Live data from Hacker News

Microsoft, Google, Facebook Back Apple in Blocked Phone Case

bloomberg.com

201–210 of 261 posts

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#201
post #22

From recent polls most people think this debate is about: "Should Apple be forced to give the Terrorist's phone data to the FBI" When what it's really about: "Should the FBI be able to compel technology companies to use their resources against their own and their Customers right to Security." In order for the public to be properly informed about what's really at stake this case needs to be about the "Technology Indus…

> "Should the FBI be able to compel technology companies to use their resources against their own and their Customers right to Security."

We can put the case into an even larger context and ask: should the FBI be able to compel [banks, accounting firms, insurance companies] to use their resources against their own and their Customers right to financial privacy? The answer to date, has been "yes." The right of the justice system to "every man's evidence",[1] has so far been thought to trump the interests of the customer relationship.

For decades, government has had the power to compel accounting firms and banks to search through their records (often at significant expense) to deliver information relevant to an investigation. I imagine those companies would love to be able to advertise that they won't cooperate with a government investigation of your taxes or financial transactions.

In my view, there are two different questions:

1) can the government ask Apple to unlock one iPhone; 2) can the government ask Apple to weaken security for all iPhones?[2]

The first question, at issue in this case, is something companies deal with all the time in many different contexts. The second question, on the other hand, may well be sui generis. I understand why Apple taking a stand on this particular hill--in their shoes I'd do it too. Better to "fight them over there so you don't have to fight them over here" so to speak.

I'm a little worried about the potential for blowback, though. The tech community is forced, in a way, to spread FUD to justify their argument as to (1). There are a lot of people who are confused by the reporting and think that this case involves the FBI requesting Apple to put backdoors in all of their phones, rather than leveraging an existing security weakness. That's not necessarily a great place to be in if you're found out.

[1] United States v. Nixon, 418 U.S. 683, 709 (1974).

[2] I don't think it's technically justifiable to say that (2) is implied by (1). Apple apparently already has the capability to subvert anyone's phones by using their signing keys to load weakened software. At a purely technical level, signing an "evil build of iOS" using an existing "backdoor" is different than introducing a backdoor into everyone's phone.

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#202
post #113

Earlier quoted context omitted.

"From recent polls most people think this debate is about..." ...or maybe people understand the debate, and they simply disagree with your opinion on the matter. For example, even as phrased in the second form, my answer is "yes, sometimes" , with an additional "there is no such thing as a 'customer's right to security'" , added for good measure. Even if I believed there were an absolute "right" to security, I don't…

> Even if I believed there were an absolute "right" to security, I don't think it's Apple's job to enforce it. Well, do you not believe the First Ammendmant protects against compelled speech? Because the FBI's argument here boils down to "we have the right to require people to cryptographically sign things against their will"

[deleted]

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#203
post #22

From recent polls most people think this debate is about: "Should Apple be forced to give the Terrorist's phone data to the FBI" When what it's really about: "Should the FBI be able to compel technology companies to use their resources against their own and their Customers right to Security." In order for the public to be properly informed about what's really at stake this case needs to be about the "Technology Indus…

> "Should the FBI be able to compel technology companies to use their resources against their own and their Customers right to Security." We can put the case into an even larger context and ask: should the FBI be able to compel [banks, accounting firms, insurance companies] to use their resources against their own and their Customers right to financial privacy? The answer to date, has been "yes." The right of the jus…

(2) is implied by (1) because once Apple has created the tool to do it once (1), the government has access to it and can (and will) use that tool endlessly (2). This is why Apple refuses to create this tool to unlock 1 iPhone.

History has shown we cannot restrict this by implementing laws/rules, just look at the news to see how these laws are abused right now, accessing all our private data.

EDIT: ok i get your point now; I imagine the reason this 'technical backdoor' exists in the first place, is because Apple wants to be able to update that part of the OS in case of bugs. If they make it 'not-updateable' the backdoor is closed but then if problems arise, bugs can't be fixed (for example the recent Error 5/home button bug).

