Earlier quoted context omitted.
Plenty of good if you have a reasonable passphrase and the vendor hasn't been compelled to assist. "Can only try 10 times" isn't anything guaranteed by encryption. My laptop has an encrypted partition, but an attacker can brute-force it at will. Even if I had software to say "only let it happen 10 times, then erase the partition" the whole drive could just be cloned. That's why I have a 20+ character passphrase.
Apple goes way out of their way to avoid scenarios where they can be compelled to subvert iOS security. For instance, see pg44+ of the iOS security white paper: https://www.apple.com/business/docs/iOS_Security_Guide.pdf ... the HSMs that manage the escrow scheme for credentials stored in iCloud are themselves rigged to blow up on 10 failed tries, and, not only that, but the code that implements that process is burned…
Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
61–70 of 364 posts
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#62So if I get this right, they want to (1) disable the delete feature after x retries (therefore enabling unlimited retries) and (2) enable to submit tries via a connector/wifi, bluetooth (therefore enabling a bruteforce approach). What good is an encrypted filesystem in that scenario?
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#63I always wondered why more people don't go around bricking iPhones by entering the wrong pin several times. Same goes for any other lockout. Why not do this to someone famous by constantly logging in as them from a botnet?
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#64I always wondered why more people don't go around bricking iPhones by entering the wrong pin several times. Same goes for any other lockout. Why not do this to someone famous by constantly logging in as them from a botnet?
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#65Does Apple get to bill the FBI for the time that their engineers and legal department will be busy on this request?
Perhaps only engineering resources. (it's always gonna be a big legal hassle)
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#66Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#67Earlier quoted context omitted.
It sounds like since the UID is fused it cannot be erased; it's probably the GID that's erased, and it sounds like the GID is known to Apple.
but fuses can be blown. Simply by blowing one of the fuses the key will change. Even a single bit change means it's useless to authorities.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#68Earlier quoted context omitted.
> they may have talked to other people planning attacks. I'm not particularly concerned with crimes that we believe "may have" occurred. Of course, they may have. Anything may have happened -- I'm asking for more than just correlation that criminals know criminals. Do we have any evidence, or even any hints or clues, that the phone contains evidence that would help solve or prevent any crimes?
I'm sorry, but I don't understand what you're getting at here. The legitimate concern is prevention of future attacks. They may have collaborated with people who were never apprehended on the attack that actually happened.
Right, but we don't go searching everyone's papers just in case they are conspirators.
If Alice punches Bob in the face, then is hit by a bus and dies, we don't go searching through all of Alice's stuff just in case there might have been someone else involved with the Bob-punching incident, right?
Is there any evidence, any at all, that the shooters collaborated with anyone?
> The legitimate concern is prevention of future attacks.
I'm not questioning the "legitimate concern", but I don't think "legitimate concern" should be sufficient to get a warrant.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#69Can't they use the dead guys finger print?
Also even if it did, simply rebooting the device will require a complex passcode instead of a stored fingerprint.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#70A second: What happens if Apple states that it will take a 50-person team with an average annual labor cost of $200K/person approximately 5 weeks to fix the problem with a 50% chance of success. Can Apple bill the court a million dollars to try to fix the issue?
A third: Apple open-sources their encryption modules and firmware. They no longer have proprietary information for how to unlock the phone. Are they legally required to be the ones who defeat a system to which they hold no proprietary information?
A fourth: The small team that built the system no longer works for Apple. Perhaps their visa was revoked and they left the country, perhaps they were poached by a competitor, or perhaps they retired in the years since this module was published. Who is responsible for complying with the order?
A fifth: The data is actually corrupted. Apple presents this conclusion under penalty of perjury after a thousand hours spent on the project, which it requests are compensated.
A sixth: Apple requests that trading of its stock is frozen for one month while it expends considerable resources on complying with an unexpected court order relevant to national security.