episode.ascii — live render
● episode

Episode 5: Backdoors, Apple, and the FBI

TL;DRFBI vs. Apple encryption battle and the history of software backdoors — from individual hackers planting secret access points to nation-states compromising firewall and VPN manufacturers to infiltrate thousands of targets at once.

We explore the history of backdoors and discuss Apple vs FBI. Jordan tells stories and interprets the nerdiness of Scott.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: By midnight, Hatton Street in London is quiet. Not dead, but quiet. It's a nice enough neighborhood. It's mostly businesses. There's some interesting history. But at midnight, that's the thing you'd notice most. It's quiet. But say you were there last year on a summer night in April at about 12:15 in the morning. Well, exactly 12:15 in the morning, this particular night has been studied to death. At 12:15 in the morning, you might have heard something that you would have heard nowhere else in London. If on April 22, you'd pressed your ear to the concrete at 12:15 in the morning, you would have heard the sound of a drill, a low rumble as four men cut a backdoor into the vault of the Hatton Gardens Safety Deposit Company. Over the course of this weekend, these men, the youngest of whom was almost 60 and the oldest almost 80, stole £14,000,000 in jewelry, gold, and cash. They didn't crack the vault door. They made their own door, a backdoor, with a 30 pound drill through five foot concrete. This idea that if the front door is just too tough to crack, you make your own backdoor is the goal of most computer viruses, bugs, and worms you've probably ever heard of. If they can just get a backdoor into your otherwise secure system, a hacker can come and go as they please, even as you look at the front door and say, Yeah, yeah, that looks secure. So what can you do to keep out the viruses, the lead in the drills, the boring the back doors? Well, you beef up security of the whole system. You install a firewall. You make that wall even thicker. Which is why, if you're a hacker in 2016, you don't really go after users anymore. You go after the firewall they're using to keep you out. You install a backdoor in the thing they're using to keep out backdoors, and you just wait and see how long it takes for someone to notice. My name is Jordan Bluman.

Speaker 2: And I'm Scott Winder.

Speaker 1: And this is Software Backdoors, on this very timely episode of Hacked. If, hypothetically, you had ever, hacked a computer, Scott, would, hypothetically, you have ever left a backdoor somewhere?

Speaker 2: What's a backdoor, Jordan?

Speaker 1: I don't know. You tell me.

Speaker 2: Hypothetically, yes. You know, hypothetically, back in the day, as a troubled youth, you would, when you when you get access to a server that you weren't supposed to have access to, often you'd leave something that allowed you to come back. So even if you hacked it and, you know, maybe you've changed a password at this point or something that an admin's gonna realize and fix, you might still leave something that lets you come back.

Speaker 1: So you've done something really difficult. You've gained access to this thing that doesn't want. You to have gained access to it, and you leave behind a way in. You've literally put a little tiny little backdoor that only you know about into this building.

Speaker 2: Yeah. So, like, the the whole idea of a backdoor is is it's not the front door. You don't need the key. You're coming into the patio door that nobody locks. It's you've got your own private entrance. You're the mouse coming through the little hole that no one knows about.

Speaker 1: So is that how this whole thing started, just one individual trying to get into some place that they're not really supposed to be?

Speaker 2: In, you know, the history that I would tell, yes. It would start with backdoors were a way that once you've gained access to something, you would put a backdoor in it to let you come back. You know, that's kind of the first thing. It's like back in the in the early days of cybercrime when you hacked into something and you weren't supposed to be there. You know? You might not create yourself a user account that they would, like, be able to see and be very obvious. So what you would do is you would put something that let you come back whenever you want to super user privileged accounts. So so you'd never have to hack that computer again, but you'd always have access to it. Does that make sense?

Speaker 1: Yeah. So even if someone knew that something had happened to their system and they think, oh, I fixed this problem, that initial problem is still persistent because that person's kinda coming and going in the night as they please. When did it start evolving beyond that?

Speaker 2: The the big the big change happened when it went from, like, gaining access to a server was tough. And, like, you know, we'll do an episode later on, like, something called smashing the stack and, like, exploits, like, coming up with exploits. It's not child's play. But backdoors were kind of child's play. Like, a backdoor wasn't too difficult. Like, once a computer had a backdoor, anybody could come through it that knew it was there. So all of a sudden, there was a little bit of a mind shift in hacking that went from, okay. I hack and I gain access, and then I leave myself a backdoor to come in, to just being like, hey. If I can trick somebody into installing a backdoor without them knowing, I can walk through that. I don't have to hack anything. I use the ignorance of the end user to give myself the hack and the backdoor all at the same time.

