Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

151–160 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#151
post #4

Remember, this is an iPhone 5C, which doesn't have Touch ID or the Secure Enclave; the security model for this phone is significantly different from that of more recent iPhones. On phones with a Secure Enclave, the wipe-on-failures state is managed in the coprocessor (which runs L4), and is not straightforwardly backdoor-able. If you're worried about the police brute-forcing your phone, enable Touch ID and set a pass…

Also, don't use your actual fingerprint, since it's becoming harder to avoid giving it to the government, even if you're not a criminal.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#152
post #85

The 5th amendment protects evidence inside the brain of the accused. As devices becomes more and more an extension of the brain, the more I think we'll need to adjust the rule of the 5th amendment to cover things outside of the brain.

Let's go off the deep end, shall we, and speculate? Consciousness (the process that manages your evidence) is already encrypted. It's encrypted by quantum events occurring in the brain. The going conjecture is that microtubules in brain cells provide a latticework to maintain and force collapse of quantum states which somehow drive neuron activity. Regardless if you believe that or not, it is now known that brains are storing information in DNA and that DNA processes appear to be governed by quantum events. It's a reasonably palatable conjecture which may be testable in the next few years, and it's speculation for the hell of it here anyway.

Having essentially hardware equipped encryption, you brain ends up being completely unique and probably uncopyable in total from a quantum level process, given it lives half here and, ahem, half there. Any connection to it by a non-quantum devices in reality, especially high speed ones, are probably a bad idea as it increases the exposure surface area beyond what nature has likely already secured. Given your brain is reprogrammable, it's probably not a good idea to hook up weird shit to it until we know more about how the universe and it work. That includes any shit a government asks you to hook up to yourself now and again when you pass through its borders.

The 5th amendment being out of date is the least of our problems. Our government in the US, in its valiant attempt to protect us, has somehow decided it needs to keep increasing the efficiency of protection in response to what appear to be escalating abilities with the bad guys. The problem is, of course, is that eliminating all suffering is completely impossible, and that the idea of what is a decent amount of suffering to endure is constantly shifting as it's being squabbled over by people infected with angry cooperative memes...memes which have forgotten that this country was founded on freedom to do whatever you wanted, when you wanted to do it, as long as you weren't shitting on your neighbor when you did it.

Frankly, I'm more concerned about cloud services nowadays than phones. Seems as if a phone is just a viewport to the cloud and with so many services and apps accessing my phone's data (seems like every day another apps asks for more data) that the exposure area of my phone's cloud footprint is probably easier to hack than the phone itself.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#153

I thought this was an excellent write-up regarding how the iOS security platform (recent iPhone models) works from someone obviously in the know, as posted in the forums of Apple Insider. (Source: http://forums.appleinsider.com/discussion/191851 ) " Apple uses a dedicated chip to store and process the encryption. They call this the Secure Enclave. The secure enclave stores a full 256-bit AES encryption key. Within th…

Someone pointed out that the device in question doesn't have all of the features described above as it is an iPhone 5c. My apologies. I'll leave my comment as some may still find it interesting. Relevant-ish, perhaps.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#154
post #68
post #50

Earlier quoted context omitted.

I'm sorry, but I don't understand what you're getting at here. The legitimate concern is prevention of future attacks. They may have collaborated with people who were never apprehended on the attack that actually happened.

> They may have collaborated with people who were never apprehended on the attack that actually happened. Right, but we don't go searching everyone's papers just in case they are conspirators. If Alice punches Bob in the face, then is hit by a bus and dies, we don't go searching through all of Alice's stuff just in case there might have been someone else involved with the Bob-punching incident, right? Is there any ev…

> If Alice punches Bob in the face, then is hit by a bus and dies, we don't go searching through all of Alice's stuff just in case there might have been someone else involved with the Bob-punching incident, right?

Wrong. If Alice announces that she's looking for people to attack then of course we go looking so see why she's doing that and if other are others involved.

This wasn't some random emotional attack like a bar fight. Stop setting up nonsensical strawmen for your arguments, argue the hard cases not the easy ones.

If your argument/objection can survive the hard cases then you have something, arguing the easy cases is meaningless.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#155
post #145

It's at times like these they're surely knocking on the door of every company whose R&D in quantum computing, information theory and algorithms they've been funding for at least the past 2 or so odd decades. "So, is it ready yet?"

