for likely exists in an unencrypted version somewhere, Kerr and Schneier suggested; cloud copies are increasingly common. In the San Bernardino case, investigators were able to get iCloud backups of the shooter’s phone. The information was six weeks out of date – which is why the FBI paid for the workaround -- but it still provided insight.

Read the full paper here.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.