Live data from Hacker News

A Message to Our Customers

apple.com

911–920 of 1001 posts

Re: A Message to Our Customers

#911
post #894

Earlier quoted context omitted.

Cook wouldn't have to go that far. The court order specified Apple, not Tim Cook personally. He can simply resign instead of following the court order. For that matter, so can the engineers that Apple would need to work on this project.

That's interesting. IANAL but seems like you're missing something. Apple can simply let Employee B take Employee A's place after A quits. When the authorities come for B, B can quit, and Apple can re-hire A. Apple never has to comply.

If an order is directed to Apple, and Apple fails to comply, the court can order sanctions against Apple for contempt.

The authorities don't have to "come for" any person (they might follow up with orders directed at particular persons, in which case those persons would be at risk of personal sanctions, as well.)

Re: A Message to Our Customers

#912
post #827

Earlier quoted context omitted.

"I don't want to be deposed" I'm not familiar with that phrase. What does it mean in this context?

A deposition in the American judicial system is a legal proceeding in which a witness provides testimony to the courts. The witness may be examined by members of either sides legal team. This is a routine proceeding in civil cases. [0] Interestingly, people usually don't want to be deposed when they have something to hide. [0] http://litigation.findlaw.com/filing-a-lawsuit/what-is-a-dep...

Please tell me you said 'Interestingly, people usually don't want to be deposed when they have something to hide.' off-the-cuff.

I would associate this view/tone with a corrupt, small-town, sheriff in a movie, rather than a real, human citizen who shares the the values of our society, which includes due process, the right of the accused, and presumption of innocence.

Re: A Message to Our Customers

#913
post #826

Earlier quoted context omitted.

> Bringing a bunch of special agents along with you to a meeting is intimidating Again, what is intimidating about that? The agency they were dealing with was the FBI, right? And that's the correct agency to deal with this matter, right? Well in the FBI, 'special agent' simply means any worker who does investigatory work.

The way powerful people often maintain control of a situation is through contrivances such as unusual dress, unusual ways of speaking, unusual rituals or by having a large entourage. If you analyse each element closely it's clear that they're silly. Why do they need earpieces in when visiting Apple? Why must all the cars match? Why must they dress in the same way? Why do they need to bring all those people, what are…

[deleted]

Re: A Message to Our Customers

#914
post #41
post #17

Earlier quoted context omitted.

[deleted]

I don't have an iPhone so correct me if I'm remembering correctly but aren't they by default protected by a 4 digit numeric pin? A 4 digit numeric pin that a brute force attack can be used on is effectively no security/a backdoor imo.

I use an alphanumeric password on all my iOS devices

Re: A Message to Our Customers

#915
post #504

Earlier quoted context omitted.

And it'd seem to open the floodgates for certificate authorities to be compromised as well. What's to stop the FBI from compelling a CA to create a special MITM certificate for a criminal investigation of a Yahoo user?

What makes you think the FBI, or a certain assisting agency, don't already have CAs in their pocket? They only need one. The 'rogue CA' threat that encouraged the development of HPKP covers this scenario. Hell, DNS TLSA records (which are a part of the now dead DANE concept) let you pin to any combination of PKI CA, public key, or certificate. One day we'll regret not deploying this stuff.

HPKP at least is growing and getting attention. I would have prefered to do the pinning on TLS level instead of http level. Sadly Tack (see tack.io) was to late and HPKP was already to far along and supported by google.

DNSSEC has some value, and DANE does as well, but sadly both are stuck in a strange limbo. Pinning can be deployed now and add a huge amount of security. Even if we had DANE, we would still want to have pinning.

There are interesting ideas how you could scan the internet and it pins and publish this information in a secure way. Then you back this trusted site pin into your browser. Its a similar ideas like Certificat Transparancy. A browser could then load itself with all the needed pins or verfy them on demand. One could also get preloaded pins from a trusted party, or use network vision to check with many different parties on first use. Lots of options once everybody has TOFU.

This combination of Network Vision and TOFU would be quite nice and CA could be replaced, at least for non EV.

Re: A Message to Our Customers

#916

Earlier quoted context omitted.

> Interestingly, people usually don't want to be deposed when they have something to hide. You know who really talks a lot about their rights? Terrorists.

This is both patently false and the single most deeply un-American mindset you can have. Your statement is so deeply naive and insulting to the patriots who fought for the rights you enjoy today. Those who made major strides for: 1) Black Civil Rights 2) Gay Marriage 3) Women's Rights 4) Anyone who fought government intimidation based on speech 5) Democratic Socialists 6) Abortion Activists 7) Environmentalists 8) Yo…

As sibling says, you're being downvoted because you've failed to recognize sarcasm.

Re: A Message to Our Customers

#917

A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but…

This is all very standard for a VIP visit and the president of Indonesia was at Facebook and Twitter today. So there's probably a simpler, less exciting explanation here.

Re: A Message to Our Customers

#918

Earlier quoted context omitted.

The government wants Apple to disable the auto-erase after so many unlock attempts. Apple argues in this letter that with modern computing power, this amounts to a backdoor. The details of the gov't request are in another story on the HN front page https://www.techdirt.com/articles/20160216/17393733617/no-ju...

The encryption key used on the root filesystem is too hard to brute force. It's not based on some crappy password that a human created, it's some hash value stored in the hardware. In a scenario like that it is easy to create a key that would require all of the computers working till the heat death of the universe to crack.

They're not trying to brute-force the encryption key. They're attempting to brute-force the PIN lock on the phone. Currently they can't because the settings on the phone cause a timeout after each unsuccessful login, the phone wipes after 10 failed attempts, and the PIN cannot be accepted from anywhere except the device display. These are the security functions that the FBI wants Apple to remove. They want to be able to hook up a computer via the lightning cable to brute-force the PIN and give them access to the phone's contents.

Re: A Message to Our Customers

#919

Earlier quoted context omitted.

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

> That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security. Is this true? That would have to mean that either the passphrase is stored on the device or that the data is not encrypted at rest. Neither of these sound likely, frankly

It doesn't have to mean any of that. As long as the 10 mistakes limit is enforced in software or in a separate chip that can be replaced without replacing the actual encryption key, it can be bypassed. Then it is a simple matter of simply brute-forcing the pin code. Since these are usually 4 digits, there's only 10000 possibilities, which is laughable to a brute force attacked.

Re: A Message to Our Customers

#920

Earlier quoted context omitted.

I think the only problem here is the strongness with which it is worded. It would be fair to say one of the reasons he is doing it is because of stock price, but to assert the only reason he is doing it is to cast him as completely uncaring about security and privacy. Without evidence to back this up (in this case, evidence that he doesn't care about security and privacy), it's an attack on his character. It's entire…

He's an older gay man, I would be shocked if this didn't influence greatly his opinion in this realm. He's lived through some times that weren't too friendly to "his kind" that were open.

He's pretty much said so:

We still live in a world where all people are not treated equally. Too many people do not feel free to practice their religion or express their opinion or love who they choose. A world in which that information can make a difference between life and death. If those of us in positions of responsibility fail to do everything in our power to protect the right of privacy, we risk something far more valuable than money. We risk our way of life.

See pages such as http://qz.com/344661/apple-ceo-tim-cook-says-privacy-is-a-ma...

Post reply on HN