Live data from Hacker News

A Message to Our Customers

apple.com

611–620 of 1001 posts

Re: A Message to Our Customers

#611
What are the odds that Apple has been ordered to do this before, but every other time they were asked it was in a FISA court? That would mean that this is the first time they've been allowed to talk about it.

Re: A Message to Our Customers

#612
As others have noted, this is probably mostly about branding. But that's why it is genius. Tim Cook is committing Apple to this pro-privacy position in a very public way. This means that a reversal of this position or a revelation that Apple has been acting contra it, would be extremely expensive to Apple's reputation with its customers, effectively costing the company a huge amount of money.

By publicly committing Apple to this cause, Cook makes it more likely that internal teams at Apple as well as future versions of the company will adhere to this position. By defining a set of actions which, if made public, would ruin the company's brand, Cook makes it less likely Apple will take those actions.

Re: A Message to Our Customers

#614

Earlier quoted context omitted.

"From what I understand Tim is doing, and I greatly admire, is trying to avoid a judicial requirement that they be able to do this on demand. The so called "back door" requirement, because he knows, as others do, that such a feature would be used by more than the intended audience, and for more than the intended uses, to the detriment of Apple's users." To be fair - the only reason he's doing it is because it would c…

"To be fair - the only reason he's doing it is because it would cause a significant drop in sales for Apple devices." That's not being fair at all. To say the only reason he is doing it is to protect iPhone sales doesn't speak to Tim's character. Of course he cares about sales, but he also cares about privacy.

Normally people on HN are much more skeptical about airy promises and assertions from corporate executives. I don't see what behavior on Tim Cook's part has indicated he's more to be trusted than anyone else.

Re: A Message to Our Customers

#615
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

In a lot of consumer devices, JTAG is at least partially disabled (sometimes they can throw a fuse that only lets you do boundary scan for manufacturing).

I would not be surprised at all that Apple's internal 'backdoor' (if you can call it that) is just resetting the security enclave, essentially erasing everything on the NAND. That'd be fine for refurb/manufacturing, desirable even as that guarantees that full system wipes happen before a refurb goes to a new customer.

Re: A Message to Our Customers

#616

Earlier quoted context omitted.

What do you want thone other companies to get behind? They don't manufacture phones like Apple does, right...? Note that this letter says: "When the FBI has requested data that’s in our possession, we have provided it." Seels like that detail is getting very little attention in this announcement. Really? If the FYI requests any data, they hand it over...?

Would you complain about Apple handing in information to solve the murder of a loved one? Why is it always the "bad government" argument? It's not that it doesn't happen, but usually those requests are aimed towards more "mundane" cases. For example, I have friends who work in law (though not in the US), and the number 1 data request -which is revised by a judge, and only then given by companies- are call logs from t…

I'm all for supporting law enforcement efforts, but the wording seemed to imply that Apple hands over any requested info to the FBI, which seems excessive.

But I was mainly pointing out that quote because it wasn't clear what lesson the parent commenter wanted Google, Facebook, and Amazon to be learning from Apple. I would have guessed it'd have something to do with protection of user data, but the letter says they turn over any user data they have!

Re: A Message to Our Customers

#617

Earlier quoted context omitted.

What do you want thone other companies to get behind? They don't manufacture phones like Apple does, right...? Note that this letter says: "When the FBI has requested data that’s in our possession, we have provided it." Seels like that detail is getting very little attention in this announcement. Really? If the FYI requests any data, they hand it over...?

Would you complain about Apple handing in information to solve the murder of a loved one? Why is it always the "bad government" argument? It's not that it doesn't happen, but usually those requests are aimed towards more "mundane" cases. For example, I have friends who work in law (though not in the US), and the number 1 data request -which is revised by a judge, and only then given by companies- are call logs from t…

Can the information bring my loved one back to life? Or will it just result in more terrible things happening to someone else's loved one?

Re: A Message to Our Customers

#618

Earlier quoted context omitted.

What do you want thone other companies to get behind? They don't manufacture phones like Apple does, right...? Note that this letter says: "When the FBI has requested data that’s in our possession, we have provided it." Seels like that detail is getting very little attention in this announcement. Really? If the FYI requests any data, they hand it over...?

Would you complain about Apple handing in information to solve the murder of a loved one? Why is it always the "bad government" argument? It's not that it doesn't happen, but usually those requests are aimed towards more "mundane" cases. For example, I have friends who work in law (though not in the US), and the number 1 data request -which is revised by a judge, and only then given by companies- are call logs from t…

[deleted]

Re: A Message to Our Customers

#619
post #579

Earlier quoted context omitted.

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

They don't even have to do that. They wrote the OS, they have the signing key for OS updates. All they need to do is push an update to the device with a backdoor that allows reading off the unencrypted contents post-boot (possibly with the addition of a judicially compelled fingerprint scan or PIN brute force to get the encryption key out of whatever on-device escrow it's stored in). The only way to secure the device…

This is not really true. The secure enclave is a separate computer. It doesn't get software updates.

> possibly with the addition of a judicially compelled fingerprint scan or PIN brute force to get the encryption key out of whatever on-device escrow it's stored in

This is the whole problem. The keys are in the SE. You can't brute force the PIN because the SE rate-limits attempts (and that rate limiting cannot be overridden by an OS update because the SE is not run by the OS).

If you can get a fingerprint scan then all bets are obviously off, but then you don't need Apple at all.

Re: A Message to Our Customers

#620

Earlier quoted context omitted.

What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…

Did you read the release? They are up front that its entirely an issue about setting a bad precedent. Its completely and totally about the fact that it would be used over and over again, and nothing to do with the fact that is it possible. Your overly cynical stance on this is misguided, as you seem to not have grasped the information in the letter.

The court order says that the software must only work for the specific device in custody. Apple is not supposed to create a general tool.
Post reply on HN