Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

191–200 of 217 posts

Re: Apple – Privacy – Government Information Requests

#191
post #175

Earlier quoted context omitted.

>"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" Too bad they (and other phone manufacturers) don't protect phone calls with some kind of end-to-end encryptio…

There's not much one company can do about the standards. [1] They can only control their own output. Apple asserts that Facetime and Facetime Audio are end-to-end encrypted. And Google claims Hangouts are encrypted as well. I don't know whether there are caveats (or how many) to either of those claims. But that's about as much as one could hope for in the current climate. [2] [1] Particularly upstart computer compani…

I heard a rumor that the FaceTime open spec never happened due to complicated patent issues, possibly related to this one: http://www.bbc.com/news/technology-20236114

All of this is a damn shame because in my experience the competing standards don't have the usability and quality that FaceTime provides.

Re: Apple – Privacy – Government Information Requests

#192
post #121

Earlier quoted context omitted.

Which doesn't help them much because the fingerprint will only reveal the passcode if they gain physical access to the device's "secure element" and its contents (which is reportedly hard).

It is really surprising how much HN turns a blind eye to / lacks imagination for potential security issues just because it's Apple. Well, actually it isn't surprising at all.

I'm inclined to reverse that. Whenever Apple tells the world about a way they're attempting to protect their users' privacy above and beyond what any other for-profit technology company of comparable size and scope has done, HN immediately tries to deconstruct it--which is by and large good, since we need to remember that no security model is perfect. But a small but vocal subset always demonstrates a remarkable level of imagination in presenting scenarios in which Apple can actively conspire against their users while remaining within the letter of their guarantee. I'm not positive this happens jut because it's Apple, but I have my suspicions.

Re: Apple – Privacy – Government Information Requests

#193
post #30

Earlier quoted context omitted.

>If they provide user-data after being served with a warrant their servers were never accessed, yet the data was provided. Yes, that's true. But if you run an email service that's based in Cupertino, what do you do when served with a lawful search warrant or wiretap order? Say "no," and be found in contempt of court and have all your servers carted away by some men in black so they can find the file they're looking f…

I go under the assumption that if I'm not the one generating and providing the encryption keys (and really, pre-encrypting the data), absolutely nothing is secure/encrypted. And in all honesty, if it touched the internet, it's already insecure to some extent. It's been "fun" to read Jewel vs. NSA proceedings, press statements, and officials' statements about these issues because of the extent to which they play word…

Why stop there? If you're not root, you're not secure either. For example, if someone else is root, they can do whatever they want with your locally generated keys, upto and including sending them to the NSA with a little bow on top.

Even if you are root it's no guarantee, thank you rootkits :/

As with all things security, sometimes it comes down to trust and legal protections.

Re: Apple – Privacy – Government Information Requests

#194

Earlier quoted context omitted.

The US government forced Lavabit to install a back door that didn't exist before (or go out of business, which isn't really an option for Apple). I wonder what is to legally stop the government from forcing Apple to do the same? I guess one answer is that Apple has more resources to fight or lobby.

Lavabit wasn't forced to install a backdoor, the guy running it just kept refusing to comply with previous legal requests which were much narrower in scope. Since he didn't comply they took the nuclear option (which he could have easily prevented).

Whether or not he was in contempt, that's still a bullshit way to approach the problem.

Contempt of court? Fine and then jail him for non-compliance. Seize Lavabit's assets if required. I doubt he would have let it come to that.

But their solution was analogous to "won't give us back that alleged stolen $20 we told you about? We want your whole bank balance."

Aww hell naw.

Re: Apple – Privacy – Government Information Requests

#195

Earlier quoted context omitted.

Well it certainly doesn't work like that on an iPhone.

Please illuminate me then as to what the iPhones processor architecture looks like, seeing as iPhones also use Qualcomm basebands, same as most Android devices...

They still don't have physical keyboards.

Re: Apple – Privacy – Government Information Requests

#196

Earlier quoted context omitted.

You get the government you vote for.

You get the government the majority of voters vote for.

I'd agree if US voters actually bothered to go voting, and participated in their own democracy instead of turning their brains off and watching TV. But seeing how they don't, the US really gets the government that the most active/noisy minory supports.

(The same is largely true in the EU, even though it's possibly more pronounced the US.)

Re: Apple – Privacy – Government Information Requests

#197
post #116

Earlier quoted context omitted.

> is far beyond the scope of anything that a US court can order a private party to do. They could order Apple to disclose signing keys so that the government can install spyware themselves. See http://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_orde... for a case where they have done something similar before.

>the government can install spyware themselves It would have to be an OS update since applications don't have access to that stuff, even if signed with an apple key.

I assumed it was primarily the review process ensuring that the proper sandbox configuration was included in the bundle and applied to apps at runtime, checking for private API use automatically etc, and that Apple could probably ignore their own restrictions if they chose to, especially those private APIs.

iOS won't let even the most permissively configured, "unreviewed" app do things that apps aren't supposed to be able to do?

Re: Apple – Privacy – Government Information Requests

#198

Earlier quoted context omitted.

Please illuminate me then as to what the iPhones processor architecture looks like, seeing as iPhones also use Qualcomm basebands, same as most Android devices...

The baseband processor has no access to the parts of memory it is not meant to, possibly some of the early iPhones did but currently they are properly isolated.

Please substantiate with a link.

Re: Apple – Privacy – Government Information Requests

#199
post #121

Earlier quoted context omitted.

Which doesn't help them much because the fingerprint will only reveal the passcode if they gain physical access to the device's "secure element" and its contents (which is reportedly hard).

It is really surprising how much HN turns a blind eye to / lacks imagination for potential security issues just because it's Apple. Well, actually it isn't surprising at all.

I am certainly not "HN". If you want to argue/discuss, do so. I'm well aware that a "secure element" is never 100% unbreakable. But in the usecase the GP mentioned (government broadly gathers data), hiding the data in a separate hardware compartment will at least help.

Re: Apple – Privacy – Government Information Requests

#200

Earlier quoted context omitted.

Of course they can. All you have to do is leak passwords/private keys. An OS is actually much more powerful, it controls everything, it has direct access to memory. If a user can see his photo, the OS can.

not quite, on the platform I am on you cannot extract passwords at all, they simply are not stored. encryption at the hardware level may have a backdoor but os level is similar. lets be honest, if they want your data your the weakest link. if you want to be paranoid enough to go the route your thinking its far cheaper for them to take you to a back room and employ a hammer to you.

Doesn't matter if they are stored or not. If a user can access his files, so can the OS he is using.
Post reply on HN