Live data from Hacker News

Apple’s dangerous game

washingtonpost.com

81–90 of 113 posts

Re: Apple’s dangerous game

#81
post #33

This seems likely to be more than a little related to the recent warrant canary discovery. My expectation is that Apple was recently forced to do something they considered unlawful and the iOS8 changes will prevent that issue in the future.

the world is much simpler than that, my friend.

Apple left the canary there to not alarm their customers. As far as we know, they could have received millions of warrants and never removed it for market reasons, or they could have received warrants that told them to not change that page as to not harm ongoing investigations.

Anyway, it is very conveniently timed with the release of ios8, and their month old marketing plan of announcing that new 'super secure feature' that "we can't comply to warrants even if we wanted BS". I'd have to be a huge fool to not thing that this is a pure marketing ploy to force me to move to IOS8, and nothing more.

Also, you probably can still access iCloud pictures that the phone uploads automatically by just guessing random urls or something or another.

Re: Apple’s dangerous game

#82
post #57

Earlier quoted context omitted.

I too was surprised by the author's question. It's as if he hasn't been following the news lately about the apparent impotence of the 4th amendment these days. Yet his wiki page says he "has been regarded as a leading scholar on Fourth Amendment jurisprudence in electronic communications and surveillance." In light of that, he comes across as extremely naive. (or worse?)

His Wikipedia page also relates his career in the DoJ and as a US Attorney, a very different background from the typical libertarian HN reader. I don't agree with Orin Kerr on this, but I'm willing to accept that he's likely seen things about the day-to-day business of law enforcement that I just don't understand. It's worth us spending at least a few moments entertaining the thought that maybe we are the naive ones.

> I don't agree with Orin Kerr on this, but I'm willing to accept that he's likely seen things about the day-to-day business of law enforcement that I just don't understand.

Sorry, it's more likely he's just vested in the current (not-privacy-respecting) system of governance. One which has major drawbacks for many folks who are pushing the envelope or who just happen to be on the wrong side of one of the many folks who have access to the government's powers.

Re: Apple’s dangerous game

#83
post #9
post #7

I'll leave it to other hackers to put it more eloquently. Any means to bypass the encryption on iOS 7 and before are vulnerabilities that adversaries can use to bypass the encryption on iOS 7 and before. Apple is basically saying that they didn't build in back doors, which this author is making the case for. iOS 8 data is still available to the government by other means than warrants and at much, much, much higher ex…

are you sure they built in a real backdoor? i thought they salted user PINs with a hard-wired nonce that's specific to every device - then when the fuzz needs to get the device unlocked apple looks up what the hard-wired nonce is for that specific device, and then crack the 4 digit pin. anyone have details on how apple actually unlocked devices?

[deleted]

Re: Apple’s dangerous game

#84
post #46

So basically, the author wants every "secure" software system to have a backdoor. iOS versions prior to 8 all had a backdoor and he's lamenting that Apple has closed this backdoor. Not only that, if this applies to the iPhone, it must apply to any and all encryption software. While it's widely known that the government already has backdoors into a lot of popular software, codifying this in law or expecting that all s…

What I found especially telling is that the author's defense (or lack thereof) of the idea that the 5th Amendment is not applicable here did not even involve any attempt to explain why it should not apply. Like you said, he just feebly pointed at carefully-selected case law.

I think that's because any reasonable person can see that in today's society, it's completely obvious that if you force someone to turn over everything in their smartphone, that's likely to be about as incriminating as everything else you could possibly force them to say or turn over, put together.

The idea that this is not the case doesn't pass the laugh test.

Re: Apple’s dangerous game

#85

Earlier quoted context omitted.

> No it is not. Yes it is. There is no question that it is evidence, so you can only be questioning whether the evidence supports the proposition. You want a mathematical proof? OK. Without knowing the percentage of approved warrants we can't exclude the possibility that exactly zero warrants were approved, which would be a hard disproof of the proposition that judges are uncritically approving warrants. Discovering…

Your position is circular. You are defining 'critical-ness' with the sole criteria being the approval rate. If we accept that as the only criteria, then sure the proposition stands, but then it loses meaning and becomes nothing more than a rhetorical device. Generally speaking, we mean 'critical' to involve the weighing of a decision against an ethical standard. Assuming the standard isn't changing, we would expect a…

> Your position is circular. You are defining 'critical-ness' with the sole criteria being the approval rate. If we accept that as the only criteria, then sure the proposition stands, but then it loses meaning and becomes nothing more than a rhetorical device.

There is nothing circular about it. There is no requirement to exclude other evidence. Regardless of what other evidence exists, discovering that there is a very high approval rate makes it more likely that warrants are approved uncritically than it was before the approval rate was known.

> Assuming the standard isn't changing, we would expect an equilibrium to emerge where the parties involved would come to understand the standard, especially given that the warrant process is not adversarial. So there's no reason not to expect the approval rate to settle at close to 100%, with the few denials being law enforcement attempts to skirt the boundaries.

