Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

21–30 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#23
post #12

Earlier quoted context omitted.

"back doors" that require approval from the user on the phone..??

Backdoors that require the user to unlock their device and have paired with a PC in the past. If a paired PC is compromised (a trivial task for a sophisticated hacker or the NSA, if the millions of windows pc bot nets are evidence), and wifi sync is enabled, and the device is unlocked and in use, then the compromised PC could theoretically harvest personal information from the device without any warning or notificati…

Well, true, but copying personal data to the PC is exactly what sync is supposed to do - a good chunk of that data is actually synced with the computer, and the rest needs to be included in backups (which need to be able to be restored on other devices, so they can't be encrypted with a device-specific key). If Wi-Fi sync is enabled, all that needs to happen over Wi-Fi. So I'm not sure what Apple could do about it, other than make it harder to compromise Macs.

The part of this story I think deserves more attention is security against a sophisticated adversary who does not have the passcode or access to a paired computer. In this case, data protection should be effective (the data is encrypted with a key that requires going through the hardware AES engine to derive from the passcode, i.e. slow), but for some reason most data is apparently not protected. This doesn't seem hard to improve to me, and I'd like Apple to do so.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#24
post #19
post #11

Earlier quoted context omitted.

You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…

every industry trumps up the usefulness of their product, it's called marketing. It's on the consumer to cut through the marketing-speak and understand what they actually need to pay for.

It's also on each industry to inform truthfully and honestly. As the work to "cut through the marketing speak" can obstruct business activity there are already various laws in place to punish a too liberal interpretation of the word "marketing".

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#26
post #19
post #11

Earlier quoted context omitted.

You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…

every industry trumps up the usefulness of their product, it's called marketing. It's on the consumer to cut through the marketing-speak and understand what they actually need to pay for.

> every industry trumps up the usefulness of their product, it's called marketing.

It should be called lying and bullshitting, and I strongly believe that we tolerate it far too much as a culture.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#27
post #18

Earlier quoted context omitted.

>Yet in the slides for his talk[1] under theories he writes: >"Maybe for Developers for Debugging? No." Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.) Your comment is far mor…

I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.

The fact that the other major mobile OSs gets 98% of the mobile malware (according to studies), makes this point about the "nonchalant attitude" rather week...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#28
post #18

Earlier quoted context omitted.

>Yet in the slides for his talk[1] under theories he writes: >"Maybe for Developers for Debugging? No." Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.) Your comment is far mor…

I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.

I think that buying an Apple device is implicitly consenting to have all of your communications monitored and not to have access to your own data. In other words, I don't think this is a big deal, but there's also no need to spread FUD against the people who are specifically pointing it out.

edit: It's in the EULAs. I didn't think that I was saying something controversial:) I always underestimate people's level of denial...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#29
I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features.

• It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted.

• It's good to know Apple has the power to look through your encrypted files given physical access (file relay).

• It's good to know one can extract files from his phone using a trusted computer (house arrest).

However, that's it. There's no "back door". There's no (implied or otherwise) NSA conspiracy. There's a reason why the media "misunderstood" his talk: it was full of hyperbole.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#30
post #12

Earlier quoted context omitted.

"back doors" that require approval from the user on the phone..??

Backdoors that require the user to unlock their device and have paired with a PC in the past. If a paired PC is compromised (a trivial task for a sophisticated hacker or the NSA, if the millions of windows pc bot nets are evidence), and wifi sync is enabled, and the device is unlocked and in use, then the compromised PC could theoretically harvest personal information from the device without any warning or notificati…

In other words, News flash: physical access allows an attacker in the know to compromise computer security. You laid it out, a minimum of 4 circumstances need to happen to allow these exploits to work.

If we're going to have "lawful intercept" legal requirement, I'd rather have the mechanisms require this type of intrusive action that require a warrant in most cases.

I was really hooked by this talk until he characterized supervision/enterprise enrollment as a "backdoor", and the more I read about it, the more bullshitty it really is.

Post reply on HN