Apple engineer Ivan Krstic is scheduled to host a discussion at this year's Black Hat Conference, offering a "Behind the Scenes" look at iOS security. Black Hat is an annual event designed for the global InfoSec community, giving security professionals a place to meet up and gain training on new techniques.

According to an overview of Krstic's talk, three iOS security mechanisms will be discussed in "unprecedented technical detail," including the first public discussion of Auto Unlock, a feature new to iOS 10.

blackhat

HomeKit, Auto Unlock and iCloud Keychain are three Apple technologies that handle exceptionally sensitive user data - controlling devices (including locks) in the user's home, the ability to unlock a user's Mac from an Apple Watch, and the user's passwords and credit card information, respectively. We will discuss the cryptographic design and implementation of our novel secure synchronization fabric which moves confidential data between devices without exposing it to Apple, while affording the user the ability to recover data in case of device loss.

Krstic will also cover the Secure Enclave Processor present in iOS devices that include the iPhone 5s and later, creating a discussion around how it enabled a new approach to Data Protection key derivation and brute force rate limiting within a small TCB, and he'll cover browser-based vulnerabilities and new protective features in iOS 10 Safari.

The 2016 Black Hat Conference will take place from July 30 to August 4 at the Mandalay Bay hotel in Las Vegas, Nevada. Tickets are priced at $2,595.

Top Rated Comments

keysofanxiety Avatar
119 months ago
Well the latest version of iOS 9's jailbreak got released this week, so spare yourself a ticket because the answer is: Security ain't good.
If you can't see the distinction between a user jailbreaking and unauthorised hacking, I would question why you felt the need to comment.
Score: 11 Votes (Like | Disagree)
uroshnor Avatar
119 months ago
Jailbreaking is hacking, a malicious third party can exploit the same holes that jailbreaks use. They are, like it or not, major security holes in iOS that allow you to bypass many of the systems protections. Those quick and easy jailbreak by visiting a website can easily be a malware install.
Since Apple stopped shipping the A4 processor, there has been no way to jailbreak without :

- knowing the device passcode
- having physical control of the device, and hooking it up to a computer that is running the jailbreak installation software
- rebooting the device as part of the process

Recent jailbreaks like Pangu require 10+ exploits chained together, under the above conditions (i.e. Unlocked & paired to the "hostile" computer)

Since the A7 shipped & iOS 8, there have been no "bypass the passcode attempt counter" attacks either. (There was one for A5/A6 and iOS 8, but it was patched with iOS 9).

If you look back to an earlier time, before the A5 and before secure enclave when a web based attack like JailbreakMe.com was feasible, across all 3 versions, it was unlatch for, IIRC, a total of 67 days (40 days for the first time, 20 the second and 7 the third).

If you look at the black market prices for the buying and selling of exploits to break into devices : for iOS exploits, when they are for sale, have going prices that are 10x to 100x other platforms , and a jailbreak is worth between 1 and 4 million USD.

Pangu and TaiG are funded by the pirate App Store market in China and have a comparable research budget to that.

So yes, the methods used in a jailbreak might enable malware , and might enable drive-by infestation, but in general Apple has gotten things to a point where in order to jailbreak you already have access to all the info on a phone. That's not ideal, but it's far from awful, and vastly better than 99% of Android devices and other platforms.
Score: 7 Votes (Like | Disagree)
keysofanxiety Avatar
119 months ago
Jailbreaking is hacking, a malicious third party can exploit the same holes that jailbreaks use.
Name one example of that, which has happened without user authorisation.
Score: 3 Votes (Like | Disagree)
smacrumon Avatar
119 months ago
I wish Apple would get more into the "behind the scenes" look of its technology at its keynotes as it used to in the past. In more recent keynotes, the unveilings have been more superficial and a little too sales pitchy IMHO.
Score: 3 Votes (Like | Disagree)
stepmuel Avatar
119 months ago
I wish Apple would get more into the "behind the scenes" look of its technology at its keynotes as it used to in the past.
Google "ios security white paper" and you'll get a PDF that is most likely exactly what the Apple engineer will talk about.

On https://developer.apple.com/videos/ you'll find all the technical "behind the scenes" videos. I recommend "Platform State of the Union" for a good overview.
Score: 2 Votes (Like | Disagree)
C DM Avatar
119 months ago
The iPhone 5s has a secure enclave? I did not know that.
Isn't that basically associated with TouchID and 64-bit architecture (both of which started out with 5s)?
Score: 1 Votes (Like | Disagree)

Popular Stories

iPhone 17 Pro and Air Feature

Two iPhone 17 Pro and iPhone Air Colors Appear to Scratch More Easily

Friday September 19, 2025 10:02 am PDT by
As reported by Bloomberg today, some of the new iPhone 17 Pro and iPhone Air models on display at Apple Stores today are already scratched and scuffed. French blog Consomac also reported on this topic. The scratches appear to be most prominent on models with darker finishes, including the iPhone 17 Pro and Pro Max in Deep Blue, and the iPhone Air in Space Black. Images Credit: Consoma ...
iOS 26

iOS 26.0.1 Coming Soon, Likely With iPhone Air and iPhone 17 Pro Fix

Thursday September 18, 2025 9:17 am PDT by
Apple is preparing to release iOS 26.0.1, according to a private account on X with a proven track record of sharing information about future iOS versions. The update will have a build number of 23A350, or similar, the account said. It is likely that iOS 26.0.1 will fix a camera-related bug on the new iPhone Air and iPhone 17 Pro models. In his iPhone Air review, CNN Underscored's Henry T. ...
iPhone 17 Pro Colors

iPhone 17 Pro Max Teardown Reveals Qualcomm's Snapdragon X80 Modem for 5G

Friday September 19, 2025 7:39 am PDT by
While the iPhone Air is equipped with Apple's custom C1X modem for cellular connectivity, all of the iPhone 17 models are outfitted with Qualcomm modems still. A teardown video shared on Chinese platform Bilibili today (via Reddit) appears to confirm the iPhone 17 Pro Max is equipped with Qualcomm's Snapdragon X80 modem in particular. The same modem is likely used in the iPhone 17 and iPhone ...
iphone 17 pro max techwoven

Here Are The Best Cases You Can Buy for Your New iPhone 17 and iPhone Air

Friday September 19, 2025 6:46 am PDT by
Apple's new iPhones launch today, and there are plenty of options to choose from when it comes to protecting your new device from drops and scratches. In this article, we're taking a look at some of the best options for iPhone 17, iPhone 17 Pro, and iPhone 17 Air cases, as well as a few charging accessories. Note: MacRumors is an affiliate partner with some of these vendors. When you click a...
iOS 26 on Three iPhones

iOS 26's Liquid Glass Design Draws Criticism From Users

Wednesday September 17, 2025 2:56 pm PDT by
It's been two days since iOS 26 was released, and Apple's new Liquid Glass design is even more divisive than expected. Any major design change can create controversy as people get used to the new look, but the MacRumors forums, Reddit, Apple Support Communities, and social media sites seem to feature more criticism than praise as people discuss the update. Complaints There are a long...
iphone 17 pro inside

iPhone 17 Teardowns Confirm SIM and eSIM-Only Battery Capacities

Friday September 19, 2025 8:39 am PDT by
YouTube channel REWA Technology today shared an iPhone 17 Pro teardown video, offering a closer look inside the model with a SIM card tray. We are still waiting for repair website iFixit to share a more comprehensive teardown of the latest iPhone models, but this video provides a good look in the meantime. The device features various internal design changes, including larger rear camera...