Live data from Hacker News

A Message to Our Customers

apple.com

161–170 of 1001 posts

Re: A Message to Our Customers

#161
post #70

Earlier quoted context omitted.

Ok, so: "The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID is not related to any other identifier on the device." The secure enclave must still give it's UID under some circumstances? This still does not appear to…

Unless there is a bug in their hardware implementation of AES-CCM or ( shudder ) some sort of crazy disclosure vulnerability in the APIs they provide, there is (presumably) no way to get at the UID. Even if you were to decap the chip and get at the UID physically, you still aren't any better off as it derives the actual encryption key on boot from the UID. The Secure Enclave is essentially a hardware security module,…

Thank you. So you mean to say that making an electron micrograph of this chip will not even reveal it's secrets? If the data persists after removal of power, some physical structure contains the data. Somewhere a hash of the fingerprint/password needs to be stored, then somewhere the function to compute that into an AES cipher needs to be stored.

I'm going on and on about this because I see no way in which this problem is not down-boil-able to brute-forcing the password the user puts in.

Actually Apple admits this much! They can build a work around! What stops the three-letter-agency from building it?

There must at some point be a complex user entered passphrase if you want to be safe. This can be a fingerprint of course but there is always the 4 letter password/passphrase that is the weak point.

I could be completely wrong, so far I'm not convinced I am.

Re: A Message to Our Customers

#162
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Absolutely. I'm quite amazed they had the guts to go through with this and I applaud it. I will support them with my dollars as much as possible.

Talk is cheap and these internet posts - from Tim Cooke, you, and me - are just talk. The security of this nation depends on Apple (and Google et. seq.) supporting us with its dollars as much as possible.

And I'm not optimistic that the stockholders care about anything more than doing the opposite.

Re: A Message to Our Customers

#163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments).

If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially?

And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to build it?

"Impossible" should mean "impossible", not "not yet done, but possible".

Re: A Message to Our Customers

#164
post #116

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

What I don't understand is why Apple could create such software but a hacker could not exploit it. I feel like that mean that there is already a backdoor.

Because you can only deploy it, when you have Apple's private key.

Re: A Message to Our Customers

#167

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

But how do you get the firmware updated on a locked phone? My understanding is all updates (historically) have required the phone to be unlocked and connected to the internet?

Re: A Message to Our Customers

#168

Earlier quoted context omitted.

If there's one thing that we have learned over the last few years from Snowden et al, we have learned that it is safe to assume that these state actors will be trying all the avenues that you or I can think of, and spend years discovering new ones that we have not thought of.

I have trouble understanding your point. What's the alternative to trying to minimize the probability of crypto system compromises?

That is worth doing; but I still find it quite likely that such a backdoor is existent or doable.

Re: A Message to Our Customers

#169

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

> Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate moving forward for all sorts of requests to add backdoors/decrease security.

I read it differently. Apple is saying that if they make this particular backdoor, then this very backdoor can also be used in other scenarios, to crack other phones (i.e. the backdoor would apply to all iPhones C, not just to this one).

Re: A Message to Our Customers

#170
post #122

I wonder how much of that was personally written by Tim Cook, vs. various other people within Apple (I'm sure legal, PR, product, etc. all had input, but this feels like something he wrote himself.)

This is probably the reason why someone else wrote it. Because writing in "your voice" but without filling words is incredibly hard. But then, it's not the CEOs job to be a good writer.
Post reply on HN