I'm assuming you are referring to quantum computing for it's speed computations? That wouldn't make a different here. They have only X amount of tries before the phone locks them out. It is the number of tries that is the issue here.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#156

Earlier quoted context omitted.

It's been a few years since I looked at DFU, but my impression was that installing a new OS via DFU would have the side-effect of erasing the device.

In my jailbreak days, the DFU update did indeed wipe the device. I don't know how it works.

Did it actually write zeros to the flash memory or did it leave the data sitting around somewhere?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#157

A thought experiment: Let's say the government makes hardware encryption standards in the style of FedRAMP that sets standards for preventing tampering by foreign governments. Then, imagine that a consumer electronics company voluntarily makes all devices comply with this standard. Could a court attempt to compel the company to defeat the standards which the government set as tamper-proof against governments? A secon…

1: Yes.

2: Yes.

3: No, but they will probably be the ones asked anyway, and then yes, they would be legally required.

4: Apple.

5: What's the question? Is the question will they be compensated? Then yes.

6: They can't. They don't own their stock. Bad PR is not a good enough reason.

You are treating the court like a mathematical proof and finding edge cases. I used to as well. But courts don't work that way at all - they don't care in the slightest about your proof. They analyze things on a human level, not a mathematical level.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#158

Does Apple get to bill the FBI for the time that their engineers and legal department will be busy on this request?

Yes. In the court order section 5 (on line 8 of page 3) "Apple shall advise the government of the reasonable cost of providing this service." Perhaps only engineering resources. (it's always gonna be a big legal hassle)

A reasonable cost may still be $150 to $200 per hour. Engineering time charged to a third party is never cheap.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#159

Earlier quoted context omitted.

Did you read the article? The court didn't order Apple to decrypt the phone. Instead, Apple has to disable the phone's feature that automatically wipes the hard drive after 10 failed password attempts. This is so that the FBI can brute-force its way into the data.

Yes, and that's effectively the same thing. Bypassing controls counts as a "backdoor".

Brute forcing a password could take more time, with today's technology, than we have left on Earth depending on complexity and if there are known vulnerabilities. I'm not sure I would effectively consider this order an order to "unencrypt".

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#160
post #35

Earlier quoted context omitted.

> There is an authentic need to get at the data on that phone What is the authentic need? The shooters are dead. Do we have reason to believe that there is evidence of any pending crimes or any old unsolved crimes on the phone?

If you shoot a bunch of people while declaring allegiance to an organized group known for shooting bunches of people then I think that pretty clearly demonstrates that reading your communications has a pretty high likelihood of turning up something useful in preventing future incidents. If this doesn't clear your hurdle for reasonable search then what would? To be clear, I don't think the order to Apple is necessaril…

In response to your (first?) edit:

> The woman in the couple declared it right before the shooting[0].

I'm not questioning that she declared allegiance. I'm asking if she was in private contact with anyone. If you were responding to that, can you show me where that is in the NYT article you linked? I don't see it.

> Do you want a notarized letter from the deceased?

Let's try to keep this civil, please.

> Do you really view this as a government overreach or are you just trolling?

I actually believe the things I am saying. I am not saying them to anger or upset you or anyone else. Please do not let the fact that we disagree about the scope of the 4th Amendment cause you emotional suffering.

I am not ready to declare it overreach, because I do not know all of the evidence yet. This is why I have been saying things like "Do we have reason to believe that there is evidence of any pending crimes or any old unsolved crimes on the phone?" and "did they say or hint that they had been in contact with that group" and "I have not followed the news on this shooting, so I would not be shocked if the answer were 'yes, there is some evidence of a conspiracy'."

If there is no such evidence, I do think it is overreach, but my opinions on policy are not fixed in stone, and I sometimes change my mind about them when presented with new arguments, ideas, or philosophies.

> Under what circumstances, if any, would you see as justified a search of someone's email? phone? house?

I doubt anyone has a complete enumeration of all circumstances under which they feel a search is justified. I would feel torn if there was lousy circumstantial evidence that the phone would solve or prevent crimes, I would be in support of a warrant if there was strong evidence, and I am opposed to a warrant with no evidence. One thing I would call strong evidence is a shooter having announced that he or she was part of a terrorist cell in the US.

I will no longer reading or responding to your edits that are "edited to reply". If you want to discuss with me further, please reply to reply by using the "reply" button. I will not be editing any of my posts to "edit to reply".

Post reply on HN