Live data from Hacker News

A Message to Our Customers

apple.com

451–460 of 1001 posts

Re: A Message to Our Customers

#451
This is an interesting chapter in the "Tim will never be Steve" saga that so many people are infatuated with.

This particular hill that Tim Cook has decided to defend is as important as anything Steve Jobs ever did at Apple.

Re: A Message to Our Customers

#452

Earlier quoted context omitted.

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

It may be that only the 5C or older devices have the ability to push a custom OS update to a locked device. The real problem is that you don’t want to set any precedent at all . Once it’s possible to do something for the 5C, weasel words can be introduced to make claims like “well: now you must maintain the current level of access by law enforcement ”. Next thing you know, that excuse can be used to interfere with al…

And my understanding is that everything after the 5C is less vulnerable to even this attack (Which itself may not be possible, even with a firmware update.)

Re: A Message to Our Customers

#453

Earlier quoted context omitted.

You can't make crypto behave slower on repeated attempts but you can still make each attempt more expensive. For example: https://en.m.wikipedia.org/wiki/Pepper_(cryptography)

True. But Apple, with such a focus on UX, cannot reasonably afford more than ~200 millisec when checking a password; and still it scales linearly, so the solution for concerned users still involves creating a more complex password. Doubling the amount of time it takes to hash a password will have the same effect as adding 1 more bit of entropy to the password, which can easily be beaten by adding a single character t…

If you consider caching of keys, there's no reason that the first login attempt after a cold boot couldn't take 1-2s. Each subsequent login would be roughly instant.

Re: A Message to Our Customers

#454
I heard this morning on the (semi-conservative FM radio) that this was a national security issue, and that Apple is helping terrorists in not bypassing this.

I don't get it- the shooters are dead. How is what is on their phone a matter of national security? We probably have 99% of the information we'll ever have on them. There is no larger plot. Not having what's on this device I cannot imagine puts anyone at risk.

Re: A Message to Our Customers

#455

Earlier quoted context omitted.

Secure Enclave is not really ‘hardware’; despite being isolated from the main OS and CPU, it is still software-based and accepts software updates signed by Apple.

Ok, if that part is updatable you have indeed a backdoor. In theory it should be possible to make it fixed (which Apple doesn't seem to have done).

Making it fixed just means you can't fix future bugs. The secure approach is to ensure that updates are only possible if the device is either unlocked or wiped completely.

Re: A Message to Our Customers

#456
post #163

Earlier quoted context omitted.

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

But why would you even think apple, google or facebook would be a good bet to defend your privacy in the first place ? They got the most terrible track record of not caring about. If you have things that you need to be private, don't put it on a smartphone.

I wish people would stop lumping Apple with Google/Facebook with regards to privacy.

Apple has implicitly for a long time, and lately much more vocally, cared about privacy. They don't have the same data-driven business model that Google and FB do.

Re: A Message to Our Customers

#457
The easy solution to this is to have the gov send Apple the phone. They break into themselves and then hand back the phone with the pass code turned off and whatever software they need to install to do it removed, leaving no trace of how they actually did it.

Win/Win

No software backdoor is created, the FBI gets its data and we all go on with our lives. Why are we spending so much time gnashing teeth over something that has a very simple solution to it?

Re: A Message to Our Customers

#458
post #397

Earlier quoted context omitted.

It's stated very clearly that they can push an update to an already existing device that would make it possible to retrieve "encrypted" data from said device. If the data was truly encrypted, the concept of pushing an update or creating a master key would not be possible.

They state that they can push an update that makes brute-forcing possible by disabling software-enforced delays between attempts. Apple's security PDF says that the iteration count is calibrated so that one attempt takes 80ms in hardware, so that's the hard limit on the brute forcing speed, regardless of any updates Apple releases. This means that a long alphanumeric passphrase is secure, but a 6-digit passcode could…

[deleted]

Re: A Message to Our Customers

#459
post #307

Earlier quoted context omitted.

The point is there currently is no backdoor. FBI wants Apple to create (and sign) an OS update with a backdoor and install it onto the suspect's phone. Specifically the backdoor is to remove the rate limiting and 10 attempts limitation on trying the passcode. If you have a very strong passphrase (not a 6-digit code) then even that should be unbreakable even with brute force. Of course, most users have the 6 digit cod…

> The point is there currently is no backdoor. FBI wants Apple to create (and sign) an OS update with a backdoor and install it onto the suspect's phone. If this is possible without the owner's permission, then the update mechanism is the existing backdoor. It just happens to also be the front door.

[deleted]

Re: A Message to Our Customers

#460
post #428
post #261

Earlier quoted context omitted.

A man went to his local parish priest and asked "Father, is it permissible to smoke while praying?" "No, my son, when praying you should show the utmost respect and attention to God" he answered. The next day, another man asked the same priest "Father, is it permissible to pray when I smoke?" "Of course, I encourage you to make your whole life one long prayer!" was the priest's answer. So, is Apple defending rights w…

It will become obvious, I think, in the following days. If they challenge the court order and fight vigorously to have it lifted, I am willing to believe that it is about the privacy. If they give in and say, "but we really didn't want to, they made us do it", I will consider their resistance more of a PR stunt. That story, by the way, is really nice. ;-)

I'd place a hefty wager on Apple fighting this until there is no legal recourse.
Post reply on HN