Live data from Hacker News

A Message to Our Customers

apple.com

901–910 of 1001 posts

Re: A Message to Our Customers

#901

Earlier quoted context omitted.

> at least one having MD License Plates Don't vehicles used by federal agencies typically bear U.S. Government license plates?

According to @HillRat in the other thread : "Based on open sources, NSA has a fleet of about 100 vehicles at most in CONUS, so they would be more likely to fly vehicles cross-country if DIRNSA needed to use a fleet vehicle. Having said that, NSA doesn't just arbitrarily get involved in domestic law enforcement cases, even ones involving crypto, so let's wait to see if there's more evidence than a random HN post to su…

The majority of federal government travel is done with commercially available rental cars.

The likelihood of the federal government driving a GSA-plate vehicle from Maryland to California to meet with Apple is about zero.

Re: A Message to Our Customers

#902
post #896
post #891

Earlier quoted context omitted.

I think deleting something would be considered an active action. The trick with a canary is that you're choosing not to do something, so it can't compel you to act (as compared to, for example, telling you you can't delete the canary). So for it to work, you need to issue a statement every month that says you haven't been issued a NSL, and then simply not issue a statement the month you finally were issued a NSL. Tha…

Interestingly, if you accept that code can be copyrighted, and that only things that are expressions (speech) are eligible for copyright ("A copyrighted work must be an original work of authorship which is fixed in a tangible medium of expression"), then code == speech. So, by compelling Apple to code something that doesn't exist, the government would indeed actually be compelling speech.

Compelling speech is a thing that happens under certain circumstances. E.g. subpoenas, witnesses in court. Though those are clearly different from a canary, not least because producing such a canary would not just be compelling speech, but compelling a lie.

Re: A Message to Our Customers

#903
post #869

Earlier quoted context omitted.

> The slope is that if they can order Apple to engineer one thing, they can order them to engineer another. How does that at all follow? Right now, a cop can lawfully order me to identify myself. Does that mean they can also lawfully order me to go to the nearest coffee shop dressed as Bozo the Clown and shout, "I am in love with the ghost of Princess Diana"? I don't understand how complying with an order to use an e…

Because the hole doesn't actually exist unless Apple engineers custom code for the FBI. If the FBI can force Apple to engineer code to create security holes for them, that establishes a precedent. Explained better by someone else here: https://news.ycombinator.com/item?id=11120036

I would argue that the hole is the fact that Apple can even load new software that allows this attack. It already exists.

But I'm not sure that distinction is important. The other comment you linked to lays it out pretty nicely and it doesn't rely on a hole existing it being created. It's ultimately just about compelling creation.

I wonder, what if the FBI just requested the relevant signing keys and source code? That seems like a much worse outcome, but at the same time less of a reach.

Re: A Message to Our Customers

#905

Earlier quoted context omitted.

>>> I am really glad that one of the most valuable companies in the world is drawing a bright line in the sand. So I really support Tim's position on this one. Tim's position today might not be apple's position tomorrow. Apple is a large publicly traded company. They owe a duty only to shareholders. Fighting this fight will probably impact the bottom line. Tim's continuation may turn on the outcome. Cooperation may s…

> Large contracts might be on the line should Apple not play ball. That almost certainly isn't the case. It is doubtful whether any other government organization cares about how they handle this case. Heck the FBI likely doesn't care as long as Apple doesn't do anything illegal.

Lots of places OUTSIDE the US will care, though. This is exactly the sort of $hite that is causing European companies and governments to avoid dependencies on US providers: there's no way to garauntee freedom from US government surveillance.

Re: A Message to Our Customers

#906
post #101

Earlier quoted context omitted.

Not all of CyanogenMod is free software (you still have a bunch of binary blobs, and everyone has to use Google Play Services anyway because every app seems to implicitly require it). Replicant would be a much better alternative if it actually supported anything newer than 2G.

> and everyone has to use Google Play Services anyway This isn't true. You can stick to app repositories like F-Droid and use Raccoon to download Play Store apps via your desktop without using a Google account on your phone.

Fdroid is wonderful. They even strip ads from otherwise foss projects since the licenses are usually not compatible.

Re: A Message to Our Customers

#907
post #883

Earlier quoted context omitted.

Nicholas Merrill famously fought a 11 year legal battle (and finally won) the right to reveal all aspects of a National Security Letter (NSL) served to him. Almost all such letters are accompanied by a complete gag order. https://www.calyxinstitute.org/news/federal-court-invalidate... EDITED / CORRECTIONS - Thanks commenters - The battle was won by Nicholas Merrill not Ladar Levison of Lavabit fame as I originally po…

It was Nicholas Merrill from a little ISP called Calyx Internet Access that famously challenged the NSL process. LavaBit's Lamar Levinson is assumed to be under a gag order from some request he was given by the US government, of which he declined by way of folding his company and claiming that he could not comply moving forward if he was no longer the middleman of some form of communications.

As a further correction, the Lavabit founder's name is spelled Ladar Levison.

Rather than making assumptions, you can read about the specific kinds of legal process involved in the Lavabit case at

https://en.wikipedia.org/wiki/Lavabit

You can also read the Fourth Circuit decision on his appeal, among other things.

Re: A Message to Our Customers

#908
post #881
post #852

Earlier quoted context omitted.

I guess you can argue semantics, but it's an order accompanied by a credible threat of violence if the order is not obeyed.

I know it requires Tim Cook to be willing to martyr himself, but do we really see Obama whisking the CEO of Apple Computer off to Guantanamo or some supermax prison? I'd maybe call the bluff, and take my political stand.

I presume it would just be significant fines, or perhaps some FCC or FTC regulations that would harm Apple's business.

Re: A Message to Our Customers

#909
post #891
post #861

Earlier quoted context omitted.

Not only do NSLs not require approval from a judge, they also include a very intimidating gag order that prevents you from discussing the issue with anyone else (including even your own family). One of the big problems with NSLs is that you can't let anyone know that you've received or acted on one, so there's very little accountability. Hence the recent trend of some companies including a warrant canary on their web…

I think deleting something would be considered an active action. The trick with a canary is that you're choosing not to do something, so it can't compel you to act (as compared to, for example, telling you you can't delete the canary). So for it to work, you need to issue a statement every month that says you haven't been issued a NSL, and then simply not issue a statement the month you finally were issued a NSL. Tha…

It's not necessarily deleting anything. Reddit states in its transparency reports that it has not received any NSLs. The idea is that if they ever received one they would simply omit that clause from the next report (not remove it from prior ones).

Re: A Message to Our Customers

#910

Earlier quoted context omitted.

The reasoning there is far from conclusive. The argument is that the secure enclave has been updated in the past (to lengthen enforced delays) without wiping user keys. However, without more information, this does not tell us whether it is possible in this case. The obvious implementation for a secure enclave resisting this sort of attack is to only allow key-preserving updates when already in unlocked state (which w…

You can't update the firmware on the SE without unlocking the device first.

We assume.

I'm also confused by a lot of this since don't you need the password anyway to upgrade?

Post reply on HN