Live data from Hacker News

A Message to Our Customers

apple.com

781–790 of 1001 posts

Re: A Message to Our Customers

#781
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Like you, I appreciate the sentiment - happy to hear Apple speaking up. However this shouldn't change how we use Apple products. I operate under the implication that the device is compromised from the factory. Closed source software cannot be trusted, good faith is not enough.

Considering how many massive, gaping security flaws have been found in Open Source software in the last year or so alone that have been in place for years or decades, I think we can say that open source software cannot be trusted either.

Re: A Message to Our Customers

#782
post #652

Earlier quoted context omitted.

The device in question does not have a secure enclave. It's a 5c.

But it's more interesting to think about the case where the phone does have a secure enclave.

In that case, they could just bring the phone down to the morgue and unlock it with touch id.

Re: A Message to Our Customers

#783
post #518

Earlier quoted context omitted.

I wish people would stop lumping Apple with Google/Facebook with regards to privacy. Apple has implicitly for a long time, and lately much more vocally, cared about privacy. They don't have the same data-driven business model that Google and FB do.

Actions speak louder than words. The most revealing test of the strength of a company's commitment to privacy is how it handles situations when privacy can conflict with profits. Privacy on the internet relies critically on browsers only trusting trustworthy certificate authorities. When CNNIC breached its trust as a certificate authority last year, Apple sat tight waiting for the furor to subside ( https://threatpos…

I would argue that handling security problems in general has not been Apple's strength historically.

I agree that failing to fix a problem like this in a timely fashion is bad, but sins of omission are generally judged differently than sins of commission, for better or worse. Apple failing to apply proper prioritization to security holes isn't the same as Apple collecting data to be sold to the highest bidder.

So, again, Apple should not be treated as equivalent to Google and Facebook. Feel free to judge them harshly, but don't paint them with the same brush.

Re: A Message to Our Customers

#784

To play devil's advocate: Mr. Cook expressed concern that "the government could intercept your messages, access your health records or financial data, track your location, or even access your phone's microphone or camera without your knowledge". As I read this I wondered, "what harm would actually happen if that occurred"? If the government did read my messages and get my health records & financial data and track my…

"Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say"

Re: A Message to Our Customers

#785

Earlier quoted context omitted.

That doesn't sound all correct. Assuming the phone holds an encryption key that can read/write local data, a software update could simply command it to decrypt all data and save it as a copy.

A device containing an encryption key that's just protected by a software password check would be absolutely useless. Part or all of the encryption key (maybe even the IV) is derived from the phone passphrase, this is why you can't just pop the NVRAM off a phone and try to find the key.

yes this is very interesting!

Re: A Message to Our Customers

#786

Earlier quoted context omitted.

If in pursuit of an active investigation (i.e. the devices are still in active use), a police agency could invoke the All Writs act of 1789, and have Apple be instructed to introduce security vulnerabilities, with the next regular upgrade of iOS, such that after the phone is upgraded, it can be captured by the FBI, or whatever police force is involved, and the data recovered. A large percentage (and presumably the th…

But this request was made specifically for the phone in the San Bernardino case. In which the owner is dead and the phone is locked. This implies it is possible for Apple themselves to apply an iOS update to a locked phone in order to disable the erase-on-repeated-failure feature.

The owner is alive, the phone is owned by the government and always has been.

Re: A Message to Our Customers

#787

Earlier quoted context omitted.

> The government isn't even asking them to crack the phone, they just want Apple to remove the limits so the government can try to brute force it. They're even paying Apple for their trouble. Well this exact thing isn't THAT big of a deal but it's a slippery slope. If Apple agreed to this then what else can the government ask them to do under the banner of "public safety"? And if Apple were to give the government an…

I don't see the slippery slope here. The government is asking Apple to do something that is both possible and reasonable. I see no slope to that from other typical court orders. Giving the government a way to brute force PINs wouldn't break the trust of every iPhone owner, merely the owners of iPhones with pre-A7 CPUs. And great, if they trusted Apple on this their trust was misplaced. You can't trust companies not t…

The slope is that if they can order Apple to engineer one thing, they can order them to engineer another.

It is possible for Apple to the weaken the secure enclave on all future iPhones. It would be reasonable to do so from the point of view of giving law enforcement a useful tool. Therefore since Apple can be ordered to do engineering to make law enforcement easier, why should they not be ordered to do this?

That is the slippery slope.

Re: A Message to Our Customers

#788

A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but…

What's intimidating about sun glasses and ear pieces?

Re: A Message to Our Customers

#789
post #601

Earlier quoted context omitted.

The problem is that once created, it would be easier for future warrants to ask Apple to simply re-perform the same trick it's done in the past. Apple's core argument is that allow this once opens the door to doing it repeatedly because right now Apple doesn't have the toolchain to do this. Once the toolchain exists, its deployment is trivial.

So? At least in American jurisdiction, the 4th Amendment doesn't guarantee the right to unbreakable crypto. It says: "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the p…

>I mean, let's get real for a second. The toolchain already exists. Apple has the source code, hardware simulators, debugging harnesses, and the original engineers. There's no magic. As long as those things exist, the danger of a hack getting public is real, especially if the source for iOS is ever stolen, or one of the core engineers goes rogue. If Apple's own internal security can't keep a more polished tool under wraps, they won't be able to keep the subcomponents of it under wraps.

>As long as those things exist This is false. Apple could hand you all the things you mentioned and you still wouldn't be able to break an iPhone 5C. You would still need Apple's master private encryption key.

As you are framing the question, is, the government should force Apple to hand over their private encryption keys. If thats so, should citizens in other countries be wary of the fact that their data stored in Apple servers are privy to the US govt? Or should Americans be worried that China can coerce Apple to hand over encryption keys?

In terms of global politics, The vault maker in this scenario has to worry about other strong men asking for such a master key when they need to hunt down gay men or something as trivial, once they realize this is possible.

Re: A Message to Our Customers

#790
post #601

Earlier quoted context omitted.

The problem is that once created, it would be easier for future warrants to ask Apple to simply re-perform the same trick it's done in the past. Apple's core argument is that allow this once opens the door to doing it repeatedly because right now Apple doesn't have the toolchain to do this. Once the toolchain exists, its deployment is trivial.

So? At least in American jurisdiction, the 4th Amendment doesn't guarantee the right to unbreakable crypto. It says: "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the p…

[deleted]
Post reply on HN