Live data from Hacker News

A Message to Our Customers

apple.com

441–450 of 1001 posts

Re: A Message to Our Customers

#441

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

I think the missing information here is how the phone is encrypted. If it's done with the 4-digit numeric PIN, then the software could be built; it would take 10000 tries, but at less than .1 seconds per try, it would be able to crack the code in about 15 minutes. The current iPhone has a protection for this; after some number of tries, it will lock you out for increasing time intervals. This is the only way that the…

Also note that new iPhones default to 6 digit pins. Still possible, but harder.

Re: A Message to Our Customers

#443

Publicizing the case themselves in a very good move. However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode). The amo…

And to think, just two weeks ago that same enforcement which prevents compromising the secure enclave was the target of vitriol right here on HN (Error 53).

Re: A Message to Our Customers

#444
post #307

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

The point is there currently is no backdoor. FBI wants Apple to create (and sign) an OS update with a backdoor and install it onto the suspect's phone. Specifically the backdoor is to remove the rate limiting and 10 attempts limitation on trying the passcode. If you have a very strong passphrase (not a 6-digit code) then even that should be unbreakable even with brute force. Of course, most users have the 6 digit cod…

> The point is there currently is no backdoor. FBI wants Apple to create (and sign) an OS update with a backdoor and install it onto the suspect's phone.

If this is possible without the owner's permission, then the update mechanism is the existing backdoor. It just happens to also be the front door.

Re: A Message to Our Customers

#445
post #331

Earlier quoted context omitted.

The FBI is asking that it be built now and then loaded onto the already recovered phone. > Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation.

Why the downvote? That is what I said. I merely used a slew of different words. > The FBI is asking that it be built now Because it's not possible _now_. > and then loaded onto the already recovered phone. Thus it becoming possible after they have built the new version of iOS, and since they cannot go back in time and build it, it would indeed be _in_the_future_ that it became available, if Apple complied, that is.

I didn't downvote but Cook's letter suggests that the backdoor needs to apply retrospectively to existing phones (not just future phones).

Hence the parent post's suggestion that the argument is moot -- if Apple has the capability to retrospectively backdoor existing phones it would imply that Apple didn't secure it in a foolproof way in the first place.

Re: A Message to Our Customers

#446

So the FBI is asking Apple to build a tool that will unlock security measures of an existing iPhone, like the one in the San Bernadino shooting, and allow it to be read. The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have. If it is pos…

iPhone 5s and newer have a Secure Enclave, which limits brute force-ability and can not be changed via a software update (there is a belief, though undocumented, that any firmware patches would also wipe the stored keys). Apple could not help the FBI to get into these phones.

The phone in question, however, is an iPhone 5c, which does not have a Secure Enclave.

Re: A Message to Our Customers

#448
post #352
post #326

Earlier quoted context omitted.

What happens to all your stuff when you die?

Why care about "stuff" once you are dead?

Because you don't want to make a difficult situation even harder for your relatives?

See, for example, the people who know they're going to die and who leave their iPads to their relatives in their wills. Apple doesn't take grants of probate as sufficient legal documents (everyone else does (eg banks)) and insist on a court order.

http://www.bbc.co.uk/news/technology-26448158

Re: A Message to Our Customers

#449

Earlier quoted context omitted.

Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order

> Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order Exactly like Apple. Or do you think that the emails in iCloud are not given to the prosecutors?

Not exactly like Apple.

Google and Facebook's core competency is using your personal data to sell ads.

Apple's core competency is selling you appliances. Yes, they wind up with some personal data because of the services they also provide, but it's far less valuable to them than Google or Facebook.

Re: A Message to Our Customers

#450
post #397

Earlier quoted context omitted.

Nowhere in this letter they say that it's possible and it seems very carefully worded to avoid stating that. They say, if it were possible they wouldn't do it anyway. That's an important legal and moral distinction. To be fair, they could have stated it explicitly.

It's stated very clearly that they can push an update to an already existing device that would make it possible to retrieve "encrypted" data from said device. If the data was truly encrypted, the concept of pushing an update or creating a master key would not be possible.

No, they state clearly that this is what the court ordered them to do. That doesn't mean it is possible. The court doesn't care whether something is possible or not.
Post reply on HN