Live data from Hacker News

A Message to Our Customers

apple.com

191–200 of 1001 posts

Re: A Message to Our Customers

#191

Earlier quoted context omitted.

You are right. What you say about Facebook is true, but Google's Android is open source, so there is no way they can plant a privacy-invading code and get away with that.

There are parts of Android phones that are closed and proprietary now. Even CyanogenMod.

None that are necessary to run it, still (not including drivers, but that's hardware dependent)

Re: A Message to Our Customers

#192
post #70

Earlier quoted context omitted.

Ok, so: "The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID is not related to any other identifier on the device." The secure enclave must still give it's UID under some circumstances? This still does not appear to…

Unless there is a bug in their hardware implementation of AES-CCM or ( shudder ) some sort of crazy disclosure vulnerability in the APIs they provide, there is (presumably) no way to get at the UID. Even if you were to decap the chip and get at the UID physically, you still aren't any better off as it derives the actual encryption key on boot from the UID. The Secure Enclave is essentially a hardware security module,…

on page 11 of the security white paper, there is a diagram illustrating the key hierarchy.

i believe that 'Hardware Key' refers to the UID. if this is the case, then learning the UID + user passcode gives you the root keys, from which you can decrypt the remaining key hierarchy until you reach the decrypted files.

Re: A Message to Our Customers

#193

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

Why wouldn't they believe in protecting their customers privacy? In Apple's case there is no conflict of interest to make you doubt that statement. If it came from Google or Facebook I would be more skeptical.

Re: A Message to Our Customers

#194

Since Apple is part of PRISM[0], the FBI can just ask the NSA. [0] https://en.wikipedia.org/wiki/File:PRISM_Collection_Details....

No: data held on Apple servers (iCloud) can be provided with a warrant, but this is about data held on an iPhone but not saved to Apple servers. As a result, neither Apple nor the NSA can immediately provide it, and some means of hacking the iPhone is needed.

Re: A Message to Our Customers

#195

Question: is it possible to design a cryptographic system that, whenever it is accessed by a third party (government), this is made publically visible in a log? Can blockchain technology help here?

No, because I put the device in a faraday cage, with whatever proxies I need, crack it, then put it in a woodchipper. No one ever finds out.

Re: A Message to Our Customers

#196
post #163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

I think they're being asked for a few things—private keys and the ability to automate and not limit passcode entry attempts.

Re: A Message to Our Customers

#197

While basically being on Apple's side here, as I understand it, jailbroken devices are unofficial builds of iOS that have some security features removed (e.g. limits on which apps can be installed). Is it not possible for law enforcement to get what they want from that, if all they want is a custom build of iOS that can be hacked around? And why is it even possible for that to work if the data is supposed to be kept…

I think jailbreaking requires you to erase the phone first.

Re: A Message to Our Customers

#198
post #100

Earlier quoted context omitted.

Please read carefully. They don't have that capability. The FBI wants them to create it.

if they can create it, they have the capability.

They never say they can create it. They say the FBI wants them to create it, which may or may not be possible and is not addressed in this letter.

Re: A Message to Our Customers

#199
Apple does deserve the respect their getting for standing up to the government about this. They're absolutely right that this is an attempt to fatally undermine security for a whole host of devices, and sets a disturbing precedent.

What do find interesting, is that Apple isn't the first manufacturer that the government as ordered to crack a device. An "unnamed smartphone manufacturer" was ordered to crack the lock screen on October 31, 2014.[1] No one made a fuss then, so someone caved.

[1] https://en.wikipedia.org/wiki/All_Writs_Act

Re: A Message to Our Customers

#200
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

This is not apparent from the article. Where could I find out about this ability?
Post reply on HN