Live data from Hacker News

Justice Department Wants Apple to Unlock Nine More iPhones

nytimes.com

241–250 of 314 posts

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#241
post #16

> “What we discover is that investigation into one crime often leads into criminal activity in another, sometimes much more serious than what we were originally looking at,” They want access so they can go fishing too? They're really not doing a good job of sticking to the 'necessary and proportionate' line.

That sentence caught my eye, too. So they are publicly stating that they are not really interested in just solving the case and prosecuting the offender. Instead, they want to see what else they can stick to the man. I'm sure if you just dig deep enough, you will find some crime in everyone's data. Guilty until proven innocent.

>We are to look upon it as more beneficial, that many guilty persons should escape unpunished, than one innocent person should suffer. The reason is, because it’s of more importance to community, that innocence should be protected, than it is, that guilt should be punished; for guilt and crimes are so frequent in the world, that all of them cannot be punished; and many times they happen in such a manner, that it is not of much consequence to the public, whether they are punished or not. But when innocence itself, is brought to the bar and condemned, especially to die, the subject will exclaim, it is immaterial to me, whether I behave well or ill; for virtue itself, is no security. And if such a sentiment as this, should take place in the mind of the subject, there would be an end to all security what so ever.

-John Adams

http://rotunda.upress.virginia.edu/founders/default.xqy?keys...

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#242

Might criminals, paranoids and privacy extremists wishing for their phones never to be cracked, just choose an 11 digit passcode? I hear this would take too long for a computer to crack. Everyone else can choose a 4 digit code, and still enjoy very good security up until the point they are wanted by the FBI. People are confusing the fight for unbreakable encryption with this new fight to keep manufacturer-specific pa…

The question at hand is whether or not the DOJ can use the AWA to compel a company to weaken its product. It's unclear as yet whether the court will consider this too burdensome for Apple, or too expensive for the FBI to be able to reimburse Apple for any costs. Apple's argument is that this will set a precedent, and the FBI will ask to unlock many phones in the future, possibly even to the point of preventing Apple…

I'm aware of all that, your summary wasn't needed, and is lacking your personal opinion! "I think" is not a bad thing to say once in a while.

I'll take a guess that your position is identical to Apple's recent letter on the matter.

I think Apple should help unlock these phones, with the condition that such help may be impossible in future versions of the OS. Who wouldn't want future versions of iOS to prevent these requests from being possible even with Apple's intervention? How that can be achieved I don't know. Perhaps some fancy new hardware chip that kills the phone at any sign of tampering. I'd vote for that, most people would, but the FBI would hate it.

The crucial point is getting as much of the public on side as possible. Most people would support increased security and privacy measures for their phones. They would feel threatened by legislation denying Apple or others the right to improve security for customers, meaning such legislation would unlikely pass.

By fighting this current situation, Apple are putting themselves in an awkward situation of "not helping criminal investigation" which is not easy to get everyone on side if you're not being helpful.

It's a bit like chess, and Apple might have done better to make their move at a later time, first helping with these iPhones, then shutting the door on that option in later OS releases. "Sorry, it's encrypted inside and out, no way in, that's how good the security is, because that's what our customers wanted" would be impressive, and hard to defeat with new legislation.

So Apple should comply now, and make a better chess move later. I could be wrong, but that's what I think for now :)

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#243
post #12

Earlier quoted context omitted.

I can't think of any way in which the FBI's incompetence would have legal implications for Apple's obligations. How would that work? If they're able to help, and can be compelled legally, why would the FBI having previously had the ability to get the data but losing it to a mistake change their obligation?

Perhaps because the FBI's error deprived them of the only clearly legal means of recovering the data. Their mistake shouldn't confer access through arguably illegal means (the legality of the court order compelling Apple not yet being settled).

