Live data from Hacker News

Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

nytimes.com

151–160 of 376 posts

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#151
post #109

Earlier quoted context omitted.

How exactly are they supposed to permanently remove all semblance of privacy? Short of infiltrating popular open source projects in plain view and proving the (potentially) unprovable, I don't see how this is possible.

They can make refusal to decrypt a federal felony.

As it already is in some cases in the United Kingdom. Granted, their freedom of speech protections aren't as great as ours, but if Congress really wanted to, what's to stop them from making a Consitutional ammendment that declares encryption keys as not being protected under the Fifth Ammendment?

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#152

Earlier quoted context omitted.

There are no terrorists. It's a fiction imposed upon the American people by a government with a power trip.

That assertion is patently absurd. There are absolutely people and organized groups who perpetrate horrible acts solely to terrorize others. They are not some 'fiction' created by a 'power tripping' government. However, the risk that these people present to the world, at this point, does not merit sacrificing economic and civil liberties in their entirety to combat them. Rather, the dilemma is in determining an accep…

Yes, +1. The world is not black and white. We need to make tradeoffs.

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#153
post #99

I honestly feel that engineers need not fall on their swords over this. The decision is up to them, of course. But ultimately, shareholders would expect someone to comply with the court order should the DOJ win. Note that Yahoo was threatened with daily fines of $250,000 for failing to comply in a FISA court case in 2008, and we only just learned this in 2014 [1]. I don't think we would live in a forced back door wor…

> I don't think we would live in a forced back door world for too long. After another 2, 4, or 8 years, we will eventually realize that giving the government a back door to the iPhone did not give it a back door to the myriad of other encrypted communications tools out there. Terrorists will find other ways to hide their communications. I'm going to disagree with you here. Didn't we think, back in 2001, that we'd onl…

> You will get to choose between using paper [...]

Let's give imagination a run:

After 10 years of FBI cases where child molesters and terrorist houses were raided only to find they were able to shred evidence last minute, the FBI decided that they don't have time, energy, money and will-power to sit down all day long and play with 10,000 pages-long paper puzzles.

Therefore they asked congress to pass a law where every company selling shredding machines will attach a little tiny camera to their device. Upon shredding, a photo will be taken of what you shred. This photo will be obviously securely transferred and stored in FBI vault, just in case, locked with each shredder's individual key until proper Court gives a warrant to give out encryption key and decrypt photos of documents that have been previously destroyed.

There you have it!

And don't get me started on 2030, where we will be able to read and print out people's thoughts...

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#154

Earlier quoted context omitted.

> Is the FBI then going to make a grab for source code, signing keys, and conscript people to do the work? I think it's become clear that they'd at least try .

Interesting. A draft targeting software engineers to forcibly enlist them in the government's "war on encryption". What kind of dystopia are we living in again?

Not a draft. As we've seen in Snowden, there are tons of engineers who support the security state and will volunteer to serve.

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#155
post #36
post #19

Earlier quoted context omitted.

The DOJ couldn't shut down apple. Apple has $200,000,000,000 in cash and marketable securities. DOJ's budget is only 27 billion. That's a lot of lawyer time. It's a huge waste of money, but there it is. Way less likely, but Apple could move HQ to another country. And take their secret source code and keys with them.

I wonder if there's any advantage for Apple to form their own sovereign nation to operate out of. They are already richer than many existing countries. Can't they just buy out a Singapore-sized island somewhere?

Couldn't the government just ban sales from that country (i.e. Apple). They have done that for Cuba, so why not for a company , country I mean, that "supports terrorism".

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#156

Earlier quoted context omitted.

> engineers need not fall on their swords I would quibble with this characterization. Security engineers may well improve their employment prospects and professional visibility by publicly demonstrating that they are unwilling to do work that is counter to the mission of securing systems. It seems likely to me that this sort of highly public gesture would be personally profitable, rather than a net sacrifice.

Ultimately the decision is up to those engineers. I'm just sharing my opinion. I've left former employers on moral grounds and later realized I could've resolved those differences within myself and effected change in ways other than quitting. Quitting doesn't save Apple. Does it help your job prospects as a security engineer? I'm not so sure about that either, but then again I'm not a security employer. Hypotheticall…

> Hypothetically, if I were, then as an employer I might be more interested in the guy who stuck it out working with the government at Apple.

One of the principal drivers of the positive effect on career prospects is the publicity this sort of public gesture would generate. Sure, all else being equal, many may prefer the engineer that sticks with the company. But all else is not equal. This particular gesture would generate a lot of publicity tied to the engineers eligibility for hire. Sticking with the company ends the story and would not likely garner nearly the same level of personal publicity, if any.

I'm not making any sort of value judgement as to whether this would be an ethically good or bad thing for an Apple security engineer to do. I just don't think they will really be risking much because enough people will view it as an attractive public display of personal integrity that s/he would have her/his pick of jobs. It would also be an ideal opportunity to launch a security consultancy.

The move isn't completely devoid of personal risk, but the risk seems to be overwhelmed by the opportunities that it would generate in my estimation. That is to say, it would be a good bet, and far from a true self sacrifice.

