Full Video of Apple Engineer's Black Hat Security Talk Now Available

Earlier this month, Apple's head of security engineering Ivan Krstic gave a talk at the Black Hat Conference, an annual event designed for the global InfoSec community. During the event, Krstic spoke about Apple security and unveiled the company's new bug bounty program.

Krstic's briefing is now available in full on YouTube, shared this morning on the Black Hat YouTube channel in a video entitled "Behind the Scenes of iOS Security."


In the talk, Krstic covers three major iOS security mechanisms -- HomeKit, Auto Unlock, and iCloud Keychain -- in "unprecedented technical detail," along with other iOS security measures.

HomeKit, Auto Unlock and iCloud Keychain are three Apple technologies that handle exceptionally sensitive user data - controlling devices (including locks) in the user's home, the ability to unlock a user's Mac from an Apple Watch, and the user's passwords and credit card information, respectively. We will discuss the cryptographic design and implementation of our novel secure synchronization fabric which moves confidential data between devices without exposing it to Apple, while affording the user the ability to recover data in case of device loss.

Data Protection is the cryptographic system protecting user data on all iOS devices. We will discuss the Secure Enclave Processor present in iPhone 5S and later devices and explain how it enabled a new approach to Data Protection key derivation and brute force rate limiting within a small TCB, making no intermediate or derived keys available to the normal Application Processor.

Traditional browser-based vulnerabilities are becoming harder to exploit due to increasingly sophisticated mitigation techniques. We will discuss a unique JIT hardening mechanism in iOS 10 that makes the iOS Safari JIT a more difficult target.

The most notable moment of Krstic's briefing features the unveiling of Apple's first ever bug bounty program, which will see the company paying out up to $200,000 to researchers who discover vulnerabilities in Apple software. Apple's bug bounty program, initially limited to a few dozen researchers, launches this September.

Popular Stories

iPhone 17 Pro Render Front Page Tech

iPhone 17 Pro Launching Later This Year With These 8 New Features

Tuesday March 4, 2025 3:15 pm PST by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. iPhone 17 Pro's alleged design via Front Page Tech Below, we recap key changes rumored for the iPhone 17 Pro models as of March 2025: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone...
Apple MacBook Air hero

Apple Announces New MacBook Air With M4 and 'Sky Blue' Color Option

Wednesday March 5, 2025 6:02 am PST by
Apple today announced refreshed 13- and 15-inch MacBook Air models, now featuring the M4 chip, an upgraded camera, and a new "Sky Blue" color option. "Sky Blue" is an all-new blue finish that joins Midnight, Starlight, and Silver. Apple describes it as a "beautiful, metallic light blue that creates a dynamic gradient when light reflects off of its surface." Space Gray is no longer available. ...
ipad 11 feature

Apple Unveils 11th-Gen iPad With A16 Chip and More Storage

Tuesday March 4, 2025 6:06 am PST by
Apple today announced the 11th-generation iPad, now featuring the A16 chip and more storage. The announcement came alongside the debut of the new iPad Air, which now features the M3 chip. From Apple's press release: The A16 chip provides a jump in performance for everyday tasks and experiences in iPadOS, while still providing all-day battery life. Compared to the previous generation, the...
M3 iPad Air

Apple Announces New iPad Air With M3 Chip, Updated Magic Keyboard

Tuesday March 4, 2025 6:04 am PST by
Apple today introduced new 11-inch and 13-inch iPad Air models with the M3 chip, along with an updated Magic Keyboard for the device. With the M3 chip, the new iPad Air should offer up to 20% faster performance compared to the previous-generation model with the M2 chip, which was released in May 2024. In addition, the M3 chip brings hardware-accelerated ray tracing to the iPad Air for the...
CarPlay Hero

iOS 18.4 Upgrades CarPlay in Two Ways

Tuesday March 4, 2025 8:39 am PST by
The upcoming iOS 18.4 update for the iPhone includes two smaller but meaningful improvements for Apple's in-car iPhone mirroring system CarPlay. First, CarPlay now shows a third row of icons, up from two rows previously. However, this change is only visible in vehicles with a larger center display. For example, a MacRumors Forums member noticed the change in a Toyota Tundra with a 14-inch...
Apple MacBook Air hero

