Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

41–50 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#41

Why the worry about auto-wiping? Is it not possible to make a copy of the encrypted data and then play around with it as much as you want?

Can someone answer this? Raw read the memory to an external device and then brute force that shit using super computers until it cries.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#42

Why the worry about auto-wiping? Is it not possible to make a copy of the encrypted data and then play around with it as much as you want?

The data the DOJ wants is encrypted with AES, so all the phone has to wipe is the key; a copy of the encrypted data is useless.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#43
post #13

Earlier quoted context omitted.

Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

I only recently got a touchID iPhone so I'm still having fun with it. But I did my right thumb, index, and middle finger, and left thumb and index.

If under police duress I keep trying to unlock a phone with my pinkie finger I think that would be suspicious.

If I have that much access to the device I should just force-reboot it by holding the lock and home buttons for about 2 seconds. Or maybe have done that before being arrested.

Upon a reboot the iPhone will always require its passcode.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#44

Earlier quoted context omitted.

I don't know about that but I'd be fairly certain a court would just order you to unlock the phone regardless of whether it's your finger locking it or a password.

In the USA the courts treat passwords as testimony, and in most cases you can invoke your 5th amendment right and refuse to provide passwords or encryption keys, given the state does not already know the contents of the device. This same protection does not extend to physical keys, which I think fingerprints would fall under. http://www.uclalawreview.org/the-fifth-amendment-encryption-...

That seems to be representative of the only actual ruling on this topic that I can find

>The Fifth Amendment to the U.S. Constitution gives people the right to avoid self-incrimination. That includes divulging secret passwords, Judge Steven C. Frucci ruled. But providing fingerprints and other biometric information is considered outside the protection of the Fifth Amendment, the judge said.

[1] http://blogs.wsj.com/digits/2014/10/31/judge-rules-suspect-c...

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#45
post #30

I always wondered why more people don't go around bricking iPhones by entering the wrong pin several times. Same goes for any other lockout. Why not do this to someone famous by constantly logging in as them from a botnet?

On IOS this would only wipe user data and reset to factory settings, not wipe the entire filesystems.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#46
post #38
post #13

Earlier quoted context omitted.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

If you do this on purpose after asked to unlock your phone you will probably be charged with destruction of evidence or something like that. However, while a court is (afaik) able to ask you to put your finger on the fingerprint reader, you do not need to tell them which of the fingers the correct one is. So instead of purposely using a wrong finger, I'd ask the court to explicitly tell me which of my fingers I shoul…

It would be a very long and involved case, anyway.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#47
post #37
post #35

Earlier quoted context omitted.

> There is an authentic need to get at the data on that phone What is the authentic need? The shooters are dead. Do we have reason to believe that there is evidence of any pending crimes or any old unsolved crimes on the phone?

Sure, of course that's a legitimate concern: they may have talked to other people planning attacks.

> they may have talked to other people planning attacks.

I'm not particularly concerned with crimes that we believe "may have" occurred. Of course, they may have. Anything may have happened -- I'm asking for more than just correlation that criminals know criminals. Do we have any evidence, or even any hints or clues, that the phone contains evidence that would help solve or prevent any crimes?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#48
post #38
post #13

Earlier quoted context omitted.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

If you do this on purpose after asked to unlock your phone you will probably be charged with destruction of evidence or something like that. However, while a court is (afaik) able to ask you to put your finger on the fingerprint reader, you do not need to tell them which of the fingers the correct one is. So instead of purposely using a wrong finger, I'd ask the court to explicitly tell me which of my fingers I shoul…

I think the court would similarly consider that obstruction and contempt. If they tell you to unlock your phone and you try to play some "first you have to guess which finger's the right one!" game, the judge will slap you with either contempt of court or refusal to comply with a subpoena.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#49
post #38
post #13

Earlier quoted context omitted.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

If you do this on purpose after asked to unlock your phone you will probably be charged with destruction of evidence or something like that. However, while a court is (afaik) able to ask you to put your finger on the fingerprint reader, you do not need to tell them which of the fingers the correct one is. So instead of purposely using a wrong finger, I'd ask the court to explicitly tell me which of my fingers I shoul…

You better hope they don't say the one that you designated to unlock your phone?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#50
post #47
post #37

Earlier quoted context omitted.

Sure, of course that's a legitimate concern: they may have talked to other people planning attacks.

> they may have talked to other people planning attacks. I'm not particularly concerned with crimes that we believe "may have" occurred. Of course, they may have. Anything may have happened -- I'm asking for more than just correlation that criminals know criminals. Do we have any evidence, or even any hints or clues, that the phone contains evidence that would help solve or prevent any crimes?

I'm sorry, but I don't understand what you're getting at here. The legitimate concern is prevention of future attacks. They may have collaborated with people who were never apprehended on the attack that actually happened.
Post reply on HN