Live data from Hacker News

A Message to Our Customers

apple.com

511–520 of 1001 posts

Re: A Message to Our Customers

#511
post #326

Earlier quoted context omitted.

What happens to all your stuff when you die?

I guess my family will take care of my physical stuff. For the online part, some of it can probably be handled through support (facebook, etc...), and the rest will stay as is until it is deleted for lack of use. Or never deleted. Both are okay. Leaving a physical trace of my passwords is not only bad practice from security point of view, but quite useless since I know them. Also, my online accounts are useless if I…

Watch this https://archive.org/details/Online_No_One_Knows_Youre_Dead

Re: A Message to Our Customers

#512
I think, as a society, it boils down to this: "And while the government may argue that its use would be limited to this case, there is no way to guarantee such control."

Can a private, for profit, company deny the will of an elected government working to solve a heinous crime based not on what they say they will do but because they cannot give a 100% guarantee that this is the only time/way it'll be used? Apple acknowledges that the government is saying it's limited to this case but because there's no guarantee (100% certainty) they feel they can deny it?

If yes, what does that mean as a broader precedent. Are we comfortable with private companies denying an elected government based not on what they agree to, but instead because there's a chance it'll be used in other ways?

As terribly flawed one might feel about government very few would think it has less accountability than a private company.

Re: A Message to Our Customers

#513
post #353

Earlier quoted context omitted.

It's not a backdoor, it's a frontdoor. In cryptography, there's no way to make repeated attempts more computationally expensive. The lockout just an extra feature Apple put on, that Apple could easily remove. If we're going to have 4- and 6- digit PINs, there is no way to stop a dedicated attacker frome brute-forcing it. None.

"there's no way to make repeated attempts more computationally expensive" That's not true actually. For example, the industry standard for storing passwords on a server (bcrypt) is specifically designed to slow down password match attempts.

Bcrypt isn't an industry standard.

Re: A Message to Our Customers

#514
post #163

Earlier quoted context omitted.

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

But why would you even think apple, google or facebook would be a good bet to defend your privacy in the first place ? They got the most terrible track record of not caring about. If you have things that you need to be private, don't put it on a smartphone.

[deleted]

Re: A Message to Our Customers

#516

Earlier quoted context omitted.

I'm really interested to know more about this. Does TouchId secure enclave really enforce the password attempt limits?

Yes, see page 12 here https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Its really a pretty impressive design. Android phones are lacking here.

Re: A Message to Our Customers

#517
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

I found this article about this [1] to be rather enlightening.

1) http://blog.trailofbits.com/2016/02/17/apple-can-comply-with...

Re: A Message to Our Customers

#518

Earlier quoted context omitted.

But why would you even think apple, google or facebook would be a good bet to defend your privacy in the first place ? They got the most terrible track record of not caring about. If you have things that you need to be private, don't put it on a smartphone.

I wish people would stop lumping Apple with Google/Facebook with regards to privacy. Apple has implicitly for a long time, and lately much more vocally, cared about privacy. They don't have the same data-driven business model that Google and FB do.

Actions speak louder than words. The most revealing test of the strength of a company's commitment to privacy is how it handles situations when privacy can conflict with profits. Privacy on the internet relies critically on browsers only trusting trustworthy certificate authorities. When CNNIC breached its trust as a certificate authority last year, Apple sat tight waiting for the furor to subside (https://threatpost.com/apple-leaves-cnnic-root-in-ios-osx-ce...).

Re: A Message to Our Customers

#519

Earlier quoted context omitted.

Yes exactly like apple. To quote the link: "When the FBI has requested data that’s in our possession, we have provided it." The point I was trying to make is that Google and Facebook have direct access to all the data of their customers, and already provide access to government agencies. Contrary to Apple they don't safely store some data of their costumers safely on the device, which this case is about.

> The point I was trying to make is that Google and Facebook have direct access to all the data of their customers, and already provide access to government agencies. Contrary to Apple they don't safely store some data of their costumers safely on the device, which this case is about. Your point is wrong regarding Google and smartphones if the smartphone is encrypted

There's a huge distinction between Google (Android) and Apple (iOS) though: Apple affirms they don't have your keys, and this case bears that out (else the FBI would obtain the keys via subpoena to Apple rather than asking the court for a circumvention tool). Google is ambiguous about whether they have your Android keys; they claim they don't, however if you forget your device password it is possible to unlock your device via your Google account on a PC[1], and that alone is telling. If this were an Android device, the FBI would have already unlocked the phone with a simple subpoena.

Beyond that, Google definitely has the keys to your encrypted backups on their servers, so access to the phone might not even be necessary.

[1] http://visihow.com/Recover_Android_Device_in_case_of_Forgot_...

Re: A Message to Our Customers

#520

Earlier quoted context omitted.

iCloud backups are 100% encrypted. Only some iTunes backups are not, and only if the option to use encryption to protect the backup is not selected.

They are, but apple have the keys : https://thehackernews.com/2016/01/apple-icloud-imessages.htm... So basically, they could be in clear text, it's pretty much the same.

Please see this link[1], Apple explains exactly how keys are stored in their datacenters (Hint: it is not in clear text). They use HSM's which destroy the user's key after 10 failed attempts.

[1]: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Post reply on HN