Live data from Hacker News

A Message to Our Customers

apple.com

81–90 of 1001 posts

Re: A Message to Our Customers

#81
post #73

Earlier quoted context omitted.

With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.

Not too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.

But you can always root your phone and install Cyanogenmod from scratch, right? Agreed that this is not too trivial right now because of standardization issues, but it could be done if you really care about privacy.

Re: A Message to Our Customers

#82

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

The last part actually surprises me too.

Re: A Message to Our Customers

#83

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

Exploiting is a bit loaded. Where I’m from, we call this “a free round”. There’s no downside to doing this, and a sizeable one to complying with the order. Still, it’s nice to see that Apple don’t hesitate, which makes me feel good about any other future challenge the feds will throw at Apple.

Re: A Message to Our Customers

#84

Im generally not an apple supporter(i dont like the closed eco system), i am very plesantly surprised they posted this. I am quite disappointed that the us courts are trying to force apple todo this, and in my opinion, its just to use this case to set a precedent. I hope Apple cant get it to work, but id hate to see what the courts would do if that happened.

There are basically two groups of large software companies around right now: those which make their business by collecting data, and those which make their business by licensing software[1]. The first group has an overwhelming incentive to not support privacy too strongly. The second group has an overwhelming incentive to not allow too much openness. Until a better business model (or zero-knowledge machine learning)…

I can't upvote enough that excellent summary of the situation of software companies.

One way to solve that would be to have governments support and subsidies open source software development, but I don't see that happening in the next 5 years at the very least.

Re: A Message to Our Customers

#85
post #70

Earlier quoted context omitted.

read section 'Hardware Security Features' here: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Ok, so: "The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID is not related to any other identifier on the device." The secure enclave must still give it's UID under some circumstances? This still does not appear to…

"The device’s unique ID (UID) and a device group ID (GID) are AES 256-bit keys fused (UID) or compiled (GID) into the application processor and Secure Enclave during manufacturing. No software or firmware can read them directly; they can see only the results of encryption or decryption operations performed by dedicated AES engines implemented in silicon using the UID or GID as a key."

re: brute forcing. they are AES 256 bit keys. good luck.

Re: A Message to Our Customers

#86
Good on them. I was hoping that they'd be able to manage a way to unlock this one without potentially breaking the whole model (by exploiting some bug in the presumably outdated version installed or something that wouldn't positively degrade the security model), but given that that's not the case then I think they're making the right choice.

Re: A Message to Our Customers

#87
post #73

Earlier quoted context omitted.

With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.

Not too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.

Or, said differently, Play Services are already a backdoor. They can (and do) install updates or other software pushed by server automatically, without you being able to do anything about it. And they have access to anything on the phone.

Re: A Message to Our Customers

#88
post #42

I'm really impressed that Apple is standing up to the government and protecting its users' rights. I've never really considered the iPhone worth the premium price tag, but policies like this have changed my mind. Could someone answer a question I have though? The government wants Apple to create this backdoor and tailor it to the specific device, so presumably it will have a line that goes if (!deviceID.equals("san_b…

Technically you're right, legally think of the huge precedent. FBI is using the San Bernardino case as a legal crowbar, and it's awful.

Re: A Message to Our Customers

#89
post #75

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

See other comment: https://news.ycombinator.com/item?id=11116439 Potentially, Apple cannot circumvent their own protections on some models (in software anyway), and could in others.

Thanks. This explains it. I was just thinking about my old Thinkpad X41. That had TPM module and hardware encryption. There's nothing that IBM or the TPM manufacturer could've done to decrypt it (unless the TPM module already had backdoors, haha). Latest iPhones are basically the same?

Re: A Message to Our Customers

#90

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

"we believe the contents of your iPhone are none of our business."
Post reply on HN