Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…
A Message to Our Customers
61–70 of 1001 posts
Re: A Message to Our Customers
#62Link to the FBI order: https://assets.documentcloud.org/documents/2714001/SB-Shoote... (Edit: deleted part where I was wrong. Thanks robbiet480 for correcting me. It's 2am here and I was tired.) Also, prediction: if Apple refuses to build a brute forcer, someone else will do it and sell it to the FBI. Just wait and watch.
Re: A Message to Our Customers
#63Link to the FBI order: https://assets.documentcloud.org/documents/2714001/SB-Shoote... (Edit: deleted part where I was wrong. Thanks robbiet480 for correcting me. It's 2am here and I was tired.) Also, prediction: if Apple refuses to build a brute forcer, someone else will do it and sell it to the FBI. Just wait and watch.
In addition, there is a setting on all iPhones to erase data after 10 failed pin code entry attempts.
The FBI wants Apple to provide a custom iOS build that can be installed on the device that allows for remote (over the network) brute forcing with the increasing timeout/erase data protections totally disabled.
Re: A Message to Our Customers
#64Im generally not an apple supporter(i dont like the closed eco system), i am very plesantly surprised they posted this. I am quite disappointed that the us courts are trying to force apple todo this, and in my opinion, its just to use this case to set a precedent. I hope Apple cant get it to work, but id hate to see what the courts would do if that happened.
[1] Sure, Apple only really sells hardware directly, but the software is a significant part of the reason a lot of people by Apple hardware (e.g. 'Mac's don't get viruses', 'iPhones have a better user experience').
[2] Sure, Google has some significant internal efforts for supporting better user privacy (e.g. https://googleonlinesecurity.blogspot.com/2014/12/an-update-... ) and Apple maintains some superb open-source software (e.g. http://llvm.org/ ). But in the end, Google can't be a "privacy company" without hurting their business model and Apple can't be an "open source company" for the same reason.
[3] Or the non-trivial inconvenience of being a self-hosting free software purist
Re: A Message to Our Customers
#65It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy.
They are just exploiting that competitive advantage.
Cfr. https://ar.al/notes/apple-vs-google-on-privacy-a-tale-of-abs...
Re: A Message to Our Customers
#66Earlier quoted context omitted.
[deleted]
I don't have an iPhone so correct me if I'm remembering correctly but aren't they by default protected by a 4 digit numeric pin? A 4 digit numeric pin that a brute force attack can be used on is effectively no security/a backdoor imo.
Re: A Message to Our Customers
#67This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…
As I understand it, the FBI wants Apple to create a version of iOS that would disable the current feature where the data is deleted after more than 10 failed passwords attempts. This would allow the FBI to brute force the password.
Re: A Message to Our Customers
#68Earlier quoted context omitted.
Well the FBI would have to have the iPhone in their possession to unlock it I presume. SO that's one level of security - I don't think the USA has become a place where property can just be confiscated without reason (I hope I am right here). If Apple were custodians of the unlock process then only once due legal process had been followed would an iPhone be unlocked i.e. Apple would own the unlocking mechanism. Maybe…
> I don't think the USA has become a place where property can just be confiscated without reason Civil Forefeiture has been a problem for a long time.
Re: A Message to Our Customers
#69Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…
Re: A Message to Our Customers
#70Am I wrong to think that this brute forcing can still be applied when the raw memory chip is taken of the iPhone? The wipe-all-data-feature requires write access to the chip + some intelligence and monitoring. These capabilities should be physically removable from the actual memory chip, right?
read section 'Hardware Security Features' here: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
The secure enclave must still give it's UID under some circumstances? This still does not appear to be immune to hardware hacking.
Moreover, this UID can also be brute forced imo, when the memory chip and secure enclave are physically separated. Whatever is needed to de-encrypt the data must be brute force-able, especially when the memory is separated from the wipe-all-data initiator which does not seem to be impossible if you know the chip design well enough?