Elcomsoft iOS Forensic Toolkit 10.12 adds bootloader-level extraction for the Apple HomePod mini, returning the full file system image and the decrypted keychain. The speaker is built on the S5, the same chip as the Apple Watch Series 5, so the usbliter8 SecureROM exploit applies to it regardless of the installed audioOS version. The device is not booted into its operating system, the data partition is not modified, and repeated extractions return the same image.
The HomePod mini has no passcode, which makes the extraction simpler; nothing has to be known or recovered first. The same property limits the contents. A device without a passcode cannot access end-to-end encrypted iCloud data, so the keychain holds mostly local records. It does include the Wi-Fi passwords for every access point the household configured, not only the ones the speaker itself used.
Smart devices are an increasingly important source of evidence, and in some cases the only one. The Apple ecosystem extends well past the iPhone: the Apple Watch, the Apple TV, and the HomePod family all accumulate data that can matter in an investigation. iOS Forensic Toolkit is the first and only tool to perform full file system extraction from these devices, with other tools being limited to logical acquisition, which returns a small fraction of what the file system holds.
A smart device becomes central whenever the primary device is out of reach. The phone may be absent from the case, destroyed or never found. It may have been wiped or reset before it was seized. It may be present but locked behind a passcode that cannot be broken. In each of these situations the Watch, the Apple TV, or the HomePod can carry the evidence the phone would have carried.
Smart devices do contain a fraction of the data accumulated by today's smartphones or tablets. Yet, thanks to cloud-based synchronization, even a humble HomePod can help reconstruct the device owner's timeline or become a key to the data stored in the owner's cloud account. Information stored in a smart speaker can help recover the list of other devices on the user's Apple ID, including their names and identification numbers.
HomePod mini extraction is available in the macOS and Linux editions of iOS Forensic Toolkit 10.12. The hardware list and the full procedure are in our blog: HomePod mini extraction, step by step. This release also fixes the bootloader exploit for checkm8 acquisitions on several devices and iOS versions.
Release notes
Per saperne di più
• Leggi l’articolo «Low-Level Extraction of the HomePod mini» sul nostro blog (in ing.)Links