Speaker 1: So at that point, it just becomes kind of a law of large numbers thing where if you you you put enough of these ruses out there into the world, a certain number of people are gonna fall for them, and a certain number of people are gonna install these backdoors for you. Yeah.

Speaker 2: And, the beauty of it is is that, you know, there's a lot of ruses out there. There's a lot of ways to put these tricks into things, you know, piracy. Like, one of the big parts of piracy is that you never really know what you're installing. You're getting it from some sketchy place on the Internet that some sketchy person's put up. You have no clue what's on it. You know, you just blindly trust that you're installing whatever, Adobe's new creative suite or whatever you're stealing, and you don't know what's bundled with it. This style of attack is typically referred to as a, you know, a Trojan horse, you know, kind of referencing how the Greeks entered the city of Troy by packing soldiers inside of a large wooden horse. And at night, when everybody went to sleep, the soldiers filed out of the horse and went to attack. And the same kind of thing happens here where you download and install something, and bundled up with it is a backdoor that some hacker can get access to. And these backdoors aren't even just quiet. Some of them will do callbacks. So, like, they don't know where these are gonna land. So when you install it, it'll actually ping out to the Internet and say, hey. I'm IP address, you know, one one one dot one one one dot one one one dot one one one.

Speaker 1: I still can't believe you got that IP address.

Speaker 2: And I have this backdoor now. You know? Hey. I'm here. Come in. The key's under the rock on the back porch.

Speaker 1: So that's one way of casting a really, really, really wide net. But what are some other ways you might go about trying to get a backdoor into someone's system? Maybe someone that doesn't dabble in piracy or isn't tech savvy enough to dabble in piracy.

Speaker 2: There's a ton of ways, like, you know, the to install trojans. You know, phishing is a very common one, you know, going back to email spoofing. Sending a false email and having somebody download and install something or auto run from last episode is another great way that these would've spread is, you know, if you drop in a CD or a USB key that has some files on it, even though it could be legitimate installers, it could also, at the same time, just, like, pop in this little backdoor software. You know? These are things that we trust our antivirus softwares to keep us from a lot of the time, but they don't always work.

Speaker 1: Especially when we tell them not to work because we think we're installing something that we want on our computer. Correct. Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked. It's funny. The more you look into this whole world, the more it seems like so many of these things like bugs, viruses, worms are all out there in the world working in service of getting a backdoor onto your computer. Yeah.

Speaker 2: And there's some great examples of this with, like, distributed denial of service attacks and botnets. So once somebody's got you to install this little backdoor, there's an agent. So, like, a little piece of software running on your computer that's taking commands from somebody else on the Internet. And that's the big thing is, like, you know, if you want to attack sony.com and you've got 4,000,000 computers waiting to do whatever you tell them to do, it's really easy. And and these little, you know, botnet agents are are essentially Trojan horse onto your computer with malware or piracy that you download, you know, vulnerabilities in certain plugins like Flash. You know, there's a bunch of different ways that these things find themselves on your computer. But once they're there, you know, someone else has full control or can have full control.

Speaker 1: So far, this has all been driven by software whose author was trying to leave a backdoor on your computer, who was trying to expose the user to a vulnerability. This is a leading question, but does the creator of the software always know that they're exposing the user to a vulnerability, or could they have been tricked?

Speaker 2: Well, there's definitely instances of backdoors existing and people not knowing that they were there, if that makes sense. The you know, there's been a bit of a a shift in the quote, unquote nation state style, hacking world where you're seeing things like VPN service providers, like firewall companies, like software providers, even Apple, other software development kits, the SDK that allows you to build Apple applications to go on iPhones. You're seeing some really, really high level hacks where people are actually hacking into product manufacturers and building in backdoors into their code without them knowing. So all of a sudden these things roll out, and whoever put that little, you know, malicious piece of backdoor code in it, similar to that hypothetical teenage boy putting, you know, a module into the send mail system that allows him to get access. You're seeing major hacking groups, potentially nation states, building backdoors into really widespread pieces of software. So all of a sudden, anybody running this firewall is vulnerable to the person that put the backdoor there. All of a sudden, anybody running this VPN software is vulnerable to the person that put the backdoor there. You know? It's it's things like that that are the massive shift. Instead of one person attacking one target, you're getting one person or one group attacking thousands of targets.

Speaker 1: So instead of getting someone to install a piece of what they think is legitimate software but actually has a backdoor in it, they're just going after the manufacturer of the actual legitimate software, putting the backdoor in at that level, and then they ship it for you.

