{"id":53485,"date":"2014-02-24T07:31:36","date_gmt":"2014-02-24T05:31:36","guid":{"rendered":"http:\/\/businesstech.co.za\/news\/?p=53485"},"modified":"2014-02-24T07:31:36","modified_gmt":"2014-02-24T05:31:36","slug":"too-many-ifs-to-crack-pistorius-iphone-expert","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/mobile\/53485\/too-many-ifs-to-crack-pistorius-iphone-expert\/","title":{"rendered":"Too many &#8216;ifs&#8217; to crack Pistorius iPhone: expert"},"content":{"rendered":"<p>The likelihood of investigators getting any information off of Oscar Pistorius&#8217; locked iPhone will need a lot of technical boxes to be ticked, a security expert has said.<\/p>\n<p>This follows reports that investigators are having a tough time gaining access to the murder-accused paralympian&#8217;s phone for crucial evidence &#8211; with the much-publicised trial date drawing nearer.<\/p>\n<p>Pistorius stands accused of murdering his model girlfriend, Reeva Steenkamp, on 14 February 2013.<\/p>\n<p>Pistorius claimed that he believed Steenkamp was an intruder at the time the incident took place, and opened fire on her behind a closed door. The state is pursuing murder charges.<\/p>\n<p>Two iPhones and a BlackBerry were taken as evidence in the case &#8211; though Pistorius reportedly could not remember the four-digit PIN code needed to unlock the phone at the time.<\/p>\n<p>Pistorius&#8217; legal representative, Brian Webber, has handed over Pistorius&#8217; Apple ID and password to authorities. Investigators claim that the details are not correct.<\/p>\n<p>On Thursday, 13 February, news outlet eNCA claimed to have gained access to Pistorius\u2019 iTunes account using the Apple ID and password provided by Webber, without any issues.<\/p>\n<p>\u201cAll it appears to reveal is that Oscar Pistorius likes legal TV dramas, cello concertos and dance music,\u201d the news group said.<\/p>\n<p>Investigators, however, are looking for more than download and app information \u2013 rather seeking to gain access to iMessage history and other data stored on the paralympian\u2019s traceable digital footprint.<\/p>\n<p>Content such as text messages and communication through message applications are not held by network operators (which only track &#8220;to&#8221; and &#8220;from&#8221; cellphone numbers), meaning RICA would not help with any content insight in this case.<\/p>\n<h3 class=\"my-4\">Is the content even accessible?<\/h3>\n<p>According to an iPhone security expert, gaining access to data on a locked iPhone using an Apple ID and password alone is unlikely.<\/p>\n<p>&#8220;With an iPhone 4S and above, no there isn&#8217;t a way to unlock the device without the PIN &#8211; you can&#8217;t do it with the Apple ID only,&#8221; the expert said.<\/p>\n<p>&#8220;With the Apple ID you can wipe and restore the phone, but it requires that you have access to either on-computer or iCloud backups of the device.&#8221;<\/p>\n<p>Previous version of Apple&#8217;s iOS software allowed users to bypass the PIN lock-screen using an emergency call exploit, while the iPhone tracking app, Find my iPhone, allowed a remote PIN reset.<\/p>\n<p>Both of these work-arounds have since been removed by Apple.<\/p>\n<p>If the incorrect PIN is repeatedly entered into the device a number of times, it locks up temporarily. There are options available to erase data from the device if the incorrect PIN is entered 10 times.<\/p>\n<p>For iPhone users who &#8220;forgot&#8221; their passwords or blocked their devices, gaining access to their devices requires a system restore through iTunes (on-computer of iCloud back ups), or a complete system reset.<\/p>\n<p>This process, again, has a few prerequisites which, if not met, means all data on the device will be lost.<\/p>\n<p>To successfully bypass a locked device and restore its data:<\/p>\n<ul>\n<li>The correct Apple ID and password associated with the required Apple account are needed.<\/li>\n<li>The specific Apple account needs to be linked to the device in question.<\/li>\n<li>The device needs to have been backed up to iCloud &#8211; or physically back-up to a computer.<\/li>\n<li>The right data (iMessage and app data) needs to be backed up.<\/li>\n<li>The account, device and passwords must have not been remotely tampered with.<\/li>\n<\/ul>\n<p>&#8220;That&#8217;s quite a few &#8216;ifs&#8217; &#8211; there&#8217;s a lot of hypothesis here,&#8221; the expert said.<\/p>\n<p>In the Pistorius case and the problems investigators have been facing, the security expert weighed that it&#8217;s possible that the Apple ID provided isn&#8217;t the one used for the iCloud backups &#8211; if any exist.<\/p>\n<p>A number of forensic tools exist that can extract data from the iCloud; however, proper processes need to be followed for any evidence to stand up in court.<\/p>\n<p>Further, there&#8217;s no way to tell if Pistorius didn&#8217;t nuke his iMessage or WhatsApp history before handing it over to police, or restored his data to another device, remotely.<\/p>\n<p>&#8220;He could maybe have closed his account remotely, and linked a new phone to a new account.&#8221;<\/p>\n<p>Pistorius&#8217;s murder trial is set to start on 3 March 2014.<\/p>\n<h3 class=\"my-4\">More on Oscar Pistorius<\/h3>\n<p><strong><a title=\"Permalink to Pistorius iPhone code remains elusive: report\" href=\"http:\/\/businesstech.co.za\/news\/general\/53190\/pistorius-iphone-code-remains-elusive-report\/\" rel=\"bookmark\">Pistorius iPhone code remains elusive: report<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/general\/80859-apple-asked-for-help-in-pistorius-murder-case.html\">Apple asked for help in Pistorius murder case<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/general\/75307-social-media-disturbs-pistorius-family.html\">Social media \u201cdisturbs\u201d Pistorius family<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/internet\/71782-the-oscar-pistorius-shooting-effect.html\">The Oscar Pistorius shooting effect<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/internet\/71324-oscar-pistorius-spin-on-the-internet.html\">Oscar Pistorius\u2019 spin on the Internet<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The likelihood of investigators getting any information off of Oscar Pistorius&#8217; locked iPhone will need a lot of technical boxes to be ticked, a security expert has said.<\/p>\n","protected":false},"author":10,"featured_media":53341,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[51,26,209,5213,375],"class_list":["post-53485","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mobile","tag-apple","tag-headline","tag-iphone","tag-oscar-pistorius","tag-security"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/53485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=53485"}],"version-history":[{"count":2,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/53485\/revisions"}],"predecessor-version":[{"id":53507,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/53485\/revisions\/53507"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/53341"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=53485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=53485"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=53485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}