Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

121–130 of 217 posts

Re: Apple – Privacy – Government Information Requests

#121

Earlier quoted context omitted.

You're not limited to 4 digits. In fact, when you set up Touch ID, the phone prompts you to enter a longer text-based passcode on the basis that you shouldn't have to enter it often.

The government has your fingerprint.

Which doesn't help them much because the fingerprint will only reveal the passcode if they gain physical access to the device's "secure element" and its contents (which is reportedly hard).

Re: Apple – Privacy – Government Information Requests

#122

The honest truth about all of this is, even if Apple were handing over information because of back doors, custom database interface applications for the NSA, they wouldn't tell us and would probably be gagged from doing so anyway, have we all forgotten about Lavabit? I hope not. I think we are all intelligent enough to know that even if Apple were handing over information, it wouldn't exactly be good for business to…

It is pretty naive nowadays to store any of your data online while thinking it is secure and no one will, or can touch it. Unless you do some hardcore encryption on your data yourself, which is really hard or even impossible with some data like call-logs, geographic location-data etc..

Re: Apple – Privacy – Government Information Requests

#123

Earlier quoted context omitted.

The quote is extremely misleading. Sure, it's encrypted by your passcode, and that's great. It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy. http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...

Not the point. The point is that they've done enough to legally respond to government requests by saying "we don't have a way to access the data". Hacking customers' phones, regardless of how easy it might be, is far beyond the scope of anything that a US court can order a private party to do.

But its something the NSA is more than capable of accomplishing

Re: Apple – Privacy – Government Information Requests

#124

Earlier quoted context omitted.

The quote is extremely misleading. Sure, it's encrypted by your passcode, and that's great. It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy. http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...

Not the point. The point is that they've done enough to legally respond to government requests by saying "we don't have a way to access the data". Hacking customers' phones, regardless of how easy it might be, is far beyond the scope of anything that a US court can order a private party to do.

But its something the NSA is more than capable of accomplishing

Re: Apple – Privacy – Government Information Requests

#125

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

What's keeping government agencies from putting keylogging code on the SIM card or baseband processor (whichever has the best access to host cpu/memory) via the carriers to obtain the passcode? Not much I guess. Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?

>keylogging code on the SIM card or baseband processor

That won't work.

>Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?

No, and even though I strongly doubt the government would even try to do this and even more strongly doubt Apple would comply, their new tech (apple pay and touch ID use hardware support to even protect against this sort of breach which shows that they are certainly thinking about it). I'm pretty sure Apple won't even have the ability to silently push an OS update (if they did then someone could find out because it would be in the OS and then all hell would break loose) - it would have to be accepted by the target which means there is a reasonably large chance of detection.

Re: Apple – Privacy – Government Information Requests

#126

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

The quote is extremely misleading. Sure, it's encrypted by your passcode, and that's great. It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy. http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...

It is only protected with just the passcode when on the physical device - Apple cannot bruteforce it because they don't have the capability to access it remotely (they can only wipe it).

Re: Apple – Privacy – Government Information Requests

#127
post #116

Earlier quoted context omitted.

Not the point. The point is that they've done enough to legally respond to government requests by saying "we don't have a way to access the data". Hacking customers' phones, regardless of how easy it might be, is far beyond the scope of anything that a US court can order a private party to do.

> is far beyond the scope of anything that a US court can order a private party to do. They could order Apple to disclose signing keys so that the government can install spyware themselves. See http://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_orde... for a case where they have done something similar before.

>the government can install spyware themselves

It would have to be an OS update since applications don't have access to that stuff, even if signed with an apple key.

Re: Apple – Privacy – Government Information Requests

#128

Earlier quoted context omitted.

> Not if they designed it properly. You can (and always should) design encryption code without having a single root key. Entirely open sourcing that code should not make any difference to the security of the encrypted data.

And then NSA forces Apple I to issue the OS update that breaks all your efforts.

That sort of order is out of scope of anything a US court can order, and I believe that an Apple employee would leak it before they complied with such an order.

Re: Apple – Privacy – Government Information Requests

#129
Except it's not open source. If it's not open source then you have no idea what's going on beyond what Apple tells you.

Ask your self:

Would Snowden use this phone? Your answer to this question is the same as the answer to the question "Is this phone secure?"

I guess I'll get downvoted for this sense it goes against the Apple circlejerk, but this issue is more important to me than magic internet points.

Re: Apple – Privacy – Government Information Requests

#130

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

Aren't all these data backed up to iCloud? Is it also protected with a passcode?

This seems like the flaw in the argument, yeah. iCloud isn't mandatory, of course, but most people do use it, so peoples' photos and things will be in The Cloud, anyway. Possibly several The Clouds; Google+ on iOS keeps badgering me to enable automatic photo uploading.
Post reply on HN