Live data from Hacker News

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

404media.co

181–190 of 565 posts

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#181
post #39

Earlier quoted context omitted.

This (I think) refers not to the people securing their devices against third parties but the vendors "securing" the devices against loss of profits. Essentially, the question referenced here is that of ownership. Is it your device, or did you rent it from Apple/Samsung/etc. If it is locked down so that you can't do anything you want with it, then you might not actually be its owner. ___ _Ideally_ you wouldn't need to…

> Essentially, the question referenced here is that of ownership. Is it your device, or did you rent it from Apple/Samsung/etc. If it is locked down so that you can't do anything you want with it, then you might not actually be its owner. Both goals actually are possible to implement at the same time: Secure/Verified Boot together with actually audited, preferably open-source, as-small-as-possible code in the boot an…

The TPM can be programmed (ie designed) to lie about the whitelist though.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#182

Earlier quoted context omitted.

Absolutely every aspect of it? What’s so hard about adding a feature that effectively makes a single-user device multi-user? Which needs the ability to have plausible deniability for the existence of those other users? Which means that significant amounts of otherwise usable space needs to be inaccessibly set aside for those others users on every device—to retain plausible deniability—despite an insignificant fractio…

It doesn't seem fundamentally different from a PC having multiple logins that are accessed from different passwords. Hasn't this been a solved problem for decades?

You can have a multiuser system but that doesn't solve this particular issue. If they log in to what you claim to be your primary account and see browser history that shows you went to msn.com 3 months ago, they aren't going to believe it's the primary account.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#183
post #4

[flagged]

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

> What’s so hard to make 2-3 pins and each to access different logged in apps and files.

I've been advocating for this under-duress-PIN feature for years, as evidenced by this HN comment I made about 9 years ago: https://news.ycombinator.com/item?id=13631653

Maybe someday.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#184

Earlier quoted context omitted.

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

They are willing to kill people and then justify it by calling them terrorists. Plausible deniability is pointless.

Uh, that escalated quickly.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#185

Earlier quoted context omitted.

It doesn't seem fundamentally different from a PC having multiple logins that are accessed from different passwords. Hasn't this been a solved problem for decades?

Multi-user has been solved for decades. Multi-user that plausibly looks like single-user to three letter agencies? Not even close.

Doesn't having standard multi-user functionality automatically create the plausible deniability? If they tried so hard to create an artificial plausible deniability that would be more suspicious than normal functionality that just gets used sometimes.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#186

Earlier quoted context omitted.

Lockdown mode significantly effects the usability of the phone. It completely disables JIT js in Safari for example.

You can choose to exclude Safari from these protections[0]. Honestly, looking at the list of "limitations" you'll have while running Lockdown mode, I'm surprised most of them aren't the system default. [0] https://support.apple.com/en-us/105120 - under "How to exclude apps or websites from Lockdown Mode"

Sure but the JIT js disable and limiting of image/video decoders are combined basically all the security from lockdown mode, so disabling it seems pointless.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#187
post #91

Earlier quoted context omitted.

I get so annoyed by this Socratic line of questioning because it’s extremely obvious. Terrorist has plans and contacts on laptop/phone. Society has a very reasonable interest in that information. But of course there is the rational counter argument of “the government designates who is a terrorist”, and the Trump admin has gleefully flouted norms around that designation endangering rule of law. So all of us are adults…

At the risk of being kind of ass, which I've been trying to be better about lately, I'm going to offer some advice. If you can't even respond to a question about secure computing without bringing American presidential politics into things, perhaps you need to take a break from the news for a few weeks. The reason I asked that question is because I don't think it's complicated. I should be able to lock down my device…

The line of reasoning is more like this: if you make and sell safe-cracking tools then it would not be unreasonable for the government to regulate it so only registered locksmiths could buy it. You don't want people profiting from the support of criminal acts.

The government could similarly argue that if a company provides communication as a service, they should be able to provide access to the government given they have a warrant.

If you explicitly create a service to circumvent this then you're trying to profit from and aid those with criminal intent. Silkroad/drug sales and child sexual content are more common, but terrorism would also be on the list.

I disagree with this logic, but those are the well-known, often cited concerns.

There is a trade-off in personal privacy versus police ability to investigate and enforce laws.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#188
post #23

Earlier quoted context omitted.

Serious question: What are the "valid concerns" about people securing their computing devices against third parties?

I get so annoyed by this Socratic line of questioning because it’s extremely obvious. Terrorist has plans and contacts on laptop/phone. Society has a very reasonable interest in that information. But of course there is the rational counter argument of “the government designates who is a terrorist”, and the Trump admin has gleefully flouted norms around that designation endangering rule of law. So all of us are adults…

> ...the Trump admin has gleefully flouted norms around that designation...

One would have to hold a fairly uninformed view of history to think the norms around that designation are anything but invasive. The list since FDR is utterly extensive.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#189
post #51

Earlier quoted context omitted.

Perhaps you should? From pages 20 and 22: > 52. These warrants would also permit law enforcement to obtain from Natanson the display of physical biometric characteristics (e.g., fingerprint, thumbprint, or facial characteristics) in order to unlock devices subject to search and seizure pursuant to the above referenced warrants > 60. Accordingly, if law enforcement personnel encounter a device that is subject to searc…

>From pages 20 and 22: From pages 20 and 22 of ... not the warrant: It'd certainly be a good first step to figure out how to identify whether or not the PDF you're linking to is in fact a warrant at all before trying to educate others on them.

So post a link to the warrant.

This document is specifically asking for the right to force biometric access. It seems based on reporting that biometric access was granted.

If you're claiming the warrant doesn't force biometric access despite it being request, you need to substantiate the claim.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#190
post #7

> Natanson said she does not use biometrics for her devices, but after investigators told her to try, “when she applied her index finger to the fingerprint reader, the laptop unlocked.” Curious.

She has to have set it up before. There is no way to divine a fingerprint any other way. I guess the only other way would be a faulty fingerprint sensor but that should default to a non-entry.

Could be a parallel construction type thing. They already have access but they need to document a legal action by which they could have acquired it so it doesn't get thrown out of court.

I think this is pretty unlikely here but it's within the realm of possibility.

Post reply on HN