August 11th, 2024

Apple Prototypes and Corporate Secrets Are for Sale Online–If You Know Where

Matthew Bryant discovered sensitive Apple data in secondhand devices, including a Time Capsule and a prototype iPhone 14, highlighting risks of data security and asset management for companies.

Read original articleLink Icon
Apple Prototypes and Corporate Secrets Are for Sale Online–If You Know Where

Independent security researcher Matthew Bryant discovered sensitive Apple corporate data while purchasing secondhand electronics, including a Time Capsule that contained a backup server's worth of information from European Apple Stores. His findings, which he presented at the Defcon security conference, stemmed from a project where he scraped listings from platforms like eBay and Facebook Marketplace, using computer vision to identify devices that were once part of corporate IT fleets. Bryant's system, which utilized optical character recognition, alerted him to significant items, including a prototype iPhone 14 and a Mac Mini from a Foxconn assembly line. The Mac Mini, despite being listed for parts due to physical damage, contained internal software and credentials that could reveal insights into Apple's manufacturing processes. After notifying Apple about his discoveries, he returned the devices. Bryant's work highlights the risks companies face regarding data security and asset management, as discarded corporate devices can end up on secondhand markets, potentially exposing sensitive information.

- A researcher found sensitive Apple data in secondhand devices purchased online.

- The project involved scraping listings and using computer vision to identify corporate IT equipment.

- Bryant discovered a Time Capsule with extensive internal documentation and a prototype iPhone 14.

- The findings emphasize the importance of data security and proper asset management for companies.

- Discarded corporate devices can pose significant risks if not properly decommissioned.

Link Icon 16 comments
By @krackers - 8 months
>chaining together a dozen dilapidated second-generation iPhone SEs and harnessing Apple's Live Text optical character-recognition feature to find possible inventory tags

This is the second time I've read about an iPhone OCR rack https://findthatmeme.com/blog/2023/01/08/image-stacks-and-ip...

Is this still state of the art in terms of local OCR?

By @epakai - 8 months
Some of these developer devices get 'destroyed' and sold as scrap. dosdude1 has restored some of these kinds of devices to working order. There's pretty neat video of the restorations:

ARM Apple Silicon Developer Transition Kit: https://www.youtube.com/watch?v=reQq8fx4D0Q iPod Touch dev board: https://www.youtube.com/watch?v=qLCt6oHPTQM

The PCB repair technique for the DTK is pretty cool on its own.

By @JKCalhoun - 8 months
By @miki123211 - 8 months
This is why solutions like Bitlocker with a good TPM or FileVault are so important.

They can essentially guarantee that the disk encryption key will only be released from the security module if the computer is running a fully-trusted and signed OS. Even if you take the drive out of the machine, the data on that drive is completely useless to you.

Incidentally, this is also what makes short PINs secure; the TPM contents are unreadable, even to a skilled attacker, so if the TPM is guaranteeed to wipe itself after 10 tries, even a 4-digit PIN is secure enough.

By @noident - 8 months
I don't understand. Why aren't these devices using full disk encryption?
By @grishka - 8 months
> After he evaluated the Time Capsule's contents, Bryant notified Apple about his findings, and the company's London security office eventually asked him to ship the Time Capsule back.

> Bryant again reported his findings to Apple and returned the Mac Mini to them.

Why the hell did he do that?! It's, like, the worst thing one can possibly do with these kinds of devices. Just publish stuff that doesn't have anyone's personal data in it. That'll make the world better in the end.

By @rbanffy - 8 months
The ones I’m interested would be the ones donated to Berkeley. I hope one day they make it to a proper museum.

Or, at least, catalogued, scanned, and photographed.

By @JKCalhoun - 8 months
Looks like the software was looking for labels like this: https://www.reddit.com/media?url=https%3A%2F%2Fpreview.redd....
By @jamesy0ung - 8 months
A lot of prototypes can be found on a Chinese website called xianyu
By @The_SamminAter - 8 months
Would you be willing to publish the iOS OCR server you made? It would be greatly useful in some of my products, as as you’ve noted other options have either low-quality results (tesseract, some cloud-based solutions) or are expensive in comparison for large amounts of images (most cloud-based solutions). That and it’d allow some of us to put our old phones to use.
By @kotaKat - 8 months
The amount of corporate crap I find on eBay from e-recycling is abundant and fantastic. And cheap!

I've seen everything from Amazon's palm-scanners to a tactical LTE base station once used by NIST to all sorts of Zebras full of fun software.

By @kome - 8 months
very, very brilliant! but the fact he returned the data is mind-blowing to me... i would have published everything on a torrent and good luck.
By @jfdjkfdhjds - 8 months
the only things anyone ever wanted to know from apple is their aggressive business tactics... and most of that is already public thanks to the many processes they lost along the way. from labour salary fixing across industries to pushing obvious monopolies in the face of the publishing industry.

I think the only piece I'd pay to read is how they negotiated with spotify.