Live data from Hacker News

A Message to Our Customers

apple.com

91–100 of 1001 posts

Re: A Message to Our Customers

#91
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.

Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free.

Anyone who does is a rounding error.

Re: A Message to Our Customers

#92
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.

Not necessarily.

Despite the openness of Android/AOSP, there are still, unfortunately, things like binary blobs for certain graphics chips and closed-source firmware for things like Wi-Fi chipsets. Given what we've seen agencies like NSA are capable of (intercepting hardware in transit to apply backdoors, paying off RSA to make Dual EC the default pRNG in their crypto libraries, etc.), them compelling a manufacturer of a component to include a backdoor in their closed-source blobs is no stretch of the imagination.

Apple even has this problem: basebands in cellular modems are notorious for being the source of exploits in otherwise-secure phones.

Re: A Message to Our Customers

#93
I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate moving forward for all sorts of requests to add backdoors/decrease security.

It's entirely possible, that the FBI can then use this precedent to simply have Apple remove all security from an iPhone in pursuit of an active investigation, which can be done with a straightforward firmware update - which IOS users tend to do without much thought.

Re: A Message to Our Customers

#95
post #70

Earlier quoted context omitted.

read section 'Hardware Security Features' here: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Ok, so: "The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID is not related to any other identifier on the device." The secure enclave must still give it's UID under some circumstances? This still does not appear to…

Where is the reply button under your comment chillaxtian? Edit: hmm, now it suddenly appeared...

How about disabling the wipe signal by cutting some interconnects in the silicon?

Is the function by which the AES keys are calculated from the password really completely inaccessible?

Re: A Message to Our Customers

#96
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order

If government agencies has unfettered access to data, it undermines the reputation of these companies. For instance, in Europe, many companies and organisations are likely even more hesitant to use Google's services since the Snowden leaks. This is a large loss of potential revenue.

Google has been (even more) proactive about security and encryption since then, since part of their business model relies on trust.

Re: A Message to Our Customers

#97
To all in-love-with-Apple downvoters, please read this Schneier sound analysis of the same type of situation that RIM(Blackberry) has been met with: https://www.schneier.com/blog/archives/2010/08/uae_to_ban_bl...

/quote: "RIM's carefully worded statements about BlackBerry security are designed to make their customers feel better, while giving the company ample room to screw them." /endquote

I have lost enough points on this thread to simply double down on this issue.

This is not a good sign at all. While Google can't compete with Apple on the principle of "not spying on their users". All Apple has to to is to publicize it and then ask for forgiveness from it's users later.

Re: A Message to Our Customers

#98
post #39

It makes sense for them. If they put a backdoor in iPhone for US government, they are effectively thrown out of Chinese market. Interesting enough, what will Apple do if Chinese government demand they to decrypt/put backdoor in exchange of staying in the market?

I was about to mention the Chinese case, the Chinese government asking foreign companies to install means of control and access in their products.

Does that mean that apple will not provide such means or disable security for phones sold on the Chinese market? That would be surprising given the potential size of this market.

Re: A Message to Our Customers

#99

With the due legal process the police can search property, safety deposit boxes, bank accounts, vehicles, etc. etc. Why should a smartphone be any different just because Apple says it is ? As much as I value privacy I really don't agree with Apple's stance here - if due legal process has been followed, why shouldn't they be able to read the contents of an iPhone ? And yes I get that third party encryption can be used…

Why do you assume that a "due legal process" will be followed every time, in every country?

Or maybe you think it's OK to do it just this once?

Sort of the "just the tip" mentality here?

The problem is that once such a capability is added to the OS, there is no going back. And it can then be used with or without your wonderful US due legal process, potentially by criminals and definitely by governments in countries where human and civil rights are a joke.

Re: A Message to Our Customers

#100
post #28

What im reading is that apple can remote install an update that disable encryption. They dont want to do it. But that they have the capability is a bit scary.

Please read carefully. They don't have that capability. The FBI wants them to create it.

if they can create it, they have the capability.
Post reply on HN