Live data from Hacker News

A Message to Our Customers

apple.com

771–780 of 1001 posts

Re: A Message to Our Customers

#771

Can someone explain this to me: if the data is encrypted, how does switching the operating system out enable one to read the data? I'm a layman in this area but I can only surmise that the data is stored unencrypted and it's the operating system itself that's somehow locked. If a change of operating system can open up encrypted data, then what's the point of encrypting hard drives or data sent over a network?

It doesn't. Changing the OS allows removal of the anti-bruteforcing feature(s): the delay between attempts that increase exponentially, or the delay limit of 10 where the encryption key(s) are deleted and in effect all user data. This may not be possible on iPhones with secure enclave though, the anti-bruteforcing is in part built into the secure enclave, but the iPhone 5c in question in this case doesn't have a secure enclave so it might be possible. And further they want an automated way to iterate the password. Basically they want a backdoor to make it easier to bruteforce the phone through guessing the passphrase.

So there is nothing for Apple to hand over. There are no actual keys (they're on the phone itself in an unaccessible way, practically). The court order in effect orders them to write a derivative OS without bruteforce inhibition features. They probably can do that, it probably isn't burdensome, but is it legal to compel a company to write code? Can a court order you to write a book? Or a letter? They can make you turn over facts or evidence, but it's specious they can make you create something, even if you have the capacity to create it.

Re: A Message to Our Customers

#772

Earlier quoted context omitted.

1) They're not saying they don't want to help investigate the SB shooters, only that the order illegally expands the use of the All Writs Act and sets a bad precedent for democracy. 2) If they beat the order then the FBI needs to find a new way to compel Apple to help them do shit. That likely means the FBI needs federal legislation passed, which in the current climate will buy Apple considerable time. This is why th…

But this all hinges on the naive assumptions that this is a one off and will never happen again, and that later generation devices are immune from any circumvention attempt. History says this isn't how this plays out. If you crack the encryption once you'll get orders to crack it again and again, and in much lower profile and lower stake cases. Look at the prevalence of espionage tactics such as Stingrays and "parall…

wrt to "Of you're arguing that iPhone 6="

The iPhone 5S and newer has a coprocessor (or co-computer) that has a hardware enforced rate limiter as part of one of the features of the "Secure Enclave" (which, word on the street is, cannot be overridden by software).

Re: A Message to Our Customers

#773

If I were Cook, I'd draw a line in the sand. If we are force to comply, we exit the phone business, because we won't make phones that compromise our customer's security. But that would take more balls than anyone left here in this "Land of the free and home of the brave" seems to have left anymore.

Okay so ignoring the fact that this would be insane from a business perspective. It also doesn't make sense from a game theory perspective, if you're a Good Company that's going to fight on this issue, it makes sense to be in business as long as possible to be a pain in the rear for authoritarian jerks. If every company who was willing to stand up to these guys went out of business immediately after you'd only have p…

It's no longer a business issue, and if it is, then Apple is just posing.

Apple's positive affect on our economy, our technology, and even our nation, would make such a line that our government would have to think long and hard about pursing their demands.

Imagine if Apple, and the tech community as a whole, stood behind that decision. Of course they won't because they rather be rich than free.

Re: A Message to Our Customers

#774
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

it's probably pretty safe to assume google did the opposite

Re: A Message to Our Customers

#775
post #391
post #355

Earlier quoted context omitted.

Would it be infeasible to construct part of the private key out of hardware-specific id's + time-of-creation hashes? I assume it's not only the PIN?

That's what the A7 (iPhone 5S and later) design does: “Each Secure Enclave is provisioned during fabrication with its own UID (Unique ID) that is not accessible to other parts of the system and is not known to Apple. When the device starts up, an ephemeral key is created, entangled with its UID, and used to encrypt the Secure Enclave’s portion of the device’s memory space. Additionally, data that is saved to the file…

Thanks for the link! I knew there had to be more technical information out there but couldn't find it on an initial search.

Re: A Message to Our Customers

#776

Earlier quoted context omitted.

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

>>> I am really glad that one of the most valuable companies in the world is drawing a bright line in the sand. So I really support Tim's position on this one. Tim's position today might not be apple's position tomorrow. Apple is a large publicly traded company. They owe a duty only to shareholders. Fighting this fight will probably impact the bottom line. Tim's continuation may turn on the outcome. Cooperation may s…

> the US government is Apple's largest customer

I'm having trouble finding numbers, but I seriously doubt this. The reason that's true (or more likely true) for Microsoft, is Windows. The US gov't has massive site licenses for Windows and most of MS's software portfolio. Apple is used where in the US government? Some cell phones? A few public affairs offices that convinced their purchasing officer to buy a Mac Pro for video editing? Maybe some labs that wanted a unixy OS and, again, convinced their purchasing officer to buy a Mac Pro?

Per: http://investor.apple.com/secfiling.cfm?filingid=1193125-14-...

The bulk of Apple's revenue comes from outside the US. Perhaps the US government is their largest single customer (I still hold this is a dubious claim), but it is not essential to their continued existence. They would do just fine without those sales.

Re: A Message to Our Customers

#777
To play devil's advocate:

Mr. Cook expressed concern that "the government could intercept your messages, access your health records or financial data, track your location, or even access your phone's microphone or camera without your knowledge".

As I read this I wondered, "what harm would actually happen if that occurred"? If the government did read my messages and get my health records & financial data and track my whereabouts, I can't think of anything bad that would actually happen as a result of that.

Is there anything specific that I should be worried about in that scenario?

Re: A Message to Our Customers

#778

Earlier quoted context omitted.

Meh. Then the attacker can simply replace the hardware. Remember, our attacker model is Apple; non-cryptographic security measures mean very little to a company with such complete knowledge of the hardware and software involved.

Nope. On newer devices the key is derived from a random key fused into the SE during manufacturing, a key fused into the ARM CPU, and a key randomly generated on-device during setup (derived from accelerometer, gyro, and altitude data) and stored in the SE. The SE's JTAG interface is disabled in production firmware and it won't accept new firmware without the passcode. You can't swap the SE or CPU around, nor can you…

Can't you? Seems like the kind of problem you can point an electron microscope at, and perhaps some very high precision laser cutting. In any case, I imagine if you are willing to spend resources on it, you could read the on-chip memory somehow and start cryptoanalysing that.

Against a sufficiently capable adversary, tamper-resistance is never infalible, but good crypto can be.

Re: A Message to Our Customers

#779
A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but given Tim's message last night, as well as the reaction of folks on campus who were bandying about comments like "I don't want to work on this or because I don't want to be deposed" the impression certainly was it was not a friendly visit. Given Tim's very public push-back I'd think delivery of an NSL with accompanying intimidation is at least possible. I submitted this HN and updated in real-time. There's a bit more discussion here:

https://news.ycombinator.com/item?id=11120365

Re: A Message to Our Customers

#780

Earlier quoted context omitted.

Is there a list of sensibly built phones available? I'd like to buy a phone where the modem and SIM do not have access to main memory (AIUI most phones use a single-chip SoC with a built-in modem).

What's the point of accessing main memory in a locked and encrypted phone?

Main memory is rarely encrypted, unless you have special security features in your CPU to do so. Only the disk is encrypted; main memory is vulnerable while running. Also see https://en.wikipedia.org/wiki/Cold_boot_attack

So you don't want any hardware to have access to main memory if it doesn't need to. For instance, you can use an IOMMU to ensure that devices can only access the specific areas the OS wants to allow them to DMA to/from, not all of memory.

Post reply on HN