Live data from Hacker News

A Message to Our Customers

apple.com

391–400 of 1001 posts

Re: A Message to Our Customers

#391
post #355

Earlier quoted context omitted.

Why doesn't the FBI simply clone the current device, make brute force attempts and then clone again if locked out? Yes, lots of work but also doesn't force Apple to participate.

Would it be infeasible to construct part of the private key out of hardware-specific id's + time-of-creation hashes? I assume it's not only the PIN?

That's what the A7 (iPhone 5S and later) design does:

“Each Secure Enclave is provisioned during fabrication with its own UID (Unique ID) that is not accessible to other parts of the system and is not known to Apple. When the device starts up, an ephemeral key is created, entangled with its UID, and used to encrypt the Secure Enclave’s portion of the device’s memory space. Additionally, data that is saved to the file system by the Secure Enclave is encrypted with a key entangled with the UID and an anti-replay counter.”

https://www.apple.com/business/docs/iOS_Security_Guide.pdf

The device in question is an iPhone 5C, which uses the older A6 design.

Re: A Message to Our Customers

#393
Can't they dump all the data from that particular device and then send it to the FBI? Maybe the judge will order that? Obviously they're confessing they can break the encryption but they would not do it, on principle. I don't see how they can win this fight. If it's the iphone of the shooter, and they can decrypt it, they should do it. It is not the same as to give the FBI a tool to unlock any iphone.

Re: A Message to Our Customers

#394
post #295

While we believe the FBI’s intentions are good, it would be wrong for the government to force us to build a backdoor into our products. And ultimately, we fear that this demand would undermine the very freedoms and liberty our government is meant to protect. Tim Cook Kudos to this guy for standing up to an idea. Now on practical notes, this is about security, providing a digitally secure platform to both users and pr…

The court order says Apple should make the software only work on the specific phone in question. Nobody could modify the software to work on other phones any more than they could make the changes to iOS themselves. Apple is misrepresenting the situation and perhaps it's because they're afraid that in the future the government will come knocking again, but I think it hurts them to not be completely above-board about t…

That's not really possible. There isn't a mechanism to create this condition: "Nobody could modify the software to work on other phones"

Tim Cook is right. Once this is unleashed, there are no limits and all iPhones are insecure.

Re: A Message to Our Customers

#395

Earlier quoted context omitted.

Yeah. Loving your spouse and hiding things from them are also not mutually exclusive. Yet, you hardly find people that do both. Not to mention, this situation would never have arisen if iphone were open-sourced, since all activity would have been monitored by the community.

You have way too much faith into the the idea, that open source projects are free of backdoors / exploits and that the community can prevent creation of those. Aside from that, there is currently no platform, where 100% code is open source.

Of course we can't. But we are in a vastly better position to positivity affect these things if we do have the source.

It is immaterial whether or not any platform is currently 100% open source. rms_returns is right in noting the discrepancy between noble apple sticking it to the man and walled garden apple sticking it to the user.

Re: A Message to Our Customers

#397

Earlier quoted context omitted.

+1. If it is possible to push software updates to a "locked" phone then is this not tantamount to remote code execution with root privileges, and hence the BACKDOOR ALREADY EXISTS? "Locked" seems like an improper term for such a scenario. I applaud apple for appealing this case to the public however there is a HUGE HUGE difference between "we can't unlock" and "we shouldn't unlock". This distinction will likely be lo…

Nowhere in this letter they say that it's possible and it seems very carefully worded to avoid stating that. They say, if it were possible they wouldn't do it anyway. That's an important legal and moral distinction. To be fair, they could have stated it explicitly.

It's stated very clearly that they can push an update to an already existing device that would make it possible to retrieve "encrypted" data from said device.

If the data was truly encrypted, the concept of pushing an update or creating a master key would not be possible.

Re: A Message to Our Customers

#398

Earlier quoted context omitted.

I agree. I was under the impression that Apple's security was such that even they didn't have the power to decrypt a device because the crypto made it impossible without the password/pin/key. I'm interested to understand the reasons that it was not done this way.

The current implementation is done this way indeed: even Apple cannot decrypt without using the right password. The right password can be obtained by either knowing it, or by guessing it. As an additional security measure, the software shipped with the phone prevents brute force attacks by wiping the device after a given number of failed attempts. Apple has been asked to modify the software so that it won't wipe the…

I'm really curious as I have been hearing this many times.

"even Apple cannot decrypt without using the right password."

Could you please explain?

Re: A Message to Our Customers

#399

Earlier quoted context omitted.

If in pursuit of an active investigation (i.e. the devices are still in active use), a police agency could invoke the All Writs act of 1789, and have Apple be instructed to introduce security vulnerabilities, with the next regular upgrade of iOS, such that after the phone is upgraded, it can be captured by the FBI, or whatever police force is involved, and the data recovered. A large percentage (and presumably the th…

But this request was made specifically for the phone in the San Bernardino case. In which the owner is dead and the phone is locked. This implies it is possible for Apple themselves to apply an iOS update to a locked phone in order to disable the erase-on-repeated-failure feature.

Well, looks like the ask is for a custom DFU tool:

https://www.theiphonewiki.com/wiki/DFU_Mode

Re: A Message to Our Customers

#400
post #295

While we believe the FBI’s intentions are good, it would be wrong for the government to force us to build a backdoor into our products. And ultimately, we fear that this demand would undermine the very freedoms and liberty our government is meant to protect. Tim Cook Kudos to this guy for standing up to an idea. Now on practical notes, this is about security, providing a digitally secure platform to both users and pr…

The court order says Apple should make the software only work on the specific phone in question. Nobody could modify the software to work on other phones any more than they could make the changes to iOS themselves. Apple is misrepresenting the situation and perhaps it's because they're afraid that in the future the government will come knocking again, but I think it hurts them to not be completely above-board about t…

Thanks for the heads up about these details. As you mention if you agree to one request you agree to all requests plus proving you can do it. A nice side effect of agreeing to this request would be to put an update that closes all the loops that allowed to perform the request on first place.
Post reply on HN