Unfortunately, there's no good outcome here. If Apple can unencrypt the phone, it will prove to everyone that backdoors exist. If they can't, and they tell the FBI as much, it will just give politicians more reasons sound off about how we have to have backdoors, because this shooter was a "terrorist" after all, and we just have to suck it up and do whatever is necessary to go after people like that. Either way, we en…
Did you read the article? The court didn't order Apple to decrypt the phone. Instead, Apple has to disable the phone's feature that automatically wipes the hard drive after 10 failed password attempts. This is so that the FBI can brute-force its way into the data.
Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
111–120 of 364 posts
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#112Earlier quoted context omitted.
Even without the Secure Enclave, is it even possible for Apple to do this? The article talks about how Apple could add a backdoor to the OS and update the software on the device in order to break this, but I'm not sure how anyone is supposed to update the software on the device while it's locked, without erasing the device in the process (assuming of course that the iPhone is running a relatively recent version of th…
The court order refers to the need to load the custom OS image via DFU (device firmware upgrade) mode. I am not an iPhone user but I'm assuming that is exactly what the name implies. (some pre-boot recovery environment)
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#113Unfortunately, there's no good outcome here. If Apple can unencrypt the phone, it will prove to everyone that backdoors exist. If they can't, and they tell the FBI as much, it will just give politicians more reasons sound off about how we have to have backdoors, because this shooter was a "terrorist" after all, and we just have to suck it up and do whatever is necessary to go after people like that. Either way, we en…
Did you read the article? The court didn't order Apple to decrypt the phone. Instead, Apple has to disable the phone's feature that automatically wipes the hard drive after 10 failed password attempts. This is so that the FBI can brute-force its way into the data.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#114Earlier quoted context omitted.
IANAL, but I don't think there's much of a difference between asking someone to reveal the correct password and asking someone to reveal the correct finger. In both cases you would be asked to incriminate yourself. If it would be lawful for a court to ask you to "unlock the phone with the correct finger" then they might as well also ask you to "unlock this harddisk with the correct keyboard keys pushed in the correct…
I don't think there's much of a difference between asking someone to reveal the correct password and asking someone to reveal the correct finger. There's a huge difference. Authorities can force you to give up your fingerprint, but not your password[1]. 1. http://jolt.law.harvard.edu/digest/telecommunications/court-...
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#115Earlier quoted context omitted.
If you shoot a bunch of people while declaring allegiance to an organized group known for shooting bunches of people then I think that pretty clearly demonstrates that reading your communications has a pretty high likelihood of turning up something useful in preventing future incidents. If this doesn't clear your hurdle for reasonable search then what would? To be clear, I don't think the order to Apple is necessaril…
> reading your communications has a pretty high likelihood of turning up something useful in preventing future incidents Would you agree that "high likelihood" is too low a bar for justifying searching the phones of people who live in high-crime neighborhoods? > If this doesn't clear your hurdle for reasonable search then what would? Evidence of a conspiracy would help. You said they declared allegiance to an organiz…
Is there some other issue we're missing here, or does that pretty much wrap it up?
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#116This order says Apple must... - bypass the auto-erase feature - enable the FBI to "submit" passcodes - not purposefully introduce additional delays I don't see that this requires Apple to do anything in particular with whatever passcodes the FBI submits. bool tryPasscode (string passcode) { return false; } Reasonable cost of service: $5?
Games like this will get you contempt of court. I don't know if an obstruction of justice charge could come out of this, but I wouldn't test it myself...
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#117So if I get this right, they want to (1) disable the delete feature after x retries (therefore enabling unlimited retries) and (2) enable to submit tries via a connector/wifi, bluetooth (therefore enabling a bruteforce approach). What good is an encrypted filesystem in that scenario?
Plenty of good if you have a reasonable passphrase and the vendor hasn't been compelled to assist. "Can only try 10 times" isn't anything guaranteed by encryption. My laptop has an encrypted partition, but an attacker can brute-force it at will. Even if I had software to say "only let it happen 10 times, then erase the partition" the whole drive could just be cloned. That's why I have a 20+ character passphrase.
I was talking specifically about this scenario where the phone pin may be 4 or 6 numbers and Apple is helping them.
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#118Earlier quoted context omitted.
Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.
After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…
How is that actually enforced? Is there an if statement and a counter somewhere? Couldn't that just be disabled by a sufficiently advanced attacker?
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#119Earlier quoted context omitted.
I don't think there's much of a difference between asking someone to reveal the correct password and asking someone to reveal the correct finger. There's a huge difference. Authorities can force you to give up your fingerprint, but not your password[1]. 1. http://jolt.law.harvard.edu/digest/telecommunications/court-...
It's the "which finger" that becomes similar to a password, not the fingerprint (ianal)
Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone
#120Earlier quoted context omitted.
Ironically, many .gov organizations are rolling out iPhones by the thousand because of the strong security controls available on the platform.
Cite your source(s), please.