Earlier quoted context omitted.
Thanks. This explains it. I was just thinking about my old Thinkpad X41. That had TPM module and hardware encryption. There's nothing that IBM or the TPM manufacturer could've done to decrypt it (unless the TPM module already had backdoors, haha). Latest iPhones are basically the same?
I don't get it. How would they be load the backdoor is the phone is still locked?
A Message to Our Customers
281–290 of 1001 posts
Re: A Message to Our Customers
#282Earlier quoted context omitted.
Absolutely. I'm quite amazed they had the guts to go through with this and I applaud it. I will support them with my dollars as much as possible.
Talk is cheap and these internet posts - from Tim Cooke, you, and me - are just talk. The security of this nation depends on Apple (and Google et. seq.) supporting us with its dollars as much as possible. And I'm not optimistic that the stockholders care about anything more than doing the opposite.
I voted for, and to my surprise so did a majority of other stockholders, and that avenue of opportunities was removed.
Re: A Message to Our Customers
#283Will they, can they do anything about data in iCloud as well? While you can turn off iCloud I'd guess the majority of people are using it. Given you can access much of it at iCloud.com that would seem like whether or not you can unlock an iPhone most customers' data is available directly from Apple. Mail, notes, messages, photos, etc. No idea about other apps data that get backuped
Again I'm applauding Apple for standing up for encryption. If they could some how offer the same on iCloud I'd switch from Google (Google is not encrypted either. My point is I'd switch to a service that offers it)
Re: A Message to Our Customers
#284Re: A Message to Our Customers
#285Earlier quoted context omitted.
Not too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.
Or, said differently, Play Services are already a backdoor. They can (and do) install updates or other software pushed by server automatically, without you being able to do anything about it. And they have access to anything on the phone.
Re: A Message to Our Customers
#286Earlier quoted context omitted.
Not too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.
Or, said differently, Play Services are already a backdoor. They can (and do) install updates or other software pushed by server automatically, without you being able to do anything about it. And they have access to anything on the phone.
Re: A Message to Our Customers
#287I do believe there is no backdoor for when a city court requests it, but i don't really believe that the FBI or CIA doesn't have access to it.
Considering that iPhone already exists a long time, they must have some means to backdoor the "iCloud"...
Re: A Message to Our Customers
#288Earlier quoted context omitted.
If in pursuit of an active investigation (i.e. the devices are still in active use), a police agency could invoke the All Writs act of 1789, and have Apple be instructed to introduce security vulnerabilities, with the next regular upgrade of iOS, such that after the phone is upgraded, it can be captured by the FBI, or whatever police force is involved, and the data recovered. A large percentage (and presumably the th…
But this request was made specifically for the phone in the San Bernardino case. In which the owner is dead and the phone is locked. This implies it is possible for Apple themselves to apply an iOS update to a locked phone in order to disable the erase-on-repeated-failure feature.
Tim Cook doesn't offer an opinion about how possible that might be. As a matter of principle, he doesn't believe that Apple should be forced to make the attempt.
That doesn't stop anyone else from doing so, however. And I suppose that the FBI could seek discovery on all requisite information, take depositions, etc, etc. However, I vaguely recall that discovery can't compel production of new work product. But maybe that's just a limitation in civil litigation.
Re: A Message to Our Customers
#289Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…
Apple says:
All that information needs to be protected from hackers and criminals who want to access it, steal it, and use it without our knowledge or permission
As I understand, Apple complains about the introduction of this new threat model:
1. criminal steals someone's iPhone,
2. gets hold of a special iOS version that Apple keeps internally to assist the government,
3. pushes the OS update to the iPhone by themselves,
4. uses some tool to automate brute-forcing the user passcode
At least that's what I get from these excerpts:Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation.
The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer.
Now how serious is this threat? And how useful is it to have the FBI be able to look into a phone when they have a warrant? Does the balance between the right to privacy and the need to assist criminal investigation really tilt towards privacy in this specific case?
Meanwhile there are serious threats that do affect a lot of users in practice, where Apple does a good job but could do better still such as:
- Remote code execution on iOS (6 vulnerabilities in 2016 so far[1])
- Phishing, brute force and social engineering attacks (the improved two-factor authentication is not yet available to everyone[2])
Am I wrong in thinking that users are way more likely to be affected by these threats except when the government has a warrant?
If Apple is actually worried about the FBI getting access to the modified iOS version, they should focus their complaint on that and propose to do the whole data extraction in-house.
[1] http://www.cvedetails.com/vulnerability-list/vendor_id-49/pr...
Re: A Message to Our Customers
#290Earlier quoted context omitted.
I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…
In the world of cryptography, it is always possible, because you can always be lucky and guess the right "unlock" code. In fact, social engineering is normally used to find the right "unlock" code[0]. The FBI can also unsolder the components in the phone, make a full image of the content, find the encrypted section and then brute-force. This is what is done for SSD. They do not power up the drive, unsolder, put the m…