Live data from Hacker News

FBI Director Comments on San Bernardino Matter

fbi.gov

111–120 of 142 posts

Re: FBI Director Comments on San Bernardino Matter

#111
post #57

There's a certain hypocrisy I'm noticing in these forum discussions whereby many of you are distrusting the FBI, but apparently you're fine with Apple having the best chance of cracking your phone. Everyone is going on about encryption, but notice it's not just encryption that protects us, but also vendor-controlled measures such as self-destruct. I prefer a level playing field in these matters. I don't want the FBI…

The hypocrisy is only superficial. It seems at first thought that the government (being owned by the people) would be more trustworthy. But... Based on incentives, the government is incentivized to put as many people in jail as possible. Apple is incentivized to make people's phone/laptop experience as good as possible. Based on worst-case actions, Apple can use your data to 1) sell you more devices, 2) generally red…

Your idea that Apple are incentivized to make people's phone experience as good as possible sounds like a wishful proposition. There's plenty of examples of Apple features and restriction designed as eco-system lock-in, behavior manipulation, or control limiting for commercial reasons. "What's good for Apple is good for our customers" is what they want you to believe, but as a long time iOS device owner, I reject that on numerous grounds.

There's also an equivalence flaw in your argument that sounds like it's coming straight from infowars.com: "the government is incentivized to put as many people in jail as possible".

I'm with your on incentives though. And one thing Apple have no commercial interest or incentive for, is fighting crime.

We don't live in Star Wars. There's more than dark vs light. My position doesn't mean I am not aware of western government corruption, bungling, even war crimes. But I am not permanently polarized, forever holding "the government" in contempt for misguided actions and evil intentions.

On history... if we're talking tyrannical governments, then "protection of user data" I suggest would not have stopped any given government in your examples from unleashing hell on its people one way or another.

Re: FBI Director Comments on San Bernardino Matter

#112
post #109

Earlier quoted context omitted.

I conclude that you potentially misunderstand what is perhaps the core governing doctrine of US law because you keep re-presenting the same tired argument that this is about a single firmware tied to a single phone. If you truly believe it's about one phone, we don't have much to discuss. Whatever you think they should do, judges absolutely consider the precedent effect when ruling on accepting arguments, and lawyers…

> you keep re-presenting the same tired argument that this is about a single firmware tied to a single phone I mention that only when people assert incorrect facts about the case. Correcting someone when they're wrong about a matter of fact does not imply any legal opinions. About your point: there's a difference between "If I agree with argument X in this case, I should agree with it in that case; however, X shouldn…

It's possible that I missed any concern the judge may have had for precedent when I read the ruling. If you know of any (or any other document I may have missed), I'd appreciate a pointer.

I think you're applying some fairly strict high-mindedness to the US legal system while others (myself included) worry that creative extension of intent appears rampant in cases that touch on technology or terrorism and therefore fall into your second form. Many of us don't, as a general rule, trust the courts, law enforcement, or our government to do anything but what is politically expedient and beneficial to them at the moment.

While the wording of this ruling is about one phone and a particular method the FBI has laid out, it appears to set precedent that law enforcement can compel a product company create a non-existent product (no matter how trivial) in order to exploit a known security vulnerability in one of their products. This is what concerns me and many others, because it brings us very short steps away from "make us a version that works against the Secure Enclave" to "make it work as an OTA update over WiFi" to then "make it work as an OTA update over cellular" and subsequently "make a version we can incorporate into a StingRay" and forward. None of these would be illogical steps to take in abject pursuit of stamping out terrorism and might even applauded by parts of society, but taken as what some perceive as an inevitable whole they paint a dim picture for personal privacy.

It's an improbable coincidence that the FBI has elected this particular charged case in which to stake their flag. Given their pleas with technology companies for cooperation over bypassing cryptography in recent months, this appears to be a logical continuation of that campaign.

In conclusion, we likely disagree, specifically due to my cynicism and your seeming lack thereof.

Re: FBI Director Comments on San Bernardino Matter

#113
post #74

Earlier quoted context omitted.

