I haven't had much luck finding a video of the talk, has anyone else?
Apple Confirms “Back Doors”, Downplays Their Severity
21–30 of 114 posts
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#22Cache: http://webcache.googleusercontent.com/search?q=cache:www.zdz...
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#23Earlier quoted context omitted.
"back doors" that require approval from the user on the phone..??
Backdoors that require the user to unlock their device and have paired with a PC in the past. If a paired PC is compromised (a trivial task for a sophisticated hacker or the NSA, if the millions of windows pc bot nets are evidence), and wifi sync is enabled, and the device is unlocked and in use, then the compromised PC could theoretically harvest personal information from the device without any warning or notificati…
The part of this story I think deserves more attention is security against a sophisticated adversary who does not have the passcode or access to a paired computer. In this case, data protection should be effective (the data is encrypted with a key that requires going through the hardware AES engine to derive from the passcode, i.e. slow), but for some reason most data is apparently not protected. This doesn't seem hard to improve to me, and I'd like Apple to do so.
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#24Earlier quoted context omitted.
You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…
every industry trumps up the usefulness of their product, it's called marketing. It's on the consumer to cut through the marketing-speak and understand what they actually need to pay for.
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#25Re: Apple Confirms “Back Doors”, Downplays Their Severity
#26Earlier quoted context omitted.
You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…
every industry trumps up the usefulness of their product, it's called marketing. It's on the consumer to cut through the marketing-speak and understand what they actually need to pay for.
It should be called lying and bullshitting, and I strongly believe that we tolerate it far too much as a culture.
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#27Earlier quoted context omitted.
>Yet in the slides for his talk[1] under theories he writes: >"Maybe for Developers for Debugging? No." Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.) Your comment is far mor…
I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#28Earlier quoted context omitted.
>Yet in the slides for his talk[1] under theories he writes: >"Maybe for Developers for Debugging? No." Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.) Your comment is far mor…
I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.
edit: It's in the EULAs. I didn't think that I was saying something controversial:) I always underestimate people's level of denial...
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#29• It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted.
• It's good to know Apple has the power to look through your encrypted files given physical access (file relay).
• It's good to know one can extract files from his phone using a trusted computer (house arrest).
However, that's it. There's no "back door". There's no (implied or otherwise) NSA conspiracy. There's a reason why the media "misunderstood" his talk: it was full of hyperbole.
Re: Apple Confirms “Back Doors”, Downplays Their Severity
#30Earlier quoted context omitted.
"back doors" that require approval from the user on the phone..??
Backdoors that require the user to unlock their device and have paired with a PC in the past. If a paired PC is compromised (a trivial task for a sophisticated hacker or the NSA, if the millions of windows pc bot nets are evidence), and wifi sync is enabled, and the device is unlocked and in use, then the compromised PC could theoretically harvest personal information from the device without any warning or notificati…
If we're going to have "lawful intercept" legal requirement, I'd rather have the mechanisms require this type of intrusive action that require a warrant in most cases.
I was really hooked by this talk until he characterized supervision/enterprise enrollment as a "backdoor", and the more I read about it, the more bullshitty it really is.