Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

231–240 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#233

If you read the iOS security guide you'll know Apple built the phone in such a way as to wash its hands with these types of request. They'll say it's impossible and they won't be lying. Nothing is ever impossible, but it will be very impractical. The hardware and software is built to ensure this. I think the real game here is to compel Apple to build a backdoor into future models. I expect to see a lot of rhetoric ar…

That is possibly true for current models of the iPhone. It is significantly less true for the 5c in question, which has less robust security features. See other answers referring to the Secure Enclave.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#234

For me, the most interesting question I would have is absent from the article. The court is basically ordering Apple to produce new firmware that doesn't block brute forcing. If Apple were to comply, who keeps this firmware after the fact? There's no mention of this at all, but if the firmware image stays with the FBI then the implications are much more profound with regard to privacy.

I would bet you all the money in the world that the very second such a firmware image was provided to the FBI it would find its way to the CIA/NSA. All with the assumption of course that the FBI has no rogue agents who work for foreign governments or criminal organisations.

Apple is right to be terrified at the thought of being asked to make such a firmware image.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#235

Who goes to jail if Apple flat out refuses?

Nobody would have to go to jail. They'd hold Apple in contempt and charge them a non-trivial sum of money for every day they refuse. If they continue refusing, the amount increases exponentially until the company is threatened with bankruptcy. In short: they can't refuse without a justified explanation of why they are unable to comply.

In which case the best way to proceed would be to say that they will try to do it and after few months of investigation say the data became corrupted before they even got the phone. Who's going to verify it? No one.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#236
post #176

this is smoke screen. Purely. they can already desolder the flash memory chips and brute force the data, programatically no less, all they want.

Are you suggesting they can brute force AES-256? iOS's security is quite sophisticated: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

well, now that you mention...

i was commenting only on the article that says they wanted apple to remove the "wipe data after X tries"

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#237

So, Apple says that "the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation." https://www.apple.com/customer-letter/ If it's possible to make such a "backdoored" build of iOS, then there are state actors who will be throwing $Millions at doing it already, with or without any willing help f…

I'm guessing this would need to involve stealing Apple's private code signing key.

This is mentioned here: https://news.ycombinator.com/item?id=11116390

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#239

Earlier quoted context omitted.

Courts care about precise distinctions of law (that's their purpose!). Seems clear that fingerprints aren't protected, basically the same thing as your face in terms of privacy given a good enough camera. But they would effectively be asking you the question "which finger did you use to lock this phone" to which you may plead the 5th.

It'll be contempt and possibly more if you don't unlock the device with your fingerprint. It's not hard, the "precise distinction of law," is "unlock this with your finger, whichever one does it." I don't know what complicated back and forth you're imagining, but it's never occurred in any case that I've heard of. they would effectively be asking you the question "which finger did you use to lock this phone" to which…

Imagine you were to take the example further, unlocking the device required a sequence of fingerprint reads, with a precise ordering. i.e. left-ring finger, right index finger, right little finger, etc... That sequence would be a passcode, just as a precise sequence of keypresses would be. The government can insist on all your fingerprints, but not (in this argument) the correct sequence of uses of those fingerprints to unlock it. If it's only a single finger this same argument could apply.
Post reply on HN