Live data from Hacker News

A Message to Our Customers

apple.com

321–330 of 1001 posts

Re: A Message to Our Customers

#321
post #169

Earlier quoted context omitted.

> Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate moving forward for all sorts of requests to add backdoors/decrease security. I read it differently. Apple is saying that if they make this particular backdoor, then this very backdoor can also be used in other scenarios, to crack other phon…

I interpret as the OP does. The court document asks Apple to lock the particular image to a particular serial number, so if all goes according to plan, the same image could not unlock other iPhones. Obviously, writing security code on a short deadline does not make for the best security, so that's one worry. But Apple's letter uses the expression "technique", which I think means they're worried the government will ge…

You and OP are both wrong:

"Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession."

Apple's argument isn't about a deluge of one-off court orders creating a slippery slope to reducing security. Apple is claiming that complying with just this one request would make Apple's other iPhone users significantly less secure. There would be a piece of software, signed by Apple, that could potentially be used to unlock any iPhone you have in your physical possession.

Re: A Message to Our Customers

#322

Earlier quoted context omitted.

It implies that the FBI wants Apple to do that. Tim Cook doesn't offer an opinion about how possible that might be. As a matter of principle, he doesn't believe that Apple should be forced to make the attempt. That doesn't stop anyone else from doing so, however. And I suppose that the FBI could seek discovery on all requisite information, take depositions, etc, etc. However, I vaguely recall that discovery can't com…

That's a good point. I guess I figured if they simply can't do it why not say "it's impossible by design," rather than argue the principle? It seems like their stand would be better saved for when a compromise is requested that is actually possible for them implement.

Maybe it's impossible by design in current iPhones. But this is an older one, not so secure.

As Tim Cook says, it would be a bad precedent. And obviously bad PR for Apple to admit vulnerability.

Re: A Message to Our Customers

#323

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

I think the missing information here is how the phone is encrypted. If it's done with the 4-digit numeric PIN, then the software could be built; it would take 10000 tries, but at less than .1 seconds per try, it would be able to crack the code in about 15 minutes. The current iPhone has a protection for this; after some number of tries, it will lock you out for increasing time intervals. This is the only way that the…

Check out this comment where Adam Stew explains how the phones are secured: http://slashdot.org/comments.pl?sid=8756397&cid=51524693

Re: A Message to Our Customers

#324

Publicizing the case themselves in a very good move. However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode). The amo…

You can still enable full disk wipe after 10 failed password attempts[1]. That was available in iOS 7 I believe (but someone on here will correct me if I'm wrong). [1] - http://i2.wp.com/ioshacker.com/wp-content/uploads/2014/09/Pa...

The FBI's point is that Apple can update the software on the device to not honor that setting, which means it is not effective against a government attacker.

Re: A Message to Our Customers

#325
post #314
post #308

Earlier quoted context omitted.

I don't understand your comment. The iPhone in question is protected with an unknown passcode. Auto erase is enabled, so brute-forcing the passcode will erase the data. However, a new OS version without auto erase and that accepts passcode input from USB would allow the FBI to try all combinations. How is Apple at fault because most any passcode scheme can be cracked via brute-forcing all comginations?

> However, a new OS version without auto erase and that accepts passcode input from USB would allow the FBI to try all combinations. It shouldn't be possible to just add a new OS onto the phone without the restrictions in place, without knowing the passcode first.

I see what you're saying but this has never been done before. BIOS passwords could be bypassed by draining the battery. Encryption is practically the only way to protect your data, because the storage can be taken out of the phone and hooked up to something else if need be.

Making a new OS is just the easiest way for Apple to do this; there are other ways.

Re: A Message to Our Customers

#326

Earlier quoted context omitted.

dead people were once alive. go through their pockets or their apartment.

You can go through each and every physical object I own or even was in contact with, but you won't find any of my passwords

What happens to all your stuff when you die?

Re: A Message to Our Customers

#327
post #289

Earlier quoted context omitted.

Does Apple do an amazing job protecting their users' privacy? Yes! But frankly in this case I find the FBI makes more sense than Apple. Apple says: All that information needs to be protected from hackers and criminals who want to access it, steal it, and use it without our knowledge or permission As I understand, Apple complains about the introduction of this new threat model: 1. criminal steals someone's iPhone, 2.…

I think the question is less about whether or not a "correct / valid use" of this new technology is acceptable. The problem is that it's impossible (once it exists) to guarantee it won't be used in malicious ways.

Right, but isn't "impossible" too high a bar? Or is the ability to comply with a warrant worth nothing?

It's not like iOS is impossible to hack now and it would be terrible that it becomes possible. There are other aspects of the system that allow malicious exploits more easily than this theoretical threat. So it doesn't make sense to preserve at all costs (e.g. making warrants unenforceable) an "impossibilty" that never was.

Re: A Message to Our Customers

#328
It bothers me that Tim Cook lied: he stated in his open letter that if they provided the modified OS it could be used on other phones, but the court order specifically says Apple should make the software only work on the specific phone in question.

Re: A Message to Our Customers

#329
post #326

Earlier quoted context omitted.

You can go through each and every physical object I own or even was in contact with, but you won't find any of my passwords

What happens to all your stuff when you die?

Well your opinion is kind of moot at that point.

Re: A Message to Our Customers

#330
post #321

Earlier quoted context omitted.

I interpret as the OP does. The court document asks Apple to lock the particular image to a particular serial number, so if all goes according to plan, the same image could not unlock other iPhones. Obviously, writing security code on a short deadline does not make for the best security, so that's one worry. But Apple's letter uses the expression "technique", which I think means they're worried the government will ge…

You and OP are both wrong: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Apple's argument isn't about a deluge of one-o…

Here's the exact text of the court order:

"Apple's reasonable technical assistance may include, but is not limited to: providing the FBI with a signed iPhone Software file, recovery bundle, or other Software Image File ("SIF") that can be loaded onto the SUBJECT DEVICE. The SIF will load and run from Random Access Memory and will not modify the iOS on the actual phone, the user data partition or system partition on the device's flash memory. The SIF will be coded by Apple with a unique identifier of the phone so that the SIF would only load and execute on the SUBJECT DEVICE."

How am I wrong?

Post reply on HN