Live data from Hacker News

Why Apple's iPhone encryption won't stop NSA

siliconexposed.blogspot.com

31–40 of 71 posts

Re: Why Apple's iPhone encryption won't stop NSA

#31
post #10

Although I agree with the premise -- a sufficiently dedicated attacker can defeat many mechanisms you can come up with to protect your data -- many of the points that the author makes seem to be based on either incorrect or implausible assumptions. For instance, the claim that modern cell protocols can be "silently" MITMed is not really true; the current known attack to spoof a GSM tower, I believe, is limited to usi…

> The article that the author cites the possibility of the "Secure Enclave code being able to read the UID key"; as comex mentioned yesterday [1], this isn't true.

We don't know that, we just know Apple says it's the case and nobody's broken it yet. Without a full reverse engineering of the Secure Enclave firmware, plus the IC, there's no way to know if there's a hidden backdoor, bug, or debug mode allowing the data to be read.

Re: Why Apple's iPhone encryption won't stop NSA

#32

Friendly reminder: don't embed images from other people's websites, especially if you're looking to get on HN/Slashdot/reddit/whatever. First, it's rude. The owner of the second website has to deal with the burden of hosting traffic on your site and gets nothing in return. In this case, the blog kept downloading an image from siliconpr0n.org, effectively DoSing the website and taking it offline. Horrible. Hopefully t…

You're assuming I'm not affiliated with siliconpr0n. I'm actually one of the main contributors to the site and took a lot of the photos on it, just not that particular one. John (my friend who actually admins the server) is fully aware of the situation and just raised the resource limits to counter the DoS. If either of us uses an image somewhere that we expect to stay online for a while, we make a point of leaving i…

If there's an increased bandwidth bill, I'm sure John will be grateful for the check you send him.

Re: Why Apple's iPhone encryption won't stop NSA

#33
post #13
post #9

MitM with a 0-day payload? Acid etching and SEM? You would have to be an extremely high-value target to legitimately worry about this stuff. The post is attacking a straw man. Apple's iPhone security is meant to address criminals, mass surveillance, and overzealous law enforcement. They're not claiming a single phone will withstand the entire resources of the NSA devoted to breaking it.

Yup. The reality is that you can't defeat the NSA unless you are able to design and fab your own silicon without any third party involvement, are able to write and audit your own crypto code with zero bugs, and are able to physically protect yourself from being "encouraged" to reveal your passphrases. It's not worth seriously trying to defeat an organisation as well funded/staffed/connected as NSA from obtaining your…

And if you're that important of a target, they're eventually just going to pick you up physically, black-bag style, from nearly anywhere on earth if they can. The NSA is the US military after all, there's really nowhere on earth that someone is entirely safe if they want you (maybe under direct protection by Beijing or Moscow).

Re: Why Apple's iPhone encryption won't stop NSA

#34

An interesting read, I would agree with the author, Apple is making it difficult, not impossible for govt to get your data. TLDR, apple's claim is misleading, govt can get data in other ways

It is a common mistake to assume that things written by third parties about Apple's intentions are in any way actually related.

Re: Why Apple's iPhone encryption won't stop NSA

#35

Friendly reminder: don't embed images from other people's websites, especially if you're looking to get on HN/Slashdot/reddit/whatever. First, it's rude. The owner of the second website has to deal with the burden of hosting traffic on your site and gets nothing in return. In this case, the blog kept downloading an image from siliconpr0n.org, effectively DoSing the website and taking it offline. Horrible. Hopefully t…

You're assuming I'm not affiliated with siliconpr0n. I'm actually one of the main contributors to the site and took a lot of the photos on it, just not that particular one. John (my friend who actually admins the server) is fully aware of the situation and just raised the resource limits to counter the DoS. If either of us uses an image somewhere that we expect to stay online for a while, we make a point of leaving i…

I had no idea, sorry. Most of what I said about direct-linking doesn't apply if you're affiliated with the website you're direct-linking to.

Re: Why Apple's iPhone encryption won't stop NSA

#36

If you look at the incentives for Apple in this scenario: It's best for them if we all think their phones are secure. And it's also best for them if they dont piss off LEO. So the rational thing for them to do, is convince us all they have strongly encrypted their phones, while continuing to provide some type of back door, but hiding it well. Parallel contruction etc etc

That's a terrible idea. Because when the day comes that a security researcher finds the flaw (and they will find the flaw) Apple has to admit that they lied to their customers. And that's a very bad business practice.

The enhanced encryption is Apple's way of saying that it's not their problem if LE has a beef with you. It removes Apple from the equation. If LE starts knocking at their they can say that there is nothing they can do.

It reduces warrant less spying, and removes some of the ease with which LE agencies have been able to operate. LEA agencies can collect data with broad strokes anymore, they'll need warrants (which they should have needed in the first place and they will have to conduct targeted investigations now (which is what they should have been doing all along).

Re: Why Apple's iPhone encryption won't stop NSA

#37
post #4

I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…

Rising the cost hurts the population much more in the long run - we, the people, we pay the surveillance for us. No one else. We must fight hard that we don't need to pay that tax any more - money which flows in large sums directly to the military/industrial complex.

Increasing the cost of surveillance means it becomes easier to constrain the intelligence agencies by simply not allowing them endless budgets.

Re: Why Apple's iPhone encryption won't stop NSA

#38

If you look at the incentives for Apple in this scenario: It's best for them if we all think their phones are secure. And it's also best for them if they dont piss off LEO. So the rational thing for them to do, is convince us all they have strongly encrypted their phones, while continuing to provide some type of back door, but hiding it well. Parallel contruction etc etc

I can't think of any reason why its "best" for Apple to keep LEO happy. LEO don't pay them anything and actively increase the difficulty they face running their business as well as reduce the trust the people who do pay them (ie their customers) have for their products, actively hurting their business.

The big fear is that pissing off LEO will result in harmful regulation, and, while that is certainly possible, history has shown the technology moves forward regardless. Consider the US trying to prevent the spread of cryptography. They lost that battle[1], and any government who picks a new battle will eventually lose it, too.

1. The only injuries in that battle were US companies trying to sell software overseas because they were forced to include sub-par crypto.

Re: Why Apple's iPhone encryption won't stop NSA

#40
post #4

I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…

> I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA)

Great point and one that I think typical computer savvy users already do. It is in the security-expert-fantasy-world that the perfect quickly becomes the enemy of the good.

For example, using SSL to send sensitive data like passwords or payment info is nearly ubiquitous. Yes, there are many flaws in SSL's trust model, but the cost is so small, using it is a no brainer.

However, PGP encrypted email is much more rarely used. It has numerous higher costs, from special email software to the social pain of getting your friends to also use it. The benefit is still high, but the cost is high too and that results in far less usage.

In the real world, informed people look at the cost benefit break down of security. Just like we all don't drive semi trucks around even though they are safer in a collision, we all don't communicate in the most secure fashion because there is a cost associated with that decision. With that in mind, the easiest path towards greater security in communications population-wide would be to focus less on improving the security and more on lowering the associated cost.

Post reply on HN