The fact that the process is not adversarial only makes it more likely that judges are approving warrants they shouldn't be. Moreover, prosecutors have every incentive to try to "skirt the boundaries" as often as possible, unless the boundaries are so broad they don't need to be skirted.

> Anything less than a very high rate would indicate that the standards are inconsistent or are being inconsistently applied.

Or that prosecutors are continually testing the fences as they have every incentive to do.

Re: Apple’s dangerous game

#86
> Apple’s new policy seems to thumb its nose at that great tradition. It stops the government from being able to access the phone precisely when it has a lawful warrant signed by a judge.

When the government has a warrant, the person being called into question is being served the warrant. The way it works now, the Government just bypasses the person and forces the carrier/handset manufacturer to give up information. This step is just brining the law back in line with how it was traditionally instated and enforced. That's like the Government going to Audi for a backdoor key to unlock my car while I'm not there so they can search it.

Re: Apple’s dangerous game

#87
post #10

"The first question is whether the government can lawfully compel the telephone’s owner to divulge the passcode. I believe the answer is that yes, a person can in fact face punishment for refusal to enter in the password to decrypt his own phone. If the government obtains a subpoena ordering the person to enter in the passcode, and the person refuses or falsely claims not to know the passcode, a person can be held in…

I don't know how they can reasonably prove you remember what the code is.

[deleted]

Re: Apple’s dangerous game

#88

Orin Kerr is clearly a lawyer. He argues not for what is right but for what is permissible given the existing body of law. Where the existing body of law is wrong, his writings have no sympathy for the damage inflicted on its victims nor any sense that resisting such wrongs is noble. If the government never abused its authority, I would be much more sympathetic to Kerr's position. Given the facts of prosecutorial abu…

Orin Kerr is definitely a lawyer, and has been working and writing on digital crime and civil rights for years. For example, he was part of the defense team during weev's appeal of his conviction. I do think he thinks beyond the technicalities of the law. And I think he's correct that there are legitimate reasons to pierce device encryption. If a victim is murdered, and their phone is locked, it sure would be nice to…

I completely agree with your assessment of Kerr, and there is nothing wrong with purely legal analysis.

What got to me initially was the deliberate limiting of legal scope to warranted privacy violations, as though warrantless privacy violations are insignificant. He's welcome to do so, but he should be clearer about this and less rhetorically dedicated to his agenda.

EDIT: I see now that he reasons this technology only affects warranted privacy violations, since Apple has a policy of refusing unwarranted inquiries. He is overlooking the possibility that Apple may nonetheless be pressured, deceived, or compelled to violate users' privacy. He doesn't realize that Apple's claim of being invulnerable to warrants also protects the user from Apple's own vulnerabilities. It's not just USA law enforcement that targets users by exploiting Apple's access to protected data.

My understanding is that warrantless privacy violations have grown tremendously since the Patriot Act, both in scope and quantity -- that we have many new laws or codes since then which reclassify previously warrantful privacy violations as now warrantless.

He asks "How is the public interest served by a policy that only thwarts lawful search warrants?"

This is a nasty rhetorical trick. Does Apple's policy change serve any other purpose than to thwart lawful search warrants? Kerr puts "no" in your head, but of course the answer is yes.

He then makes appeal to the "civil libertarian tradition" of protection from warrants, saying that Apple is thumbing its nose at "that great tradition". What a joke. Apple is selling a product with powerful capabilities, some of which can be used to break the law, all of which have legitimate lawful purposes. Are Ford, Boeing, Delta, Budweiser, Louisville Slugger, Smith & Wesson all playing dangerous games as well?

Lastly, this is about removing Apple's ability to unlock. Just like Colin Percival's tarsnap. Doing proper security via proper cryptography. Minimizing untrusted third parties. Apple is getting criticized by Kerr for doing the right thing for its users. There are no victims in this action. It should matter not a whit that this makes the government work harder to violate privacy. Apple has no general duty to offer permanent taps for the government's pleasure.

This is why focusing only on warrantful privacy violations is a travesty of justice.

Please watch this before re-reading Kerr: https://www.youtube.com/watch?v=eT2fQu50sMs

Re: Apple’s dangerous game

#89

Earlier quoted context omitted.

I think Orin's point is not that everything should have a backdoor (which would not comport with his many previous writings on tech and law), but that Apple's shift, and in particular the public way in which it has been done, could trigger unintended consequences from the courts or Congress. Hence the "dangerous game" title.

Is Congress now going to legislate away the fourth amendment?

There's this quotation by Scalia (whom I respect a lot, despite him mostly ruling otherwise than I would have), that four Justices probably don't think the Exclusionary Rule was a good idea in the first place (somewhere in the Pepperdine interview with Kenneth Starr).

If you're interested in the exact wording I can look it up tonight.

Post reply on HN