Live data from Hacker News

Apple’s dangerous game

washingtonpost.com

21–30 of 113 posts

Re: Apple’s dangerous game

#21
I would rather let a few murderers go free than expand the government's power to store and retrieve private communications. You never know what benign things you might be doing today that will one day be dangerously illegal (or maybe just embarrassing enough to hurt you now that you have some kind of power).

Re: Apple’s dangerous game

#22

The article asks: > How is the public interest served by a policy that only thwarts lawful search warrants? Perhaps the answer is that judges act as rubber stamps now, authorizing way too many search warrants. The author assumes that the judges are fairly applying the 4th amendment.

> judges act as rubber stamps now

Exactly. Our government is as overbearing and oppressive as it's been in a very long time. I read somewhere that judges approve something like 99% of the search warrants presented to them. They no longer serve as a check on law enforcement.

I'd love to hear otherwise, to hear how judges are doing a good job balancing the interests of people against the interests of law enforcement.

Re: Apple’s dangerous game

#23
post #9
post #7

I'll leave it to other hackers to put it more eloquently. Any means to bypass the encryption on iOS 7 and before are vulnerabilities that adversaries can use to bypass the encryption on iOS 7 and before. Apple is basically saying that they didn't build in back doors, which this author is making the case for. iOS 8 data is still available to the government by other means than warrants and at much, much, much higher ex…

are you sure they built in a real backdoor? i thought they salted user PINs with a hard-wired nonce that's specific to every device - then when the fuzz needs to get the device unlocked apple looks up what the hard-wired nonce is for that specific device, and then crack the 4 digit pin. anyone have details on how apple actually unlocked devices?

>apple looks up what the hard-wired nonce is for that specific device, and then crack the 4 digit pin.

Not quite. There are two nonces involved. One is (probably) easy for Apple to extract (the randomly generated, re-writable value in effaceable storage) and the other is (supposedly) very difficult to extract, because it's burned into the CPU hardware. If all works as intended, the only way to extract the second one is to decap the CPU and read it with a microscope.

Also, you can have arbitrarily long PINs, including alphanumeric.

If Apple's security PDF is correct, the only obvious way Apple can break the PIN is via brute force, which I believe they claim to provide when LEAs request it.

Re: Apple’s dangerous game

#25

The public is interested in (and is served by) a technical solution to lawful search warrants because the public no longer believes that lawful warrants are just.

You're speaking for an awful lot of people and an awful lot of different kinds of search warrants....

Re: Apple’s dangerous game

#26
For most of us, Orin Kerr is on the opposite side of the privacy debate. He thinks that current online privacy laws go too far in the direction of protecting the accused. There is a summary of one of his talks at http://hlrecord.org/?p=10987%7COrin. (It's a shame there is no recording or transcript of that talk.)

I think the main difference between my opinions and his is that he places much more trust in government.

Re: Apple’s dangerous game

#27
> Because the victim isn’t alive to share his password, and the phone will have locked before the body was found, the government won’t be able to search the phone to find the messages. Apple’s policy will keep the police from finding the killer. That seems bad.

The problem with this argument is that it applies to all secure encryption. The purpose of encryption is to keep people not authorized to access private data from being able to access it. The fact that it may work as designed is hardly a sufficient excuse to backdoor everything.

Kerr's position seems to be that the government should be authorized to unlock everything in one way or another. The list of problems with that is long and well known. We can't actually trust anyone, including the government, with the keys to everything. Once they have the keys there is nothing to stop them from using them without a warrant.

And backdoors are security vulnerabilities. You intend for them only to be used by the government using constitutional process but they end up being used by criminals and foreign intelligence.

Meanwhile a required lack of security causes chilling effects. Politically unpopular groups will be afraid to communicate if their devices are compelled to spy on them and corrupt government officials can use that to harass and oppress them. Not to mention the small matter that it enables corrupt government officials to harass and oppress them.

Re: Apple’s dangerous game

#28
These are the fruits of the abuse of the fourth amendment.

This action is a prime example of why (ethics and liberties aside) getting carried away with surveillance and warrentless snooping was ultimately a bad idea even for those who were doing it.

There are reasons for fair treatment of citizens that stem directly from practicality. But lack of foresight and hubris seem all too common with government officials as of late.

Re: Apple’s dangerous game

#29
The very first sentence starts with a faulty premise: "Apple has announced that it has designed its new operating system, iOS8, to thwart lawful search warrants"

Why couldn't Apple have designed it to remove itself from the burden of having to play fisherman? While it's true that there may have been moral drivers in this design decision, it makes sound business sense as well.

You can't betray what you don't know. Which is the ultimate position to take in order to be competitive in a privacy conscious world. Besides, warrants are rubber stamps now (as pointed out here and many places elsewhere) and are by no means the carefully measured moderator of state influence they may have once been.

Re: Apple’s dangerous game

#30

The article asks: > How is the public interest served by a policy that only thwarts lawful search warrants? Perhaps the answer is that judges act as rubber stamps now, authorizing way too many search warrants. The author assumes that the judges are fairly applying the 4th amendment.

> judges act as rubber stamps now Exactly. Our government is as overbearing and oppressive as it's been in a very long time. I read somewhere that judges approve something like 99% of the search warrants presented to them. They no longer serve as a check on law enforcement. I'd love to hear otherwise, to hear how judges are doing a good job balancing the interests of people against the interests of law enforcement.

I did not downvote you, but there's a perfectly good explanation for why 99% of warrants would be approved.

Consider that the police know what warrants a judge is likely to approve and which he's likely to turn down. Over time, police departments will learn to submit the warrants they can get approved and not bother wasting a judge's time with warrants that won't be approved.

So very high approval rates do not necessarily signal the loss of the judge's ability or willingness to check police power. Just that everybody involved is doing their jobs as professionals in their domain.

Post reply on HN