Live data from Hacker News

A Message to Our Customers

apple.com

411–420 of 1001 posts

Re: A Message to Our Customers

#411

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

But how do you get the firmware updated on a locked phone? My understanding is all updates (historically) have required the phone to be unlocked and connected to the internet?

I think the ask is for a custom recovery mode tool / image.

See https://www.theiphonewiki.com/wiki/DFU_Mode

Not same thing as an OS update.

Re: A Message to Our Customers

#412
post #180
post #163

Earlier quoted context omitted.

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

What it means is that the best the FBI can come up with is "Make a way for us to brute force attack the passphrase." And brute force attack is worthless for a strong enough passphrase. That's what is reassuring. Not to mention that this is for the iPhone 5c. As other comments have mentioned, newer iPhones have the hardware-based Secure Enclave which add to the difficulty of breaking into the phone. https://www.apple.…

My reading of that PDF is that Secure Enclave software can be updated too, it simply does an independent verification of the Apple's digital signature.

So while the Secure Enclave enforces the delay between brute force attempts, Apple could still release an update that removes that delay.

Re: A Message to Our Customers

#413

Earlier quoted context omitted.

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

Exactly. Plus, all backups of the iphones on icloud are already unencrypted, so half of the phones are already indirectly unlocked. EDIT: backups are encrypted, but apple have the keys. See below.

[deleted]

Re: A Message to Our Customers

#414

Earlier quoted context omitted.

Exactly. Plus, all backups of the iphones on icloud are already unencrypted, so half of the phones are already indirectly unlocked. EDIT: backups are encrypted, but apple have the keys. See below.

iCloud backups are 100% encrypted. Only some iTunes backups are not, and only if the option to use encryption to protect the backup is not selected.

They are, but apple have the keys : https://thehackernews.com/2016/01/apple-icloud-imessages.htm...

So basically, they could be in clear text, it's pretty much the same.

Re: A Message to Our Customers

#415
I like the position apple is taking, However, after reading the letter, I noticed it misses a point I consider even more important than just "a dangerous precedent".

Apple is selling devices on the whole planet, not just in the USA. So, what's the FBI (an American agency) is requesting is not dangerous for only American citizen, but also for iPhones' owners in Europe, Asia, Africa, Oceania. Hell, these people are not even part of the debate, because they don't belong in the "American democracy".

If I'm going to be affected by someone else's policies, I would like to be at least allowed in the discussion.

Re: A Message to Our Customers

#416

If I were Cook, I'd draw a line in the sand. If we are force to comply, we exit the phone business, because we won't make phones that compromise our customer's security. But that would take more balls than anyone left here in this "Land of the free and home of the brave" seems to have left anymore.

http://www.commondreams.org/news/2014/04/17/lavabit-company-...

Re: A Message to Our Customers

#417
post #397

Earlier quoted context omitted.

Nowhere in this letter they say that it's possible and it seems very carefully worded to avoid stating that. They say, if it were possible they wouldn't do it anyway. That's an important legal and moral distinction. To be fair, they could have stated it explicitly.

It's stated very clearly that they can push an update to an already existing device that would make it possible to retrieve "encrypted" data from said device. If the data was truly encrypted, the concept of pushing an update or creating a master key would not be possible.

Ok, I read the entire thing once again. Nowhere in there do they state that they can comply with the request, only the consequences that would result if it were possible. In fact they say they "even put that data out of our own reach".

If it is stated very clearly, can you quote me a sentence?

In the security guide linked here it seems possible for this iPhone model but not later ones.

Edit: According to the discussion below Apple can ship updates to the secure enclave. I don't know if that's possible to a locked phone.

Re: A Message to Our Customers

#419
post #397

Earlier quoted context omitted.

Nowhere in this letter they say that it's possible and it seems very carefully worded to avoid stating that. They say, if it were possible they wouldn't do it anyway. That's an important legal and moral distinction. To be fair, they could have stated it explicitly.

It's stated very clearly that they can push an update to an already existing device that would make it possible to retrieve "encrypted" data from said device. If the data was truly encrypted, the concept of pushing an update or creating a master key would not be possible.

They state that they can push an update that makes brute-forcing possible by disabling software-enforced delays between attempts.

Apple's security PDF says that the iteration count is calibrated so that one attempt takes 80ms in hardware, so that's the hard limit on the brute forcing speed, regardless of any updates Apple releases.

This means that a long alphanumeric passphrase is secure, but a 6-digit passcode could be broken in half a day, and a 4-digit passcode would take just a dozen minutes.

Re: A Message to Our Customers

#420

If I were Cook, I'd draw a line in the sand. If we are force to comply, we exit the phone business, because we won't make phones that compromise our customer's security. But that would take more balls than anyone left here in this "Land of the free and home of the brave" seems to have left anymore.

Apple could also put the software under a free license. The community could remove any backdoors that Apple is required to put in. They could still sell the hardware if they wanted to keep making money, just like Google does now.
Post reply on HN