Live data from Hacker News

A Message to Our Customers

apple.com

741–750 of 1001 posts

Re: A Message to Our Customers

#741

Earlier quoted context omitted.

> The government isn't even asking them to crack the phone, they just want Apple to remove the limits so the government can try to brute force it. They're even paying Apple for their trouble. Well this exact thing isn't THAT big of a deal but it's a slippery slope. If Apple agreed to this then what else can the government ask them to do under the banner of "public safety"? And if Apple were to give the government an…

I don't see the slippery slope here. The government is asking Apple to do something that is both possible and reasonable. I see no slope to that from other typical court orders. Giving the government a way to brute force PINs wouldn't break the trust of every iPhone owner, merely the owners of iPhones with pre-A7 CPUs. And great, if they trusted Apple on this their trust was misplaced. You can't trust companies not t…

"Per US versus Apple in the San Bernardino matter, we request a warrant be issued for encryption bypass in this (separate) matter".

Re: A Message to Our Customers

#742

Earlier quoted context omitted.

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

> That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security. No, they can't. A quick update to recent hardware practices: modern SoCs like Apple's have something called "Secure Enclave Processor" that's on-die. This is the first thing to start when the c…

[deleted]

Re: A Message to Our Customers

#743

Earlier quoted context omitted.

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

> They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security. When a passcode is entered, the SoC queries the Secure Enclave with the passcode. If the passcode is correct, the Secure Enclave responds with the decryption key for the flash storage. The best Apple could do is sign a…

> The best Apple could do is sign a malicious update to the Secure Enclave firmware that either removes the time delays or dumps the keys.

Dumping the Secure Enclave would not result in the keys necessary to read the files on the filesystem. Each file has a unique key, which is wrapped by a class key, and for some classes, the class key is wrapped by a key derived from the passcode. If you don't have the passcode, you can't unwrap any of the keys (Page 12 of https://www.apple.com/business/docs/iOS_Security_Guide.pdf).

Re: A Message to Our Customers

#744
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order

Because their SSL certificate authority is going to be the next one to be legally compelled to sign something.

Re: A Message to Our Customers

#745

There's a simple way to defeat Apple's argument. The judge could simply ask Apple to flash the new firmware on that phone, let the FBI run the brute force under their supervision and obtain the contents they need, and then flash back a non-compromised version of the OS. The government would never have access to a phone with a compromised version of an OS that they could use to repeat this trick. Rather, the governmen…

"The cynic in me thinks that this letter is more about brand image."

The cynic in me agrees. My cynic also notes the sudden indifference to corporate power publicly defying a federal judge. I cynically believe that if the shooters had been fundy white supremacists Apple would have quietly dumped the phone long ago.

Cook is no dummy and picks his battles with care. That's why he makes the big bucks.

Re: A Message to Our Customers

#746
post #652

Earlier quoted context omitted.

The device in question does not have a secure enclave. It's a 5c.

But it's more interesting to think about the case where the phone does have a secure enclave.

and yet it would be less interesting to consider if the password was a "six-character alphanumeric passcode with lowercase letters and numbers" because even if the software rate-limiting was disabled with a rogue firmware update, the PBKDF2 or similar iteration count makes brute-forcing impractical.

> A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 milliseconds. This means it would take more than 51⁄2 years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers

(Page 12 of https://www.apple.com/business/docs/iOS_Security_Guide.pdf).

Re: A Message to Our Customers

#747

Earlier quoted context omitted.

They need to break the boot trust chain to load unsigned code. Simply rewriting the flash isn't enough.

Why would the code be unsigned? If Apple wrote the backdoor OS, they could presumably sign it.

I incorrectly totally misread the OP and thought was talking about FBI flashing it themselves, without Apple help. Yes, of course Apple can sign it. I stand corrected but can't delete my comment.

To clarify, I agree that nothing they ask of Apple is technically impossible or even that difficult for Apple to pull off, probably via simple DFU without touching the flash at all.

Re: A Message to Our Customers

#749

If I were Cook, I'd draw a line in the sand. If we are force to comply, we exit the phone business, because we won't make phones that compromise our customer's security. But that would take more balls than anyone left here in this "Land of the free and home of the brave" seems to have left anymore.

Okay so ignoring the fact that this would be insane from a business perspective.

It also doesn't make sense from a game theory perspective, if you're a Good Company that's going to fight on this issue, it makes sense to be in business as long as possible to be a pain in the rear for authoritarian jerks. If every company who was willing to stand up to these guys went out of business immediately after you'd only have people who aren't willing left over.

Post reply on HN