Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

241–250 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#241

Earlier quoted context omitted.

In response to your (first?) edit: > The woman in the couple declared it right before the shooting[0]. I'm not questioning that she declared allegiance. I'm asking if she was in private contact with anyone. If you were responding to that, can you show me where that is in the NYT article you linked? I don't see it. > Do you want a notarized letter from the deceased? Let's try to keep this civil, please. > Do you reall…

You keep switching between legal and normative requirements. We disagree on the 4th amendment in the same way that scientists and climate change deniers disagree about global warming. You have a fringe understanding of it with no support from the relevant literature and your arguments about it are poorly structured, deny evidence, and rely on intentionally misunderstanding context and terms of art. The legality of se…

The point of a search is to gather evidence, requiring the evidence that would be the result of a search is obviously a non-starter as a system.

That kind of reasoning allows wholesale collection of communications data by the NSA and other agencies. Since that practice has been widely criticized, there must be something missing from your argument.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#242
post #35

Earlier quoted context omitted.

> There is an authentic need to get at the data on that phone What is the authentic need? The shooters are dead. Do we have reason to believe that there is evidence of any pending crimes or any old unsolved crimes on the phone?

>evidence 14 dead people and a stack of unused guns and bombs.

two dead attackers, stack confiscated. case closed.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#243
post #13

Earlier quoted context omitted.

Even if touch id, it would be of no use. TouchID requires a password after 48 hours. or after the device resets. Which is interesting. If you happen to use TouchID, is your best bet to hope a court will not be able to compel you to unlock it within 48 hours of arrest? That sounds very probable.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

having made the request for both an erase password as well as an erase finger print I would not mind going one further, a setting which wipes the phone if neither are entered in a set amount of time. The would protect you when the phone is stolen or confiscated.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#244
post #228

Earlier quoted context omitted.

Brute forcing a password could take more time, with today's technology, than we have left on Earth depending on complexity and if there are known vulnerabilities. I'm not sure I would effectively consider this order an order to "unencrypt".

Passcodes are only 4 or 6 digits.

The encryption key is calculated from your passcode + the AES key etched into the chip inside the phone. There's no way to read that key directly, unless you do some crazy chip imaging where you read the actual electron state of the memory - could be done, but the chance of corrupting that memory is very high, and if they read even one bit wrong then the entire key is useless.

So there are two ways to go about this - they can either brute force AES, which, quite simply, can't be done(and I don't mean can't be done with current computers, the number of possible combinations is larger than the atoms in the universe or something stupid like that), unless NSA has a way to crack AES faster(but if they do, they won't make that knowledge public). Or try every passcode combination going through the Apple's full algorithm, which takes about ~5 seconds to generate a key. So it's doable, but it would take some time.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#245
post #155
post #145

It's at times like these they're surely knocking on the door of every company whose R&D in quantum computing, information theory and algorithms they've been funding for at least the past 2 or so odd decades. "So, is it ready yet?"

I'm assuming you are referring to quantum computing for it's speed computations? That wouldn't make a different here. They have only X amount of tries before the phone locks them out. It is the number of tries that is the issue here.

No, what I am assuming is the company will be compelled to provide the data on the phone without the potential for lock=out or erasure during brute-force. Then, in all likelihood state-of-the-art methods in brute-forcing AES (with the best theoretical speed-up up to and including quadratic due to Grover's algorithm on a quantum computer, or some unknown state-of-the-art slower than that on a classical computer) will be employed until the data is ultimately decrypted.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#246

Why no one is attacking on hardware level? Cut the processor to get the GID and UID, dump the flash, pregenerate rainbow tables with pin, power flash chip externally and give the codes ... Yeah it is expensive, but I would not be surprised if there aren't such labs that could provide such service. Why does FBI goes trough such pains?

As I've understood from other posts in the thread, you can't reproduce the hardware security module on the chip. It has a unique per-device key that cannot be read out (except perhaps with an electron microscope).

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#247
post #157

A thought experiment: Let's say the government makes hardware encryption standards in the style of FedRAMP that sets standards for preventing tampering by foreign governments. Then, imagine that a consumer electronics company voluntarily makes all devices comply with this standard. Could a court attempt to compel the company to defeat the standards which the government set as tamper-proof against governments? A secon…

1: Yes. 2: Yes. 3: No, but they will probably be the ones asked anyway, and then yes, they would be legally required. 4: Apple. 5: What's the question? Is the question will they be compensated? Then yes. 6: They can't. They don't own their stock. Bad PR is not a good enough reason. You are treating the court like a mathematical proof and finding edge cases. I used to as well. But courts don't work that way at all - t…

Thanks for answering. And original question was great too. Are you a lawyer, not trying to dismiss your answer because it seems logical, but asking so that I can ask something else

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#248

For me, the most interesting question I would have is absent from the article. The court is basically ordering Apple to produce new firmware that doesn't block brute forcing. If Apple were to comply, who keeps this firmware after the fact? There's no mention of this at all, but if the firmware image stays with the FBI then the implications are much more profound with regard to privacy.

Exactly this! Once it's in existence somewhere it's immediately part of the NSA/CIA/FBI basic iPhone toolkit.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#249

For me, the most interesting question I would have is absent from the article. The court is basically ordering Apple to produce new firmware that doesn't block brute forcing. If Apple were to comply, who keeps this firmware after the fact? There's no mention of this at all, but if the firmware image stays with the FBI then the implications are much more profound with regard to privacy.

>The SIF will be coded by Apple with a unique identifier of the phone so that the SIF would only load and execute on the SUBJECT DEVICE.

If I understand the cited order correctly the firmware is ordered to be constructed in a way that it runs only on the target phone.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#250
post #13

Earlier quoted context omitted.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

The countermeasure is for the authorities to push your finger of their choice by force. Thumb and index finger should cover 98% of people.

What if I bite the skin off my fingers? God this conversation is turning into an horror movie.
Post reply on HN