Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

61–70 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#61
post #33

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

> It's good to know Apple has the power to look through your encrypted files given physical access (file relay). So the requisites are: "be Apple" and "have physical access"? That's awfully little for what's supposed to be encrypted files. It (seems to be) no secret that law enforcement sends devices to Apple when they can't handle them themselves. So if I'm understanding it right: you can't protect yourself with an…

I think this is relevant; Apple says "diagnostic info" while others say that it's the users' personal encrypted files.

I haven't found confirmation on whether the list Zdziarsky has in his presentation is exaggerated, completely true, or false.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#62

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

> Apple has the power to look through your encrypted files given physical access > However, that's it. There's no "back door". What? How is that not a backdoor? Edit: Also, from the article, "Apple apparently has admitted to the mechanics behind file relay, which skip around backup encryption, to get to much the same data. In addition to this, it can be dumped wirelessly, without the user’s knowledge." So not even ph…

you need access to a computer that your target device has paired with in order to recover the pairing keys in order to pull this off.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#63

What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access? You'd be pretty annoyed if the front door to your house, when you…

There are USB condoms built exactly for the scenario you describe.

http://int3.cc/products/usbcondoms

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#64
post #63

What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access? You'd be pretty annoyed if the front door to your house, when you…

There are USB condoms built exactly for the scenario you describe. http://int3.cc/products/usbcondoms

That's an amazing name.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#65

What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access? You'd be pretty annoyed if the front door to your house, when you…

This is what is worrying me the most.

Why can something even repeatedly ask for permission? (My iPhone was asking me every 5 seconds the other day due to a faulty cable.) Even if there's a reason for that, why isn't there a "don't ask again" button?

Why doesn't such a thing need a pin code or iCloud password entry?

Why isn't services like file_relay or pcap a setting deep inside the Advanced section of Settings.app that requires password entry on enabling and features a warning message?

These things are advanced features. Few use them, why not make it a little more difficult?

Why can't I opt-out of Apples access to my files? Sure, I can say "No" when they ask at the store, but I could say no as well in the Settings app.

It's easier to enable packet capture than complete the Provisioning Profile process when releasing an app update to App Store.

These are the things Apple should be answering instead of the vague support note entry they published today.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#66
post #64
post #63

Earlier quoted context omitted.

There are USB condoms built exactly for the scenario you describe. http://int3.cc/products/usbcondoms

That's an amazing name.

I think the name may have been coined in this HN thread: https://news.ycombinator.com/item?id=6146279 around August 2nd, 2013.

Google shows some uses before hand[1], but Wayback Machine does not corroborate. I think Google is using the self-reported page date and pages dynamically update with "latest news' content.

[1] http://int3.cc/collections/all

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#67

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

Are you joking? Remote access for a specific party will virtually always become remote access for malicious actors, whether that was the original intent or not.

> It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted or been tricked into trusting

> It's good to know Apple or anyone who can spoof Apple has the power to look through your encrypted files given physical access (file relay).

> It's good to know one can extract files from his phone using a trusted or seemingly trusted computer (house arrest).

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#68
post #59
post #55

Earlier quoted context omitted.

> and be able to imitate Apple cryptographically Like impersonate them cryptographically with a forged/stolen ssl cert?[1] > one also needs to have physical access to the phone The user only has to pair the device with their PC for the PC to become a "trusted device", from which this exploit can be run. [1] > Serious Security: Google finds fake but trusted SSL certificates for its domains, made in France http://naked…

That is about the browser CA system, which is a mess of questionable trust. It's not an attack that is applicable to Apple's own root certificate.

> That is about the browser CA system

No, SSL certs are using to sign packages and software too. And Apple would not have a root cert, their cert would be signed by a root CA, which could be used to sign other certs if it's tricked into thinking its' Apple requesting them (like in the recent Google cert example).

So one could impersonate a company if they have a cert that says they are that company.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#69
post #63

What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access? You'd be pretty annoyed if the front door to your house, when you…

There are USB condoms built exactly for the scenario you describe. http://int3.cc/products/usbcondoms

It partially matches what he's talking about, but it's still a trinary choice.

1> Don't tether

2> Get only power

3> Give away the keys to the castle

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#70

What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access? You'd be pretty annoyed if the front door to your house, when you…

This is what is worrying me the most. Why can something even repeatedly ask for permission? (My iPhone was asking me every 5 seconds the other day due to a faulty cable.) Even if there's a reason for that, why isn't there a "don't ask again" button? Why doesn't such a thing need a pin code or iCloud password entry? Why isn't services like file_relay or pcap a setting deep inside the Advanced section of Settings.app t…

I think my iPhone was repeatedly asking about it for similar reasons to yours, as the connector is worn and it can take several plug attempts to make it even charge. However, a malicious USB socket could cause repeated prompts by just briefly dropping the power from time to time to trigger it. (n.b. I'm sure my experience wasn't a sinister attack on my phone, just stating that this is possible to do)

The "Don't ask again" is a little tricky - is there enough information present for the phone to tell if it is plugged into the same or different computer?

A better UI would be for the phone to always default to not pairing. No popup choice would be shown at all. After all, how often do you need to pair to a new computer?

Post reply on HN