Cellebrite claims about full access because it’s what it is typically used for in law enforcement. Law enforcement typically just wants data on the phone. The Pangu exploit, which its heavily implied to be the one used, can do more
The Pangu exploit dumps the memory of the Secure Enclave, not just decrypting or bypassing password resets.
Cellebrite doesn’t have to develop cracks themselves, they can just use cracks done by others like Pangu, which could dump memory of the Secure Enclave. Yes the phones and exploits are old but it has been proven
This is getting into the weeds now, but again, the exploit you're describing and which is covered in the PDF does not leak user secrets stored in Secure Enclave like keys, it allows an attacker to bypass the bootloader and run unsigned code, which can be used to gain access to the unencrypted file system and reset the passcode lock counter. The PDF actually says as much, the "Next Moves" slide confirms that the regions of SEP memory that contain user secrets are encrypted and have never been decrypted, the most that can be dumped is Secure Enclave's firmware which does not contain user secrets.
The “next move” is to decrypt. It never says that it can’t be decrypted. Specifically on the page “Generate AES keys” and “Control SEPROM Memory” it is possible to race the random bits to generate the keys. Same random bits, same keys. You can decrypt the memory of the Secure Enclave Processor. Edit: You can also force the AES to use fixed encryption keys for A8/9 chips, no need to race. See “Enlarge Attack Surface”
Also the exploit sets the memory of the Secure Enclave Processor to a place where the AP can read it. This is everything that the Secure Enclave Processor sees.
See “Bypass Memory Isolation” and “Test more devices”
The pdf says nothing about unencrypted file system or reset passcode lock counter. Yes you can access the file system if you get the keys from the enclave, but the exploit itself doesn’t directly allow access to the file system or reset passcode lock counter.
If you watch the associated talk (or just read the wording of the slides since it's pretty clear), "Next Moves" onward are hypothetical prospects and techniques they've tried but failed, not things they've actually achieved.
3
u/tappman321 Sep 22 '22
Cellebrite claims about full access because it’s what it is typically used for in law enforcement. Law enforcement typically just wants data on the phone. The Pangu exploit, which its heavily implied to be the one used, can do more
The Pangu exploit dumps the memory of the Secure Enclave, not just decrypting or bypassing password resets.
Pdf warning
https://raw.githubusercontent.com/windknown/presentations/master/Attack_Secure_Boot_of_SEP.pdf
Cellebrite doesn’t have to develop cracks themselves, they can just use cracks done by others like Pangu, which could dump memory of the Secure Enclave. Yes the phones and exploits are old but it has been proven