Live data from Hacker News

A Message to Our Customers

apple.com

431–440 of 1001 posts

Re: A Message to Our Customers

#431
post #350

Earlier quoted context omitted.

Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order

Was going to point out that you spelt "prosecutors"as "persecutors", but then realised you might have genuinely meant that spelling!

I'm not a native english speaker and that actually was just a typo.

Re: A Message to Our Customers

#432

Earlier quoted context omitted.

Not if the check and wiping is done in hardware as claimed by Apple for newer devices than the one in question here.

Secure Enclave is not really ‘hardware’; despite being isolated from the main OS and CPU, it is still software-based and accepts software updates signed by Apple.

Ok, if that part is updatable you have indeed a backdoor.

In theory it should be possible to make it fixed (which Apple doesn't seem to have done).

Re: A Message to Our Customers

#433
It's hard for me to have respect for an organization that was built by J. Edgar Hoover, a person who did not respect the law or American's rights.

The philosophy of corruption and oppression still echoes throughout the FBI. Even today, there are FBI agents that work for private interests. You can't reform a mafia, you must abolish it and start over.

Re: A Message to Our Customers

#434

Earlier quoted context omitted.

That's a good point. I guess I figured if they simply can't do it why not say "it's impossible by design," rather than argue the principle? It seems like their stand would be better saved for when a compromise is requested that is actually possible for them implement.

Maybe it's impossible by design in current iPhones. But this is an older one, not so secure. As Tim Cook says, it would be a bad precedent. And obviously bad PR for Apple to admit vulnerability.

It is, of course, possible; any iPhone can be forced to enter the restore mode or the DFU mode (don't remember which one) and be erased/reflashed via iTunes.

It won't get unlocked by that, because as soon as the new iOS takes over, it will detect the activation lock and require the Apple ID password to be provided. Also, going through iTunes erases all the data.

But presumably a custom DFU update can only replace the OS without replacing the data. The iPhone doesn't try to protect against valid updates, and will happily run anything signed by Apple; the locked/unlocked state is only about the encrypted user data on the device.

Re: A Message to Our Customers

#435
Being realistic, ¿how many fewer iphones will apple sell if they remove the SE? ¿How many people will not buy an iphone if they are told that their info can be accessed with a judge's warrant? I'm guessing a 0.1% drop in sales?

Re: A Message to Our Customers

#436
post #41

Earlier quoted context omitted.

I don't have an iPhone so correct me if I'm remembering correctly but aren't they by default protected by a 4 digit numeric pin? A 4 digit numeric pin that a brute force attack can be used on is effectively no security/a backdoor imo.

There are escalating time limits on incorrect PIN attempts, which is also enforced in hardware by the Secure Enclave in A7 chips and above. This would mean even breaking a 4-digit pin code without that delay being removed would take a long time. Additionally the device may be set to wipe after 10 incorrect attempts. Attempts | Delay 1-4: none 5: 1 minute 6: 5 minutes 7-8: 15 minutes 9: 1 hour Source: https://www.appl…

Secure Enclave is _not_ hardware; despite being isolated from the main OS and CPU, it is still software-based and accepts software updates signed by Apple.

Re: A Message to Our Customers

#437

Earlier quoted context omitted.

> Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order Exactly like Apple. Or do you think that the emails in iCloud are not given to the prosecutors?

Yes exactly like apple. To quote the link: "When the FBI has requested data that’s in our possession, we have provided it." The point I was trying to make is that Google and Facebook have direct access to all the data of their customers, and already provide access to government agencies. Contrary to Apple they don't safely store some data of their costumers safely on the device, which this case is about.

> The point I was trying to make is that Google and Facebook have direct access to all the data of their customers, and already provide access to government agencies. Contrary to Apple they don't safely store some data of their costumers safely on the device, which this case is about.

Your point is wrong regarding Google and smartphones if the smartphone is encrypted

Re: A Message to Our Customers

#438

Earlier quoted context omitted.

Meh. Then the attacker can simply replace the hardware. Remember, our attacker model is Apple; non-cryptographic security measures mean very little to a company with such complete knowledge of the hardware and software involved.

The point is that the key is stored there too (part of it burned during production in silicone) and can't be read or changed. Sure, if they wanted to they could implement a backdoor. But assuming they correctly created and shipped the secure enclave it shouldn't be possible to circumvent it even for Apple.

It's sounding like that's the problem. They left an opening for this sort of thing by allowing firmware updates to the secure enclave. That basically makes it a fight over whether the FBI can force Apple to use the required key to sign an update meeting the specifications the FBI directs.

Re: A Message to Our Customers

#439
A possible compromise would be to add a backdoor to the security module that would unlock the phone in exchange for a proof of work.

It would be relatively easy for the chip to offer a challenge and accept, say, a $100,000 proof of work to unlock the phone. This way, we prevent bulk surveillance but still allow the government to access high value targets' devices.

Post reply on HN