Live data from Hacker News

A Message to Our Customers

apple.com

351–360 of 1001 posts

Re: A Message to Our Customers

#351
post #331

Earlier quoted context omitted.

It's not possible now. The FBI is asking Apple to change iOS so it will be possible in the future.

The FBI is asking that it be built now and then loaded onto the already recovered phone. > Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation.

Why the downvote? That is what I said. I merely used a slew of different words.

> The FBI is asking that it be built now

Because it's not possible _now_.

> and then loaded onto the already recovered phone.

Thus it becoming possible after they have built the new version of iOS, and since they cannot go back in time and build it, it would indeed be _in_the_future_ that it became available, if Apple complied, that is.

Re: A Message to Our Customers

#352
post #326

Earlier quoted context omitted.

You can go through each and every physical object I own or even was in contact with, but you won't find any of my passwords

What happens to all your stuff when you die?

Why care about "stuff" once you are dead?

Re: A Message to Our Customers

#353
post #163

Earlier quoted context omitted.

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

It's not a backdoor, it's a frontdoor. In cryptography, there's no way to make repeated attempts more computationally expensive. The lockout just an extra feature Apple put on, that Apple could easily remove. If we're going to have 4- and 6- digit PINs, there is no way to stop a dedicated attacker frome brute-forcing it. None.

"there's no way to make repeated attempts more computationally expensive"

That's not true actually. For example, the industry standard for storing passwords on a server (bcrypt) is specifically designed to slow down password match attempts.

Re: A Message to Our Customers

#354
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Like you, I appreciate the sentiment - happy to hear Apple speaking up. However this shouldn't change how we use Apple products. I operate under the implication that the device is compromised from the factory. Closed source software cannot be trusted, good faith is not enough.

Re: A Message to Our Customers

#355

Earlier quoted context omitted.

The current implementation is done this way indeed: even Apple cannot decrypt without using the right password. The right password can be obtained by either knowing it, or by guessing it. As an additional security measure, the software shipped with the phone prevents brute force attacks by wiping the device after a given number of failed attempts. Apple has been asked to modify the software so that it won't wipe the…

Why doesn't the FBI simply clone the current device, make brute force attempts and then clone again if locked out? Yes, lots of work but also doesn't force Apple to participate.

Would it be infeasible to construct part of the private key out of hardware-specific id's + time-of-creation hashes? I assume it's not only the PIN?

Re: A Message to Our Customers

#356
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…

Did you read the release? They are up front that its entirely an issue about setting a bad precedent. Its completely and totally about the fact that it would be used over and over again, and nothing to do with the fact that is it possible. Your overly cynical stance on this is misguided, as you seem to not have grasped the information in the letter.

Re: A Message to Our Customers

#357
post #285

Earlier quoted context omitted.

Or, said differently, Play Services are already a backdoor. They can (and do) install updates or other software pushed by server automatically, without you being able to do anything about it. And they have access to anything on the phone.

And it can reportedly grant itself new permissions without the user's knowledge, bypassing a fundamental security mechanism of Android (any Android devs know how this is done?). http://arstechnica.com/gadgets/2013/09/balky-carriers-and-sl...

Google Play Store manages the permission dialog for apps installed via Play Store (Play Services is one). It just doesn't show it for Play Services and just auto-accepts installation.

Re: A Message to Our Customers

#358

Earlier quoted context omitted.

The current implementation is done this way indeed: even Apple cannot decrypt without using the right password. The right password can be obtained by either knowing it, or by guessing it. As an additional security measure, the software shipped with the phone prevents brute force attacks by wiping the device after a given number of failed attempts. Apple has been asked to modify the software so that it won't wipe the…

Why doesn't the FBI simply clone the current device, make brute force attempts and then clone again if locked out? Yes, lots of work but also doesn't force Apple to participate.

I thought @csoghoian's take was interesting. The FBI doesn't want one specific phone unlocked, they want precedent.

https://twitter.com/csoghoian/status/699841360963108864

Re: A Message to Our Customers

#359

Earlier quoted context omitted.

The current implementation is done this way indeed: even Apple cannot decrypt without using the right password. The right password can be obtained by either knowing it, or by guessing it. As an additional security measure, the software shipped with the phone prevents brute force attacks by wiping the device after a given number of failed attempts. Apple has been asked to modify the software so that it won't wipe the…

Why doesn't the FBI simply clone the current device, make brute force attempts and then clone again if locked out? Yes, lots of work but also doesn't force Apple to participate.

The iPhone uses AES encryption which would prevent cloning the flash storage [1]. There was an informative discussion of this over on AppleInsider - http://forums.appleinsider.com/discussion/191851

[1] http://www.darthnull.org/2014/10/06/ios-encryption

Re: A Message to Our Customers

#360
Can they publish a copy of the FBI letter. Otherwise, Apple's description feels a bit circumstantial and opinionated. I feel like I can make a better judgement on this whole issue if the request is made public.
Post reply on HN