Live data from Hacker News

Sundar Pichai Responds to Apple and the FBI Hacking Request

twitter.com

31–40 of 114 posts

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#31
post #6
post #3

Not quite as hard hitting as I would've hoped. Gruber's take: http://daringfireball.net/linked/2016/02/17/pichai-apple-fbi

Gruber's response is lukewarm too. Pot calling the kettle black.

He's a blogger, why does his response matter? It's the response of the tech companies that matters.

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#32
post #5

I really wish the restrictions can be reduced or removed so @pmarca etc can tweet more on the companies of which they are the directors of. Same for the CEOs itself, and CEOs and other executives should be allowed to tweet at board of directors and vice versa.

Google owns blogpost. Google has several blogs there. Surely it'd be a vote of confidence for him to use it?

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#33
post #11

Earlier quoted context omitted.

I believe the difference is that Apple/Google are okay with turning over user data on a case-by-case basis provided there's a proper subpoena from a judge, but not okay with building a tool for the FBI that will allow them to look at any user's data. The former is equivalent to allowing the government to open your mail and wander around your house provided that they've obtained a search warrant. The latter is equival…

I don't think Apple has been asked to build a tool, just to help unlock a single device. I think Pichai is making a distinction between handing over data they already own (eg. a Gmail account) and data stored on user-controlled devices, which must be hacked to access. Which is interesting, since he's essentially admitting that their push to send everything to "the cloud" makes their users less safe from governmental…

Actually, this is a quite interesting distinction to consider. There is significantly more danger in hacks which can "scale" due to centralization and non-physical access compared to physical access.

In the case of cloud data, the government should be held to a higher standard of restriction, because all of the data is in one location, and requires only a single "factor", the identity of the target to collect data for. This applies to both "encrypted at rest" and "encrypted in flight" data.

But for data encrypted at rest on actual physical devices, there's an inherent '2-factor' security to the private invasion. The government must not only know the identity of the target to collect the information, they must possess the physical device as well. ("something you know" + "something you have")

This means, IMHO, there is far less danger, and far less scalability to "one off" hacks like the ones being requested to Apple. They don't scale to Snowden-level dragnets, they don't present low transaction cost barriers to acquisition.

The dangerous think for decentralized data is having an active attack on the device, or something which intercepts the data "in flight". These are scalable attacks you need to worry about. E.g. "push a key logger to every iphone software update"

Perhaps the law needs to make a distinction to warrants for 1-factor data vs 2-factor data, due to the inherent danger of 1-factor data, given that it scales easily to monitoring millions with little transaction cost.

So in this regard, I think there should be MORE push back for collection of cloud data, but individual one-offs for physical devices have a safer threat model.

I view this more like a Vault being found at the home of a murderer, and the cops asking the Vault maker to help unlock the Vault without revealing the proprietary locking mechanism, or without the cops needing to blow up the vault and potentially lose whats inside.

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#34
post #25

This is the most concise summary I have found on the legal issues/possible ramifications concerning this case. The worry in this case is the troubling precedent it would set. https://lawfareblog.com/not-slippery-slope-jump-cliff Quotation from, Not a Slippery Slope, but a Jump off the Cliff By Nicholas Weaver. The request to Apple is accurately paraphrased as "Create malcode designed to subvert security protections,…

This is precisely why I think the San Bernardino case is ideal for the FBI to establish this precedent. If they actually wanted access to the device they could have served Apple a National Security Letter and had it done on the sly. But they're taking the public route on this one because of how bad Apple would look if they refused to unlock the phone of a known terrorist. That's probably why Apple had to go out of th…

they could have served Apple a National Security Letter and had it done on the sly

NSL's don't work like that.

A national security letter (NSL) is an administrative subpoena issued by the United States federal government to gather information for national security purposes... By law, NSLs can request only non-content information, for example, transactional records and phone numbers dialed, but never the content of telephone calls or e-mails.[1]

Apple would challenge a NSL on three grounds:

1) The subject of this investigation in this is dead. The secrecy requirements are unrequired.

