Live data from Hacker News

A Message to Our Customers

apple.com

691–700 of 1001 posts

Re: A Message to Our Customers

#691
Wow this made my day. I think my faith in Apple's privacy concerns got a much needed revitalization. Privacy and encryption are the number one reason I stick with iPhone and Mac with File Vault. It was always hard to completely trust them after PRISM. However, that was arguably a different Apple.

This stance against the government come poetry reaffirms my faith in the genuineness of Apple'e encryption efforts and Tim Cook specifically.

Re: A Message to Our Customers

#692
post #666

Earlier quoted context omitted.

It's definitely one of those rare times doing the right thing is also the most profitable thing.

Doing the right thing is very often (if not almost always) the most profitable thing. It's very difficult to make a business out of serving your customers poorly; if you disagree, give it a shot, and let me know how it turns out for you.

Serving your customers well is good for profit, but it is not the same thing as doing the right thing. Ad-based companies have customers and users. By serving their customers too well they easily screw over the users, with obnoxious and even unethical ads.

Re: A Message to Our Customers

#693
post #634

Earlier quoted context omitted.

Why would it cause a significant drop? Where would those people go?

Not saying I necessarily agree (or disagree), but the premise is that right now iOS phones are the only ones that do security right, out of the box. They're worth the premium price for that feature. As soon as they no longer have that edge, there's no reason to choose them over any commodity Android device, so sales would drop as they lose their differentiating feature.

Not that they're more intuitive to use, have a higher quality app ecosystem, and "just work" for most people.

Re: A Message to Our Customers

#694
post #660

Earlier quoted context omitted.

Freedom from forced update is one of Stallman's motivations for free software. Just one terrorist attack + PR letter to customer + forced update away from loosing encryption on your phone.

On the other hand, if iOS were open source / the iPhone was able to run unsigned code there would be nothing stopping the FBI from just doing what they've asked apple to do themselves (assuming it's actually technically possible).

[deleted]

Re: A Message to Our Customers

#695
The All Writs Act is a United States federal statute, codified at 28 U.S.C. § 1651, which authorizes the United States federal courts to "issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law."

well, as far as I can see, it is not agreeable to the use and principle of law to force a company (or a person since corporations are people) to spend money and waste resources to compromise its own security systems, which happens to be something they morally object to.

Re: A Message to Our Customers

#696

Earlier quoted context omitted.

I think the missing information here is how the phone is encrypted. If it's done with the 4-digit numeric PIN, then the software could be built; it would take 10000 tries, but at less than .1 seconds per try, it would be able to crack the code in about 15 minutes. The current iPhone has a protection for this; after some number of tries, it will lock you out for increasing time intervals. This is the only way that the…

I mean this sincerely: has the government used one of its 10 tries on the attacker's birth year? I hope the government has burned a couple tries on low-hanging guesses before going through this legal hassle.

You don't want to burn any tries in case the Apple developers would need a few?

Re: A Message to Our Customers

#697
post #47
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

> Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. Why against hope?

When a US senator expressed upset with Wikileaks, Amazon shut them down. Not even a court order, just a tantrum from a politician. If you really think Amazon aren't cheerfully inviting the US government into their datacentres, you haven't been paying attention.

Re: A Message to Our Customers

#699
post #653

Earlier quoted context omitted.

This is not really true. The secure enclave is a separate computer. It doesn't get software updates. > possibly with the addition of a judicially compelled fingerprint scan or PIN brute force to get the encryption key out of whatever on-device escrow it's stored in This is the whole problem. The keys are in the SE. You can't brute force the PIN because the SE rate-limits attempts (and that rate limiting cannot be ove…

Fingerprint scan really isn't enough though since after a restart, iPhones require the password to be entered.

Because fingerprints are not sufficient to generate / recover KEKs from.

Re: A Message to Our Customers

#700
What's the potential fallout on this case? I assume Apple is appealing the ruling - what happens if the ruling is upheld and Apple refuses to comply (unlikely IMO, but what if)? Could the DOJ target individual Apple engineers and order them to do it or face contempt of court charges?
Post reply on HN