Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

121–130 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#121
post #82

Earlier quoted context omitted.

IANAL, but I don't think there's much of a difference between asking someone to reveal the correct password and asking someone to reveal the correct finger. In both cases you would be asked to incriminate yourself. If it would be lawful for a court to ask you to "unlock the phone with the correct finger" then they might as well also ask you to "unlock this harddisk with the correct keyboard keys pushed in the correct…

I don't think there's much of a difference between asking someone to reveal the correct password and asking someone to reveal the correct finger. There's a huge difference. Authorities can force you to give up your fingerprint, but not your password[1]. 1. http://jolt.law.harvard.edu/digest/telecommunications/court-...

Yes, and when they do force you to give your fingerprints they don't ask you what finger you want them to print they tell you which finger and when to print.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#122

A thought experiment: Let's say the government makes hardware encryption standards in the style of FedRAMP that sets standards for preventing tampering by foreign governments. Then, imagine that a consumer electronics company voluntarily makes all devices comply with this standard. Could a court attempt to compel the company to defeat the standards which the government set as tamper-proof against governments? A secon…

A seventh: What if there's influence from super-secret organizations to make those FEDRAMP-style standards less "tamper-proof"? Then a court wouldn't even need to be involved: https://www.eff.org/deeplinks/2014/11/eff-joins-call-nist-we...

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#123

Earlier quoted context omitted.

It's the "which finger" that becomes similar to a password, not the fingerprint (ianal)

All the court cares about is for the person to supply the one that unlocks the phone, they're not going to play guessing games.

Courts care about precise distinctions of law (that's their purpose!). Seems clear that fingerprints aren't protected, basically the same thing as your face in terms of privacy given a good enough camera.

But they would effectively be asking you the question "which finger did you use to lock this phone" to which you may plead the 5th.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#124
post #25

Earlier quoted context omitted.

A lot of research has gone into information recovery from silicon inspection since it's tied closely to reverse engineering ICs. It's not the most trivial of pursuits but widely done. There are some hardware HMACs (Atmel's in particular IIRC) where the process of opening the chip package destroys the area of silicon that encodes the private keys. I don't know if Apple used the same tech but if they did, any attempt t…

Quantum cryptography would be fullproof. Any attempt to view the algorithm instead of using it would render it useless.

That's not how quantum crypto works (it's based on observation of state, not the algorithm). Further, we've had cases of quantum crypto that just wasn't good enough to stop an observer from MITMing the internal state.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#125
Big problem. People will generally stop using phones of which they suspect that they are back-doored. At the same time, it would be a hopeless endeavour for law enforcement to get a swarm of (Chinese or other Asian) companies to help with unlocking their phones. They would literally not even answer the phone. Therefore, this may very well spell the end of highly centralized, Apple-style companies that can be effectively pressured and browbeaten into "compliance".

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#126
post #40

Earlier quoted context omitted.

Yeah I've got the same question. Is there some hardware safeguard that prevents copying the memory itself? You'd think the first rule of crypto forensics is to work on a copy.

Even if there were no such safeguard, you'd still have to break AES encryption...

[deleted]

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#128
Why no one is attacking on hardware level? Cut the processor to get the GID and UID, dump the flash, pregenerate rainbow tables with pin, power flash chip externally and give the codes ...

Yeah it is expensive, but I would not be surprised if there aren't such labs that could provide such service. Why does FBI goes trough such pains?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#129

Earlier quoted context omitted.

Did you read the article? The court didn't order Apple to decrypt the phone. Instead, Apple has to disable the phone's feature that automatically wipes the hard drive after 10 failed password attempts. This is so that the FBI can brute-force its way into the data.

This could be example of parallel construction[1]. They may already have unencrypted it via a backdoor, but they wouldn't be able to use anything they find as evidence in court because they'd have to reveal the backdoor. If they can plausibly show they brute-forced it instead, they keep the backdoor hidden. [1] https://en.wikipedia.org/wiki/Parallel_construction

Ok, but IMO this is a much lesser evil than (1) compulsory lawful-override of encryption/back door or (2) legislation to exclude devices which don't provide back doors.

Ultimately states will develop the capacity for brute forcing and you have relatively little recourse. While I hate the idea of a three letter agency doing this at any scale large or small, the potential for corrupt local LEOs to abuse their power with an encryption backdoor is very great.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#130

Who goes to jail if Apple flat out refuses?

Nobody would have to go to jail. They'd hold Apple in contempt and charge them a non-trivial sum of money for every day they refuse. If they continue refusing, the amount increases exponentially until the company is threatened with bankruptcy.

In short: they can't refuse without a justified explanation of why they are unable to comply.

Post reply on HN