Live data from Hacker News

A Message to Our Customers

apple.com

31–40 of 1001 posts

Re: A Message to Our Customers

#32
Very impressive letter. They've expressed their position in language that a layman can understand, there's abundant evidence that they respect the intent of the law authorities, and even clearer evidence that they are drawing a line in the sand based on their principles. They will protect their customers.

I wish more companies could speak so clearly and courageously.

Re: A Message to Our Customers

#33

Earlier quoted context omitted.

> The fact that they can create this backdoor, doesn't that mean it already exists? Quite likely. As I posted on the other discussion here: https://news.ycombinator.com/item?id=11116343 > If it's possible to make such a "backdoored" build of iOS, then there are state actors who will be throwing $Millions at doing it already, with or without any willing help from Apple.

The security here is Apple's signing key that is used to sign updates. If you believe RSA is safe (which I assume is being used) and the key has a reasonable length, throwing a couple of millions at it won't bring you much. I guess what the FBI wants is a backdoored iOS version and to have Apple sign it with their signing key (which means that the FBI can use it over and over again).

That is hard, we know. But it is not impossible for those with time, resources and willingness to think outside the box.

For instance, signing keys can and have been stolen, on the principle of "if you can't brute-force it, hack in and take it".

http://arstechnica.com/security/2013/02/cooks-steal-security...

http://blogs.adobe.com/security/2012/09/inappropriate-use-of...

http://www.androidauthority.com/ssl-added-removed-google-moc...

http://arstechnica.co.uk/tech-policy/2016/02/its-legal-for-g...

Re: A Message to Our Customers

#34
post #28

What im reading is that apple can remote install an update that disable encryption. They dont want to do it. But that they have the capability is a bit scary.

Please read carefully. They don't have that capability. The FBI wants them to create it.

Re: A Message to Our Customers

#35

The fact that they can create this backdoor, doesn't that mean it already exists? What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.

The letter describes it:

"The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer."

Re: A Message to Our Customers

#36
post #17

The fact that they can create this backdoor, doesn't that mean it already exists? What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.

[deleted]

So what would you call it, a back gate? It still loosens the extant security measures, facilitating compromise. That's pretty backdoor-y in my book.

Re: A Message to Our Customers

#37
post #17

The fact that they can create this backdoor, doesn't that mean it already exists? What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.

[deleted]

It's reducing the complexity of decryption (from O(∞) to O(2^n)), so it's clearly a backdoor.

Re: A Message to Our Customers

#38
Plot twist.

This is actually the result of a barter. The Gov gets to have some low level TOP-SECRET access in trade for this easy access code and that Apple gets to go public to keep the populace calm and pretend they are fighting this thing.

Re: A Message to Our Customers

#39
It makes sense for them.

If they put a backdoor in iPhone for US government, they are effectively thrown out of Chinese market.

Interesting enough, what will Apple do if Chinese government demand they to decrypt/put backdoor in exchange of staying in the market?

Re: A Message to Our Customers

#40
post #28

What im reading is that apple can remote install an update that disable encryption. They dont want to do it. But that they have the capability is a bit scary.

You're not reading that, you're implying it. It doesn't say anything at all about remote installs, and it's not even suggested.
Post reply on HN