Live data from Hacker News

A Message to Our Customers

apple.com

241–250 of 1001 posts

Re: A Message to Our Customers

#241
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

>The fact that they can push weak OS updates to a locked phone is the backdoor.

This times nine hundred and eleven thousand.

Re: A Message to Our Customers

#242

Question: is it possible to design a cryptographic system that, whenever it is accessed by a third party (government), this is made publically visible in a log? Can blockchain technology help here?

No, because I put the device in a faraday cage, with whatever proxies I need, crack it, then put it in a woodchipper. No one ever finds out.

But what if you need the blockchain to crack it?

Re: A Message to Our Customers

#243
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…

> sets a horrible precedent

That's a large part of the fuss!

Re: A Message to Our Customers

#244
If the UK record on anti-terror scope creep is anything to go by, not creating this backdoor is a very good idea.

In the UK, laws originally intended for surveilling terrorists were/are routinely used by local councils (similar to districts I think) to monitor whether citizens are putting the correct rubbish/recycling into the correct bin. [1]

This is a pandora's box, and the correct answer is not to debate whether we should open it just this once, it's to encase it in lead and throw it into the nearest volcano. Good on Apple for "wasting" shareholders money and standing up for this.

[1] http://www.telegraph.co.uk/news/uknews/3333366/Half-of-counc... - and lest the source be questioned, this is one of the more reactionary newspapers in the UK.

Re: A Message to Our Customers

#245
"In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession."

Someone who believes in conspiracy theories would make a statement that "now it is official" :)

Re: A Message to Our Customers

#246
post #84

Earlier quoted context omitted.

There are basically two groups of large software companies around right now: those which make their business by collecting data, and those which make their business by licensing software[1]. The first group has an overwhelming incentive to not support privacy too strongly. The second group has an overwhelming incentive to not allow too much openness. Until a better business model (or zero-knowledge machine learning)…

I can't upvote enough that excellent summary of the situation of software companies. One way to solve that would be to have governments support and subsidies open source software development, but I don't see that happening in the next 5 years at the very least.

Not quite the same, I can appreciate, but inroads are being made with the UK Digital efforts being mostly open source.

http://blog.quickpeople.co.uk/2013/05/17/the-uk-government-p...

Re: A Message to Our Customers

#247

Earlier quoted context omitted.

It's not a backdoor to the phone only being unlocked by the passphrase, but a backdoor to the number of attempts limitation.

This limitation must be built into security hardware used by iPhone so software couldn't do anything about it. I was under impression that it's how iOS security model works. If it's not and in fact this check implemented in iOS itself, it's much weaker protection and it's really looks like an intended backdoor from Apple.

It sounds like it is built into hardware with newer iPhones containing the secure enclave, but not for an older phone like the iPhone 5C.

Re: A Message to Our Customers

#249
post #201
post #163

Earlier quoted context omitted.

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

In the world of cryptography, it is always possible, because you can always be lucky and guess the right "unlock" code. In fact, social engineering is normally used to find the right "unlock" code[0]. The FBI can also unsolder the components in the phone, make a full image of the content, find the encrypted section and then brute-force. This is what is done for SSD. They do not power up the drive, unsolder, put the m…

It's kind of hard to social engineer dead people, though.
Post reply on HN