Speaker 2: Right. Instead of bundling the Trojan horse with, you know, whatever you're downloading, pirating, etcetera, etcetera, accidentally auto running, they're putting it in the actual software.

Speaker 1: So suddenly your backdoor has a marketing budget and a sales team and branding and TV commercials.

Speaker 2: Right.

Speaker 1: So some of the things that you just described, the things like firewalls and VPNs, those are things that are designed to keep you safe. So if we've gotten to that high level where we started with infiltrating one person's system, and then we got to a point where we're talking about infiltrating a bunch of people's systems, and now we're at a point where we're talking about infiltrating the people who make the stuff that stops you from getting infiltrated, how do the manufacturers of software then intend to stay safe if the products that would keep them safe are the ones that are being compromised?

Speaker 2: I think that's why those have been chosen as targets.

Speaker 1: It's kind of the top of the pyramid.

Speaker 2: You know, if you wanna hack into a major corporation and they're well protected and have a massive budget and great security team and all the rest of this jazz, it's gonna be really hard. Like, it's not gonna be easy without, you know, people messing up, which is how 90% of good hacks happen. And when I say good, I mean impressive. So if you can take out some of those roadblocks that this great highly priced IT security team has built, if you've already got a hole carved in their firewall or a hole carved in their encrypted VPN or a hole carved in, you know, whatever else they're looking to stop you with, their antivirus program, it makes it a lot easier for you. It it's it's a a fascinating world. So

Speaker 1: It's it's a very it's an approach that wouldn't really have worked on any other scale but a digital scale because it's not like it's like instead of trying to crack a vault, instead of even trying to cut your own backdoor, you're just going to the vault manufacturer, making a backdoor there, and stealing the master key.

Speaker 2: And the and the, you know, your reference to the master key is very accurate. You know, it's I wouldn't say it's well documented, but it's well known that a lot of software companies build in their own backdoors for testing, for whatever. You know, it's not uncommon, and it's been found, like, a lot of pieces of software have been found that have a master password. They have a key. The vault has one key that opens every one of the vault. The vault manufacturer made a key that will open all of their vaults. You know, that does exist. That has been found. Hackers have found master keys buried in source code before.

Speaker 1: Speaking of software backdoors, if you think you can find one, bugcrowd.com has a bunch of partners who will pay you to do just that. Bugcrowd.com runs bug bounty programs along the security curious to hunt down bugs and vulnerabilities in some of the world's biggest companies, companies like Tesla and Pinterest and Dropbox. So if you wanna challenge yourself and make some money at the same time, you should really check Bugcrowd out.

Speaker 2: And if you're a company and want security of the same league as, you know, Tesla, Pinterest, Dropbox, you know, we're looking for a partner, and we wanna run a special hacked challenge where the prizes won't just be, you know, some money, which we think is fair, people's time. But they'll also include special edition hacked gear.

Speaker 1: Talking about talking about hacked swag?

Speaker 2: Yeah. I'm talking about, like, hacked graft. Mhmm. Like like merch? Yeah. Like, you know, like a like a Wiki crew neck Sure. Sweater. Sure. Kinda that sketchy gray color that kids like these days Yeah. With, you know, like, a hacked logo on.

Speaker 1: I mean, really, how can you say no? Visit bugcrowd.com/hacked to learn more.

Speaker 2: When it comes to writing software, like, I've written a fair chunk of software in my life, and it's really tempting to put a master password in, especially when you're just dev ing, like, for dev use. The it's literally, like, three lines of code. Because you've gotta remember that, like, if you go back to our problem with passwords, you're taking in the password, you're hashing or encrypting it, and then you're comparing that against the hash. So, like, the software code there is, you know, get input value for the password field, encrypt it, compare against database object, and then return true or false. If you have a master password, you just have another line above that that says, if input value equals Jordan's master key, return true. Like, it's so easy to add a backdoor at the code level that I'm sure I'm sure there's more backdoors out there that we just don't know about because it would be very easy or is very easy, and it's generally very useful to have.

Speaker 1: There's been a lot of talk lately about backdoors and the relationship between Apple, the FBI, and the phone of the San Bernardino shooter. So what exactly is the FBI asking for, and is it actually a backdoor?

Speaker 2: I don't think it's actually a backdoor in the encryption that they're asking them to create. All they're really asking is for them to remove some of the safeguards that prevent them from brute forcing the password. So if you go back to episode three, we talked about the idea of, you know, trying to mass guess passwords. And and one of the preventative measures of that is is between every failed attempt, the timing gets longer. You know, it's a five second delay after the first attempt, a ten second delay after the second attempt. And after 10 attempts, you know, you can't guess anymore, or the phone formats itself, which is the problem with this one. So they're not really asking for them to build or construct actual backdoor. They're not asking for a master key. They're just asking them to let them brute force this person's password.

