Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

11–20 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#11
Schneier knows this, and this is a particularly idealistic op-ed, but this is just how the exploit market works and while it would be nice if law enforcement would take the white-hat road, the hazard here is still vastly better than some kind of legal precedent for requiring backdoors.

The good thing about the exploit market is that it is naturally self-limiting: you don't burn a zero-day on a dragnet; you limit its use to high-value (and ideally court-sanctioned) targets.

Re: Your iPhone just got less secure. Blame the FBI

#12
The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap.

I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama, and certainly not the DOJ.

Bruce Schneier's previous coverage from 2015-07 [1] is what first got me interested and up to speed in the recent SB case. Even if Apple isn't demanding the FBI's method at this moment, I respect what Bruce has to say here.

[1] https://www.schneier.com/blog/archives/2015/07/back_doors_wo...

Re: Your iPhone just got less secure. Blame the FBI

#13
Your iphone just got less secure - so don't use iphones anymore.

It always amazes me when people get on their high horse and start complaining about something when the remedy is quite simple - don't use the iphone. Get an Android phone, or an Ubuntu phone, or a Blackphone or a Windows phone. There's plenty of other devices that haven't been cracked by the FBI.

There's irony in the fact Apple resisted the FBI attempts to crack the phone and now this vulnerability will go unpatched and the FBI now has a zero-day exploit they can use whenever they want.

Re: Your iPhone just got less secure. Blame the FBI

#14

If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.

The FBI doesn't owe Apple. It owes the public - many of whom own an Apple product.

Re: Your iPhone just got less secure. Blame the FBI

#15
To be clear, the FBI isn't compelling Apple to leave the vulnerability open, are they? My understanding is they simply found/were informed of a vulnerability that existed in this model of the phone, and are not informing Apple of it. If Apple themselves finds the vulnerability and patches it, the FBI can't do anything about it.

Re: Your iPhone just got less secure. Blame the FBI

#16

If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.

Because FBI spent taxpayer's money to find a vulnerability in a device used by millions of people - it should release that information so that apple can fix it. Simple as that.

Re: Your iPhone just got less secure. Blame the FBI

#18

Your iphone just got less secure - so don't use iphones anymore. It always amazes me when people get on their high horse and start complaining about something when the remedy is quite simple - don't use the iphone. Get an Android phone, or an Ubuntu phone, or a Blackphone or a Windows phone. There's plenty of other devices that haven't been cracked by the FBI. There's irony in the fact Apple resisted the FBI attempts…

I don't believe even for a second that Android devices are any more secure than iPhones. And I use an android phone. But let's be honest - with dozens of manufacturers there isn't a single one who dedicated the same amount of work to securing their devices or engineering things like the secure enclave in iPhones. I use a Sony phone but I'm sure Sony wouldn't have the guts to stand up to FBI, or that FBI would even need to ask - the hardware is most definitely not on the same level of polish as Apple's.

Re: Your iPhone just got less secure. Blame the FBI

#19
This is bad reporting.

The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Basically, if your phone supports Apple Pay, you're good.

And if it's the case, it was a design decision rather than a bug. The secure hardware wasn't ready for consumer use when those devices were designed (and even then, the first generation of iPhone fingerprint readers was pretty bad). Apple knew a desoldering attack could be successful, but such attacks are very expensive, require long-term physical possession of the phone, and are impossible to pull off covertly. There may be another way to pull off a direct hardware access attack without actually needing to desolder the flash memory, but that would still only be effective in the absence of a hardware security module. The only defense against this type of attack is a secure hardware encryption module like the one Apple included to support Apple Pay (because the banks likely insisted on this level of security).

Re: Your iPhone just got less secure. Blame the FBI

#20
I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it.

The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in question had a short passcode set. I'd bet dollars to donuts that whatever attack they used would not work against my phone with a secure passphrase.

I'm usually a fan of Schneier, but I think he really missed with this one.

Post reply on HN