The point is that the legality of the court order compelling Apple does not depend on whether or not the FBI made a mistake in other investigative approaches. If the order is illegal, then it doesn't matter whether the FBI needs the access it provides or not, it's still illegal. On the other hand, if the order is legal, then the FBI needing it due to a mistake doesn't suddenly make the order illegal.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#244
Cant a legal hack be to move core security development out of US jurisdiction, and let Apple USA lease tech from Apple Iceland/Switzerland/Ireland/etc, as is done with taxes today ? This would make Apple USA unable to fulfil any court order demanding change to source code.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#245
post #240
post #207

Earlier quoted context omitted.

Do we know what can the software running on the secure enclave do exactly? If the software itself doesn't have access to the master key (a.i. can't read it directly), and if the slow authentication is inherent from running the algorithm on the chip, rather than a having been slowed down artificially, then even an update to the secure enclave would not compromise the security of the system. Do we know exactly what the…

> if the slow authentication is inherent from running the algorithm on the chip, rather than a having been slowed down artificially There is no known cryptographic algorithm that provides inherently increasing times. The slowdown is entirely artificial, and it is believed that an update could remove it.

I was under the impression that the algorithm (running on the secure enclave?) takes at least 200ms. Yes, obviously longer times are artificial, but my question is whether the 200ms baseline is artificial or not.

Of course this doesn't really matter at all if modified software could just read the key from the chip. That is the most interesting question. So, can it? Or can the software only provide data to the chip, to do the algorithm in hardware, but the software can't read the key burned (?) into the chip.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#246
post #109

It seems hard for me to believe that Apple now has at least 10 instances where the government is trying to force them to decrypt their phones, and this hasn't happened with Google or MS yet. I don't recall ever hearing a big standoff with MS refusing to decrypt a Windows desktop or server. Is encryption just that much more common on Apple devices? or is Apple just the first ones to make this all public?

Windows desktop full-disk encryption means Bitlocker, which is basically breakable by anyone who can google stuff and buy the right firewire cable: https://github.com/carmaa/inception Note that this is the open source, made by one guy in his spare time version, so it has some caveats. But I'll bet you dollars to donuts that the three-letter agencies have their own, more capable version.

That is an disingenuous representation of how the attacks works. That attacks OPSEC, not the Bitlocker itself. Any full-disk encryption is "vulnerable", to this kind of attack.

The page even explains this:

https://github.com/carmaa/inception#awesome-but-why

https://github.com/carmaa/inception#unlock

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#247
post #234
post #211

Earlier quoted context omitted.

A US court can order Apple to do what it likes inside US jurisdiction, including things that would normally be illegal in the US.

Citation? It seems pretty unbelievable that a US court can order someone to do something that violates US law.

What is it you are seeking a 'citation' for? This is so obvious nobody with a legal background would question it, let alone write about it. The gp is so silly it doesn't warrant discussion. Law is not a logic game with a closed rule set, it's nonsensical to reason based on that assumption.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#249
post #127

Earlier quoted context omitted.

We also will wind up (already have) with more smart terrorists who hide data in better places. So the only people who lost are we (again).

As a devil's advocate, couldn't we say the same thing about guns?

We can. But we'd still reduce the accidental gun deaths tremendously—as well as killings by people who weren't previously criminals. Yes, we probably won't get the guns away from criminals—there are too many guns, and they've been around for too long. But we'll still reduce the deaths.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#250
post #221
post #72

Earlier quoted context omitted.

This makes a lot of sense since the government could issue an order through FISA and afaik apple would be required to comply with it. The fact that they can resist the order and in a such a public way feels a little bit theatrical, given what we know about how these things work. I wonder how much of what's happening between apple and the fbi / rest of the government is the tip of the iceberg.

FISA should apply only to foreigners' data. That's why it has "Foreign" in its name.

> foreigners' data

That's commonly assumed, but it's not quite accurate. It's not about "data originating from foreigner". Instead, the criteria[1] is "foreign data" or "data that traveled over a foreign connection". It's not the person that must be foreign, but the data or specific wire on which it travels.

Several sources have explained how the NSA captures domestic data when it travels internationally, such email (gmail) that is stored or processed at a foreign data center. This probably allows almost any data to be captured with some clever packet re-routing.

[1] this may be from one of the infamous "new interpretations" of FISA/etc

Post reply on HN