Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

331–340 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#331

Earlier quoted context omitted.

I think my comment was misinterpreted. Our legal system is a part of our government, which is a representative democracy. Part of the idea behind a representative democracy is that it is designed to protect the minority from majority mob rule. By definition, edge cases are cases that fall outside of the normal majority. Our legal system is fuzzy because it is operated by humans, not silicon. The design of a case law…

I disagree, I think precedent reduces fuzziness because it shows how the law has been interpreted in the real world. No cases are identical, but knowing how a similar situation was handled in the past clarifies, not confuses the situation. It gets us closer to a consistent interpretation of the law, which is, in my opinion, paramount because consistency ideally means predictability and equality. Indeed the roots of t…

From my parent comment:

The design of a case law system however, which the U.S. operates under, is intended to minimize fuzziness by looking at case precedent for guidance on issues moving forward.

Aren't we in agreement?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#332

Earlier quoted context omitted.

So all the FBI has to do is desolder the flash chips and hope it was a weak passcode? Seems like they're just hoping to use this as an opportunity to set a precedent. Never let a serious crisis go to waste? Also hasn't Apple been able (and previously willing) to unlock pre-Secure Enclave phones for law enforcement for... ever?

No, because the flash chips are only decryptable when they're installed in the phone. The user's passcode is tangled with a long key burned into the SoC, so you need both to decrypt the flash.

Is that true of non-Secure Enclave phones like the 5C?

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#333

Earlier quoted context omitted.

> I'm NOT for backdoors I think you've just learned that you are, in fact, for backdoors. A backdoor doesn't become any less of a backdoor when it's only used against bad people.

No, don't put words into my mouth. I think Apple should go to some extraordinary means to assist here. Any system is hackable if have physical possession and control over the input.

It's true that we haven't seen perfection yet, but there are tamper-resistant devices where the above is not trivially true. If each device were protecting the same keys or we just needed to break the platform, I might be more inclined to agree, but given that they have individual keys and a failed break could leave the data unobtainable, I'm not so confident.

That said, I think this particular phone doesn't have the secure enclave, so it may be breakable here.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#334

Earlier quoted context omitted.

I disagree, I think precedent reduces fuzziness because it shows how the law has been interpreted in the real world. No cases are identical, but knowing how a similar situation was handled in the past clarifies, not confuses the situation. It gets us closer to a consistent interpretation of the law, which is, in my opinion, paramount because consistency ideally means predictability and equality. Indeed the roots of t…

From my parent comment: The design of a case law system however, which the U.S. operates under, is intended to minimize fuzziness by looking at case precedent for guidance on issues moving forward. Aren't we in agreement?

But then you go on to speak of edge cases that precedent can't deal with, but I would argue that your view of case law as essentially "algorithmic" is flawed. Obviously precedent cannot be exact, but using prior interpretations helps guide thinking.

For example, look at Katz v. US, one of the seminal cases that would inform this case. In Katz, the court starts with existing law, one that prevents illegal searches, and tries to decide whether that law can apply to electronics (such as tapping a phone). At this point the OCCSSA is in effect, but not really tested, so we've got a pretty fuzzy legal area despite the fact that phones are a well established technology. The court rules that even though law enforcement did not search or seize things, that privacy is still implied in electronic communications because of other acts a user takes surrounding the act of making a phone call (closing the door, making the phone call from home, etc.).

In fact, there's a whole legal concept at work here called lawful intrusion that is built upon every time a case is judged. These concepts, and human application of them to the case at hand, help attorneys, judges and juries deal with edge cases.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#335
post #325
post #4

Remember, this is an iPhone 5C, which doesn't have Touch ID or the Secure Enclave; the security model for this phone is significantly different from that of more recent iPhones. On phones with a Secure Enclave, the wipe-on-failures state is managed in the coprocessor (which runs L4), and is not straightforwardly backdoor-able. If you're worried about the police brute-forcing your phone, enable Touch ID and set a pass…

I was under the impression that law enforcement can coerce you to put your finger on the touch pad to unlock your device much easier than they could coerce you to provide the pass code. I have Touch ID disabled on my device for exactly this reason. Is that not the case?

The FBI is trying to set a precedent but the phone in question is an iPhone 5c.

If the device in question was an iPhone 5s or above, then all they'd need is the dead man's hands.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#336

Earlier quoted context omitted.

Because designing a law that makes sense when interpreted strictly formally is a friendly-AI-equivalent problem, i.e. it requires figuring out what values humans actually care about and then implementing it in a system that can outsmart anyone trying to game it. Failing that, people will get hurt by corner cases in such a law, or suffer abuse from people gaming the system.

