Live data from Hacker News

Apple Letter on iPhone Security Draws Muted Tech Industry Response

nytimes.com

171–180 of 204 posts

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#171

Earlier quoted context omitted.

I don't think it's about opposing the government, the line in Apple's letter that symbolises for me the importance of their argument is "because we believe the contents of your iPhone are none of our business." – for many other companies, the contents of your device is absolutely their business, it's how they maintain revenue. If Facebook can't read your data, then they can't sell your eyeballs to advertisers.

If the contents are none of Apple's business, why did Apple give themselves (via their signing keys) a backdoor that allows them to replace the firmware out from under the owner of an ostensibly locked device? If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI. "Can't do it" is a strong defense. "Won't do it" isn't.

You'll have to excuse any naivety on my part, but is that for all devices or for <= 5C? I was under the impression that was not possible for the 6 and 6S because of the secure enclave, and that the device had to be unlocked for a firmware update to occur.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#172
post #124
post #98

Earlier quoted context omitted.

Do you think they choose to ask Apple to do this in such a public way, because they are very confident the phone will contain information that will help with the investigation, which will make a positive precedent about this method for future requests, and also provide 'lobbying power' when new laws will be considered?

The iPhone in question was his (government) work phone and they already found a bunch of their other 'burner' phones in a trash bin, which they got access to. I find it unlikely he used his work phone for planning when they purposefully ditched other devices. Additionally, I doubt he knew the iPhone encryption would block investigators from accessing the data, so the fact they can't access it is most likely just coin…

Yes I agree. I can't be a coincidence. They deliberately picked the best weapon in this debate, biased public opinion.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#173

Earlier quoted context omitted.

This just made me realise that Apple is a true "do no evil" company and not Google, for all its technology powress and fancy marketing. A sad realisation as I have been using Google products for almost everything-- they pitch up everything under the F/OSS banner and it's so tempting. I think I should consider moving to iOS pretty seriously. I had been dismissing it for being over-priced and not being OSS. But the tru…

I've actually been having similar feelings lately. I'm still not totally happy with Apple and fundamentally disagree with their closed ecosystem policy, but over the years I feel like they have been gradually gaining trustworthiness just as Google has been losing it. (Of course, Facebook never had it in the first place.) I still don't think it's so much a true desire to "do no evil" rather than Apple's business incen…

The problem as I see it: your stuck choosing the lesser evil. I agree with you on apple's stuff. If they opened up the ecosystem more, I'd like their stuff. And Google left "do no evil" so long ago, its not even funny.

I'd love a good FOSS alternative to their software/services. I try to run my own software/services, but there are some things I still just can't replicate.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#174

Earlier quoted context omitted.

If the contents are none of Apple's business, why did Apple give themselves (via their signing keys) a backdoor that allows them to replace the firmware out from under the owner of an ostensibly locked device? If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI. "Can't do it" is a strong defense. "Won't do it" isn't.

You'll have to excuse any naivety on my part, but is that for all devices or for <= 5C? I was under the impression that was not possible for the 6 and 6S because of the secure enclave, and that the device had to be unlocked for a firmware update to occur.

The weight of evidence is that they can update the secure enclave firmware in place, too, without losing keying material.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#175
post #170
post #121

Earlier quoted context omitted.

Could it be possible that the government want to lose in this case(and in the media) - creating a strong illusion that the iPhone is 100% safe from spying ? How valuable such an illusion would be ?

In fact, they swore to it. https://twitter.com/mmasnick/status/700394031218499584

Who swore on it ? how high is he on the org chart ? is it possible that he is being kept in the dark ,intentionally ? or could such skills only availble at other agencies ,but the knowledge acquired can be shared ,like it has been in the past ?

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#176

I'm not really surprised that other companies aren't coming out of the woodwork to make themselves targets. It's clear that in the main they will hold similarly strong views to Apple, but any PR worth their salt will not want the CEO of a company not implicated in something as politically charged as this to enter into the discussion. For those who oppose this kind of behaviour by the US Government, it's a relief that…

> it's a relief that they picked on Apple: a company with strong opinions about this topic

Not only that, but so many other tech companies rely on user-data. They can't sell it, then turn around and say no when the govt asks for it.

I don't think it was luck, I think they picked on apple specifically because they clearly state that they don't rely on that data.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#177

Earlier quoted context omitted.

If the contents are none of Apple's business, why did Apple give themselves (via their signing keys) a backdoor that allows them to replace the firmware out from under the owner of an ostensibly locked device? If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI. "Can't do it" is a strong defense. "Won't do it" isn't.

You'll have to excuse any naivety on my part, but is that for all devices or for <= 5C? I was under the impression that was not possible for the 6 and 6S because of the secure enclave, and that the device had to be unlocked for a firmware update to occur.

People are disputing that now; apparently Apple has hinted that they could defeat the Secure Enclave on the newer phones.

e.g.: http://daringfireball.net/linked/2016/02/17/panzarino-apple-...

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#178
post #175
post #170

Earlier quoted context omitted.

In fact, they swore to it. https://twitter.com/mmasnick/status/700394031218499584

Who swore on it ? how high is he on the org chart ? is it possible that he is being kept in the dark ,intentionally ? or could such skills only availble at other agencies ,but the knowledge acquired can be shared ,like it has been in the past ?

The source link is a few tweets down. https://www.documentcloud.org/documents/2714170-SB-Shooter-M... The signatures are on page 20 but they're the same names as on the first page:

  Eileen M. Decker, United States Attorney
  Patricia A Donahue, Assistant US Attorney &
    Chief, National Security Division
  Tracy L. Wilkinson, Assistant US Attorney
  Allen W. Chiu, Assistant US Attorney

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#179

Earlier quoted context omitted.

Google doesn't care. They're the "if you have nothing to hide you have nothing to fear, and you better not fear advertisers, because we just told them all about you" crowd. Few years back Cornell University adopted Gmail for their staff and faculty under the condition that the company wouldn't data-mine the emails. Google did anyway. Now we use Outlook.

Google does care in some cases, a couple of years ago they started encrypting links between their datacenters because the NSA was snooping on internal Gmail traffic.

The difference is: Apple is putting their money where their mouth is. Google only fixed that after they got caught with their pants down. Apple is pro-actively trying to prevent it from happening.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#180

Earlier quoted context omitted.

If you read the letter, they already said they have, do and will aid law enforcement in any lawful way they are able. They question the lawfulness of this particular request.

I understand the technical issues, and understand the broader implications... But, one thing has been bugging me about this case and your comment that Apple questions the " lawfulness of this particular request " leads me to ask: Does 4th Amendment protection end at death...?...the terrorist is obviously dead... I've been looking and don't find answers that satisfy me...? Anyone?

Apple isn't questioning the legality of the request based on 4th amendment concerns. Most requests from law enforcement ask a company to give up information they already have. What makes this unique is that the request is for Apple to decrypt the device -- an ability they do not currently have. Further, there is no law requiring Apple to have the ability to decrypt the device.

So this request is really a request for Apple to develop a way to break their own encryption, which brings up a lot of slippery slope concerns. If Apple can be forced by the government to develop a way to break into this version of their OS, what would stop them from being forced to develop cracks for other versions of their OS?

Post reply on HN