Speaker 1: Which is to say just guess over and over and over again.

Speaker 2: Yeah. Like, they're asking for the system to be modified to allow them to better break the security, but they're not asking for them to break the security. Apple's already provided them with the iCloud backups of the phone, so the data's not secure. If Apple has access to the data, they're willing to provide that. So your the information has already been handed over. They just want the most recent copy of what is on the phone. And one of the articles that I read, and I've you know, I'm just citing this article randomly. Don't know how much truth there is to it, but the FBI actually reset the iCloud account password for the phone. So the person who had the phone, they changed his password in an attempt to get access to the phone. And by doing so, they actually removed Apple's ability to force a backup of the phone because they need to actually key in the new password into the iCloud settings on the phone. So had they not reset the password, Apple could have forced a backup of the phone and then given them the new data. So it's not like it's not like we're trying to protect people's information here. They're just asking for a way to let them bypass some of the protective measures.

Speaker 1: So on one hand, Apple already kind of had a bit of a backdoor if they had the ability to force a backup.

Speaker 2: Yeah. It's actually given what I've read, it's surprising that Apple doesn't have access to this information. It sounds like they have a bunch of control over this device even though they don't have the password for it. So that to me is essentially a remote administration backdoor. If they can force a backup, force a software patch, force whatever, I don't know how they can't just access the data on it. To me, that's shocking.

Speaker 3: From athletic stuff like a full court pickup game, swish to athletic stuff

Speaker 2: like a half mile stroll.

Speaker 3: Get those steps in. Head to Sierra or sierra.com for the brands you want at the prices that let you do it all. From athletic to athletic ish, Sierra's got it.

Speaker 1: But on the other hand, if they were to develop something that could force the phone to respond to a digital brute force attack as opposed to a punching it in, wouldn't that effectively function as a backdoor if someone else could implement the same thing?

Speaker 2: Technically, no. To me, it's not a backdoor. A backdoor is a master key. Right. If Apple says, oh, all phones will unlock if you push 555-4123, that's a backdoor.

Speaker 1: So they're not asking them to create a backdoor. They're asking them to create a vulnerability.

Speaker 2: Right. Yeah. Exactly. So the there's been a lot of discussion about how this legally plays out, and I'm by no means a lawyer in intellectual property, so I can't really gauge how expansive the decision in this case could be. But to me, a lot of people are drawing the lines between this case and backdoor in encryption, which is something that's long been discussed. And there's, you know, kind of rumors that the NSA has backdoors and standard types of encryption already. That's a much bigger thing. So that means that if I actually take my information and encrypt it, you can unlock it without my key. And if my key is long enough to be really big, then you'll just probably never get it. And a backdoor in encryption allows them to bypass that. It says, you know, if this key is NSA rules, you know, exclamation point exclamation point, unlock immediately. And and encryption is a different beast because it's highly based on math, so backdoors in it are, you know, much more complicated, but this is not, to me, a backdoor. This isn't them backdooring into your information. Like, Apple's already giving up the data. They're already, you know, playing along. So this is just a it's a it's a weird situation.

Speaker 1: So if the takeaway from this is that the easiest way to stop a backdoor from getting on your system is to really just not install stuff that could come from a malicious source. Don't install software that came to you from an email from someone you don't recognize.

Speaker 2: Definitely do not install anything that downloads just on its own. If you're ever on a website and it downloads an executable to your computer, never.

Speaker 1: But it says I need it to stream episodes of Friends.

Speaker 2: Never ever. Why are you pirating episodes of Friends?

Speaker 1: But that only takes you so far because that's that's kinda how you prevent the easy way of these backdoors getting onto your system. How do you prevent them from getting on your system when they're coming from trusted sources? If you can't trust a firewall manufacturer, a company that makes stuff that's expressly designed to stop sketchy things from getting on your system, what can you trust?

Speaker 2: I think we're doing it again. We're scaring everybody again. Are we? There's no way to stop that stuff. And it's it's scary even to me. Like, I don't get scared by these things. I just accept them as reality. But people are getting smarter. Hackers are getting smarter. Nation states are getting smarter. The cyber war will come, and things like this are in the toolbox of the people that are gonna fight that war. They're not they're not playing with, you know, getting your buddy to install a piece of malware that lets you, like, turn on his webcam. These people are playing with, okay, if a piece of software that sits on your computer that makes sure that everything is, you know, signature checksummed authorized is gonna prevent us from having a future attack. It's gonna change the way that our attack chain can work. Well, what if we just hack that piece of software, and then we can tell it that our illegal software is now, you know, validated, secure, good stuff. It's it's a fascinating thing that's going on right now.

