Live data from Hacker News

Under iOS 11, authorities won’t be able to image your device without a passcode

arstechnica.com

171–180 of 296 posts

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#171

Earlier quoted context omitted.

I am not a diehard android, but i'm replying to you from a LineageOS phone without the Gapps, using microg as an alternative to the google services, and firefox as a browser. Privacy is achievable on Android. However, I do agree it os very involved.

The services provided by Gapps that send data to Google (push messaging, aGPS, crash reporting, app installs, safe browsing, etc.) also exist on iOS with exactly the same privacy policies. The only difference is that you can remove or disable them on Android devices if you are paranoid, while no such remedy exists on iPhones. By your standards, privacy is achievable with difficulty on Android and not at all on iOS.

Safe Browsing and Crash Reporting can be turned off with no repercussions. You can turn off location altogether, though I'm not sure if you can turn off aGPS only.

That leaves app installs (Android allows side loading) and push messaging (I'm not sure about this one) as the ones that you can't disable on iOS.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#172

Earlier quoted context omitted.

The services provided by Gapps that send data to Google (push messaging, aGPS, crash reporting, app installs, safe browsing, etc.) also exist on iOS with exactly the same privacy policies. The only difference is that you can remove or disable them on Android devices if you are paranoid, while no such remedy exists on iPhones. By your standards, privacy is achievable with difficulty on Android and not at all on iOS.

There is another, more fundamental difference. With Apple, you are the customer. With Google, you are the product.

Yet this "fundamental difference" does not change the fact that both companies' devices provide exactly the same amount of privacy out of the box, while only the Google device is truly yours to put whatever software you want on it, down to the OS.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#173
post #170

Earlier quoted context omitted.

Sorry, I did not mean to say that is how it is but how it seemed. My understanding is that the modems aren’t capable. That being said, activation is done only with a nexus or pixel device (software) and while switching might be a hardware issue, iPhone works on both sprint and Tmobile (on an iPhone on Tmobile after moving from Verizon) and so google fi should still work.

As I mentioned, I AM already using Google Fi on my iPhone. What does not work is the hardware feature of handing off between providers mid-flight. With my [now deceased] Nexus X, a call would seamlessly [to me, anyways] switch between providers during medium/longer commutes. With my iPhone using just T Mobile, calls get dropped during my daily route as there are certain "T Mobile blind spots".

Sorry, I completely misunderstood. Thanks for clarifying!

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#174

Earlier quoted context omitted.

You are correct. Android does not require you to enter a passcode to trust a computer if you have a fingerprint registered. The change is that Apple now requires you to enter a passcode if you have set up a passcode on the device in the past. If you haven't, the attack vector still exists, and if you are traveling with a trusted laptop with fingerprint unlock, the attack vector still exists with one level of indirect…

> If you haven't, the attack vector still exists, and if you are traveling with a trusted laptop with fingerprint unlock, the attack vector still exists with one level of indirection. You can't setup TouchID without a passcode. The "attack vector" only exists if you 0 security on your iPhone to begin with. (So , yes, technically the attack vector exists if you choose to use no locks at all).

You misunderstand. The vector is: I take random persons phone, compel them to provide me their finger print, and now when I plug the phone in to a computer, I can unlock the device and then tap "trust" in order to back up the phone to the computer. If the iPhone was already powered on and the user had entered their passcode after it turned on, even if it was two weeks ago (there may be a time out I'm not aware of, but you get the point), I'd be able to backup their device to my computer.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#175
post #62

Earlier quoted context omitted.

I see your point, but: That's not an excuse, that's an explanation. It is anti freedom whether that's their end game or not. I don't really care about Apples motives, I care about the product. Really, Apple is anti Nothing and pro only one thing: money. Everything else is a corollary. Including ease of use, freedom, and privacy. It's just that those things do matter to me (and GP).

What's an example of a common use case in which Apple is anti-freedom in your opinion?

Presumably they're talking about the App Store walled garden.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#176

Earlier quoted context omitted.

There is another, more fundamental difference. With Apple, you are the customer. With Google, you are the product.

Yet this "fundamental difference" does not change the fact that both companies' devices provide exactly the same amount of privacy out of the box, while only the Google device is truly yours to put whatever software you want on it, down to the OS.

I trust the vendor whose primary revenue stream comes from me, rather than the one whose primary revenue stream is me (or my private data). I trust Google to abide by their T&C's about as much as I trust the NSA to abide by the laws governing the extent of their actions. Which is to say, precisely none.

You can argue until you're blue in the face but Apple have little to no incentive to exploit my private data while Google have every incentive to do so.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#177
post #169

Anyone could shed a light on how difficult would be the implementation of the following: - All data encrypted by default - The "dump" of the phone memory or macbook hard-drive makes it looks like the whole drive is full. It means that the free space is populated with random data that is, itself, encrypted. - User can switch from his user profile to a fake user-profile and import some data (like contacts/messages/phot…

This would be awesome.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#178

In the February 2017 case of a California artist who was questioned at San Francisco International Airport upon re-entry, after he finally agreed to unlock his iPhone, it was taken out of his sight for several minutes and could have been imaged without his knowledge. Under iOS 11, unless the artist, Aaron Gach, decided to actually give up the passcode (rather than type it in himself), he could at least have been reas…

As mentioned elsewhere, Apple can't prevent "rubber hose decryption" (where someone compels/coerces/tortures you to get access to an unlocked phone). I suspect this feature wasn't designed to prevent that threat. My guess is this somehow foils or mitigates the workaround that the Israeli company sold to the FBI after the San Bernadino phone issue.

I believe that they simply dumped the NAND to circumvent the passcode entry limit then brute-forced. But it was also an iPhone 5C model which does not include the Secure Enclave. This method could not be reproduced on any model beyond the 5S.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#179

Earlier quoted context omitted.

Yet this "fundamental difference" does not change the fact that both companies' devices provide exactly the same amount of privacy out of the box, while only the Google device is truly yours to put whatever software you want on it, down to the OS.

I trust the vendor whose primary revenue stream comes from me, rather than the one whose primary revenue stream is me (or my private data). I trust Google to abide by their T&C's about as much as I trust the NSA to abide by the laws governing the extent of their actions. Which is to say, precisely none. You can argue until you're blue in the face but Apple have little to no incentive to exploit my private data while…

I understand your position now. You're a conspiracy theorist. Google and Apple have exactly the same incentive to exploit your private data — money. They also have exactly the same disincentive to disobeying their privacy policies — lawsuits and bad press leading to loss of money.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#180
post #177
post #169

Anyone could shed a light on how difficult would be the implementation of the following: - All data encrypted by default - The "dump" of the phone memory or macbook hard-drive makes it looks like the whole drive is full. It means that the free space is populated with random data that is, itself, encrypted. - User can switch from his user profile to a fake user-profile and import some data (like contacts/messages/phot…

This would be awesome.

No it is not. It signifies a divide between the tech sector which strives for privacy and government (which is/was supposed to protect the people)
Post reply on HN