iPhone's remote wiping may help crooks cover tracks

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Criminals can remotely destroy incriminating evidence by exploiting security features on the Apple iPhone, a leading digital-forensics expert has warned.

The head of the Serious Fraud Office's digital forensics unit, Keith Foggon, cautioned that the ability to remotely wipe the iPhone and other smartphones used by enterprises could be exploited by law-breakers.

Foggon said: "The iPhone 3G is brand new, there are not many tools for dealing with it and it can be remotely wiped. It's a bit like the BlackBerrys, where users can carry out remote deletion."

He added that the unit took precautions to guard against the feature being exploited. "Because we isolate the devices immediately and never reconnect them to their network, the remote-wiping capability does not present us with much of a problem," he noted.

The 21-strong unit, which hunts out incriminating evidence from crime scenes, uses a number of hi-tech tools to get the sensitive data needed by the police to build a case. Advanced forensics tools, such as the Logicube CellDEK, allow the forensics organisation to pull data from more than 1,100 of the most popular mobile phones and PDAs, while the team members carry suitcases containing handset connectors of every shape and size to help collect data from the devices.

However, Foggon warned that the shift away from PCs towards mobile devices is posing an increasing headache for the digital-forensics teams.

He said: "It is a concern that society is moving more towards using mobile phones. The PC architecture is usually stable but, with mobile devices, they change daily. If a mobile device comes out tomorrow, we will not be able to look at it until a tool becomes available."

"We can still analyse it, by photographing every screen on it, but we won't be able to get hidden data on it, so photographing every screen is not a very practical way of doing it," Foggon said. "That is an area where we are almost playing catch-up."

Another growing problem, as regards forensics teams' ability to recover evidence, is the encryption features found in modern operating systems.

"With Windows Vista, you have BitLocker, which will cause us some problems," Foggon noted.

"It ties in the encryption to a chip. There are ways around it but it is something we can't crack; we need a pass to get around that."

The team cracks low-grade encryption using 100 quad-core PCs but, for high-grade encryption, it relies on the threat of a prison sentence for individuals refusing to hand over passwords or decrypted files.

Foggon believes that the unit's years of experience in unearthing evidence from everything from 186s to MacBooks will mean it will have a key role to play in any central UK e-crime policing unit.

The government has committed itself to funding such a unit and indicated it could be part of the proposed National Fraud Reporting Centre, under the Attorney General's Office, while the Metropolitan Police Service and the Association of Chief Police Officers have put forward proposals to the government to establish a policing central e-crime unit.

Foggon said the unit's structure could soon be transformed, and it may even tackle a wider range of criminal investigations, following the publication of its reaction, due imminently, to a review of the Serious Fraud Office carried out by former senior New York City prosecutor Jessica de Grazia.

The review called for clarity about the roles, responsibilities and qualifications of case controllers and assistant directors within the Serious Fraud Office.

Talkback

This may be an issue when dealing with organized crime, but probably not for garden variety criminals. The iPhone's 'remote wipe' capability must be set up in advance, and requires an Exchange Server. Remotely wiping the data from an iPhone cannot be done merely as an afterthought.

The remote wipe ability is set up by use of a configuration file which includes the user's Exchange account information, so if the iPhone is captured and not connected to its network (and therefore is not able to be remotely wiped), the Exchange account information may lead the authorities to the criminal's organization as well.

For criminals setting up this feature, it's a double-edged sword.

Curmudgeon 3 September, 2008 19:33
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

2 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

8 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

9 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

9 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

14 hours ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

15 hours ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

17 hours ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

1 day ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

1 day ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

1 day ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit
apexwm

Interesting article and definitely see your points on the products mentioned. One of the top products for our Help Desk (approximately 20% of all...

2 days ago by apexwm on Ten flawed products that derail productivity
Paul Hutchinson

Absolutely - this should obviously not be handled my isp - but handled by their hosting operator. What's been suggested here is that my isp police...

2 days ago by Paul Hutchinson via Facebook on MPs urge ISPs to take down terrorist material
Techs UK

Looks like a great phone. I don't notice any deficiencies in WP7. used IOS before, that's pretty good. I don't spend much time in Apps, all i need...

2 days ago by Techs UK on Nokia pins US 're-entry' hopes on Lumia 900
Larry Bloggy

Now with the help of these apps you are always synced with MS outlook while on the move. Just download apps like xobni or outlookreflex and get...

2 days ago by Larry Bloggy via Facebook on Outlook Social Connector beta 2 and the LinkedIn connector
mike40g123

Your details are wrong. The version currently being made is the one with 2 USB ports, 256MB RAM and a network port. This is the Model B. The...

2 days ago by mike40g123 on Raspberry Pi boards set to go on sale
Moley

The thing that has been puzzling me for quite a while is how Anonymous can remain anonymous whilst not only being active on the Internet but also...

2 days ago by Moley on Anonymous activists release PCAnywhere source code
Don Dilly

If what Semantec is saying is rue, that is even worse and shows a complete disregard for thier users. If what Anonymous claims is true and the...

2 days ago by Don Dilly via Facebook on Anonymous activists release PCAnywhere source code
MattChurchy

Didn't seem particularly biased to me either. Oh though you might have mentioned some other competitors with free search and email services...

3 days ago by MattChurchy on Time for an evil umpire: Google, Microsoft & privacy
Simon Bisson and Mary Branscombe

James - exactly as much as anyone paid you for your comment; I don't feel that I need to say that I'm independant and unbiased, but just for you...

3 days ago by Simon Bisson and Mary Branscombe on Time for an evil umpire: Google, Microsoft & privacy
Carl White

Once they realise symantec are willing to pay real money, they will simply keep extorting, unless of course symantec/authorities can use the...

3 days ago by Carl White via Facebook on Symantec offered hackers $50k in source code sting