There is a different point to be made here though. You can't predict everything ahead of time, but what do you do when somebody finds an edge case? For the future the answer is obvious. You consider the edge case, decide what to do what it happens, publish the decision and follow it from now on. The real question is, what do you do for the person who fell into the edge case before it was decided? And the problem with…

I think there's yet another point to be made here. In an imperfect world, where we can't design axiomatic systems that are corner-case free and where we can't get stuff right on the first try, the judge's flexibility seems like a necessary safeguard against the letter of the law totally missing its spirit. I like to imagine it as a grease, a lubricant - you need to apply it, or else minor imperfections will grind your machine down.

A fundamental question here is - do you want the law to be a completely trustless system? Sticking to the letter of the law and enumerating all imaginable corner cases are examples of going into that direction.

I'm not totally convinced trustless systems are a good idea for society, because of inefficiencies they introduce as a cost of not having to trust anyone.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#337

Earlier quoted context omitted.

The fact that courts don't have ways to handle edge cases is a huge problem with our case law style legal system.

They do have ways to handle edge cases: judges. They are imperfect and I'm sure you can find much wrong with the courts, but attempting to codify every edge case is not only impossible, but dangerous. The more laws you create, the more likely you can find a way you're breaking one. It's not a perfect system, but a cornerstone of American democracy is that you are judge by people , people like you, not by an algorithm…

> ...people, people like you...

We've been reminded again and again by recent events how horribly wrong things can go when the is system is applied to people who are not like the judge/jury/officers/etc. There's got to be a better way than relying on inherently biased people, especially for commonly persecuted groups (minority races/orientations/occupations).

I think when someone says they want an axiomatic or algorithmic legal system, they're saying people are not like them, and they would rather be judged by an algorithm. Also that they would rather know in advance what behaviors will be judged positively or negatively.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#338
If Apple is capable of compromising security on its devices (by using its root key to sign a custom version of iOS, or through some other method), then I see no way that they will avoid eventually being subject to a court order in some jurisdiction that compels this action. If that's true, then device security is already compromised and Apple knows this. Let's say the facts of the case were slightly different, that the FBI "knows" a terrorist attack is about to occur, and Jack Bauer-style demands that Apple assist in compromising a specific device that has the top seekrit plans on it. In that instance, do you think Apple would comply with a warrantless request for cooperation? Hm...

Reading Tim Cook's announcement in light of this thought experiment, methinks he doth protest too much! Apple does not have any objection to compromising user security at the root level, and in fact has already done so by creating a device that has some limited vulnerability to malicious action by the manufacturer signed with its root key. (By the way, no doubt every other manufacturer has done worse, so this is not to deprecate Apple vs. any other big company.)

I would speculate that Tim Cook's goals with this announcement are largely PR-based, and that the goal of Apple's legal strategy is not to avoid cooperation but rather to retain the ability to decide whether to cooperate, and/or to impose a higher perceived cost on the government for such requests. No doubt Apple is correct to say that once a precedent is established, then it will be widely used by law enforcement even in routine cases.

At the end of the day, I am not optimistic that we can avoid a world in which large device manufacturers are compelled (legally and practically) to build security flaws into their devices. Perhaps not the flaw of a back-doored crypto implementation, but other flaws such as those that have been identified in current iOS devices that allow the government (with commitment of sufficient resources) to chip away at some of the more superficial protections.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#339
post #85

The 5th amendment protects evidence inside the brain of the accused. As devices becomes more and more an extension of the brain, the more I think we'll need to adjust the rule of the 5th amendment to cover things outside of the brain.

Regardless, this wouldn't apply in this case however. The device wasn't the shooter's to begin with. He didn't own it. His employer did. They've already given permission to access the device.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#340

Earlier quoted context omitted.

They do have ways to handle edge cases: judges. They are imperfect and I'm sure you can find much wrong with the courts, but attempting to codify every edge case is not only impossible, but dangerous. The more laws you create, the more likely you can find a way you're breaking one. It's not a perfect system, but a cornerstone of American democracy is that you are judge by people , people like you, not by an algorithm…

> ...people, people like you... We've been reminded again and again by recent events how horribly wrong things can go when the is system is applied to people who are not like the judge/jury/officers/etc. There's got to be a better way than relying on inherently biased people, especially for commonly persecuted groups (minority races/orientations/occupations). I think when someone says they want an axiomatic or algori…

I understand this, and if I thought it were possible, I would agree.

However...

The law is essentially trying to codify a moral code, one that changes with time. We've seen how the law struggles with changes to technology, lifestyle and shifting attitudes. But sometimes the very axioms change (see slavery, suffrage, common law). Because the law cannot keep up with changes, we're stuck with messy human interpretation to smooth over some of those rough edges. Something like Brown v. Board of Education, which seems obvious in retrospect, may not have occurred in an axiomatic system (perhaps Plessy v. Ferguson may not have occurred either, though considering the primary axiom that American law is based on once said that blacks were 3/5 of a human, I find that unlikely).

I would argue that we ought to try to introduce algorithms into the enforcement of the law (policing, traffic enforcement, jury selection, public defenders, etc) rather than the interpretation of it. Of course, one could argue mass surveillance is exactly that, so I don't know.

Post reply on HN