With access to *any* computer that has synced with an iPhone, or a little time to recover the plain-text password, the entire phone’s contents can be read in as little as 20 minutes, according to Elcomsoft, a well-known supplier of password decryption software tools.
From their crackpassword.com blog:
When developing the iOS 5 compatible version of iOS Forensic Toolkit, we found the freshened encryption to be only tweaked up a bit, with the exception of keychain encryption. The encryption algorithm protecting keychain items such as Web site and email passwords has been changed completely. In addition, escrow keybag now becomes useless to a forensic specialist. Without knowing the original device passcode, escrow keys remain inaccessible even if they are physically available.
Now the good news: iOS Forensic Toolkit can still recover the original plain-text device passcode, and it is still possible to obtain escrow keys from any iTunes equipped computer the iOS device in question has been ever synced or connected to. Once the passcode is recovered, iOS Forensic Toolkit will decrypt everything from the keychain. If there’s no time to recover the passcode or escrow keys, the Toolkit will still do its best and decrypt some of the keychain items.
Devices supported:
1) iPhone 3G
2) iPhone 3GS
3) iPhone 4 (GSM and CDMA models)
4) iPod Touch (1st, 2th, 3rd and 4th generations)
5) iPad (1st generation only)
Note, this product is not available to the public
“ElcomSoft restricts the availability of the toolkit to select government entities such as law enforcement and forensic organizations and intelligence agencies.”
My comment: Acquire means reading and copying *everything* off the phone, including email passwords and website passwords. Physical access to the phone is required, this cannot be done remotely.
In a hypothetical intelligence/surveillance scenario a phone could be removed from a bag or pocket, taken to a back-room, acquired and returned within an hour, whilst the owner is kept occupied with drinks, food, chat, “eye-candy” or a direct physical diversion!
{ 0 comments }