Of course the FBI will ask again and again. And Apple could be compelled to comply each and every time. The slippery slope argument being applied here is that FBI search warrants will now work on phones less than the iPhone 5S from now on (until Apple closes the iOS update backdoor I guess). This is far from "China will be able to mass-hack into iPhones from now on"-style comments I've seen from others. The fact is t…

Apple _will_ be compelled. You either don't understand the US legal doctrine of stare decisis or are being intentionally obtuse. Furthermore, the US legal system encourages elaboration on stare decisis, applying prior case law to novel cases rather than hashing out new decisions. This means that creative applications of this ruling ("give me an uncontrolled backdoor") are simply a question of time once the landmark c…

considering that the single-use nature of this exploit is a fundamental part of the ruling (and of the validity of the search warrant itself), you would not be able to use precedent to just get an uncontrolled backdoor.

Re: FBI Director Comments on San Bernardino Matter

#114
post #109

Earlier quoted context omitted.

> you keep re-presenting the same tired argument that this is about a single firmware tied to a single phone I mention that only when people assert incorrect facts about the case. Correcting someone when they're wrong about a matter of fact does not imply any legal opinions. About your point: there's a difference between "If I agree with argument X in this case, I should agree with it in that case; however, X shouldn…

It's possible that I missed any concern the judge may have had for precedent when I read the ruling. If you know of any (or any other document I may have missed), I'd appreciate a pointer. I think you're applying some fairly strict high-mindedness to the US legal system while others (myself included) worry that creative extension of intent appears rampant in cases that touch on technology or terrorism and therefore f…

>I think you're applying some fairly strict high-mindedness to the US legal system while others (myself included) worry that creative extension of intent appears rampant in cases that touch on technology or terrorism and therefore fall into your second form.

My main point related to this was above:

>The only concern would seem to be if the future court fails to analyse a case properly. But they can fail regardless of what precedent is or is not set.

To argue against that, you'd need to claim that precedent makes it easier for the later court to fail. Do you have examples, where it should have been clear that precedent didn't apply, yet the court reached the conclusion that it did, incorrectly?

(Preferably in important cases.)

>While the wording of this ruling is about one phone and a particular method the FBI has laid out, it appears to set precedent that law enforcement can compel a product company create a non-existent product (no matter how trivial) in order to exploit a known security vulnerability in one of their products.

I've said elsewhere that this argument seems to be useless. If Apple says it's "unreasonable" to expect them to do this, then they might be forced to hand over the source code, and the FBI will create it themself. The problem is

1. iOS is closed source and

2. iPhone requires a signature from Apple

If Apple doesn't help them, they could conceivably be forced to simply hand the keys and code over. It's a benefit to Apple to be able to create it themselves and maintain control over the keys.

>This is what concerns me and many others, because it brings us very short steps away from "make us a version that works against the Secure Enclave" to "make it work as an OTA update over WiFi" to then "make it work as an OTA update over cellular"

All of these seem fine, assuming that Apple is not modifying the phones to make it easier to hack. In other words, I agree that they follow as direct precedent from this case. (Although they can decide to only update a phone after a proper warrant.)

>make a version we can incorporate into a StingRay

This is the part that doesn't follow from precedent. Giving over control of the tool to the FBI who could use it without a warrant is novel, and would require a judge to justify it.

>In conclusion, we likely disagree, specifically due to my cynicism and your seeming lack thereof.

Maybe I'm just more cynical than you. You worry about a future court doing the wrong thing because they're misled by precedent here, I'm worried about a future court doing the wrong thing just because. I don't think the risk goes up significantly based on this precedent, because I think it could happen anyway.

>It's an improbable coincidence that the FBI has elected this particular charged case in which to stake their flag. Given their pleas with technology companies for cooperation over bypassing cryptography in recent months, this appears to be a logical continuation of that campaign.

Pure tinfoil material here. Do you know of any cases where the FBI had a phone but didn't try to unlock it, that could be said to be as urgent as this? This isn't the only court case with Apple going on, it's merely the one that got a lot of attention, and certainly much of that attention is Apple's fault (not all, but a lot).

Re: FBI Director Comments on San Bernardino Matter

#115

Earlier quoted context omitted.

A few things. If you want to make your argument legit, refrain from calling the other person names. Second, besides drinking and making yourself essentially useless, what are you doing to improve this situation. One person may not be enough to make a difference but its better than zero. America is entirely being driven by fear and anger. The current presidential race is a perfect reflection of the hate, anger, and fe…

Counterpoint: Just going out on a limb here, but I'm pretty sure James Comey isn't leafing through Hacker News reading our arguments. If he'd like to have a civil discussion, I'd be more than happy to bring the civility. Second, our system is essentially set up to make me powerless. It's actually engineered that way. I do what I can to educate people around me, but when it comes to voting or having any control over w…

I actually wouldn't bet on that. As much as I dislike the FBI based on previous behaviour, I'm happy Comey is running it now, because he seems to have a fair amount of personal integrity. I wouldn't rule it out completely that on a matter this politically charged and visible he does some homework himself, and HN would be one of the first places to start.

