Site navigation

Apple Updating iPhone to Avoid Law Enforcement Access

Brian Baglow

,

Apple iOS Security Update

Changing settings on the iPhone will make it more difficult for criminals – and law enforcement – to access personal data.

Apple has announced changes to default iPhone settings in a forthcoming iOS update which will make it far harder for law enforcement officials (and criminals presumably) to access personal data.

The change will cut off communication through the phone’s USB port after it has been ‘locked’ for an hour. The USB is the access point for technologies from a number of forensic software companies, which bypasses security settings to limit the number of passcode guesses which can be made before the device locks down or deletes data.

Apple said it aims to protect all customers, especially in countries where phones are readily obtained by police or by criminals with extensive resources, and to head off the further spread of the attack technique.

To date these companies have made their services available to law enforcement agencies around the world, either selling a machine directly, or offering an unlocking service on a pay-per-phone basis.

Techniques Leaked Online

An Apple spokesperson said the change will protect customers in countries where law enforcement seizes and tries to crack phones of offenders or even suspects. The company also noted that criminals, spies and unscrupulous people often use the same techniques. Even some of the methods most prized by intelligence agencies have been leaked on the internet.

“We’re constantly strengthening the security protections in every Apple product to help customers defend against hackers, identity thieves and intrusions into their personal data,” Apple said. “We have the greatest respect for law enforcement, and we don’t design our security improvements to frustrate their efforts to do their jobs.”

Apple reportedly began working on the USB issue before learning it was a favourite of law enforcement. The change was had been documented in beta versions of iOS 11.4.1 and iOS12, and according to Reuters, it will be made permanent in a forthcoming general release.

According to Apple, after it learned of the techniques, it reviewed the iOS security and decided to simply alter the setting, a cruder way of preventing most of the potential access by unfriendly parties. Once the change has been implemented, anyone seeking unauthorised access to an iPhone will typically have an hour or less to get a phone to a cracking machine.

Enterprise Data Planning in Financial Services event

Law Enforcement Response

Of course this could simply spur sales of cracking devices, as law enforcement agencies try to get more machines closer to where seizures occur. The change is likely to draw criticism from law enforcement agencies around the world, which are increasingly struggling with the issue of encrypted data being used by criminals and terrorists.

Police Scotland was recently criticised for the force’s use of ‘Kiosk’ technology, which allows them to access data on seized mobile phones.

There is also the complication of the facial recognition system in use on the iPhone X and similar biometric security measures. While the rights of an individual vary from country to country in terms of law enforcement’s right to demand a pin code or even a fingerprint, facial recognition means that police could simply point the phone at the owner in order to unlock it.

Movers and shakers

Brian Baglow

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data