LTN Law Technology News
  • Home
  • News
  • Reviews
  • Commentary
  • Surveys
  • Events
  • LegalTech® Directory
  • About LTN
  • Register
  • Topics:
  • E-Discovery & Compliance
  • Litigation Support
  • Practice Management
  • Office Tech
  • Mobile Lawyer
  • Research & Libraries
  • Tech Law

Home > Apple iOS Forensics Advancing Slowly

Font Size: increase font decrease font

Apple iOS Forensics Advancing Slowly

By Evan Koblentz Contact All Articles 

Law Technology News

February 20, 2013

  •    
  •    
  •    
  •       Comments (1)
 
iPhone 5

iPhone 5
Image: Apple Inc.

When mobile forensic investigators and e-discovery experts work with the latest generation of Apple Inc. mobile devices, they remain stumped about how to view password-protected emails.

In many cases, passwords and pass-phrases are handed over during discovery proceedings to unlock encrypted content. But when passwords aren't available, investigators can only see encrypted data instead of email contents. That's true on the iPhone 5, iPad 4, and iPad Mini. Even the most common forensic products, such as Cellebrite Mobile Synchronization's Universal Forensic Extraction Device (UFED) system and Micro Systemation's XRY, cannot cross that chasm. Progress has been slow.

"We continue to monitor that very closely. I wish I could tell you that the industry as a whole is going to crack this nut very soon," Cellebrite USA CEO James Grady said. Glen Rock, N.J.-based Cellebrite officials explained that their products access data on other phones and on older i-devices by intervening in the device's memory before it reaches the booting stage, but that technique doesn't help on the newer iOS 6 devices running on Apple's A5X and A6 chipsets such as the iPhone 5 and iPad 4 devices. "It's an ongoing piece of research for us though. We're not giving up by any means," Grady said.

Micro Systemation also acknowledges the challenge. "I would say it's an obstacle for all the companies," said CEO Joel Bollö noted, in Stockholm, Sweden. Both companies' products are used by the majority of cellular carriers and by myriad law enforcement agencies and militaries.

Security researchers are making slight progress toward viewing i-device emails. The process is advancing slowly because Apple focuses on protecting data, and legitimate forensic techniques often have technical similarities to malicious attacks.

A special class of computer hackers known as "jailbreakers" are developing software that forensic companies can use as foundations to make e-discovery products capable of extracting unencrypted email messages from iOS 6 devices. Jailbreaking is slang, referring to programs that circumvent manufacturer restrictions on the device's file system. The software is meant for consumers and, despite its name, is not ominous. Jailbreaking one's phone has useful implications for ordinary users, such as being able to install software from any source rather than just from Apple's App Store. American law, as of Oct. 28, 2012, allows jailbreaking on smartphones but not on tablets. Laws in other countries vary.

Progress arrived on Feb. 4 when a hacker community called "evad3rs" -- pronounced "evaders" -- released what's believed to be the first jailbreak for the current-generation of Apple mobile devices. The software, "evasi0n", successfully lets users install third-party software. By having that capability, companies that make forensic software have a new arrow in their quiver for developing forensics software, because a jailbreak is often the first step toward accessing protected or encrypted data.

Apple and groups such as evad3rs compete in the cat-and-mouse game of jailbreaks vs. iOS updates designed to thwart them. "Jailbreaks can be the only mechanism to get access to that physical image," said Guidance Software Inc.'s Ken Mizota, product manager for EnCase products. "But we also see jailbreaks as an inherently risky exercise… any jailbreak introduces a risk to the device itself. While that risk may be minute, if performed inexpertly, it can have an unintended consequence of the loss of evidence," Mizota observed.

"Our main approach as a product company is that jailbreaking is temporary. For the cases where you can't get any evidence at all, like where you have a password that you can't break, then it's a valuable means," Mizota said. Pasadena, Calif-based Guidance has an update to its EnCase software for iOS devices due this spring, but that won't include any major advancements toward viewing protected messages, he said.

Other approaches to accessing protected iOS messages passwords including using brute-force methods, independent password applications, or memory alteration techniques. Each method has limited usefulness. Brute-force methods can take days, weeks, or even years to work, depending on a password's complexity. Companies such as Passware Inc. have modest iOS functions, such as recovering passwords for backup files. For actual device passwords, "We understand the importance of mobile forensics and plan to add this feature in the future," spokeswoman Nataly Koukoushkina said, without elaborating. Memory alteration, similar to Cellebrite's method, puts user-controlled software into a device's memory ahead of the standard boot sequence. It worked as a password circumvention method on iOS 5 and older devices but doesn't apply to iOS 6.

Messages also can't be accessed by exploiting a recently discovered iOS 6.1 design bug. The bug, which Apple pledged to fix, lets users perform an obscure sequence of device actions to view phone numbers and pictures. Apple has not released a patch as of Wednesday.

