Live data from Hacker News

U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

bloomberg.com

281–290 of 350 posts

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#283
post #103

I hypothesize that this is a coordinated yet simple ruse to rebuild trust in these brands post-Snowden [1][2]. There was similar press coverage regarding the DEA and iCloud encryption that was misreported in a similar way [3]. The Intercept (where Glenn Greenwald is now reporting from) has a story on what data Apple can still easily give away if you do believe they can't decrypt individual machines [4]. But maybe you…

indie phone might be another, in development: https://ind.ie/phone/ I suspect there will be some competition that Apple/Google/Samsung will be up against for privacy at lease changing some market leaders towards privacy a bit. But in the end there is no privacy on a network with enough time so all of this is surface PR.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#284

Earlier quoted context omitted.

Yes, but it still makes their jobs a lot more difficult. I'm of the opinion that this is not a ruse or scheme, and that law enforcement are genuinely dissatisfied with this. Note that law enforcement and the NSA have a tenuous relationship at best. Even if the NSA still do have privileged access after default mobile encryption is fully rolled out, law enforcement generally will not be able to tap into that except in…

>law enforcement generally will not be able to tap into that except in extreme and rare cases Like when they pull someone over for having a tail light out? I can't reconcile your statement here with what we already know about parallel construction.

Okay... so I guess someone here knows more about parallel construction than I do, however while they were kind enough to let us know this by downvoting my apparently wrong post, they were not kind enough to share their thoughts.

Are law enforcement agencies not getting data from the NSA to use in arresting and prosecuting defendants via parallel construction?

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#285
post #213

Earlier quoted context omitted.

But the article isn't just talking about the NSA and National Security Letters - this is about law enforcement . If Apple and Google claim to be technically unable to comply with LE requests, it won't take long to see whether that is indeed the case or not - unlike national security-related demands, law enforcement won't be able to keep their successes or failures at demanding access to this data a secret. If this wa…

A very good point. Local police will likely be able to access the device but only after calling up the chain. Previous versions of iOS and other smartphones had forensics kits that made it trivial for local law enforcement to grab data out of memory (via DMA/firewire for example) or by device management services. I expect those kits to continue working for devices that have not been powered off.

hhhhh, keys in RAM. Life is so difficult.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#286
post #218

Earlier quoted context omitted.

Out of interest do you have an example of Google's weasel wording this issue? They're getting criticised by all the same people and seem to be doing the same thing - is there actually an advantage either way here? Just to clarify, I'm skeptical on both sides - both companies were in the prism leaks after all. But I haven't seen weasel wording and I'm curious if I missed it.

Actually, no, that was just a prediction. I am making an assumption - and maybe not a fair one - that because Google mines user data on the web that they also mine user data on the phone. Skepticism seems warranted. With Apple, I try to be skeptical, but with Google, I always assume that I am the product until they demonstrate otherwise.

I do believe in that claim.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#287

Earlier quoted context omitted.

i think it's great to see ppl being skeptical of security claims from phone manufacturers. trying to secure a normal cellphone is pretty much impossible and if you're storing sensitive information on one, you are just waiting to get fucked. i think all this "sound and fury" is likely a ruse to entice ios and android users into a false sense of safety post snowden disclosure. being able to encrypt your drive doesn't m…

> being able to encrypt your drive doesn't matter if your OS and its applications are exploitable Because, you know, security measures that aren't 100% perfect are on equal footing as no security at all. Seriously? That's a huge fallacy. In the end, it's all about the cost. When speaking of the NSA, we are primarily concerned with mass surveillance, because lets be honest, if you're targeted directly then you don't s…

GP is actually making a factual statement not just waving his hands around. Data at rest encryption doesn't matter if one can gain execution control with supervisor level privileges (or control another processor or part of the process which does.) This is why security is hard. These aren't NSA level attacks, they're what are used for the jailbreaks that come out for every version. It's a good idea to ask questions before getting fired up if it isn't your area of expertise.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#288
post #164

Earlier quoted context omitted.

They have leaked it with Apple's warranty canary which was removed.

That definitely could imply they have received an NSL. But as a user, when I say "they would leak that they're fighting it", I would consider that completely insufficient. If they are pulling the kind of crap you say they are, then it will come out. Guaranteed. And then nobody, including me, will ever trust them again. editing my comment since I can't reply to hellbanner: Percentage doesn't matter, it only takes one.…

I'd love to believe that, but then: http://www.reuters.com/article/2013/12/20/us-usa-security-rs... Plenty of people were furious with RSA over that, yet they still seem to be in business.

Then again, RSA isn't in the business of making consumer hardware. I'm not sure what difference to expect that to make.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#289
post #280
post #103

I hypothesize that this is a coordinated yet simple ruse to rebuild trust in these brands post-Snowden [1][2]. There was similar press coverage regarding the DEA and iCloud encryption that was misreported in a similar way [3]. The Intercept (where Glenn Greenwald is now reporting from) has a story on what data Apple can still easily give away if you do believe they can't decrypt individual machines [4]. But maybe you…

How and does this protect against attacks via the baseband radio processor. That thing is a black box with proprietary firmware that has pretty much unrestricted access to memory (the way I understand it, someone please correct me). So now it is a bit farcical to say "these are all secure" now. But if you happen to know how the baseband processor works (say you are friends with Qualcomm), you can try to get the encry…

If a (co)processor, firmware, battery, daughterboard, memory, (really anything on the north/south bridge), UEFI certs or code, harddrive, OS, microcodes, transistor doping amounts, protocols, touchscreen, drivers, services or crypto standards have either flaws or backdoors the encryption could be circumvented. Apologies for the incomplete list.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#290

Earlier quoted context omitted.

>law enforcement generally will not be able to tap into that except in extreme and rare cases Like when they pull someone over for having a tail light out? I can't reconcile your statement here with what we already know about parallel construction.

Okay... so I guess someone here knows more about parallel construction than I do, however while they were kind enough to let us know this by downvoting my apparently wrong post, they were not kind enough to share their thoughts. Are law enforcement agencies not getting data from the NSA to use in arresting and prosecuting defendants via parallel construction?

According to Binney they almost certifiably are. I think they downvoted because Binney cites the DEA, CIA and FBI - which are law enforcement - however in this thread posters have taken law enforcement to mean your friendly neighborhood municipal police officer.
Post reply on HN