Live data from Hacker News

A Message to Our Customers

apple.com

181–190 of 1001 posts

Re: A Message to Our Customers

#181
post #84

Earlier quoted context omitted.

There are basically two groups of large software companies around right now: those which make their business by collecting data, and those which make their business by licensing software[1]. The first group has an overwhelming incentive to not support privacy too strongly. The second group has an overwhelming incentive to not allow too much openness. Until a better business model (or zero-knowledge machine learning)…

I can't upvote enough that excellent summary of the situation of software companies. One way to solve that would be to have governments support and subsidies open source software development, but I don't see that happening in the next 5 years at the very least.

So, it is far from a simple problem. For common infrastructure, one can argue governments could fund open source in the same way they fund highways and bridges and physical fiber optic links. But I am not so sure that model would be the best to innovate in end user applications, and I say so as someone working on publicly funded research software.

There is something to be said about the market's ability to make decentralized decisions and focus on satisfying people wants[1], so a centralized software economy is also not a good solution. The problem with markets here is that strong privacy and open source are, for the most part, positive externalities. As a user, the benefit you get from having strong privacy yourself is not usually noticeably high, nor that of having access to the source, specially for a non-technical user, yet society arguably benefits from both. Usually the answer to a problem of unaccounted externalities is government regulation, but in this case, large-enough-to-matter governments have been unanimously on the side of less privacy, rather than more (as is the case of the original article).

[1] Ideally, software should be designed so that it preserves privacy as much as possible while achieving its function, and is open source, and it provides all the million features and reasons people use something like Facebook, Snapchat, Youtube, etc. Just having privacy preserving software written for and by technophiles is not and can never be a complete solution.

Re: A Message to Our Customers

#182
post #163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

It's not a backdoor to the phone only being unlocked by the passphrase, but a backdoor to the number of attempts limitation.

Re: A Message to Our Customers

#183
post #169

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

> Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate moving forward for all sorts of requests to add backdoors/decrease security. I read it differently. Apple is saying that if they make this particular backdoor, then this very backdoor can also be used in other scenarios, to crack other phon…

The Apple 5C is an older phone not even manufactured by Apple anymore, and, for the longest time, Apple had capabilities that allowed them to brute force iPhones under direction of a court order. Apple has some concern, clearly, about it's customer's security, but doesn't care as much about this particular iPhone Model's security, as it does about the general principle that, without explicit legislation such as [1]CALEA 47 USC 1001-1010), that technology companies such as Apple would then come under the whim and direction of all sorts of requests - there is no explicit restraint in the All Writs Act of 1789 - they can now be told by police agencies to do effectively anything necessary to the pursuit of an investigation - and you know, with 100% certainty, that once the "good cases" are used as an excuse for this, the crappy follow on scenarios will also be making use of the All Writs Act of 1789.

It's massive, massive overreach - and if Apple doesn't draw the line here, it will quickly spin out of control.

[1] https://en.wikipedia.org/wiki/Communications_Assistance_for_...

Re: A Message to Our Customers

#184
post #170
post #122

I wonder how much of that was personally written by Tim Cook, vs. various other people within Apple (I'm sure legal, PR, product, etc. all had input, but this feels like something he wrote himself.)

This is probably the reason why someone else wrote it. Because writing in "your voice" but without filling words is incredibly hard. But then, it's not the CEOs job to be a good writer.

It absolutely is the job of the CEO of the world's (second) most valuable company to be a good writer.

Re: A Message to Our Customers

#185

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

Their business model just happens to align well with what is best for their customers. It's interesting that it's almost an anomaly. The business models of Goole and Facebook in comparison does not really align with what is best for their customers.

Apple are a company so they'd be stupid to not take advantage of this and as a consumer I am happy that the premium I pay for Apple products is benefiting me.

Re: A Message to Our Customers

#186
post #163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

I agree. I was under the impression that Apple's security was such that even they didn't have the power to decrypt a device because the crypto made it impossible without the password/pin/key. I'm interested to understand the reasons that it was not done this way.

Re: A Message to Our Customers

#187
Question: is it possible to design a cryptographic system that, whenever it is accessed by a third party (government), this is made publically visible in a log? Can blockchain technology help here?

Re: A Message to Our Customers

#188

Earlier quoted context omitted.

Absolutely. I'm quite amazed they had the guts to go through with this and I applaud it. I will support them with my dollars as much as possible.

Talk is cheap and these internet posts - from Tim Cooke, you, and me - are just talk. The security of this nation depends on Apple (and Google et. seq.) supporting us with its dollars as much as possible. And I'm not optimistic that the stockholders care about anything more than doing the opposite.

Some people already complain that the iPhone is too expensive, especially compared to non-equal Android phones. Not enough people complain about any company not fighting for their user's security.

Talk is all we need so far. Publicly saying no to the FBI is a step rarely taken.

Re: A Message to Our Customers

#189
post #12

With the due legal process the police can search property, safety deposit boxes, bank accounts, vehicles, etc. etc. Why should a smartphone be any different just because Apple says it is ? As much as I value privacy I really don't agree with Apple's stance here - if due legal process has been followed, why shouldn't they be able to read the contents of an iPhone ? And yes I get that third party encryption can be used…

The major difference is that a warrant to access a safety deposit box allows the keys for that specific safety deposit box and no other. What the FBI is asking for is the equivalent of asking for a master key to all the safety deposit boxes to access just the one box. Given what was revealed in the summer of 2013 by Snowden, I think we'd all agree that the FBI and other state agencies (not just American agencies) wil…

Does Apple really have to create a "master" key though? Couldn't Apple write the backdoor that would only activates on the iPhone in question? Even if it was something as simple as "if (secure_id == terrorist_phone_id) [accept any pin]", it's not like the FBI could remove the condition without invalidating the signature. If they could, they wouldn't need Apple's help to begin with.

Re: A Message to Our Customers

#190

Earlier quoted context omitted.

Technically you're right, legally think of the huge precedent. FBI is using the San Bernardino case as a legal crowbar, and it's awful.

If they beat the order they could always do what GP said, crack the password, and hand in a decrypted copy of the device. Everyone goes home happy: no precedent set, FBI gets their data, going into the future as old iOS devices die Apple won't even be able to pull that stunt again if they want to.

But if they beat the order, and that they've made a big deal about going against the order, why would they go ahead and compromise the device's security? What would be the point? Just to tell the government, "Hey, don't worry about all that stuff we said, we didn't mean it?"

If they do it once, they'll do it again.

Post reply on HN