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#204
post #22

From recent polls most people think this debate is about: "Should Apple be forced to give the Terrorist's phone data to the FBI" When what it's really about: "Should the FBI be able to compel technology companies to use their resources against their own and their Customers right to Security." In order for the public to be properly informed about what's really at stake this case needs to be about the "Technology Indus…

When what it's really about: Are remote "software updates" to a buyer's phone, under the sole control of the seller of the phone, at any time (even after purchase), for any reason (e.g. the one being proposed here), a good idea? Why? Why not? Should Apple customers be given the option to flash the hardware they purchase from Apple with their own choice of software, whereby they might better control the HW and hence s…

[deleted]

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#205

So there's an encrypted blob. The way you input a password has nothing to do with that blob or the encryption that was used to create it. The argument that this would be some kind of cryptographic back door seems a little specious to me, and I'm usually the biggest edgelord imaginable when it comes to decrying government surveillance. If we were talking about a safe somewhere, and the government asked the safe manufa…

[deleted]

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#206

Earlier quoted context omitted.

Heh. Open firmware would not solve this issue. If the firmware were open, the FBI would have already broken into the device. Apple's signing key (or, for the paranoid, the government's unwillingness to admit that they have obtained it through espionage) is primarily what is keeping the FBi's fingers out of the cookie jar. A better question is how to further lock the phone down in future updates so that Apple can't co…

Open doesn't mean it's an unlocked door. Open means that the owner of the device can replace the firmware. There's nothing not-open about requiring that the owner authenticate first. It's only not open if the vendor, rather than the owner, is the only one who the device will permit to replace its firmware.

> means that the owner of the device can replace the firmware

It means that a small minority of owners of the device can replace the firmware. Most people don't have the resources to do something like that.

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#207

Earlier quoted context omitted.

Heh. Open firmware would not solve this issue. If the firmware were open, the FBI would have already broken into the device. Apple's signing key (or, for the paranoid, the government's unwillingness to admit that they have obtained it through espionage) is primarily what is keeping the FBi's fingers out of the cookie jar. A better question is how to further lock the phone down in future updates so that Apple can't co…

Open doesn't mean it's an unlocked door. Open means that the owner of the device can replace the firmware. There's nothing not-open about requiring that the owner authenticate first. It's only not open if the vendor, rather than the owner, is the only one who the device will permit to replace its firmware.

Okay, so how do you verify that only the owner can do that, on the OS level, if the firmware is not first totally locked down? The security of iOS devices comes from the fact that Apple has engineered the devices to behave a certain way when using Apple firmware and that that firmware can't be modified or replaced without the signing key of Apple. And Apple is making it clear that they are on the side of the consumer, not the three letter agencies.

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#208
I (, in a non facetious manner) honestly don't get this. Aren't all of the above listed giants the ones that are going out of their way to track, spam and use our personal lives as objects of advertisement in the first place?

How or why are they petitioning for the government to not be able to do what they're already doing? Isn't that completely ironic? Is this a case of "it's okay if /WE/ steal your data, but we don't want to government too (so that only we have total access to it)"?

Someone more enlightened than me, please help me out.

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#209

Earlier quoted context omitted.

Open doesn't mean it's an unlocked door. Open means that the owner of the device can replace the firmware. There's nothing not-open about requiring that the owner authenticate first. It's only not open if the vendor, rather than the owner, is the only one who the device will permit to replace its firmware.

> means that the owner of the device can replace the firmware It means that a small minority of owners of the device can replace the firmware. Most people don't have the resources to do something like that.

The resources required to replace the firmware on a non-crippled Android device is access to the Internet from that device. This is not a big ask. Most people who own an iPhone have a data plan and/or access to WiFi.

Sure, only a small minority of device owners can actually make new firmware, but fortunately only one of them needs to make and distribute some firmware for everyone to be able to install it, if the device is open.

Re: Microsoft, Google, Facebook Back Apple in Blocked Phone Case

#210

Earlier quoted context omitted.

When what it's really about: Are remote "software updates" to a buyer's phone, under the sole control of the seller of the phone, at any time (even after purchase), for any reason (e.g. the one being proposed here), a good idea? Why? Why not? Should Apple customers be given the option to flash the hardware they purchase from Apple with their own choice of software, whereby they might better control the HW and hence s…

Heh. Open firmware would not solve this issue. If the firmware were open, the FBI would have already broken into the device. Apple's signing key (or, for the paranoid, the government's unwillingness to admit that they have obtained it through espionage) is primarily what is keeping the FBi's fingers out of the cookie jar. A better question is how to further lock the phone down in future updates so that Apple can't co…

[deleted]
Post reply on HN