Live data from Hacker News

A Message to Our Customers

apple.com

941–950 of 1001 posts

Re: A Message to Our Customers

#941
post #761

If I understand correctly, any piece of software that would be used would need to be signed by Apple. Furthermore, the FBI's warrant(?) says specifically that it would only need to work for one device ID. Thus it would be relatively straightforward to create an update for the FBI that could pretty clearly only be used on the phone in question. Unless the FBI had Apple's signing key they could not reuse the software (…

> would be relatively straightforward to create an update for the FBI that could pretty clearly only be used on the phone in question How? Wouldn't the FBI reverse engineer it? It seems like apple would have to update all phones to a new version (which would prevent the exploit provided to the FBI) before handing it to them.

It's not that reverse engineering is difficult - the FBI could theoretically do that now. It's that it needs to be signed to be accepted by the phone.

Edit: see, for example, here: https://stratechery.com/2016/apple-versus-the-fbi-understand...

Re: A Message to Our Customers

#942
post #869

Earlier quoted context omitted.

Because the hole doesn't actually exist unless Apple engineers custom code for the FBI. If the FBI can force Apple to engineer code to create security holes for them, that establishes a precedent. Explained better by someone else here: https://news.ycombinator.com/item?id=11120036

I would argue that the hole is the fact that Apple can even load new software that allows this attack. It already exists. But I'm not sure that distinction is important. The other comment you linked to lays it out pretty nicely and it doesn't rely on a hole existing it being created. It's ultimately just about compelling creation. I wonder, what if the FBI just requested the relevant signing keys and source code? Tha…

Why is that less of a reach?

Re: A Message to Our Customers

#943
#)WATCH BOX OFFICE MOVIE NOW!! Find the Film click here MOVIE FREE https://t.co/nLGLMehTaI & here TV MOVIE SHOWS https://t.co/zJWRHf75RF

*)My website provides a lot of movie box office include: Jurassic World Trailer (2015) The Stanford Prison Experiment Trailer (2015) Ex Machina Trailer (2015) Ant-Man Trailer (2015) The Wedding Ringer Trailer (2015) Child 44 Trailer (2015) Poltergeist Trailer (2015) Aloha Trailer (2015) Faith of Our Fathers Trailer (2015) Terminator Genisys Trailer (2015) Mad Max Fury Road Trailer (2015) Jupiter Ascending Trailer (2015) The Age of Adaline Trailer (2015) Cinderella Trailer (2015) The DUFF Trailer (2015) Entourage Trailer (2015) Danny Collins Trailer (2015) Bedlam Trailer (2015) Southpaw Trailer (2015) Little Boy Trailer (2015) Chappie Trailer (2015) Zon 261 Trailer (2015) Maggie Trailer (2015) Rage Midsummer's Eve Trailer (2015) Tomorrowland Trailer (2015) Anegan Trailer (2015) Ex-Free Trailer (2015) Insectula! Trailer (2015) Inside Out Trailer (2015) McFarland Trailer (2015) and many other box office movies

Re: A Message to Our Customers

#944
post #292

Earlier quoted context omitted.

My understanding is that the iPhone 5C is not _simple_ to brute force as sold from the store. The FBI is asking Apple to weaken the software in this particular one enough for them to be able to brute-force by creating custom software that would allow them to try millions of passcode combinations rapidly. In the past law enforcement could use their own tools and Apple didn't have any legal way to say "it is beyond our…

> After their name showed up on that slide in the Prism leak without their cooperation (meaning they had been stepped around by the FBI. Some of the earlier companies had willingly volunteered data) I know it's a bit off topic but I'm really curious about this - do you have a source that shows which companies willingly volunteered data and which were stepped around? I wasn't aware that anything like that had come out…

> I wasn't aware that anything like that had come out.

You're not aware of nothing like that ever come out. The guy just made it up (or it's just his wishful thinking). We still don't know which companies cooperated with the NSA.

We do know that Google didn't intend for its traffic between data centers to be scooped up - and that has been fixed in the meantime - but that doesn't prove that Google didn't cooperate in other matters.

Same with Apple. For all we know, they are all gagged due to NSLs.

Re: A Message to Our Customers

#946

Earlier quoted context omitted.

With a sensibly-built phone, that SIM card does not have the ability to access anything of value on the device.

Is there a list of sensibly built phones available? I'd like to buy a phone where the modem and SIM do not have access to main memory (AIUI most phones use a single-chip SoC with a built-in modem).

The iPhone, for one.

Re: A Message to Our Customers

#947

Earlier quoted context omitted.

According to @HillRat in the other thread : "Based on open sources, NSA has a fleet of about 100 vehicles at most in CONUS, so they would be more likely to fly vehicles cross-country if DIRNSA needed to use a fleet vehicle. Having said that, NSA doesn't just arbitrarily get involved in domestic law enforcement cases, even ones involving crypto, so let's wait to see if there's more evidence than a random HN post to su…

The majority of federal government travel is done with commercially available rental cars. The likelihood of the federal government driving a GSA-plate vehicle from Maryland to California to meet with Apple is about zero.

Commercially available rental vehicles seem an extraordinarily bad idea for the NSA to drive to and from sensitive meetings in.

What? They just drive silently to and from the meeting or listen to the radio?

Re: A Message to Our Customers

#948

This is the sort of thing that a professional organization - like what medical doctors have - could help with. Let me explain. The court order gives Apple an out: "To the extent that Apple believes that compliance with this Order would be unreasonably burdensome, it may make an application to this Court for relief". Now, imagine if this was court ordering a company to engage in unethical medical procedures, rather th…

Professional ethics of software engineering is definitely something we're going to have to grapple with more and more. Another aspect is being asked to use Dark Patterns in a UI or build a skinner box into a game or app. There's evidence that these things do harm to people and having a professional organization that could help stand up to such things could be part of a solution.

Re: A Message to Our Customers

#949
If you oppose this, please let President Obama know. The FBI is part of the executive branch of the government, and as such, directly reports to the president. In other words, if he tells them to stop, they must comply. Please register your complaint here:

https://www.whitehouse.gov/contact

Here is my letter to them:

Dear President Obama,

I've voted for you in both elections, and have been a firm supporter on all your causes (affordable care act, and more). However, your FBI has clearly overstepped it's authority by demanding that Apple spend engineering resources building a software product that can break the encryption of a terrorist's iPhone.

Seriously, you need to stop this. You are the head of the executive branch of the government, of which the FBI is directly underneath your jurisdiction. Director James Comey is directly within your chain of command.

What the FBI is asking for is a master key to be created that can decrypt any iPhone. This makes all Americans with Apple devices insecure in the face of threats to our personal security and privacy. I hope you can understand that this is clearly unacceptable, and needs to be stopped.

I want to register my complete opposition to the FBI in this circumstance. Please stop this.

Thanks, xxxx

Re: A Message to Our Customers

#950
post #706
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

What puzzles me is why the government didn't impose a gag order like they sometimes do in cases like this.

Because a gag order would have to be absolutely legally watertight, which is likely impossible in this case.
Post reply on HN