Apple Has Finally Solved One of the MacBook Air's Biggest Limitations

Wednesday March 5, 2025 11:29 am PST by
The new MacBook Air has a useful upgrade: it natively supports up to two external displays, in addition to the laptop's built-in display. In other words, the latest MacBook Air can be used with a pair of external displays without needing to keep the laptop's lid closed. Apple's tech specs for the new 13-inch and 15-inch MacBook Air:Simultaneously supports full native resolution on the...
Mac Studio 2025

Apple Announces New Mac Studio With M4 Max and M3 Ultra Chips, Thunderbolt 5, and More

Wednesday March 5, 2025 6:01 am PST by
Apple today announced that it has updated the Mac Studio with M4 Max and M3 Ultra chip options, Thunderbolt 5 ports, and more. The M4 Max chip was already released last year in the 14-inch and 16-inch MacBook Pro. It can be configured with up to a 16-core CPU, up to a 40-core GPU, and up to 128GB of unified RAM. Geekbench 6 benchmark results indicate that the M4 Max is up to 75% faster than...
Apple MacBook Air hero

Here Are Real-World Photos of the New Sky Blue MacBook Air

Wednesday March 5, 2025 1:47 pm PST by
Apple today updated the MacBook Air with the M4 chip, and the laptop is also available in an all-new Sky Blue finish alongside Silver, Starlight, and Midnight. YouTuber Andru Edwards has showed off the Sky Blue color in a few real-world photos. Keep in mind that the Sky Blue finish is not very saturated. However, the color's appearance will vary based on lighting conditions. View ...
ipad air magic keyboard

Apple Announces Redesigned Magic Keyboard for iPad Air

Tuesday March 4, 2025 6:36 am PST by
Apple today announced a completely redesigned Magic Keyboard accessory for the iPad Air. The new keyboard features a larger built-in trackpad, a 14-key function row, and a new aluminum hinge. From Apple's press release: The all-new Magic Keyboard for iPad Air expands what users can do at an even lower price. The larger built-in trackpad brings greater precision for detail-oriented...

Top Rated Comments

iTom17 Avatar
112 months ago
I don't understand most of it either, but it's pretty fun to see how serious Apple is about system security.

I'm currently doing network administration, where network security is one of the topics we learn about. May not be on a big scale, but I actually like this whole subject. And I'm planning on doing something with security engineering after this.

So I may not understand 99% of this, it's just fun to watch. :p


By the way, here are the presentation slide: https://www.blackhat.com/docs/us-16/materials/us-16-Krstic.pdf
Score: 6 Votes (Like | Disagree)
akfgpuppet Avatar
112 months ago
....and I understood like 5% of what he was talking about.
Score: 5 Votes (Like | Disagree)
69Mustang Avatar
112 months ago
Sure, compared to whom?

And who takes security+privacy as seriously?

Who has an executive team that can axe marketable features for privacy reasons, that not even 1% of people gives a damn?
Calm down dude. It was just a sarcastic joke in response to another quote.
Score: 5 Votes (Like | Disagree)
pat500000 Avatar
112 months ago
The only thing I understood is "Thanks for coming" part.
Score: 4 Votes (Like | Disagree)
yaxomoxay Avatar
112 months ago
but ios requires 6 numbers by default.
That's the trick that Cue designed. Everyone's is going for the six digits!
Score: 4 Votes (Like | Disagree)
CarlJ Avatar
112 months ago
Apple's password to unlock everything is 12345. Try it out!
I've got that same combination on my luggage!
[doublepost=1471416518][/doublepost]
RIP Jailbreak.
If the choice is between security that vexes even governments, and wacky add-ons, I'll take the security every day and twice on Sunday.
Score: 4 Votes (Like | Disagree)