Live data from Hacker News

A Message to Our Customers

apple.com

461–470 of 1001 posts

Re: A Message to Our Customers

#461
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Isn't it odd that this press release spends so much time discussing encryption? Neither the FBI nor Apple will be touching any encryption functions of the device.

It seems the primary aim of this statement is to prevent rumors that would spook Apple users into thinking their data is fair game

Re: A Message to Our Customers

#462

Earlier quoted context omitted.

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

I'm not sure you can draw the conclusion that Apple can push OS updates to a locked phone. What Tim Cook wrote is that > "install it on an iPhone recovered during the investigation." > "the potential to unlock any iPhone in someone’s physical possession." So the FBI has the physical phone already. They can deliver to Apple who can disassemble it and either use a JTAG/Flash programmer on an internal connector to manua…

They need to break the boot trust chain to load unsigned code. Simply rewriting the flash isn't enough.

Re: A Message to Our Customers

#463

If I were Cook, I'd draw a line in the sand. If we are force to comply, we exit the phone business, because we won't make phones that compromise our customer's security. But that would take more balls than anyone left here in this "Land of the free and home of the brave" seems to have left anymore.

http://www.commondreams.org/news/2014/04/17/lavabit-company-...

And, his letter is still posted on his web site, describing what he went through:

http://lavabit.com/

Re: A Message to Our Customers

#464

Earlier quoted context omitted.

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

I'm not sure you can draw the conclusion that Apple can push OS updates to a locked phone. What Tim Cook wrote is that > "install it on an iPhone recovered during the investigation." > "the potential to unlock any iPhone in someone’s physical possession." So the FBI has the physical phone already. They can deliver to Apple who can disassemble it and either use a JTAG/Flash programmer on an internal connector to manua…

Pretty sure you can upgrade the OS on a locked phone if you have physical access to it.

Re: A Message to Our Customers

#466

Earlier quoted context omitted.

If there's one thing that we have learned over the last few years from Snowden et al, we have learned that it is safe to assume that these state actors will be trying all the avenues that you or I can think of, and spend years discovering new ones that we have not thought of.

I have trouble understanding your point. What's the alternative to trying to minimize the probability of crypto system compromises?

You make a good case that Apple are far ahead as industry leaders here; that seems solid. It's less solid that this means they are impervious, or that the thinking "I can't see any holes in this process, therefore there are no holes in it" is sound.

Re: A Message to Our Customers

#467

Earlier quoted context omitted.

But why would you even think apple, google or facebook would be a good bet to defend your privacy in the first place ? They got the most terrible track record of not caring about. If you have things that you need to be private, don't put it on a smartphone.

I wish people would stop lumping Apple with Google/Facebook with regards to privacy. Apple has implicitly for a long time, and lately much more vocally, cared about privacy. They don't have the same data-driven business model that Google and FB do.

> Apple has implicitly for a long time, and lately much more vocally, cared about privacy.

They say that. But with closed source software we can't verify that it's true. I'm not saying they don't care about privacy, only that we don't really know if they do or not.

Re: A Message to Our Customers

#468

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

And it'd seem to open the floodgates for certificate authorities to be compromised as well. What's to stop the FBI from compelling a CA to create a special MITM certificate for a criminal investigation of a Yahoo user?

Re: A Message to Our Customers

#469
post #101

Earlier quoted context omitted.

But you can always root your phone and install Cyanogenmod from scratch, right? Agreed that this is not too trivial right now because of standardization issues, but it could be done if you really care about privacy.

Not all of CyanogenMod is free software (you still have a bunch of binary blobs, and everyone has to use Google Play Services anyway because every app seems to implicitly require it). Replicant would be a much better alternative if it actually supported anything newer than 2G.

Replicant supports 3G devices:

https://www.replicant.us/supported-devices.php

Re: A Message to Our Customers

#470

Earlier quoted context omitted.

I'm not sure you can draw the conclusion that Apple can push OS updates to a locked phone. What Tim Cook wrote is that > "install it on an iPhone recovered during the investigation." > "the potential to unlock any iPhone in someone’s physical possession." So the FBI has the physical phone already. They can deliver to Apple who can disassemble it and either use a JTAG/Flash programmer on an internal connector to manua…

They need to break the boot trust chain to load unsigned code. Simply rewriting the flash isn't enough.

Why would the code be unsigned? If Apple wrote the backdoor OS, they could presumably sign it.
Post reply on HN