Live data from Hacker News

A Message to Our Customers

apple.com

21–30 of 1001 posts

Re: A Message to Our Customers

#21
This is quite unlike Apple. Is this the same company that insists on keeping its source proprietary and is always against FOSS? The idea that you care for your users' privacy and still like to keep control on them by not giving them the freedom to modify source-code is not what I buy.

Re: A Message to Our Customers

#23
Publicizing the case themselves in a very good move.

However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode).

The amount of work needed to turn security into good user experience is phenomenal: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Re: A Message to Our Customers

#24

With the due legal process the police can search property, safety deposit boxes, bank accounts, vehicles, etc. etc. Why should a smartphone be any different just because Apple says it is ? As much as I value privacy I really don't agree with Apple's stance here - if due legal process has been followed, why shouldn't they be able to read the contents of an iPhone ? And yes I get that third party encryption can be used…

The issue they're talking about is that by creating a back door it's not limited to a single iPhone. Once there's a way in then anyone with that knowledge can use it on any iPhone to access encrypted data.

That seems a lot different from getting a search warrant and having the right to go through your belongings.

Re: A Message to Our Customers

#25

The fact that they can create this backdoor, doesn't that mean it already exists? What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.

> The fact that they can create this backdoor, doesn't that mean it already exists? Quite likely. As I posted on the other discussion here: https://news.ycombinator.com/item?id=11116343 > If it's possible to make such a "backdoored" build of iOS, then there are state actors who will be throwing $Millions at doing it already, with or without any willing help from Apple.

The security here is Apple's signing key that is used to sign updates. If you believe RSA is safe (which I assume is being used) and the key has a reasonable length, throwing a couple of millions at it won't bring you much.

I guess what the FBI wants is a backdoored iOS version and to have Apple sign it with their signing key (which means that the FBI can use it over and over again).

Re: A Message to Our Customers

#26

This is quite unlike Apple. Is this the same company that insists on keeping its source proprietary and is always against FOSS? The idea that you care for your users' privacy and still like to keep control on them by not giving them the freedom to modify source-code is not what I buy.

You're talking nonsense. Protecting users' privacy and keeping source code closed aren't mutually exclusive.

Re: A Message to Our Customers

#27
post #12

Earlier quoted context omitted.

The major difference is that a warrant to access a safety deposit box allows the keys for that specific safety deposit box and no other. What the FBI is asking for is the equivalent of asking for a master key to all the safety deposit boxes to access just the one box. Given what was revealed in the summer of 2013 by Snowden, I think we'd all agree that the FBI and other state agencies (not just American agencies) wil…

Well the FBI would have to have the iPhone in their possession to unlock it I presume. SO that's one level of security - I don't think the USA has become a place where property can just be confiscated without reason (I hope I am right here). If Apple were custodians of the unlock process then only once due legal process had been followed would an iPhone be unlocked i.e. Apple would own the unlocking mechanism. Maybe…

> I don't think the USA has become a place where property can just be confiscated without reason

Civil Forefeiture has been a problem for a long time.

Re: A Message to Our Customers

#29
post #22

"We have no sympathy for terrorists." They felt the need to state that, huh?

I was surprised that they felt it necessary but its pre-emptive counter to a pretty common argument - that smartphone makers are aiding and abetting terrorists by providing them encryption tools.

Re: A Message to Our Customers

#30
Am I wrong to think that this brute forcing can still be applied when the raw memory chip is taken of the iPhone? The wipe-all-data-feature requires write access to the chip + some intelligence and monitoring. These capabilities should be physically removable from the actual memory chip, right?
Post reply on HN