Live data from Hacker News

Apple Letter on iPhone Security Draws Muted Tech Industry Response

nytimes.com

181–190 of 204 posts

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#182

Earlier quoted context omitted.

Not too far off. Obviously nobody would smoke at work for the same reason they probably wouldn't drink, illegality aside. But, what people do outside of work is their own business. If my boss started seriously inquiring about my vices, first thing I'd do that night is update my resume. I've considered federal work before but every time I think hard about it, I keep coming back to the scene in Snow Crash where the fed…

> I've considered federal work before but every time I think hard about it, I keep coming back to the scene in Snow Crash where the fed works at a place where every little action - the time you arrive, the time you leave, whether you take the stairs or use electricity by taking the elevator - is scrutinized and judged. Yuck. Wasn't that the corporate guy that did that to his employees? Intruding into their homes, eve…

> Wasn't that the corporate guy that did that to his employees? Intruding into their homes, even?

Well, the Fed was the one that monitored everything at work and bugged its employees' home phones too. L. Bob Rife was the corporate guy who didn't think that that was good enough, and wanted to be able to partition work data in his employees' minds so that they didn't have access to it outside of work. I think Rife is mentioned in passing as doing the former kind of monitoring whereas the Feds' practices are described in excruciating (and entertaining) detail, so you can certainly be forgiven for conflating the two.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#183
post #178
post #175

Earlier quoted context omitted.

Who swore on it ? how high is he on the org chart ? is it possible that he is being kept in the dark ,intentionally ? or could such skills only availble at other agencies ,but the knowledge acquired can be shared ,like it has been in the past ?

The source link is a few tweets down. https://www.documentcloud.org/documents/2714170-SB-Shooter-M... The signatures are on page 20 but they're the same names as on the first page: Eileen M. Decker, United States Attorney Patricia A Donahue, Assistant US Attorney & Chief, National Security Division Tracy L. Wilkinson, Assistant US Attorney Allen W. Chiu, Assistant US Attorney

But the guy who said the specific statement you mentioned is just the regional director of the orange county forensic department in the FBI , Christopher Pluhar @pg 21.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#184

Earlier quoted context omitted.

I don't think it's about opposing the government, the line in Apple's letter that symbolises for me the importance of their argument is "because we believe the contents of your iPhone are none of our business." – for many other companies, the contents of your device is absolutely their business, it's how they maintain revenue. If Facebook can't read your data, then they can't sell your eyeballs to advertisers.

If the contents are none of Apple's business, why did Apple give themselves (via their signing keys) a backdoor that allows them to replace the firmware out from under the owner of an ostensibly locked device? If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI. "Can't do it" is a strong defense. "Won't do it" isn't.

Actually - it seems to me that "won't do it" - when based on principle, is a much better defense.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#185
It may have to do with this: http://www.wsj.com/articles/senate-intel-committee-chairman-...

An encryption bill that is being worked on by the Senate that would try and make it a crime to not help the government decrypt messages from smart phone or other device.

Suddenly these courts find they can't get evidence to convict people if their phone is encrypted and so are the messages. So they want tools to decrypt the messages to get the evidence.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#186

Earlier quoted context omitted.

I don't think it's about opposing the government, the line in Apple's letter that symbolises for me the importance of their argument is "because we believe the contents of your iPhone are none of our business." – for many other companies, the contents of your device is absolutely their business, it's how they maintain revenue. If Facebook can't read your data, then they can't sell your eyeballs to advertisers.

If the contents are none of Apple's business, why did Apple give themselves (via their signing keys) a backdoor that allows them to replace the firmware out from under the owner of an ostensibly locked device? If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI. "Can't do it" is a strong defense. "Won't do it" isn't.

If Appke weren't able to update the software on your device, they really wouldn't be able to give you software updates. Since it's the software that enforces security, well you can sees where this is going.

It's not as easy as you imply. Denying themselves the ability to end run your security might well require them to not be able to upgrade or recover user devices. At all.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#187
post #184

Earlier quoted context omitted.

If the contents are none of Apple's business, why did Apple give themselves (via their signing keys) a backdoor that allows them to replace the firmware out from under the owner of an ostensibly locked device? If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI. "Can't do it" is a strong defense. "Won't do it" isn't.

Actually - it seems to me that "won't do it" - when based on principle, is a much better defense.

Not when it comes to transparent, limited scope, reasonable writs.

This isn't some NSA mass surveillance program, or clipper chip reloaded(TM).

This is an active murder (and terrorism) investigation in which Apple's privileged position -- one they assumed by choice and to their own benefit -- already exists. It is not unusual, unethical, or establishing any new precedent for them to be compelled to use keys they already have to open this single device.

Apple does not need to, nor are they being asked to, provide a backdoor that can be used elsewhere, and any further demands of Apple will require the same judicial oversight as this one.

If Apple doesn't want to be in this position in the future, they can avoid the potential liability by not holding master signing keys that can be easily used to circumvent the security of an owner-locked device.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#188
post #91

Earlier quoted context omitted.

Google makes more money from iOS than they do from Android. Of course Google doesn't mind if you switch hardware vendors, just so long as you keep using Google products. Also, I disagree with the notion that Apple "heavily pushes vendor lock in". They certainly don't go out of their way to make it easy to switch, but I can't come up with any examples off the top of my head where they're deliberately making it harder…

> They certainly don't go out of their way to make it easy to switch, but I can't > come up with any examples off the top of my head where they're deliberately > making it harder to switch without having a good reason for that decision. Just an example for those that are not familiar with Apple devices. You can sync your calendar, reminders and contacts with iCloud. But you don't have to. iCloud calendar sync is basi…

What do you use as a CalDAV server?

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#189
post #186

Earlier quoted context omitted.

If the contents are none of Apple's business, why did Apple give themselves (via their signing keys) a backdoor that allows them to replace the firmware out from under the owner of an ostensibly locked device? If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI. "Can't do it" is a strong defense. "Won't do it" isn't.

If Appke weren't able to update the software on your device, they really wouldn't be able to give you software updates. Since it's the software that enforces security, well you can sees where this is going. It's not as easy as you imply. Denying themselves the ability to end run your security might well require them to not be able to upgrade or recover user devices. At all.

It's not as hard as you're implying; A locked device could support re-imaging by expunging all existing key material.

In general, Apple's guarantees about anonymity and security all assume that there is no risk to Apple sitting in a trust position. This case demonstrates why that's a bad idea.

Post reply on HN