Re: FBI Director Comments on San Bernardino Matter

#117
post #39
post #5

These people are either being intentionally deceitful or are simply incompetent in understanding the full implications of what they're asking. Either possibility is disturbing.

Despite the obvious application of Hanlon's razor, the latter is simply not plausible. The release statement opens with a stone cold lie. https://twitter.com/matthew_d_green/status/70115236890220134... https://twitter.com/matthew_d_green/status/70115264061335142... https://twitter.com/matthew_d_green/status/70115296105404006... https://twitter.com/matthew_d_green/status/70115860701918412... https://twitter.com/matthe…

So they know this leads to an Orwellian state and they do not care? Maybe, but it would be political suicide to admit that.

Certainly Comey is being deceitful in his first sentence. Even Hillary called for a Manhattan-like project to circumvent encryption back in December [1]. That shows it's something that's being discussed in Washington quite frequently.

I doubt any will ever admit they're trying to lead us towards an Orwellian state. Also, encryption is part of our protection from that. Heads of state and encryption currently appear to be directly at odds.

[1] http://www.cbsnews.com/news/democratic-debate-transcript-cli...

Re: FBI Director Comments on San Bernardino Matter

#118
post #102

I think it's reasonable to say that the HN crowd is predominantly more educated on this matter than the average American. We are not the target audience of this letter. Neither is Apple. Comey is playing on the emotions and technological ignorance of the bourgeois. He refers to brute force hacking as, "...try to guess the terrorist’s passcode..." Then he plays on Americans' current distaste for large corporations and…

> We are not the target audience of this letter

Maybe, but it's fun to discuss, and there are enough of us spread throughout that can educate on this single issue. It's pretty easy for me to explain to my non-tech friends the implications of what the FBI is asking. Word of mouth travels fast and I would give pro-encryption the upper hand in this "debate". I have not heard anyone outside government protesting that Apple yield on this issue and I doubt I will.

In fact, the only ones who speak up against encryption are those who do not listen to the people. Since they're supposed to represent us, they will be very easy to not vote for.

Like you said though, it isn't even a question, encryption is here to stay whether the American government permits it or not. Ironically, by putting up such a fight, the government is simply telling criminals where the weak points are in law enforcement, and are thus empowering criminals.

I hope our government can have a good sit down with tech company leaders and experts in cryptology. Despite Comey's request to have an open discussion, they seem to be excluding this group. It's apparent from his discourse, Hillary's, and Obama's that they've spent no time sincerely listening to anyone with any knowledge about the benefits of encryption. The "conversation" he so desires has only happened in Washington among people with no tech background. Presumably there will be some public hearings coming up.

Re: FBI Director Comments on San Bernardino Matter

#119
Could Cook even compel his employees to write the desired operating system? If I worked there and was asked to violate/reverse the core of my company's principles, I would quit.

Frankly, this type of order would deeply hurt moral at Apple. I imagine Cook knows that, and in addition to doing the right thing, he must double down on ensuring employee retention and future sale of products. End-to-end encryption is a feature many people buy the phone to get. If that disappeared, many techies would stop recommending it, and sales will slide.

There's a lot on the table here. I don't even think you could measure the impact for reimbursement by the government. sigh, at least you CA folks elected Ted Lieu, good job!

Re: FBI Director Comments on San Bernardino Matter

#120

> We simply want the chance, with a search warrant, to try to guess the terrorist’s passcode without the phone essentially self-destructing and without it taking a decade to guess correctly. That’s it. Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances. Forcing Apple to develop products that don't yet exists is simply a choi…

> Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances.

How? They either need to break the PIN or they need to break the AES256 key that is used to encrypt file metadata.

They cannot use EC2 GPU instances to attack the PIN because the function that derives the AES key from the PIN uses a key that is unique to each phone and not readable by software so they cannot get a hold of it unless they resort to opening the crypto chip and trying to read the key by examining the hardware (and if they do that, they won't need a GPU...any desktop computer would be able to brute force the PIN quickly).

They can use EC2 GPU instances to go after the AES256 key for metadata encryption, but that will take a hell of a lot longer than a decade.

Post reply on HN