Live data from Hacker News

A Message to Our Customers

apple.com

861–870 of 1001 posts

Re: A Message to Our Customers

#861

A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but…

Save people like me a trip to the Google: NSL = A national security letter (NSL) is an administrative subpoena issued by the United States federal government to gather information for national security purposes. NSLs do not require prior approval from a judge.

Not only do NSLs not require approval from a judge, they also include a very intimidating gag order that prevents you from discussing the issue with anyone else (including even your own family).

One of the big problems with NSLs is that you can't let anyone know that you've received or acted on one, so there's very little accountability.

Hence the recent trend of some companies including a warrant canary on their websites, under the assumption that a NSL can't prevent you from _not_ saying something (e.g. deleting the canary).

Re: A Message to Our Customers

#862

Earlier quoted context omitted.

I agree. I was under the impression that Apple's security was such that even they didn't have the power to decrypt a device because the crypto made it impossible without the password/pin/key. I'm interested to understand the reasons that it was not done this way.

It sounds like it has been built that way - the data cannot be decrypted without the correct passphrase - but the user secured the phone with a 4-digit PIN, giving a mere 10,000 possible combinations - easily brute-forceable. The iPhone prevents this by locking up (and potentially erasing the phone) after 10 failed attempts, but this a restriction created in iOS. If they provision a new backdoored version of iOS to t…

To clarify, on A6 and earlier this is enforced in software. On A7 and later this is enforced in hardware.

Re: A Message to Our Customers

#863
post #827

Earlier quoted context omitted.

"I don't want to be deposed" I'm not familiar with that phrase. What does it mean in this context?

A deposition in the American judicial system is a legal proceeding in which a witness provides testimony to the courts. The witness may be examined by members of either sides legal team. This is a routine proceeding in civil cases. [0] Interestingly, people usually don't want to be deposed when they have something to hide. [0] http://litigation.findlaw.com/filing-a-lawsuit/what-is-a-dep...

https://www.youtube.com/watch?v=6wXkI4t7nuc

Re: A Message to Our Customers

#864

I see a lot of discussion about "Secure Enclave" and other hardware security features and such, and I'm not sure I see the relevance. Assuming that the data has already been properly encrypted, stored on disk, and purged from memory (by shutting down the phone) by a version of iOS that did not already contain a backdoor when the data was encrypted, there's no magic combination of hardware and software that can decryp…

Yes. The target phone, an iPhone 5C, lacks a Secure Enclave. The password retry delay, and subsequent deletion of keys, is enforced by iOS here. Apple could provide some kind of software to allow for unlimited attempts (and an interface to do so in an automated way, which the FBI is specifically asking for). On newer phones, the Secure Enclave contains the keys, and enforces both the retry delay and the deletion of i…

Ah, I see, so with newer hardware it wouldn't even be possible for Apple to enable brute forcing with a software update. But even with older hardware, presumably allowing brute forcing is still the worst they can do, right? (Assuming no prior backdoor exists.)

Re: A Message to Our Customers

#865

A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but…

Weirdly enough, I saw a blacked out SUV with Virginia plates and a CHP SUV in front of our office at 2nd and Harrison that looked extremely out of place. Among other things, it's a no stop area on our block and there isn't really much here to begin with.

It hung out for a few minutes and then made off taking a left on Harrison (101 South, FWIW). This was around 12:30p.

Re: A Message to Our Customers

#866
post #124

Earlier quoted context omitted.

> with the exception that providing an easy means to brute force a phone to the authorities sets a horrible precedent This is the entire concern (in my opinion and in my reading of Tim Cook's opinion). If the government can force Apple to backdoor this one iPhone (because terrorist), then they can force Apple to backdoor any iPhone for any person given a valid warrant, subpoena or otherwise granted power. Once the fl…

It's worse than that. There's no guarantee that "the government" is "your government". Imagine this scenario: 1.) Apple creates the custom iOS build for the FBI to use to decrypt this iPhone. 2.) China hacks into either Apple or the FBI and downloads this build. (We know they have the capability, because it's already happened. [1]) 3.) A visiting U.S. diplomat, politician, or military officer has his iPhone pickpocke…

[deleted]

Re: A Message to Our Customers

#868
Wow. This is the first HN submission to exceed 5,000 points!

To honour Tim, and his advocacy for our industry, I'm going to spend the rest of my week developing privacy/security projects. I encourage everyone else to do likewise.

Re: A Message to Our Customers

#869
post #787

Earlier quoted context omitted.

The slope is that if they can order Apple to engineer one thing, they can order them to engineer another. It is possible for Apple to the weaken the secure enclave on all future iPhones. It would be reasonable to do so from the point of view of giving law enforcement a useful tool. Therefore since Apple can be ordered to do engineering to make law enforcement easier, why should they not be ordered to do this? That is…

> The slope is that if they can order Apple to engineer one thing, they can order them to engineer another. How does that at all follow? Right now, a cop can lawfully order me to identify myself. Does that mean they can also lawfully order me to go to the nearest coffee shop dressed as Bozo the Clown and shout, "I am in love with the ghost of Princess Diana"? I don't understand how complying with an order to use an e…

Because the hole doesn't actually exist unless Apple engineers custom code for the FBI. If the FBI can force Apple to engineer code to create security holes for them, that establishes a precedent.

Explained better by someone else here: https://news.ycombinator.com/item?id=11120036

Post reply on HN