Forensic companies are much farther along with Google Android devices. Android is built on the open-source Linux operating system, for which there are many documented ways to take control of device memory. Conversely, with Research In Motion's BlackBerry devices, security can be even tougher to crack than on the iPhone, experts have said.

Evan Koblentz is a reporter for Law Technology News. Send email or follow him on Twitter.



Subscribe to Law Technology News

You must be signed in to comment on an article

 

Reader Comments

  • Forensics1

    February 24, 2013 12:26 AM

    This is an accurate and solemn insight into the current state of iOS forensics and the future of iOS forensics as well. Our business has focused on iOS devices for five years now and it has been a wild ride. We finally settled on iXAM by Forensic Technical Services in the United Kingdom. iXAM is the only iOS software that I know of that performs a full physical acquisition without a jailbreak and without leaving so much as one fingerprint behind. We have performed a multitude of full forensic acquisitions for a variety of clients with significant results.

    That was until Apple decided to do what they needed to do to maintain the vertical market composed of those three letter government agencies that insist on security. Apple began adding encryption routines that 'vacuum' up deleted messages thus limiting iXAM's and all other programs access to the data we need the most. By the way, RIM did not as some say that is one reason behind their recent downfall.

    Currently iXAM is capable of full physical recoveries on most iTouch devices, the iPad 1, iPad2, and all iPhones up to and including the Four and up to iOS 6.1. iXAM will not acquire the 4S and beyond at this time. They are currently working on breaking through the 4S and beyond. Time will tell.

    The future of forensics for iDevices is in question. Just as this article states it will take some serious time and some serious thinking to get us back into the game. My personal concern is that it will someday become completely impractical to get the data we need to protect our clients, convict those that need convicting, and catch those that need catching.

    We can look at alternatives such as going after the backups, the synced data, the cloud, etc... No one knows where the chase for the case will take us. If there are any fortune tellers out there I hope they will chime in now.

    Thank you for this insightful peek.

Comments are not moderated. To report offensive comments, click here.

Post a Comment »
Find similar content

Companies, agencies mentioned

    
  • EnCase
  • Linux
  • Universal Forensic Extraction Device
  • Passware
  • Apple Inc.
  • Guidance Software Inc.
  • Research In Motion Ltd.
  • App Store

Key categories

    
  • Networking, Storage, Content
  • E-discovery

Most viewed stories

    
  1. 10 Devices You Should Never Take Along on a Business Trip
    •      
  2. Redacted Emails Ordered Released in Aaron Swartz Case
    •      
  3. Is Stanford Law the New Vortex of Legal Technology?
    •      
  4. Using Computer Forensics to Investigate IP Theft
    •      
  5. Law Technology News Goin' Mobile With ALM
    •      
  6. CEIC: the Destination for Digital Investigation
    •      
  7. FTC Warns Companies of Children's Privacy Violations
    •      
  8. Judge Opens Toyota's Secrets to Additional Attorneys
    •      
  9. How the Predictive Coding Process Will Affect Paralegals
    •      
  10. Cross This App Off Your To-Do List
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Taking the Reins of Legal Department Operations

In-House Law: Now in 3-D!

Simpson Helps Yahoo, Tumblr Connect for $1 Billion Deal

Kasowitz Benson Launches in Los Angeles

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Collaboration Is Key to Defending Cyberattacks

Stanford Law Builds on Role as Legal Tech Incubator

Prolific ADA Plaintiff Faces Nemesis in Harassment Suit

Ullyot Exit Closes Chapter for Facebook

Rothstein Bankruptcy Trustee Files New Reorganization Plan
  •      
    • Subscription Required

Fla. Bar Wants Disbarment for Former Judge
  •      
    • Subscription Required

Appellate Division To Roll Out Electronic Case Filing System

Court Limits Liability for Injury Or Death of One Invited To Help
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Judge Declines to Block Act-of-War Defense in 9/11 Case
  •      
    • Subscription Required

Panel Finds 'Excessive' City Fine for Poaching Antenna From Trash
  •      
    • Subscription Required

Lawsuit Testing Federal Porn Regulation Allowed to Survive

Ex-College QB Can Press Claim Over EA's Video Game
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Water Warriors: Local Governments Bring Pollution Suits
  •      
    • Subscription Required

Sanction Reversed; Filing of Sexually Explicit Chat OKd
  •      
    • Subscription Required

Brooks Looks To Political Ally For Criminal Defense

Attorney Fee Hearing in Waffle House Sex Case Heats Up
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • Contact LTN
  • Editorial Guidelines
  • Magazine
  • RSS Feeds
  • LTN Awards
  • Bookstore
  • Site Map
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media