So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…
I think the missing information here is how the phone is encrypted. If it's done with the 4-digit numeric PIN, then the software could be built; it would take 10000 tries, but at less than .1 seconds per try, it would be able to crack the code in about 15 minutes. The current iPhone has a protection for this; after some number of tries, it will lock you out for increasing time intervals. This is the only way that the…
A Message to Our Customers
441–450 of 1001 posts
Re: A Message to Our Customers
#442Re: A Message to Our Customers
#443Publicizing the case themselves in a very good move. However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode). The amo…
Re: A Message to Our Customers
#444So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…
The point is there currently is no backdoor. FBI wants Apple to create (and sign) an OS update with a backdoor and install it onto the suspect's phone. Specifically the backdoor is to remove the rate limiting and 10 attempts limitation on trying the passcode. If you have a very strong passphrase (not a 6-digit code) then even that should be unbreakable even with brute force. Of course, most users have the 6 digit cod…
If this is possible without the owner's permission, then the update mechanism is the existing backdoor. It just happens to also be the front door.
Re: A Message to Our Customers
#445Earlier quoted context omitted.
The FBI is asking that it be built now and then loaded onto the already recovered phone. > Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation.
Why the downvote? That is what I said. I merely used a slew of different words. > The FBI is asking that it be built now Because it's not possible _now_. > and then loaded onto the already recovered phone. Thus it becoming possible after they have built the new version of iOS, and since they cannot go back in time and build it, it would indeed be _in_the_future_ that it became available, if Apple complied, that is.
Hence the parent post's suggestion that the argument is moot -- if Apple has the capability to retrospectively backdoor existing phones it would imply that Apple didn't secure it in a foolproof way in the first place.
Re: A Message to Our Customers
#446So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…
The phone in question, however, is an iPhone 5c, which does not have a Secure Enclave.
Re: A Message to Our Customers
#447Re: A Message to Our Customers
#448Earlier quoted context omitted.
What happens to all your stuff when you die?
Why care about "stuff" once you are dead?
See, for example, the people who know they're going to die and who leave their iPads to their relatives in their wills. Apple doesn't take grants of probate as sufficient legal documents (everyone else does (eg banks)) and insist on a court order.
Re: A Message to Our Customers
#449Earlier quoted context omitted.
Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order
> Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order Exactly like Apple. Or do you think that the emails in iCloud are not given to the prosecutors?
Google and Facebook's core competency is using your personal data to sell ads.
Apple's core competency is selling you appliances. Yes, they wind up with some personal data because of the services they also provide, but it's far less valuable to them than Google or Facebook.
Re: A Message to Our Customers
#450Earlier quoted context omitted.
Nowhere in this letter they say that it's possible and it seems very carefully worded to avoid stating that. They say, if it were possible they wouldn't do it anyway. That's an important legal and moral distinction. To be fair, they could have stated it explicitly.
It's stated very clearly that they can push an update to an already existing device that would make it possible to retrieve "encrypted" data from said device. If the data was truly encrypted, the concept of pushing an update or creating a master key would not be possible.