Live data from Hacker News

Justice Department Wants Apple to Unlock Nine More iPhones

nytimes.com

301–310 of 314 posts

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#301

I've already made my legal and political opinions in other threads on the topic and won't rehash them here, especially since so many other people are making the points better than I did. However, here's something I haven't thought of, though I sort of hate to boil the thing down to a business proposition. The fact is that iPhone is a massive business. What all is a company allowed to claim as "burden" in the discussi…

Another twist to this is that the hypothetical burden is not being born by Apple, it's being born by Apple shareholders. I might personally own 1 Apple share, so it's not a huge burden to me if the company loses $50B in revenue and the value of that share goes down 10%. But what about some individual who has invested $1M of her own money, her entire life's savings, in Apple shares and is about to retire and pay the bills by selling shares over time? I would speculate there would be hundreds of thousands of share holders (millions?) who would be burdened as a result of that hypothetical loss of $50B in revenue.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#302

Earlier quoted context omitted.

Well, TLS with "trusted" CAs is useless, for extreme threat models.

Care to elaborate?

http://thenextweb.com/insider/2015/04/02/google-to-drop-chin...

it's not tinfoil to note that there are CAs under the control of authoritarian governments.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#303
post #300
post #299

Earlier quoted context omitted.

So if the key can't be extracted via the firmware, someone updating the firmware, even with malicious intent, should not be a problem, am I correct?

With a sufficiently complex passphrase, it's not a problem. With a typical 6-digit PIN, disabling the artificial delay and auto-wipe (which is possible via firmware updates) is all you need for a successful brute-force attack.

Thanks for the clarifications.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#304

Earlier quoted context omitted.

That sentence caught my eye, too. So they are publicly stating that they are not really interested in just solving the case and prosecuting the offender. Instead, they want to see what else they can stick to the man. I'm sure if you just dig deep enough, you will find some crime in everyone's data. Guilty until proven innocent.

>We are to look upon it as more beneficial, that many guilty persons should escape unpunished, than one innocent person should suffer. The reason is, because it’s of more importance to community, that innocence should be protected, than it is, that guilt should be punished; for guilt and crimes are so frequent in the world, that all of them cannot be punished; and many times they happen in such a manner, that it is n…

Amazing. Either I'd never seen this quote before, or didn't understand the huge negative implications of punishing the innocent on society.

If innocence isn't held in the highest regard, then society itself collapses as people no longer deem it necessary to act in an ethically- and morally-superior manner.

I see many signs in modern society that this maxim was ignored.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#305
post #295

Earlier quoted context omitted.

Not really. Full disk encryption using Pointsec/other commercial offerings, or as you typically do it on Linux with LUKS+dmcrypt, asks for the passphrase before the OS has loaded any Firewire drivers. In which case a fully shut-down computer is not vulnerable to this attack, ie. you have protection against evil maids, thieves, FBI etc. But with Bitlocker, it only requires a password at Windows login, and by then all…

IIRC BitLocker with pre-boot authentication mitigates DMA attacks. Most Windows hardware doesn't come with FireWire or Thunderbolt ports nowadays. Microsoft recommends pre-boot auth for devices with DMA ports.

These are fair points. But for businesses in particular, it's a problem since many skip on (or are unaware of the need for) pre-boot auth, and business laptops still pack FW ports, if not on the laptop itself, then surely on the docking station.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#306

Earlier quoted context omitted.

It is not settled law in the U.S. whether being forced to handover a password is "contempt of court" or actually self-incrimination protected by the Fifth Amendment. Wiretaps ordered into the U.S. phone and internet networks via CALEA and FCC rulings, which basically meant that all network and phone switches internationally would have the back door. (See what happened to Greek politicians thanks to that). But the pho…

What seems to be settled though is that people can be ordered to unlock their phones with a fingerprint… despite possible self-incrimination: http://www.dailydot.com/politics/virginia-fingerprint-key-di...

That's still not "settled." That's one state court ruling. Other states could rule differently. A federal court in that district could rule differently.

That said, if your threat model involves anyone technically sophisticated or any government actor, I would suggest not relying solely on a fingerprint ID to control access to a device.

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#307

Earlier quoted context omitted.

We live a western society, not China. If more than 50% of the population wants the phone to be cracked it should be done. That's what we all agreed on living in a democracy. Law is formed by the wishes of majority. I'm not a lawyer. Is the FBI asking something from Apple which is not legal? Than go to court.

> We live a western society, not China Exactly. So why are we asking Apple to do something which Obama rebuked China for doing last year? [1] > If more than 50% of the population wants the phone to be cracked it should be done This isn't up to the public, it's up to the courts, who've been asked by the DOJ to consider the issue. The public only comes into play around election time when there's a chance to vote in a n…

I can't imagine a country where 80% of the population is against abortion, and it still would be legal. In some indirect way law reflects what a population wants. Even the constitution can be changed with enough votes in parlement (at least in The Netherlands, US I don't know).

So the question is still open, is there any legal ground in what the FBI is asking from Apple?

And if there is, should the cooperate? And what would be the alternative, leave America?

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#309
post #48

Earlier quoted context omitted.

It's tricky. The All Writs Act clearly must have some boundaries as to reasonableness and the due process of the defendant. What Apple is being asked to do here isn't simply to unlock a phone. They're being asked to use their engineers, money, and expertise to build a tool to defeat the very encryption they developed. It's not clear the All Writs Act enables the government to simply order a search warrant recipient t…

There is also a first amendment angle in that due to the previous crypto wars code is considered speech so the act of forcing a developer to write code could be considered compelled speech.

That's an excellent idea, and certainly a tact I wouldn't initially have considered.

Reminds me of this xkcd: http://imgs.xkcd.com/comics/legal_hacks.png

Re: Justice Department Wants Apple to Unlock Nine More iPhones

#310

Earlier quoted context omitted.

They can search my phone and computer with a court order. What they should not be able to do is force companies to compromise proper encryption so they always have the ability to find something.

That's not the only angle here. Apple was asked to aide the FBI in attacking a phone, not to design bad crypto. (They may have also been asked to design bad crypto, but that's not what is happening here )

Except that the authorities do want companies to use bad crypto. The only reason they've had to fall back on demanding an attack vector is because they haven't yet been able to force their preferred solution (bad crypto) to be implemented.

Demanding an attack vector should be seen as the same concept as demanding bad crypto, because the intent behind the request is the same. They're trying to convince us that these are different requests, but the end result is the same. A workaround to attack good security is the same as having bad security to begin with. I can't imagine why anybody would think that "bad crypto" and "attack vector" are not very nearly the same thing.

Post reply on HN