Live data from Hacker News

A Message to Our Customers

apple.com

311–320 of 1001 posts

Re: A Message to Our Customers

#312

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

> Apple, if they chose to, can make a version of iOS that disables security features and encryption and load it onto existing phone even though the phone is locked and encrypted? As I understand it, the FBI wants Apple to create a version of iOS that would disable the current feature where the data is deleted after more than 10 failed passwords attempts. This would allow the FBI to brute force the password.

That doesn't explain how they would get the update on to a locked and encrypted device, even if it existed.

Re: A Message to Our Customers

#313
post #307

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

The point is there currently is no backdoor. FBI wants Apple to create (and sign) an OS update with a backdoor and install it onto the suspect's phone. Specifically the backdoor is to remove the rate limiting and 10 attempts limitation on trying the passcode. If you have a very strong passphrase (not a 6-digit code) then even that should be unbreakable even with brute force. Of course, most users have the 6 digit cod…

[deleted]

Re: A Message to Our Customers

#314
post #308

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

I don't understand your comment. The iPhone in question is protected with an unknown passcode. Auto erase is enabled, so brute-forcing the passcode will erase the data. However, a new OS version without auto erase and that accepts passcode input from USB would allow the FBI to try all combinations. How is Apple at fault because most any passcode scheme can be cracked via brute-forcing all comginations?

> However, a new OS version without auto erase and that accepts passcode input from USB would allow the FBI to try all combinations.

It shouldn't be possible to just add a new OS onto the phone without the restrictions in place, without knowing the passcode first.

Re: A Message to Our Customers

#315
Can someone explain this to me? The FBI requests a new version of iOS to be installed on a single phone that was involved in the attack. What, exactly, does this mean? If the phone is locked, how will they install new software on it without unlocking? People are suggesting an update to iOS that will get pushed-out to all users, but contain a backdoor that is specific to that one particular device -- but how will the new iOS version be installed without unlocking first?

Re: A Message to Our Customers

#316

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

I think the missing information here is how the phone is encrypted. If it's done with the 4-digit numeric PIN, then the software could be built; it would take 10000 tries, but at less than .1 seconds per try, it would be able to crack the code in about 15 minutes. The current iPhone has a protection for this; after some number of tries, it will lock you out for increasing time intervals.

This is the only way that their claims might possibly be valid.

And a reminder, then: change your iPhone's password to a more complex one. If apple doesn't make this fake OS, someone will.

Edit: to expand on this, Apple's PR goal was to take advantage of the NSA mass surveillance scare. On-device encryption is not very relevant to that. iCloud security is much more important, and they've been quietly granting data from it to the Feds. Including iPhone backups which contain most of the data they're looking for.

Re: A Message to Our Customers

#317
post #249

Earlier quoted context omitted.

It's kind of hard to social engineer dead people, though.

dead people were once alive. go through their pockets or their apartment.

You can go through each and every physical object I own or even was in contact with, but you won't find any of my passwords

Re: A Message to Our Customers

#318
post #289
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Does Apple do an amazing job protecting their users' privacy? Yes! But frankly in this case I find the FBI makes more sense than Apple. Apple says: All that information needs to be protected from hackers and criminals who want to access it, steal it, and use it without our knowledge or permission As I understand, Apple complains about the introduction of this new threat model: 1. criminal steals someone's iPhone, 2.…

I think the question is less about whether or not a "correct / valid use" of this new technology is acceptable. The problem is that it's impossible (once it exists) to guarantee it won't be used in malicious ways.

Re: A Message to Our Customers

#319

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

It's not possible now. The FBI is asking Apple to change iOS so it will be possible in the future.

Re: A Message to Our Customers

#320

Earlier quoted context omitted.

Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order

> Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order Exactly like Apple. Or do you think that the emails in iCloud are not given to the prosecutors?

Yes exactly like apple. To quote the link: "When the FBI has requested data that’s in our possession, we have provided it."

The point I was trying to make is that Google and Facebook have direct access to all the data of their customers, and already provide access to government agencies. Contrary to Apple they don't safely store some data of their costumers safely on the device, which this case is about.

Post reply on HN