Speaker 1: If we hadn't scared people before, dropping the word cyber war probably cinched it. Is it maybe about recognizing that this is just sort of going to be part of the texture of day to day life if day to day day to day life is gonna be digital? That this sort of ongoing spat on the far side of the, you know, that industry, it's just gonna be a thing that is gonna happen. We're gonna hear about it. We're gonna be exposed to vulnerabilities and, I guess, I don't even know hope that the good side wins. Like, I I don't know what conclusion to reach from that.

Speaker 2: It's you know, this is turning into a dystopian novel, but, you know, seventy years ago, to disrupt a country's economy, you know, was a big thing. You know, it was war. It was, you know, terrorism. It's all these things. A good hacking group can do that in, like, forty five minutes. You know, that's a if you've got a pretty big attack structured out and you can you can cause things to go down, like, even like, imagine turning off the New York Stock Exchange. Like, what's that gonna do to the market? Sentiment's gonna go away. The second that they know that it's that vulnerable and can be hacked, investors are gonna get afraid. You know, it's gonna it it's gonna have a ripple effect that will be hard to measure. And as everything moves online, our communications, you know, the fundamental base of how we operate as people changes.

Speaker 1: It's interesting it's interesting the way we talk about it and the stakes we associate with it because at the end of the day, it's not a bomb going off. It's nothing physical being destroyed. If the attack is femoral, isn't the damage ephemeral? When was

Speaker 2: the last time you forgot your phone at home? Yeah. Fair. It's just your phone. Now imagine all of the stuff went away. Imagine the power grids went down. Imagine, like, that there's a real tangible hack that happened. I believe it was in The Ukraine recently where a bunch of hackers shut down power grids. So imagine data communications, which is voice communications, now goes down. The only thing that's not gonna go down is radio waves. So all of a sudden, we're listening to AM radio again, and that's just to get updates. You know? This is if you've got a battery powered radio.

Speaker 1: Right. So it's not just about, you know, your Facebook profile. It's the fact that dams are controlled by computers. It's the fact that water sources are controlled by computers. It's it's all controlled by computers. Yeah. So, yeah, really not trying to scare you,

Speaker 2: but don't drink the tap water. Apple versus FBI.

Speaker 1: Yeah. I don't know how we got there, but we always do.

Speaker 2: I'm sure there's a computer that controls the amount of fluoride that goes into our drinking water.

Speaker 1: I sure hope so. Hope it's not a dude with a beaker. But at the same time, a dude with a beaker can't get hacked. He can be hungover, but he can't get hacked. Right. Damned if you do damned if you don't.

Speaker 2: Crazy. The world we live in.

Speaker 1: There has been a lot of discussion lately about backdoors and, you know, whether or not that term is kinda accurate as it applies to the Apple situation, the dialogue surrounding it is still valid. It is still worth having, and it's a conversation we'd love to have with you. So please fire us a message. Write us an email at get@hackedpodcast.com. Put us on Twitter via, it's at hacked podcast or on Facebook where you can just search hacked podcast. Let us know what you thought of the episode, how you feel about the Apple case, or just a high five Luca Harrison for being our two thousandth like on Facebook. You're the real hero, Luca. My name is Jordan Blumen.

Speaker 2: And I'm Scott Winder.

Speaker 1: And thanks for listening to this episode of Hacked.

Speaker 4: Have no fear. Chosen Foods is here to defend your favorite foods from the forces of seedy oils and sketchy ingredients. With cooking oils, salad dressings, and mayo, all powered by the good fats from 100% pure avocado oil and simple delicious ingredients, Chosen Foods.

Speaker 5: Summer weekends are all about family, sunshine, and making memories together. Before everyone arrives, I stop by my local Total Wine and More to pick up a great bottle, maybe a favorite we already love, or something new to enjoy with dinner on the patio. With so many bottles to choose from, it's easy to discover something amazing. And with the lowest prices, it's easy to grab an extra bottle for the table. Not sure what to pick? Their friendly guides are always there to help. Find what you love and love what you find only at Total Wine and more. Curbside pickup and delivery available in most areas. Visit totalwine.com to learn more. Spirits not sold in Virginia and North Carolina. Drink responsibly. Must be 21.