Apple's Secure Enclave locks down user data on iPhone and iPad, including the data for Touch ID. Recently, a hacker known as xerub posted a "decryption key" for the Secure Enclave Processor (SEP) firmware:
key is fully grown https://t.co/MwN4kb9SQI use https://t.co/I9fLo5Iglh to decrypt and https://t.co/og6tiJHbCu to processkey is fully grown https://t.co/MwN4kb9SQI use https://t.co/I9fLo5Iglh to decrypt and https://t.co/og6tiJHbCu to process— ~ (@xerub) August 16, 2017August 16, 2017
That's led to a lot of miscommunication, misunderstanding, and misreporting about what exactly it means in terms of iPhone and iPad security. Here's the deal:
Imagine the Secure Enclave as a vault. Apple hung a big, dark curtain over it to prevent anyone from even seeing the vault. Now, that curtain has been opened and people can see the vault. The vault, however, is still locked as securely as ever. No one has broken into it and no one has even gotten any closer to breaking into it.
Technically speaking, Apple encrypted the SEP firmware to obfuscate it so people couldn't easily poke around inside. That included security researchers, like those participating in Apple's bug bounty program. Now they can.
It was an additional but very superficial layer of protection. While many deride security-through-obscurity, "defensive in depth" — a multi-layered approach — is still a best-practice and making anything even a little bit harder to defeat makes it a little bit harder to defeat.
Philosophy aside, it's my understanding that the encryption key wasn't used to protect any user data or anything beyond obscuring the SEP. And absolutely no user data was or could be exposed through the leaked encryption key.
In other words, it's something to be informed about but not overly concerned with. SEP remains as secure as ever.
Master your iPhone in minutes
iMore offers spot-on advice and guidance from our team of experts, with decades of Apple device experience to lean on. Learn more with iMore!
Rene Ritchie is one of the most respected Apple analysts in the business, reaching a combined audience of over 40 million readers a month. His YouTube channel, Vector, has over 90 thousand subscribers and 14 million views and his podcasts, including Debug, have been downloaded over 20 million times. He also regularly co-hosts MacBreak Weekly for the TWiT network and co-hosted CES Live! and Talk Mobile. Based in Montreal, Rene is a former director of product marketing, web developer, and graphic designer. He's authored several books and appeared on numerous television and radio segments to discuss Apple and the technology industry. When not working, he likes to cook, grapple, and spend time with his friends and family.