BLOG

 

UPDATE –  August 29, 2014 : 

Great news has surfaced with regards to the threat of Chip-off may pose to users of PGP Encrypted BlackBerrys!

In a presentation recently put on by leading Mobile Forensics Training organization Teel Technologies, we can see that they indicate that the CelleBrite Physical Analyzer used to decode acquired raw images from BlackBerry devices in the courses they teach in fact cannot decode a raw image for a device that has been paired with a BES (BlackBerry Enterprise Server).  This would indicate that the process outlined below is NOT effective against PGP Encrypted BlackBerrys, however we would still encourage all our clients use a strong device password and a different device password for their BlackBerry Key Store (where their Private PGP Key is stored). Just because CelleBrite lacks this capability now, does not mean it may not be acquired in the future.

BlackBerry Forensics Training Presentation: https://www.nist.gov/forensics/upload/5-Punja-nist-2014-bb-forensics-FULL.pdf

Excerpt from page 16 of the presentation:

“If BlackBerry device is attached to a BES, and you don’t have access to the BES, chip off is pointless as the data cannot be decrypted by any commercial tool at this time. Real world scenario: hostile BES, BlackBerry seized and is usually PGP encrypted then you are at a dead end, even with chipoff.“

Our original Post: 

You read correctly. BlackBerry’s with content-protection can be cracked through the use of mobile forensics techniques known as chip-off and JTAG. Using these methods, forensics analysts must physically modify or remove the memory chip from the circuit board of the device. Over the air interception is not possible unless weak IT policy allows third party applications to be installed. (This is something we prevent with carefully configured BES policy for PGP encrypted email users seeking the utmost in security & privacy.)

So just how easy is this process to accomplish? In short it is a very difficult process that isn’t successful 100% of the time. Few mobile forensics analysts are currently trained with ample experience to execute the process with high success rates. However, expect the success rates of these processes and the widespread use to increase dramatically over the next 5 years due to the advent of private training courses. There are many private mobile forensics companies that you can send a BlackBerry or any cell phone too. They cannot guarantee recovery of any data — and charge $1000-$1500 per device.  These private forensics firms have successfully been able to crack iPhone, Android AND the coveted BlackBerry using JTAG for Android and the ChipOff process for most BlackBerry smart phones.

What’s the difference between JTAG & Chip-off?

JTAG

JTAG involves using existing solder points on a cell phone’s circuit board. This process is very common with Android devices, and only applicable to older BlackBerry devices.

Chip-off

Chip-off is the more difficult of the 2 techniques. It requires the use of solvents and heat to remove the memory chip from the circuit board. Then using custom made adapters, the forensics analyst attempts to make a raw dump of the data on the memory chip. If content protection is turned on (encryption + password), the analyst then will attempt to “carve” the raw hex of the raw data dump and extract the password hash. The password is then brute forced.

Most people have a BAD habit of using simple passwords on mobile devices. These password can be brute forced in a matter of hours, minutes, even SECONDS! Keep this in mind the next time you set your device password. If your password for your BlackBerry device and key store are different, the forensics analyst will also need to brute force the key stores password.

This is why it is VERY important to set both:

- A strong password

- A different password for your device & key store

Example Chip Off Procedure on BlackBerry 9320

Source: www.ForensicsWiki.org

  1. Remove the back panel.
1-bb9320-BackPanelRemoved.jpg
  1. Remove the SIM and SD Memory Card.
  1. Using a torx-6 screw driver remove the 2 visible screws on the back of the phone.
2-bb9320-ScrewRemoval.jpg
  1. Remove the screen protector using a shim, guitar pick, or prying tool.
3-bb9320-ScreenRemoval.jpg
  1. Remove 2 torx-5 screws.
4-bb9320-ScrewRemoval.jpg
  1. Use the shim to detach the outer bezel/keyboard from the device.
5-bb9320-TopPlate.jpg 5-1-bb9320-TopPlate.jpg
  1. Remove 4 additional torx-6 screws. The main board will now easily be separated from the back plate
6-bb9320-ScrewRemoval.jpg
  1. Peel off the vendor sticker.
7-bb9320-VendorPlate.jpg
  1. Remove the plastic cover protecting the track pad ribbon cable, and disconnect the track pad.
  1. Remove the final torx-4 screw located beneath the plastic protector, to remove the plastic keyboard overlay.
8-bb9320-ScrewRemoval.jpg
  1. Disconnect the ribbon cable connected to the LCD. Then using a pick separate the display from the main board.
9-bb9320-ScreenRemoval.jpg
  1. The tear down is now complete
9-1-bb9320-TearDownComplete.jpg

eMMC Removal

  1. The eMMC is located beneath the heat shield directly above the Micro SD card slot.
10-bb9320-EMMC-Location.jpg
  1. Place the main board in a stand or holder and position it approximately 2 1/2″ – 3″ inches away from a heat gun or device the blows super hot air.
11-bb9320-HeatShield.jpg
  1. Monitoring the temperature the heat shield will come off easily between 190-200 Centigrade.
12-bb9320-HeatShield.jpg 13-bb9320-HeatShieldRemoved.jpg
  1. Continue working under the high heat. With the 9315/9320′s I’ve worked on the eMMC has been ready to lift off of the main board using tweezers immediately after removing the heat shield.
14-bb9320-EMMC-Removed.jpg
  1. Using liquid flux, or flux paste and a soldering iron clean the pads on the eMMC in preparation for a read
15-bb9320-EMMC-Cleanup.jpg 16-bb9320-EMMC-Clean.jpg
  1. The eMMC is now ready to read using the appropriate adapter/programmer and software.

At the time of this writing (2013OCT29) the eMMC that was removed in this example was read using an UP828 programmer via the “VBGA169E” adapter and using the “eNAND_H9DP4GG4JJACGR-4EM/459MB” device settings. The resulting image was then parsed via the CelleBrite Physical Analyzer (V. 3.8.5.108).