Live data from Hacker News

Justice Department Wants Data from About 12 Other iPhones

wsj.com

31–40 of 101 posts

Re: Justice Department Wants Data from About 12 Other iPhones

#31
post #7

Earlier quoted context omitted.

You're telling me you would trust that software to remain in the hands of trusted actors? In 2015, alone, the IRS was breached, LastPass, the director of the CIA, Hacking Team, even Kaspersky Labs was breached! There can be no absolute guarantee that this backdoor would remain safe indefinitely. That is just the most blatant problem, not to mention the overt displays of cynicism and misuse of authority by the NSA as…

So would it be okay for the FBI to have to bring the phone to Apple?

What if there were a limit of 3 unlocks a year? Like in NFL football, where the coach is only allowed to challenge 3 plays a game, even if each challenge is successful. (I know, still too slippery a slope)

Or if each unlock cost the requester a $10 billion fee (donated to charity)? To make them think harder about when to use an unlock.

Re: Justice Department Wants Data from About 12 Other iPhones

#33
post #17
post #8

Question for HN in general: Is it possible in principle (for Apple or someone else) to construct a smartphone that can accept software/firmware updates, but that Apple cannot push malware to at some later time? E.g. can we implement all security functionality in hardware/burn it into the silicon? Or accomplish the same ends by some other means? Intuition says "no," because "security functionality" is sort of nebulous…

"can we implement all security functionality in hardware/burn it into the silicon? Or accomplish the same ends by some other means?" Yes. The software could be burnt into PROM (which is unchangeable) or one could even create a custom ROM chip, and if necessary contain hardware or code that checksums the ROM. However, a company doing that must be willing to run the risk that there is a bug in that unchangeable softwar…

> That requires a 100% open phone (hard- and software) and enough knowledgeable people willing to invest time in looking at the code.

Which, sadly, seem to not exist (cf the long term bugs in OpenSSL et al)

Re: Justice Department Wants Data from About 12 Other iPhones

#34
...and it's an entirely reasonable position to say that they should get it, if they have a warrant. Especially if the case as cut-and-dried as the San Bernardino one.

The public debate on this has reached truly sad, nigh-Trumpian levels of hysteria and uninformed commentary. There is no "back-door" here. Encryption is not being compromised. This has very little to do with encryption at all, really: if the criminals in question were to use a strong password instead of a four-digit PIN, Apple could just shrug, say "not possible in our lifetimes", and that would be the end of it. But these criminals have easily brute-forceable PIN codes, and the investigators want to brute force them.

This situation is about a legal fight of very narrow parameters: should it be possible for the government to compel a company to help extract its customers' "secure" data, via this specific, very old law. Reasonable people can disagree on this point.

Unfortunately, the public debate has gone completely round the bend, with famous people grandstanding on totally irrelevant things (like "encryption back doors"), which have no bearing on anything at all. Moreover, as it turns out, Apple has been doing this for years for police investigations, and the empire has not yet fallen. If you're worried about the slippery slope, well...we're already well downhill, and our bottoms are wet. Perspective.

I realize that it's not popular amongst the tinfoil-hat set that has set up residence here, but I think that there are times when we want our government to be able to do things like break into a suspect's phone. There should be safeguards (like warrants), of course, but it's a perfectly reasonable position to say that privacy is not absolute.

Re: Justice Department Wants Data from About 12 Other iPhones

#35
post #8

Question for HN in general: Is it possible in principle (for Apple or someone else) to construct a smartphone that can accept software/firmware updates, but that Apple cannot push malware to at some later time? E.g. can we implement all security functionality in hardware/burn it into the silicon? Or accomplish the same ends by some other means? Intuition says "no," because "security functionality" is sort of nebulous…

You could certainly reduce some of the attack surface, but you couldn't eliminate it entirely.

I think a more reasonable option is to design phone in such a way that attempting to load software on the phone when it's locked bricks it and causes the encryption keys to be destroyed.

Re: Justice Department Wants Data from About 12 Other iPhones

#36
post #16

Earlier quoted context omitted.

They could involve third parties in signing updates and if a device receives an update that isn't disseminated to all third parties it doesn't accept it. That way apple couldn't dispatch custom/backdoored updates to individual devices without revealing that they did it.

This would be a good step forward, but maybe not enough. For example, they could be forced to first publish an update to all devices (through the third parties) which disables the third-party-checks. Then, they could be forced to put the backdoor on individual devices.

> For example, they could be forced to first publish an update to all devices (through the third parties) which disables the third-party-checks.

And the device wouldn't accept it. If I subscribed to an organisation over which USG has no sway, say Computer Chaos Club from Germany, then my update wouldn't be accepted unless additional signatures were provided from them. Unless USG forced Apple to abandon such scheme for everyone then they would be powerless to backdoor individuals. I'm also not sure how relevant this is here, but in US it's been established that software is speech and is protected by the first amendment so there are limitations to ways in which US can influence Apple.

Re: Justice Department Wants Data from About 12 Other iPhones

#37
post #34

...and it's an entirely reasonable position to say that they should get it, if they have a warrant. Especially if the case as cut-and-dried as the San Bernardino one. The public debate on this has reached truly sad, nigh-Trumpian levels of hysteria and uninformed commentary. There is no "back-door" here. Encryption is not being compromised. This has very little to do with encryption at all, really: if the criminals i…

Fully agree with your comment about the discussion going full on hyperbole but at the same time agree that it's not Apple's job to intentionally weaken the security parameters of their firmware. Asking for encryption back doors is just another step from this, are you confident enough that it's not a risk worthy of consideration?

Re: Justice Department Wants Data from About 12 Other iPhones

#38
"the FBI said they are not seeking to set a precedent in the case, but to get the company to help them open a single phone that may hold crucial evidence to help explain the most deadly terrorist attack on U.S. soil since Sept. 11, 2001."

What qualifies this as being a terrorist attack? Is it because the colour of the perpetrator's skin wasn't white? Sandy Hook had double the number of resulting deaths and so is technically more deadly.

Virgina Tech was done by a South Korean born man with even more deaths than Sandy Hook.

Poor reporting WSJ

Re: Justice Department Wants Data from About 12 Other iPhones

#39
Sadly this is a tough sell, given that the general public perceives "encryption" as "password", unaware of the underlying technology and implications. It's doubly sadly that it was a government employee, in a government-controlled environment, using a government-managed device, and even when government had access they went and changed the password, locking themselves out.

Critical thinking would lead one to question the need of any data at all, given the thoroughly demonstrated incompetence. Yet public filter stops on perception that that Apple once cooperated, but now chooses not to do so.

Re: Justice Department Wants Data from About 12 Other iPhones

#40
post #7

Earlier quoted context omitted.

That's not a justified fear. Requiring Apple to backdoor all phones is not similar at all to requiring Apple to help hack particular phones, that they have the capability to hack, in response to court orders.

You're telling me you would trust that software to remain in the hands of trusted actors? In 2015, alone, the IRS was breached, LastPass, the director of the CIA, Hacking Team, even Kaspersky Labs was breached! There can be no absolute guarantee that this backdoor would remain safe indefinitely. That is just the most blatant problem, not to mention the overt displays of cynicism and misuse of authority by the NSA as…

>truly evil actor came into power

Obama is already in power..

Post reply on HN