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#157
post #112
post #107

Earlier quoted context omitted.

But how would a judge have the technical know-how to make that determination? If the answer is to have security experts listen in an make the call, would that even be legal since one of the requirements is to allow Apple to keep this in-house for fear of leaking said code? One last final question, if they do force the engineers to come in and explain themselves over and over to the government's satisfaction, that wil…

Our legal system is asked to make findings of fact all the time on technical matters. This would be just like any of the rest of those. Witnesses could be questioned. Expert testimony could be delivered. Etc. I understand that it's a common viewpoint on HN that the courts are ill equipped to make these determinations. Personally I think that viewpoint is vastly overstated, but that's a debate for another day. As to y…

> As to your question about "unreasonable burden", Apple made something like 50 billion dollars in profit last year. The burden is going to have to get pretty high before it starts to get unreasonable. A couple of hours (or dozens of hours, or hundreds of hours) isn't going to even begin to get there.

Does this mean that "unreasonable burden" is relative? That just seems really weird to me that such a vague clause would be allowed in law. Like who makes that call? (honestly trying to understand the laws here)

Edit: Also consider that pulling off key engineers to do something completely unrelated to helping the company means time away from trying to stay ahead of competition. 1 month is already a huge amount of time when you're trying to stay ahead in one of the most competitive markets (mobiles). Also, a couple hours in court doesn't factor in time away from the office, travel time, and the additional cognitive burden of being in court. This also assumes the court schedules things in a manner that works within Apple's internal schedules. To me, this just sounds like a huge burden to any company in the mobile market.

> I understand that it's a common viewpoint on HN that the courts are ill equipped to make these determinations. Personally I think that viewpoint is vastly overstated, but that's a debate for another day.

I never said the courts were ill equipped to make those determinations. I said a judge wouldn't be able to do it because... well... that's not their expertise. To restate my question more clearly (I hope), how can you safely bring in security experts without compromising the case and guarantees that the courts would be allowing Apple?

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#158
post #121

Earlier quoted context omitted.

Like this: http://arstechnica.com/information-technology/2016/03/tp-lin... If they can't quite do that, then they bring back the whole "export-grade cryptography" thing, except they call it "terrorist-grade cryptography" this time around. Then they start monitoring every crypto-capable open-source project's responsible disclosure system. When they see a vulnerability good enough to subvert that open-source project, t…

"Then they start monitoring every crypto-capable open-source project's responsible disclosure system. When they see a vulnerability good enough to subvert that open-source project, they shut down that project before the bug can be fixed. And then they suppress all knowledge of the bug." ...to exploit it? seriously? i'm not saying it's impossible or unlikely, it just sounds like 1. it's a tremendous amount of work 2.…

I know, I know, the idea is incomplete, it needs some tweaks and refinement. It's just there to demonstrate the kind of power, freedom, and creativity we should be expecting to be pointed at crypto-capable open-source projects in the future we're looking at.

As for it being a tremendous amount of work: First, I'd guess that, given the infrastructure they already have, they could probably pull it off with a few dozen people. It's not bigger than, say, Reddit (78 employees?!). Second, have you seen how much effort they're putting into the kind of thing? They already have server cabinets throughout the US that read most of American's internet. IIRC they managed to stick a black box between Google's datacenters that could snoop on people's email while it was flying back and forth between their distributed storage system. Just imagine how much money, physical access, and and reverse-engineering those things took. And not only that, but that was theoretically GCHQ that did them, not the NSA! Foreign soil!

Seriously. The right mindset here isn't that it's "too much effort" or that it "doesn't work that way". We're dealing with something that has in the past demonstrated the ability to do these kinds of things. If you want a good set of tools for getting into the right state of mind for this, we should be treating it sort of like a hostile superintelligence, not any kind of bureaucracy.

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#159
post #56

Son, go to your room! But I don't want to go to my room! Son, go to your room! Mommy, what would happen if on the way to my room I ran into a pack of wild dogs in the hallway blocking my path? Would I still have to go to my room?

We detached this subthread from https://news.ycombinator.com/item?id=11309007 and marked it off-topic.

Re: Apple Encryption Engineers, If Ordered to Unlock iPhone, Might Resist

#160
post #99

Earlier quoted context omitted.

> I don't think we would live in a forced back door world for too long. After another 2, 4, or 8 years, we will eventually realize that giving the government a back door to the iPhone did not give it a back door to the myriad of other encrypted communications tools out there. Terrorists will find other ways to hide their communications. I'm going to disagree with you here. Didn't we think, back in 2001, that we'd onl…

> You will get to choose between using paper [...] Let's give imagination a run: After 10 years of FBI cases where child molesters and terrorist houses were raided only to find they were able to shred evidence last minute, the FBI decided that they don't have time, energy, money and will-power to sit down all day long and play with 10,000 pages-long paper puzzles. Therefore they asked congress to pass a law where eve…

Ok. You've succeeded in scaring me. Thanks.
Post reply on HN