Live data from Hacker News

A Message to Our Customers

apple.com

211–220 of 1001 posts

Re: A Message to Our Customers

#211

Question: is it possible to design a cryptographic system that, whenever it is accessed by a third party (government), this is made publically visible in a log? Can blockchain technology help here?

No, because I put the device in a faraday cage, with whatever proxies I need, crack it, then put it in a woodchipper. No one ever finds out.

Existence of such system wouldn't make much difference, because no authority would wan't to use it to access the data. They would claim that the target's inability to detect a wire is crucial to the ongoing investigation.

Re: A Message to Our Customers

#212
I don't see how this message is reassuring. Are they expecting the customers to just take their word? Without Apple showing the world, every bit of software that they run on their phones, these statements are at best, meant to mislead the users that Apple is doing something on the user's behalf.

Re: A Message to Our Customers

#215
post #159

Earlier quoted context omitted.

Once they build that in for one device then they have opened pandora's box. Then it becomes a precedent in the courts that Apple has this ability so they will issue court orders to make them comply for every single case where a phone is encrypted.

One way around that is for Apple to make it extremely costly for courts to issue many of such orders, because after all Apple are free to charge whatever they like for doing this service.

Only a reasonable amount though. They could charge $100k or even $1m the first time, but they'd have a hard time justifying similar fees if only an if condition needs to be changed. Worse, they would lose the moral high ground if they even tried it. They'd go from being a good corporation standing up for the Constitutional rights of its users to a scumbag organisation trying to bleed taxpayer money for helping criminal investigations.

Re: A Message to Our Customers

#216
post #169

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

> Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate moving forward for all sorts of requests to add backdoors/decrease security. I read it differently. Apple is saying that if they make this particular backdoor, then this very backdoor can also be used in other scenarios, to crack other phon…

I interpret as the OP does. The court document asks Apple to lock the particular image to a particular serial number, so if all goes according to plan, the same image could not unlock other iPhones. Obviously, writing security code on a short deadline does not make for the best security, so that's one worry.

But Apple's letter uses the expression "technique", which I think means they're worried the government will get another court to make them change the serial number and sign a new image "next time". Before you know it, Apple will have to have an entire department to make these one-off images. Someone will say, "you know, you could save yourself a lot of time if you just made it work on any phone." Then that image will be leaked, and their security guarantees will be dead. (One might also worry about the DRM implications.)

Re: A Message to Our Customers

#217

Earlier quoted context omitted.

It doesn't say anything about remote install - in fact it says "physical possession" several times.

Come on. It can be iOS update that waits until you enter the code or use touchID - and then sends the keys or decrypted data somewhere.

It could be, but why would the FBI want that?

Re: A Message to Our Customers

#218
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

I'd also like to point out that Apple has a record of not practicing cautiously to security exposure, like _the inclusion of CNNIC root certificate despite the public exposure of security breach_.

http://apple.slashdot.org/story/15/04/09/1531237/apple-leave...

Re: A Message to Our Customers

#219
post #163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

It sounds like it'd be trivial to nop out the timer on repeated passcode attempts. Which makes sense... Leaving any short passcode trivially crackable.

Re: A Message to Our Customers

#220
post #163
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

[deleted]
Post reply on HN