2) What the FBI wants here is not information, it is to force Apple to do work. That's why they've had to try the Writs act - it's a pretty unprecedented thing to try

3) The information requested is not "non-content"

I'd say Apple would have a good case on any of these grounds, and the FBI knows it.

[1] https://en.wikipedia.org/wiki/National_security_letter

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#35
post #11

Earlier quoted context omitted.

I believe the difference is that Apple/Google are okay with turning over user data on a case-by-case basis provided there's a proper subpoena from a judge, but not okay with building a tool for the FBI that will allow them to look at any user's data. The former is equivalent to allowing the government to open your mail and wander around your house provided that they've obtained a search warrant. The latter is equival…

I don't think Apple has been asked to build a tool, just to help unlock a single device. I think Pichai is making a distinction between handing over data they already own (eg. a Gmail account) and data stored on user-controlled devices, which must be hacked to access. Which is interesting, since he's essentially admitting that their push to send everything to "the cloud" makes their users less safe from governmental…

Well, if they aren't being asked to build a tool, then there's nothing for them to help the FBI with because the device functions as designed.

It is precisely the design of the device that the FBI wants Apple to alter using some sort of tool that Apple will make for them.

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#37
> We know that law enforcement and intelligence agencies face significant challenges in protecting the public against crime and terrorism.

Do we? Crime rate has been falling. Terrorism is a statistical bleep. The majority of "crime" is government's own invention (non-violent drug-related offenses, prostitution, civil forfeiture, arresting people because they don't pay their student loans [1] [edit: not actually true, as tzs pointed out below], cop murders).

Personally, I believe that even without any ability to access any digital communication/stored data, law enforcement wouldn't be in a worse position compared to 30 years ago.

[1] http://finance.yahoo.com/news/paul-aker-us-marshal-student-l...

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#38
post #18

Twitter doesn't seem like an appropriate medium for a response to this issue from a CEO of a major tech company. Hello! This isn't a picture of the burger you had for lunch or a pithy remark fest, it's the most important thing affecting your users today. Take some time and write a god damn letter with your company's stance.

Are we (HN), the intended demographic though?

I personally get twitchy whenever I see a facebook or twitter link, but I also know that the times are changing, so I withhold my angry rants.

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#39

Earlier quoted context omitted.

Fine, but it's custom build locked to that particular device and which Apple can install itself, without providing it to the FBI. It's certainly not "a tool for the FBI that will allow them to look at any user's data". https://assets.documentcloud.org/documents/2714001/SB-Shoote...

Once they made it, locked for that device, the FBI knows Apple can make it again, locked for another device. The tool is for any user's data, via a court order on Apple.

But Apple would still need to have the court orders for each user.

Some people are suggesting that Apple would create this back-doored code, and hand it to the FBI, who would then use it to access any data they want without bothering with court orders. That doesn't seem to be what the FBI are asking for.

Re: Sundar Pichai Responds to Apple and the FBI Hacking Request

#40
post #35

Earlier quoted context omitted.

I don't think Apple has been asked to build a tool, just to help unlock a single device. I think Pichai is making a distinction between handing over data they already own (eg. a Gmail account) and data stored on user-controlled devices, which must be hacked to access. Which is interesting, since he's essentially admitting that their push to send everything to "the cloud" makes their users less safe from governmental…

Well, if they aren't being asked to build a tool, then there's nothing for them to help the FBI with because the device functions as designed. It is precisely the design of the device that the FBI wants Apple to alter using some sort of tool that Apple will make for them.

My point was just that the FBI didn't ask Apple to "build a tool for the FBI that will allow them to look at any user's data". They asked Apple to prevent some security mechanisms of that particular device from working. Whether Apple builds a tool or uses manual labour with existing tools to do so is irrelevant for the FBI.
Post reply on HN