Earlier quoted context omitted.
I think the only problem here is the strongness with which it is worded. It would be fair to say one of the reasons he is doing it is because of stock price, but to assert the only reason he is doing it is to cast him as completely uncaring about security and privacy. Without evidence to back this up (in this case, evidence that he doesn't care about security and privacy), it's an attack on his character. It's entire…
He's an older gay man, I would be shocked if this didn't influence greatly his opinion in this realm. He's lived through some times that weren't too friendly to "his kind" that were open.
A Message to Our Customers
821–830 of 1001 posts
Re: A Message to Our Customers
#822Earlier quoted context omitted.
Dan Guido just tweeted otherwise: https://twitter.com/dguido/status/699992079594864640
The reasoning there is far from conclusive. The argument is that the secure enclave has been updated in the past (to lengthen enforced delays) without wiping user keys. However, without more information, this does not tell us whether it is possible in this case. The obvious implementation for a secure enclave resisting this sort of attack is to only allow key-preserving updates when already in unlocked state (which w…
Re: A Message to Our Customers
#823Earlier quoted context omitted.
But it's more interesting to think about the case where the phone does have a secure enclave.
In that case, they could just bring the phone down to the morgue and unlock it with touch id.
Additionally you don't have to use your thumb, so if you don't know what body part was used your out of luck.
Re: A Message to Our Customers
#824Earlier quoted context omitted.
> They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security. When a passcode is entered, the SoC queries the Secure Enclave with the passcode. If the passcode is correct, the Secure Enclave responds with the decryption key for the flash storage. The best Apple could do is sign a…
Where have you heard about the erase-on-update feature?
Re: A Message to Our Customers
#825Earlier quoted context omitted.
Nothing. Bringing a bunch of special agents along with you to a meeting is intimidating, though. I suppose in their defense, they may be the particular agents working on the San Bernadino case, who arrived to explain exactly why they need the access or whatever.
> Bringing a bunch of special agents along with you to a meeting is intimidating Again, what is intimidating about that? The agency they were dealing with was the FBI, right? And that's the correct agency to deal with this matter, right? Well in the FBI, 'special agent' simply means any worker who does investigatory work.
Re: A Message to Our Customers
#826Earlier quoted context omitted.
Nothing. Bringing a bunch of special agents along with you to a meeting is intimidating, though. I suppose in their defense, they may be the particular agents working on the San Bernadino case, who arrived to explain exactly why they need the access or whatever.
> Bringing a bunch of special agents along with you to a meeting is intimidating Again, what is intimidating about that? The agency they were dealing with was the FBI, right? And that's the correct agency to deal with this matter, right? Well in the FBI, 'special agent' simply means any worker who does investigatory work.
If you analyse each element closely it's clear that they're silly. Why do they need earpieces in when visiting Apple? Why must all the cars match? Why must they dress in the same way? Why do they need to bring all those people, what are they all doing?
But the point is, when faced with something new and strange, people often pause and withdraw. This allows you to dominate the situation and prevent dissent.
Re: A Message to Our Customers
#827A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but…
I'm not familiar with that phrase. What does it mean in this context?
Re: A Message to Our Customers
#828Earlier quoted context omitted.
Normally people on HN are much more skeptical about airy promises and assertions from corporate executives. I don't see what behavior on Tim Cook's part has indicated he's more to be trusted than anyone else.
Tim Cook was asked at a shareholder meeting to only do things that were profitable. He passionately rejected the idea, and named accessibility for the blind, environmental issues/climate change, and worker safety as areas where Apple invests because it's right, without considering the "bloody ROI". [1] Compare to GE, which rolled over [2]. So I believe Mr Cook when he says his opposition to the FBI's request is roote…
[Cook] didn't stop there, however, as he looked directly at the NCPPR representative and said, "If you want me to do things only for ROI reasons, you should get out of this stock."
That's a very blunt statement that the immediate stock valuation is not Cook's only consideration.
Some people seem to have a hard time taking Cook at his word, but he's been quite consistent. This massive skepticism feels more like nostalgie de la boue than anything based in facts.
Re: A Message to Our Customers
#829Earlier quoted context omitted.
I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…
It's not a backdoor, it's a frontdoor. In cryptography, there's no way to make repeated attempts more computationally expensive. The lockout just an extra feature Apple put on, that Apple could easily remove. If we're going to have 4- and 6- digit PINs, there is no way to stop a dedicated attacker frome brute-forcing it. None.