Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

141–150 of 217 posts

Re: Apple – Privacy – Government Information Requests

#141

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

[deleted]

Re: Apple – Privacy – Government Information Requests

#142

Earlier quoted context omitted.

That sort of order is out of scope of anything a US court can order, and I believe that an Apple employee would leak it before they complied with such an order.

> That sort of order is out of scope of anything a US court can order How do you know that? Secret court orders are secret. "National security" trumps everything these days. LavaBit chose to shut down rather to insert a backdoor that was forced on them. I doubt Apple will shut down over that. And thanks to Snowden we know Apple's products have been backdoored already. http://www.spiegel.de/international/world/catalog…

But the laws that makes them legal are not secret.

Re: Apple – Privacy – Government Information Requests

#143

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

What's keeping government agencies from putting keylogging code on the SIM card or baseband processor (whichever has the best access to host cpu/memory) via the carriers to obtain the passcode? Not much I guess. Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?

Some very knowledgable iOS security people have told me how hard it is to break iOS. You need quite a few chained exploits to do anything meaningful. Browsers are pretty much the only things with Read/Write/Execute memory.

Security is always a convenience/security trade-off. iOS is about as good as you can get before inconvenience will turn people to less secure devices.

Re: Apple – Privacy – Government Information Requests

#144
post #121

Earlier quoted context omitted.

Which doesn't help them much because the fingerprint will only reveal the passcode if they gain physical access to the device's "secure element" and its contents (which is reportedly hard).

It is really surprising how much HN turns a blind eye to / lacks imagination for potential security issues just because it's Apple. Well, actually it isn't surprising at all.

You've got a lot of reasonable responses above.

Re: Apple – Privacy – Government Information Requests

#145

Earlier quoted context omitted.

You're not limited to 4 digits. In fact, when you set up Touch ID, the phone prompts you to enter a longer text-based passcode on the basis that you shouldn't have to enter it often.

The government has your fingerprint.

My government doesn't have my fingerprint, but the US government does...

Re: Apple – Privacy – Government Information Requests

#146

Earlier quoted context omitted.

The US government forced Lavabit to install a back door that didn't exist before (or go out of business, which isn't really an option for Apple). I wonder what is to legally stop the government from forcing Apple to do the same? I guess one answer is that Apple has more resources to fight or lobby.

Lavabit wasn't forced to install a backdoor, the guy running it just kept refusing to comply with previous legal requests which were much narrower in scope. Since he didn't comply they took the nuclear option (which he could have easily prevented).

Prevented by complying, ie. selling out his customers' privacy?

Re: Apple – Privacy – Government Information Requests

#147

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

I am aware of once incidence of an Australian state police forensics unit being unable to circumvent a non-simple passcode lock on iOS 6.1.3 with physical access to the device (iPhone 4s), set to wipe all user data after 10 unsuccessful attempts. Seems secure to me.

Re: Apple – Privacy – Government Information Requests

#149

Earlier quoted context omitted.

What's keeping government agencies from putting keylogging code on the SIM card or baseband processor (whichever has the best access to host cpu/memory) via the carriers to obtain the passcode? Not much I guess. Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?

>keylogging code on the SIM card or baseband processor That won't work. >Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities? No, and even though I strongly doubt the government would even try to do this and even more strongly doubt Apple would comply, their new tech (apple pay and touch ID use hardware support to even protec…

Not on the sim card, but on the base band processor it very probably will work, since the base band on many cell phone cores share the memory with the application processor.

Re: Apple – Privacy – Government Information Requests

#150
post #101

Earlier quoted context omitted.

Is this directed at me? I'm not outraged at Apple at all, I think they're trying to play the long game here. I'm just sick of the word games, deception, and legalese from anyone regarding privacy. It's hard enough fully understanding exactly how all the pieces fit together (technology, laws, politics, etc.) for people that are genuinely interested in this, let alone the average consumer. Pointing out loopholes in wor…

Well, I think whatever Apple says, you will find a "loophole" in the wording that supposedly allows them to do evil things. Try it: pretend you are Apple and just try writing a statement that you would consider acceptable and that you wouldn't call "word games, deception and legalese". Myself, I think they did fairly well, certainly the best of any tech company out there today.

Absolutely correct, no amount of wording will provide adequate proof. Thats why if you are providing a security product or product providing security features, open up the source code and provide a way to validate that that source is actually what is running on the hardware.

Until then I assume it is unsecure.

Post reply on HN