Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

161–170 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#161

Earlier quoted context omitted.

The users password goes through a password based key derivation function, that function spits out an key that is use for the AES crypto used for the file system. Now, the PBKDF requires a secret that is only stored within the iPhone itself (within the CPU even, where it can't be read out directly). So if we instead grab a copy of the data, all we get is an AES encrypted file system. We have 2 choices. 1. We can attac…

I guess that's my question...is there really no way to get the secret off of the hardware so that the function can be reproduced "offline".

restating your question: Has Apple been lying to its customers for years?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#162

Earlier quoted context omitted.

I'm having a hard time believing that you're commenting in good faith here. Yes, the police will easily get warrants to search whatever property of a mass murderer's they feel would be productive to search. No, that does not mean they can randomly get warrants to search random houses in high-crime neighborhoods. Privacy rights for mass murderers: not a high priority of US constitutional law. Is there some other issue…

> I'm having a hard time believing that you're commenting in good faith here. You can feel free to disengage from this conversation if you find it troubling. If you are incredulous that someone might be concerned with the privacy of these people (and their friends and family) in the particular way I am, then I'm not sure what I can do to make you believe. I am a person. These are my true thoughts. I actually and hone…

..... I currently have a lot of time on my hands, so sure, I'll bite....

> I did not ask if police CAN randomly get warrants to search random houses in high-crime neighborhoods, I asked the commenter if he or she thought they ought to be able to do so

Given that the answer to CAN they is a solid no, and that random searches of homes is in no way related to searching devices used in a conspiracy to commit murder, what is the point of this? In one instance, someone has clearly committed a conspiratorial crime, in another instance, people are living in houses with low property value.

> if there is any evidence of a conspiracy

Conspiracy - a secret plan by a group to do something unlawful or harmful.

Point 1: A conspiracy took place. A plan to kill people was kept secret between multiple people until it was executed.

Point 2: Immediately prior to commission of the murders, one of the participants declared that they were part of a larger group, known for organized commission of murder and terrorist attacks.

Given these points, what information is missing that would motivate you to think that a search of the attackers' phones should be conducted? Are you really asserting that there is no evidence of conspiracy that extends beyond the deceased, despite the fact that they said they were doing this under the flag of a larger organization?

I don't see any room for a normative argument defending against a search. I don't imagine that you're arguing that the post-mortem privacy interests of the terrorists prohibit investigation. Are you suggesting that the risk from not knowing the contents of the phone are so low as to not rise to outweigh the privacy interests of anyone incidentally mentioned on the device?

Sorry for all the questions, what I'm trying to get at is that from a normative perspective, societies generally allow investigators to search the shit of known participants of violent criminal conspiracies in order to detect previously unknown elements or plans of those conspiracies. What is the moral base from which you are arguing that this nearly universally accepted standard is somehow deficient?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#163

Ok someone murders a bunch of defenseless people... Why is Apple dragging their feet? This is tasteless. I'm NOT for backdoors, but this is ridiculous.

It's more than just that. It's about setting a precedent. If you let the government walk all over your security, then where do you draw the line? What's the point of security at that point? Security doesn't favor good or bad.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#164
post #155
post #145

It's at times like these they're surely knocking on the door of every company whose R&D in quantum computing, information theory and algorithms they've been funding for at least the past 2 or so odd decades. "So, is it ready yet?"

I'm assuming you are referring to quantum computing for it's speed computations? That wouldn't make a different here. They have only X amount of tries before the phone locks them out. It is the number of tries that is the issue here.

From my understanding, if you had for example a 128-qbit quantum computer, it would be able to crack any 16 character password in a single operation.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#165
post #150

Earlier quoted context omitted.

Law enforcement can legally force you to unlock your phone with your fingerprint, but cannot force you to reveal your passcode. http://pilotonline.com/news/local/crime/police-can-require-c...

So with biometrics being adopted by the mainstream population, would the law eventually be expanded to include our DNA?

They can already compel you to give a DNA sample though I believe they typically need a warrant or something official to do so.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#166
post #154
post #68

Earlier quoted context omitted.

