Live data from Hacker News

A Message to Our Customers

apple.com

811–820 of 1001 posts

Re: A Message to Our Customers

#811
post #124

Earlier quoted context omitted.

What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…

> with the exception that providing an easy means to brute force a phone to the authorities sets a horrible precedent This is the entire concern (in my opinion and in my reading of Tim Cook's opinion). If the government can force Apple to backdoor this one iPhone (because terrorist), then they can force Apple to backdoor any iPhone for any person given a valid warrant, subpoena or otherwise granted power. Once the fl…

It's worse than that. There's no guarantee that "the government" is "your government".

Imagine this scenario:

1.) Apple creates the custom iOS build for the FBI to use to decrypt this iPhone.

2.) China hacks into either Apple or the FBI and downloads this build. (We know they have the capability, because it's already happened. [1])

3.) A visiting U.S. diplomat, politician, or military officer has his iPhone pickpocketed while in China. (This also happens all the time.)

4.) The Chinese government uses this stolen software to brute-force the encryption on the device, finding access codes for classified U.S. military networks. (Because we know U.S. diplomats never use their personal email for state business [2], right?)

5.) Now a foreign power has access to all sorts of state military secrets.

The problem with backdoors is they let anyone in. Right now, there's a modicum of security for Apple devices because knowledge of how you would bypass the device encryption is locked up in the heads of several engineers there. The FBI is asking Apple to commit it to source code. Source code can be stolen, very easily. Tim Cook's open letter is making the point that once this software exists, there is no guarantee that it will stay only in the hands of the FBI.

[1] https://en.wikipedia.org/wiki/Operation_Aurora

[2] http://graphics.wsj.com/hillary-clinton-email-documents/

Re: A Message to Our Customers

#812
I think there are two orthogonal questions:

* Does Apple pretend the FBI cannot access to its devices?

* Can the FBI access to its devices?

The only thing we learn here is the answer to the first question. We know nothing more for the second one.

Re: A Message to Our Customers

#813

Earlier quoted context omitted.

What's intimidating about sun glasses and ear pieces?

Nothing. Bringing a bunch of special agents along with you to a meeting is intimidating, though. I suppose in their defense, they may be the particular agents working on the San Bernadino case, who arrived to explain exactly why they need the access or whatever.

> Bringing a bunch of special agents along with you to a meeting is intimidating

Again, what is intimidating about that? The agency they were dealing with was the FBI, right? And that's the correct agency to deal with this matter, right?

Well in the FBI, 'special agent' simply means any worker who does investigatory work.

Re: A Message to Our Customers

#814

A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but…

Save people like me a trip to the Google: NSL = A national security letter (NSL) is an administrative subpoena issued by the United States federal government to gather information for national security purposes. NSLs do not require prior approval from a judge.

Re: A Message to Our Customers

#815

Earlier quoted context omitted.

But this all hinges on the naive assumptions that this is a one off and will never happen again, and that later generation devices are immune from any circumvention attempt. History says this isn't how this plays out. If you crack the encryption once you'll get orders to crack it again and again, and in much lower profile and lower stake cases. Look at the prevalence of espionage tactics such as Stingrays and "parall…

wrt to " Of you're arguing that iPhone 6= " The iPhone 5S and newer has a coprocessor (or co-computer) that has a hardware enforced rate limiter as part of one of the features of the "Secure Enclave" (which, word on the street is, cannot be overridden by software).

ORIGINAL: Physical access.

EDIT: It's not just physical access. Physical access chains the game entirely, but what the FBI is wanting highlights the physical access problem even more. They're wanting a custom software solution today, but there's nothing to say they can't want a custom hardware solution tomorrow. Sure the enclave has some sort of lock out now but who is to say you can't simply reflash the firmware or perhaps just solder in some jumpers? Make no mistake. The FBI is wanting manufacturers to modify devices on demand.

Re: A Message to Our Customers

#816

Earlier quoted context omitted.

>>> I am really glad that one of the most valuable companies in the world is drawing a bright line in the sand. So I really support Tim's position on this one. Tim's position today might not be apple's position tomorrow. Apple is a large publicly traded company. They owe a duty only to shareholders. Fighting this fight will probably impact the bottom line. Tim's continuation may turn on the outcome. Cooperation may s…

> the US government is Apple's largest customer I'm having trouble finding numbers, but I seriously doubt this. The reason that's true (or more likely true) for Microsoft, is Windows. The US gov't has massive site licenses for Windows and most of MS's software portfolio. Apple is used where in the US government? Some cell phones? A few public affairs offices that convinced their purchasing officer to buy a Mac Pro fo…

I agree with your general point (which I take to be, Apple is not seriously threatened by loss of sales to the US Government).

But remember, iPhones and MacBooks are quite popular everywhere, including US government procurements (e.g., https://37prime.wordpress.com/2012/08/05/nasa-mars-science-l...).

Re: A Message to Our Customers

#817

Ok, so I completely fail to see how a random crazy guy with a gun who shoots up a bunch of unarmed people has "national security implications". This seems to be a "fact" that everyone wants to agree on, but is frankly a load of BS if one considers the government probably already has his entire call/texting history for the last couple years. I see this as just another "its for the children" ploy, of which I'm complete…

If it was many of the shootings perpetrated by non-muslims every day in the US, they wouldn't have cared. But because these Americans were muslims they need to scan their phones and make sure they weren't getting orders from some terrorist network.

Does it really matter? Most terrorist networks would be claiming responsibility for the attack if they were involved.

Re: A Message to Our Customers

#818

Earlier quoted context omitted.

But it's more interesting to think about the case where the phone does have a secure enclave.

In that case, they could just bring the phone down to the morgue and unlock it with touch id.

If the phone is rebooted or if 48 hours have passed since the last passcode was entered, the touch ID can't be used to unlock the phone.

Re: A Message to Our Customers

#819

Earlier quoted context omitted.

It's not just PR. It's actually really hurting their company. Weaker security means less data can be stored on the iPhone which means less need for it, which means fewer sales.

Thank you for answering one of my questions: "Why does a multi-billion-dollar company give one lick about personal freedom ?". Companies exist to make money, not to protect our rights. It even crossed my mind that the possibility that NSA et. al. rooted these devices long ago, and that this whole "debate" is just a staged thing to make it appear as though we had any privacy and feigned adherence to the democratic pro…

Same here. I find this doubly reassuring.

Re: A Message to Our Customers

#820

In the future, once terrorists have TouchID iPhones, couldn't they just use the corpse's finger to unlock the phone?

Touch ID can't be used if

- The phone was turned rebooted

- It's been more than 48 hours since the last time the passcode was entered

- The user didn't set up a touch ID fingerprint

Post reply on HN