Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

41–50 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#42
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

Just to be clear, are you suggesting that if the details aren't provided in a slide somewhere, than those details were not mentioned in the talk?

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#44
post #37

Earlier quoted context omitted.

>Yet in the slides for his talk[1] under theories he writes: >"Maybe for Developers for Debugging? No." Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.) Your comment is far mor…

I was only providing an example for pcapd rather than all of the items he is classing as backdoors. The entire slide is: Maybe for Developers for Debugging? No. - Actual developer tools live on the developer image, and are only available when Developer Mode is enabled - Xcode does not provide a packet sniffing interface for developers - Developers don’t need to bypass backup encryption - Developers don’t need access…

Since I no longer work for the company, i'll mention that I've worked with the team at Apple that used pcapd in the iphone. It was an extremely valuable tool for finding/testing issues.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#45
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

[deleted]

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#46
post #12

Earlier quoted context omitted.

"back doors" that require approval from the user on the phone..??

Backdoors that require the user to unlock their device and have paired with a PC in the past. If a paired PC is compromised (a trivial task for a sophisticated hacker or the NSA, if the millions of windows pc bot nets are evidence), and wifi sync is enabled, and the device is unlocked and in use, then the compromised PC could theoretically harvest personal information from the device without any warning or notificati…

I get a notification asking if I want to trust the computer I've just connected to every time I connect, regardless if I've trusted it in the past or not.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#48

This post appears to be gone. Here's Apple's (new) documentation on the matter: http://support.apple.com/kb/HT6331?viewlocale=en_US&locale=e... If Apple is being truthful and transparent, calling this a "backdoor" is a bit like calling sshd a "backdoor".

I don't see where they document how you disable or block these.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#49
post #6

So in short: Apple has back doors that they claim aren't really back doors since only Apple apps can use them. If the NSA hasn't been using them already, it is only a matter of time.

If it's a backdoor for Apple, then it's a backdoor for anyone who can figure it out (other apps, hackers, government agencies alike).

As I understand it, there is more than just figuring out how it works; one also needs to have physical access to the phone and be able to imitate Apple cryptographically. Not out of reach for the NSA maybe, but not exactly typical hacker stuff.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#50

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

> Apple has the power to look through your encrypted files given physical access

> However, that's it. There's no "back door".

What? How is that not a backdoor?

Edit: Also, from the article, "Apple apparently has admitted to the mechanics behind file relay, which skip around backup encryption, to get to much the same data. In addition to this, it can be dumped wirelessly, without the user’s knowledge."

So not even physical access, just proximity/same wireless network?

Post reply on HN