Live data from Hacker News

A Message to Our Customers

apple.com

121–130 of 1001 posts

Re: A Message to Our Customers

#121

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

> They are just exploiting that competitive advantage.

... and that's what I paid them for, thanks for not taking money both from me and from FBI :)

Re: A Message to Our Customers

#122
I wonder how much of that was personally written by Tim Cook, vs. various other people within Apple (I'm sure legal, PR, product, etc. all had input, but this feels like something he wrote himself.)

Re: A Message to Our Customers

#123
post #41
post #17

Earlier quoted context omitted.

[deleted]

I don't have an iPhone so correct me if I'm remembering correctly but aren't they by default protected by a 4 digit numeric pin? A 4 digit numeric pin that a brute force attack can be used on is effectively no security/a backdoor imo.

There are escalating time limits on incorrect PIN attempts, which is also enforced in hardware by the Secure Enclave in A7 chips and above. This would mean even breaking a 4-digit pin code without that delay being removed would take a long time. Additionally the device may be set to wipe after 10 incorrect attempts.

Attempts | Delay

1-4: none

5: 1 minute

6: 5 minutes

7-8: 15 minutes

9: 1 hour

Source: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Re: A Message to Our Customers

#124
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…

> with the exception that providing an easy means to brute force a phone to the authorities sets a horrible precedent

This is the entire concern (in my opinion and in my reading of Tim Cook's opinion). If the government can force Apple to backdoor this one iPhone (because terrorist), then they can force Apple to backdoor any iPhone for any person given a valid warrant, subpoena or otherwise granted power. Once the flood gates open...

Re: A Message to Our Customers

#125
post #17

The fact that they can create this backdoor, doesn't that mean it already exists? What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.

[deleted]

Nope. Once this option will be there, a single-button iPhone cracker box with lighting connector will be available on aliexpress in cca 3 weeks.

Re: A Message to Our Customers

#126
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…

> they may be kicking up a whole lot of fuss over a relatively minor issue

I strongly disagree. They are taking a stance in the debate about government mandated backdoors in software.

Re: A Message to Our Customers

#127

The fact that they can create this backdoor, doesn't that mean it already exists? What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.

This. Is Cook's letter an apology for what they already had to do (but could tell no one about)?

Re: A Message to Our Customers

#128
post #70

Earlier quoted context omitted.

read section 'Hardware Security Features' here: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Ok, so: "The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID is not related to any other identifier on the device." The secure enclave must still give it's UID under some circumstances? This still does not appear to…

Unless there is a bug in their hardware implementation of AES-CCM or (shudder) some sort of crazy disclosure vulnerability in the APIs they provide, there is (presumably) no way to get at the UID. Even if you were to decap the chip and get at the UID physically, you still aren't any better off as it derives the actual encryption key on boot from the UID.

The Secure Enclave is essentially a hardware security module, in more general terms. The only thing that leaves its boundaries are the results of crypto operations, not the parameters that went into calculating them.

Re: A Message to Our Customers

#130
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…

The problem is with the legal prescident this would provide. Although right now it's just limited to once specific use case, this ruling could and would be used in the future to require Apple (and other tech companies) to compromise security in ever increasing scope.
Post reply on HN