Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

211–217 of 217 posts

Re: Apple – Privacy – Government Information Requests

#211
post #18

Earlier quoted context omitted.

> though the celeb hacking shows the limits of that approach Apple has clearly stated that its system was not compromised. The user reset questions were socially engineered meaning it is irrelevant whether or not the data is encrypted. From Apple's perspective the owner of the data is downloading it.

> The user reset questions were socially engineered Yep, you're right. My point, perhaps poorly stated, is that if Random Hacker X can figure out the answers to the iCloud reset questions, so can a law enforcement agency. Then they can log into that account. Impersonating someone this way is legal -- or at least has not been ruled to be illegal -- as long as it's done under court supervision under the Wiretap Act or…

> if Random Hacker X can figure out the answers to the iCloud reset questions

Answers about very famous people. Wikipedia will not tell me your mothers maiden name.

Also, as much as I sympathise with the women whose accounts were breached, actors aren't always the sharpest tools in the shed, and phishing schemes are a common tool for gaining access to other peoples accounts. One of them (I don't remember which) publicly claimed iCloud backup for her iPhone was "too complicated" a while ago. Given that it's as complicated as "turn it on, and make sure it gets plugged into power with Wifi every so often", I don't doubt some of them would fall victim to even a very simple phishing scam.

Re: Apple – Privacy – Government Information Requests

#212

Earlier quoted context omitted.

What's keeping government agencies from putting keylogging code on the SIM card or baseband processor (whichever has the best access to host cpu/memory) via the carriers to obtain the passcode? Not much I guess. Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?

Some very knowledgable iOS security people have told me how hard it is to break iOS. You need quite a few chained exploits to do anything meaningful. Browsers are pretty much the only things with Read/Write/Execute memory. Security is always a convenience/security trade-off. iOS is about as good as you can get before inconvenience will turn people to less secure devices.

There is the question of vanilla iOS being susceptible to attack from NSA and any other malicious attacker and then there is the question of is the security design sufficient such that even apple could not backdoor your privacy should they desire. The latter is what the original commented was addressing. I think the statements from apple do not clarify this matter and we should assume they can backdoor should be required by warrant. I need to see detailed technical specifications for their claimed security measures before I would trust these statements (if someone has a RTFM link, much appreciated).

Re: Apple – Privacy – Government Information Requests

#213

Earlier quoted context omitted.

Lavabit wasn't forced to install a backdoor, the guy running it just kept refusing to comply with previous legal requests which were much narrower in scope. Since he didn't comply they took the nuclear option (which he could have easily prevented).

Prevented by complying, ie. selling out his customers' privacy?

By not complying he 'sold out' every single one of his customers privacy instead of the sensible choice of complying with the legal order to turn over emails of just one customer.

Re: Apple – Privacy – Government Information Requests

#214

Earlier quoted context omitted.

Lavabit wasn't forced to install a backdoor, the guy running it just kept refusing to comply with previous legal requests which were much narrower in scope. Since he didn't comply they took the nuclear option (which he could have easily prevented).

Whether or not he was in contempt, that's still a bullshit way to approach the problem. Contempt of court? Fine and then jail him for non-compliance. Seize Lavabit's assets if required. I doubt he would have let it come to that. But their solution was analogous to "won't give us back that alleged stolen $20 we told you about? We want your whole bank balance." Aww hell naw.

None of this would have happened if he would have complied with the legal court order.

I guess he made his point, but he screwed over his customers twice in this case. First by dumbing down his crypto to be easier to use and allowing it to be broken as it did by the feds, and second screwing every customer over by not complying and shutting down his service.

Re: Apple – Privacy – Government Information Requests

#215
post #57

Earlier quoted context omitted.

> The initial report of PRISM implied that the NSA and FBI had direct, unfettered access to providers' "central servers", but that has been since walked back a bit. Really? I haven't been able to follow every report, as the Snowden leaks generated a lot of content over the past year. Can you give a source to where PRISM's central server access has been "walked back a bit"?

The Wikipedia page is up to date and contains a lot of links to external sources. http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%2... The press report that most directly addresses the issue is probably this one: http://www.cnet.com/news/no-evidence-of-nsas-direct-access-t... Incidentally the author of that story is doing a startup now, visits HN, and actually has posted in this thread! Username is "declan…

Thanks, that's a really great summary.

Re: Apple – Privacy – Government Information Requests

#216
post #199

Earlier quoted context omitted.

It is really surprising how much HN turns a blind eye to / lacks imagination for potential security issues just because it's Apple. Well, actually it isn't surprising at all.

I am certainly not "HN". If you want to argue/discuss, do so. I'm well aware that a "secure element" is never 100% unbreakable. But in the usecase the GP mentioned (government broadly gathers data), hiding the data in a separate hardware compartment will at least help.

I think it's just PR bullshit. Apple has been known to abuse the law. I'm sure some government gave them the green light to lie about this and have another backdoor.

Re: Apple – Privacy – Government Information Requests

#217
post #171

Earlier quoted context omitted.

The quote is extremely misleading. Sure, it's encrypted by your passcode, and that's great. It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy. http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...

It's not quite milliseconds. According to https://www.documentcloud.org/documents/1302613-ios-security... they've increased the iteration count somewhat: “The passcode is entangled with the device’s UID, so brute-force attempts must be performed on the device under attack. A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 millisec…

This can't be true. If you restore your iCloud backup to a new device, all you need is your passcode. It obviously won't ask you to enter the UID of the device you previously backed up with.
Post reply on HN