Live data from Hacker News

A Message to Our Customers

apple.com

481–490 of 1001 posts

Re: A Message to Our Customers

#481

Earlier quoted context omitted.

What do you want thone other companies to get behind? They don't manufacture phones like Apple does, right...? Note that this letter says: "When the FBI has requested data that’s in our possession, we have provided it." Seels like that detail is getting very little attention in this announcement. Really? If the FYI requests any data, they hand it over...?

Would you complain about Apple handing in information to solve the murder of a loved one? Why is it always the "bad government" argument? It's not that it doesn't happen, but usually those requests are aimed towards more "mundane" cases. For example, I have friends who work in law (though not in the US), and the number 1 data request -which is revised by a judge, and only then given by companies- are call logs from t…

Utilitarian philosophy argument. The benefit gained by solving one murdered loved-one case is badly offset by the loss accrued to everyone by no longer having the security protections they expected.

This specific case, in fact, is pretty close to "murder of a loved one;" the phone's owner killed people, and the FBI wants to find out if they were part of a bigger plot.

Re: A Message to Our Customers

#482
[In walk the drones]

"Today we celebrate the first glorious anniversary of the Information Purification Directives.

[Apple's hammer-thrower enters, pursued by storm troopers.]

We have created for the first time in all history a garden of pure ideology, where each worker may bloom, secure from the pests of any contradictory true thoughts.

Our Unification of Thoughts is more powerful a weapon than any fleet or army on earth.

We are one people, with one will, one resolve, one cause.

Our enemies shall talk themselves to death and we will bury them with their own confusion.

[Hammer is thrown at the screen]

We shall prevail!

[Boom!]

On January 24th Apple Computer will introduce Macintosh. And you'll see why 1984 won't be like '1984.'"

------------------------------------------------------------

Apple Superbowl AD "1984"

Transcription courtesy of George Gollin, 1997

Edit:Removed the link to the video. My goal wasn't to draw traffic anywhere it was just to point out that some of Big Brother sentences in an Ad aired 30 years ago still have strong resonance today.

"Our enemies shall talk themselves to death" Hum... just read yesterday that NSA is believed to use machine learning over cell big-data to determine drone target...

Re: A Message to Our Customers

#483
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Like you, I appreciate the sentiment - happy to hear Apple speaking up. However this shouldn't change how we use Apple products. I operate under the implication that the device is compromised from the factory. Closed source software cannot be trusted, good faith is not enough.

I can't disagree with your point of view; I merely point out that a world where everyone who wants a secure smartphone needs to own their own smartphone factory isn't a very practical world.

Re: A Message to Our Customers

#484

Earlier quoted context omitted.

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

+1. If it is possible to push software updates to a "locked" phone then is this not tantamount to remote code execution with root privileges, and hence the BACKDOOR ALREADY EXISTS? "Locked" seems like an improper term for such a scenario. I applaud apple for appealing this case to the public however there is a HUGE HUGE difference between "we can't unlock" and "we shouldn't unlock". This distinction will likely be lo…

No. The word "remote" is not applicable to an attack that only works with physical possession of the device.

As far as I'm aware there is no known technique to prevent someone with physical access, a bunch of engineers, and the code signing keys from replacing firmware.

Re: A Message to Our Customers

#485
post #159

Earlier quoted context omitted.

Once they build that in for one device then they have opened pandora's box. Then it becomes a precedent in the courts that Apple has this ability so they will issue court orders to make them comply for every single case where a phone is encrypted.

One way around that is for Apple to make it extremely costly for courts to issue many of such orders, because after all Apple are free to charge whatever they like for doing this service.

The the court says "lol, make it default then". It doesn't matter how much they charge, when courts can override the decision. What apple needs to do is invalidate any way for this to happen.

Re: A Message to Our Customers

#486

Im generally not an apple supporter(i dont like the closed eco system), i am very plesantly surprised they posted this. I am quite disappointed that the us courts are trying to force apple todo this, and in my opinion, its just to use this case to set a precedent. I hope Apple cant get it to work, but id hate to see what the courts would do if that happened.

Keep in mind, it's not just the courts ordering Apple to do this on a whim. The owner of the iPhone in question has literally consented to search. It's akin to the owner of a safe asking the safe company to open it up because he doesn't have the combination, and the safe company can do it, but won't because of the fear of a slippery slope.

Re: A Message to Our Customers

#487

Earlier quoted context omitted.

But this request was made specifically for the phone in the San Bernardino case. In which the owner is dead and the phone is locked. This implies it is possible for Apple themselves to apply an iOS update to a locked phone in order to disable the erase-on-repeated-failure feature.

This is my question, too. Can iOS updates be applied to a locked phone? Seems like it should be a simple yes/no answer (and I thought the answer was 'no') but I can't find any clarity here or elsewhere.

If you physically have the phone, de-soldering and moving the flash memory to a custom board for modification is an option.

Re: A Message to Our Customers

#488

Earlier quoted context omitted.

> Apple, if they chose to, can make a version of iOS that disables security features and encryption and load it onto existing phone even though the phone is locked and encrypted? As I understand it, the FBI wants Apple to create a version of iOS that would disable the current feature where the data is deleted after more than 10 failed passwords attempts. This would allow the FBI to brute force the password.

That doesn't explain how they would get the update on to a locked and encrypted device, even if it existed.

It seems like it would be easy enough to crack it open and replace the OS boot data.

That being said, I really WANT the data in this case. I hope Apple finds a compromise where they can help get this specific data without risking leaking a compromised OS.

Re: A Message to Our Customers

#489
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

The government wants Apple to disable the auto-erase after so many unlock attempts. Apple argues in this letter that with modern computing power, this amounts to a backdoor.

The details of the gov't request are in another story on the HN front page

https://www.techdirt.com/articles/20160216/17393733617/no-ju...

Re: A Message to Our Customers

#490
post #452

Earlier quoted context omitted.

It may be that only the 5C or older devices have the ability to push a custom OS update to a locked device. The real problem is that you don’t want to set any precedent at all . Once it’s possible to do something for the 5C, weasel words can be introduced to make claims like “well: now you must maintain the current level of access by law enforcement ”. Next thing you know, that excuse can be used to interfere with al…

And my understanding is that everything after the 5C is less vulnerable to even this attack (Which itself may not be possible, even with a firmware update.)

From what I heard later revisions won't accept a firmware update without either providing the passcode, or erasing the private key.

Arguably, the fact that the 5C accepts a firmware update without the passcode is a security vulnerability and ought to be patched.

Post reply on HN