Live data from Hacker News

A Message to Our Customers

apple.com

201–210 of 1001 posts

Re: A Message to Our Customers

#201
post #163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

In the world of cryptography, it is always possible, because you can always be lucky and guess the right "unlock" code. In fact, social engineering is normally used to find the right "unlock" code[0].

The FBI can also unsolder the components in the phone, make a full image of the content, find the encrypted section and then brute-force. This is what is done for SSD. They do not power up the drive, unsolder, put the memory modules in a special reader and copy the data before the controller of the SSD automatically wipe out data because of automatic optimization after a delete/trim.

[0]: https://xkcd.com/538/

Re: A Message to Our Customers

#202

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

But how do you get the firmware updated on a locked phone? My understanding is all updates (historically) have required the phone to be unlocked and connected to the internet?

If in pursuit of an active investigation (i.e. the devices are still in active use), a police agency could invoke the All Writs act of 1789, and have Apple be instructed to introduce security vulnerabilities, with the next regular upgrade of iOS, such that after the phone is upgraded, it can be captured by the FBI, or whatever police force is involved, and the data recovered.

A large percentage (and presumably the the target in question) will willingly (at least today) upgrade their iOS to whatever Apple pushes out - we don't (for the most part) even question whether the purpose of that security patch is to reduce security.

The only thing that secures an iPhone is the iOS following the rules of security such as the security enclave - it can just as easily (in a new release of iOS) be instructed to ignore it.

What Apple/Tim Cook are doing here, is standing up for the importance of not being required to hodge-podge be at the whims and mercies of police agencies that demand they do whatever is required of it.

Re: A Message to Our Customers

#203
post #116

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

What I don't understand is why Apple could create such software but a hacker could not exploit it. I feel like that mean that there is already a backdoor.

As you say, 'Apple could create'. It doesn't exist, what could the hacker even target?

Re: A Message to Our Customers

#204

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

Looking at the wording, seems to suggest they never state whether or not it is possible. It says "the FBI wants us to make", not what we can or cannot make. "Potential" doesn't mean certainty.

Re: A Message to Our Customers

#205
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

Freedom from forced update is one of Stallman's motivations for free software.

Just one terrorist attack + PR letter to customer + forced update away from loosing encryption on your phone.

Re: A Message to Our Customers

#206
post #163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

They didn't make any mention of how feasible it would be, just that they wouldn't even try because it would threaten the security of their users.

Re: A Message to Our Customers

#207
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

This isn't the case with the newer devices though, where the delays and key destruction are enforced in hardware, and tampering would destroy the key.

Re: A Message to Our Customers

#208
post #26

Earlier quoted context omitted.

You're talking nonsense. Protecting users' privacy and keeping source code closed aren't mutually exclusive.

Yeah. Loving your spouse and hiding things from them are also not mutually exclusive. Yet, you hardly find people that do both. Not to mention, this situation would never have arisen if iphone were open-sourced, since all activity would have been monitored by the community.

You have way too much faith into the the idea, that open source projects are free of backdoors / exploits and that the community can prevent creation of those. Aside from that, there is currently no platform, where 100% code is open source.

Re: A Message to Our Customers

#209

Earlier quoted context omitted.

Just because it's open source doesn't mean it's safe. You have no control of what happens to that code before it gets installed on a phone. Samsung, whomever can and do modify the code -- those modifications aren't generally open source. Ruby on Rails is open source but that doesn't mean that all applications on rails are open source.

> Samsung, whomever can and do modify the code -- those modifications aren't generally open source. That will certainly change quite soon. In the earlier days, FOSS was not a concept that masses were aware of, but now is different. There is increasing competition in the smart-phone world and if one of the other manufacturers (say ASUS) makes their Android modifications open-source, they will see a drastic increase in…

>if one of the other manufacturers (say ASUS) makes their Android modifications open-source, they will see a drastic increase in Sales

Can you expand on this? I don't think enough people care about source access. RMS's exact hardware choices don't go on to sell millions.

edit: I didn't see your username before now.

Re: A Message to Our Customers

#210
post #159

Earlier quoted context omitted.

Once they build that in for one device then they have opened pandora's box. Then it becomes a precedent in the courts that Apple has this ability so they will issue court orders to make them comply for every single case where a phone is encrypted.

One way around that is for Apple to make it extremely costly for courts to issue many of such orders, because after all Apple are free to charge whatever they like for doing this service.

They could charge a million for this one time, but after that it's just the edit of that if statement. It's not justified to charge a million each time.
Post reply on HN