Live data from Hacker News

A Message to Our Customers

apple.com

61–70 of 1001 posts

Re: A Message to Our Customers

#61
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

[deleted]

Re: A Message to Our Customers

#62
post #53

Link to the FBI order: https://assets.documentcloud.org/documents/2714001/SB-Shoote... (Edit: deleted part where I was wrong. Thanks robbiet480 for correcting me. It's 2am here and I was tired.) Also, prediction: if Apple refuses to build a brute forcer, someone else will do it and sell it to the FBI. Just wait and watch.

Also disables the auto-lockout on entering the wrong PIN enough times, as well as the delays after the 3rd (IIRC) incorrect attempt.

Re: A Message to Our Customers

#63
post #53

Link to the FBI order: https://assets.documentcloud.org/documents/2714001/SB-Shoote... (Edit: deleted part where I was wrong. Thanks robbiet480 for correcting me. It's 2am here and I was tired.) Also, prediction: if Apple refuses to build a brute forcer, someone else will do it and sell it to the FBI. Just wait and watch.

iPhone brute force hardware already exists [1]. The issue is that when Touch ID and/or a passcode is enabled, the device locks itself for a few seconds-a few hours every time an incorrect pin is entered. So brute forcing would take an extremely long time.

In addition, there is a setting on all iPhones to erase data after 10 failed pin code entry attempts.

The FBI wants Apple to provide a custom iOS build that can be installed on the device that allows for remote (over the network) brute forcing with the increasing timeout/erase data protections totally disabled.

1. http://techcrunch.com/2015/03/19/iphone-bruteforce-pin/

Re: A Message to Our Customers

#64

Im generally not an apple supporter(i dont like the closed eco system), i am very plesantly surprised they posted this. I am quite disappointed that the us courts are trying to force apple todo this, and in my opinion, its just to use this case to set a precedent. I hope Apple cant get it to work, but id hate to see what the courts would do if that happened.

There are basically two groups of large software companies around right now: those which make their business by collecting data, and those which make their business by licensing software[1]. The first group has an overwhelming incentive to not support privacy too strongly. The second group has an overwhelming incentive to not allow too much openness. Until a better business model (or zero-knowledge machine learning) is found, no large for profit company can support both goals to their final conclusion[2]. So we are left choosing one evil or the other[3].

[1] Sure, Apple only really sells hardware directly, but the software is a significant part of the reason a lot of people by Apple hardware (e.g. 'Mac's don't get viruses', 'iPhones have a better user experience').

[2] Sure, Google has some significant internal efforts for supporting better user privacy (e.g. https://googleonlinesecurity.blogspot.com/2014/12/an-update-... ) and Apple maintains some superb open-source software (e.g. http://llvm.org/ ). But in the end, Google can't be a "privacy company" without hurting their business model and Apple can't be an "open source company" for the same reason.

[3] Or the non-trivial inconvenience of being a self-hosting free software purist

Re: A Message to Our Customers

#65
I see a lot of people saying they're impressed, admired, etc. at Apple for doing this.

It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy.

They are just exploiting that competitive advantage.

Cfr. https://ar.al/notes/apple-vs-google-on-privacy-a-tale-of-abs...

Re: A Message to Our Customers

#66
post #41
post #17

Earlier quoted context omitted.

[deleted]

I don't have an iPhone so correct me if I'm remembering correctly but aren't they by default protected by a 4 digit numeric pin? A 4 digit numeric pin that a brute force attack can be used on is effectively no security/a backdoor imo.

I believe the default on new installs is now 6, but options for a more complex PIN, either numeric or straight up alphanumeric, are available.

Re: A Message to Our Customers

#67

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

> Apple, if they chose to, can make a version of iOS that disables security features and encryption and load it onto existing phone even though the phone is locked and encrypted?

As I understand it, the FBI wants Apple to create a version of iOS that would disable the current feature where the data is deleted after more than 10 failed passwords attempts. This would allow the FBI to brute force the password.

Re: A Message to Our Customers

#68

Earlier quoted context omitted.

Well the FBI would have to have the iPhone in their possession to unlock it I presume. SO that's one level of security - I don't think the USA has become a place where property can just be confiscated without reason (I hope I am right here). If Apple were custodians of the unlock process then only once due legal process had been followed would an iPhone be unlocked i.e. Apple would own the unlocking mechanism. Maybe…

> I don't think the USA has become a place where property can just be confiscated without reason Civil Forefeiture has been a problem for a long time.

https://www.youtube.com/watch?v=3kEpZWGgJks

Re: A Message to Our Customers

#69
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.

Re: A Message to Our Customers

#70
post #30

Am I wrong to think that this brute forcing can still be applied when the raw memory chip is taken of the iPhone? The wipe-all-data-feature requires write access to the chip + some intelligence and monitoring. These capabilities should be physically removable from the actual memory chip, right?

read section 'Hardware Security Features' here: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Ok, so: "The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID is not related to any other identifier on the device."

The secure enclave must still give it's UID under some circumstances? This still does not appear to be immune to hardware hacking.

Moreover, this UID can also be brute forced imo, when the memory chip and secure enclave are physically separated. Whatever is needed to de-encrypt the data must be brute force-able, especially when the memory is separated from the wipe-all-data initiator which does not seem to be impossible if you know the chip design well enough?

Post reply on HN