> They may have collaborated with people who were never apprehended on the attack that actually happened. Right, but we don't go searching everyone's papers just in case they are conspirators. If Alice punches Bob in the face, then is hit by a bus and dies, we don't go searching through all of Alice's stuff just in case there might have been someone else involved with the Bob-punching incident, right? Is there any ev…

> If Alice punches Bob in the face, then is hit by a bus and dies, we don't go searching through all of Alice's stuff just in case there might have been someone else involved with the Bob-punching incident, right? Wrong. If Alice announces that she's looking for people to attack then of course we go looking so see why she's doing that and if other are others involved. This wasn't some random emotional attack like a b…

> Wrong. If Alice announces that she's looking for people to attack then of course we go looking so see why she's doing that and if other are others involved.

What, in your opinion, are the limits of that investigation.

So

1. Alice announces she's looking to attack someone.

2. She attacks Bob.

3. She dies.

I gather that, in your opinion, we can search her possessions. Let's say she has a living mother and a best friend who died a week before the attack. Can we search her mother's things? How about her best friend's?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#167
post #157

A thought experiment: Let's say the government makes hardware encryption standards in the style of FedRAMP that sets standards for preventing tampering by foreign governments. Then, imagine that a consumer electronics company voluntarily makes all devices comply with this standard. Could a court attempt to compel the company to defeat the standards which the government set as tamper-proof against governments? A secon…

1: Yes. 2: Yes. 3: No, but they will probably be the ones asked anyway, and then yes, they would be legally required. 4: Apple. 5: What's the question? Is the question will they be compensated? Then yes. 6: They can't. They don't own their stock. Bad PR is not a good enough reason. You are treating the court like a mathematical proof and finding edge cases. I used to as well. But courts don't work that way at all - t…

Specifically regarding question 5 - how does the burden of proof work? How do statues of limitations apply?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#168
post #157

A thought experiment: Let's say the government makes hardware encryption standards in the style of FedRAMP that sets standards for preventing tampering by foreign governments. Then, imagine that a consumer electronics company voluntarily makes all devices comply with this standard. Could a court attempt to compel the company to defeat the standards which the government set as tamper-proof against governments? A secon…

1: Yes. 2: Yes. 3: No, but they will probably be the ones asked anyway, and then yes, they would be legally required. 4: Apple. 5: What's the question? Is the question will they be compensated? Then yes. 6: They can't. They don't own their stock. Bad PR is not a good enough reason. You are treating the court like a mathematical proof and finding edge cases. I used to as well. But courts don't work that way at all - t…

[deleted]

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#169

Earlier quoted context omitted.

All the court cares about is for the person to supply the one that unlocks the phone, they're not going to play guessing games.

Courts care about precise distinctions of law (that's their purpose!). Seems clear that fingerprints aren't protected, basically the same thing as your face in terms of privacy given a good enough camera. But they would effectively be asking you the question "which finger did you use to lock this phone" to which you may plead the 5th.

It'll be contempt and possibly more if you don't unlock the device with your fingerprint.

It's not hard, the "precise distinction of law," is "unlock this with your finger, whichever one does it." I don't know what complicated back and forth you're imagining, but it's never occurred in any case that I've heard of.

they would effectively be asking you the question "which finger did you use to lock this phone" to which you may plead the 5th.

We already covered this in the link above: the 5th Amendment covers passcodes, not fingerprints.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#170
post #164
post #155

Earlier quoted context omitted.

I'm assuming you are referring to quantum computing for it's speed computations? That wouldn't make a different here. They have only X amount of tries before the phone locks them out. It is the number of tries that is the issue here.

From my understanding, if you had for example a 128-qbit quantum computer, it would be able to crack any 16 character password in a single operation.

It's not really a single operation though. How would that quantum computer test against an iPhone when each test is a mark against the 10 max test count? An iPhone is still based in standard silicon using bits; you can't exactly pop a process that uses qubits into it and expect it to work.
Post reply on HN