Page 1
FILEVAULT & SECUREENCLAVE · A GUIDE FOR UK LAWYERS File Vault, the Secure Enclave and Apple Encryption Why the Data Is Locked to the Machine and the Person, and Where the Recovery Keys Live COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM RECOVERY-KEY ANALYSIS CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: bound to machine and person 03 How Apple encryption works: File Vault and the Secure Enclave 04 Why decryption is tied to authentication 05 Recovery keys and where they live 06 Honest limits on locked and powered-off devices 07 Deployment: lawful access, orders and the escrowed key 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary The headline point: Apple encryption binds a device's data to both the specific machine and successful the recovery keys live and how to obtain access law full y, not how to break the encryption.
§ 02 · FIRST PRINCIPLES The problem in plain English: bound to machine and person
§ 03 · HOWAPPLEENCRYPTIONWORKS How Apple encryption works: File Vault and the Secure Enclave FILEVAULT WRAPPED KEY SECURE ENCLAVE AUTHENTICATION DECRYPTED DATA
Page 2
§ 04 · TIEDTOAUTHENTICATION Why decryption is tied to authentication
§ 05 · RECOVERY KEY S Recovery keys and where they live
§ 06 · HONESTLIMITS Honest limits on locked and powered-off devices
§ 07 · DEPLOYMENT Deployment: lawful access, orders and the escrowed key
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE HELD ESCROW / IPHONE / THE OR G AN IS AT I ON RECOVERABLE DEVICE KEY ROUTE USER- ICLOUD PAIRED KEY DATA IPAD
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEESCROWEDKEYTHATOPENEDTHEDEVICE EXAMPLE2 · THECORPORATEDEVICETHEEMPLOYERCOULDOPEN EXAMPLE3 · THEHONESTLIMITTHATSETTHESTRATEGY
Page 3
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTION FOR ENCRYPTED - DEVICE ACCESS 1. Please: (1) advise immediately on preservation, in particular keeping the device powered on and
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The encrypted-device checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions Can you break File Vault or extract the key from the chip? What is a File Vault recovery key, and why does it matter? Why can't you just copy the disk and decrypt it else where? The device is company-owned. Does that help? If the device is locked and no key exists, is the data gone? Why does it matter that a recovery key is escrowed in iCloud?
§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
Cite as: Joseph Naghdi, FileVault The Secure Enclave And Apple Encryption, Computer Forensics Lab, https://e-discovery.uk/library/filevault-the-secure-enclave-and-apple-encryption/pdf.
