The good thing about the exploit market is that it is naturally self-limiting: you don't burn a zero-day on a dragnet; you limit its use to high-value (and ideally court-sanctioned) targets.
Your iPhone just got less secure. Blame the FBI
11–20 of 255 posts
Re: Your iPhone just got less secure. Blame the FBI
#12I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama, and certainly not the DOJ.
Bruce Schneier's previous coverage from 2015-07 [1] is what first got me interested and up to speed in the recent SB case. Even if Apple isn't demanding the FBI's method at this moment, I respect what Bruce has to say here.
[1] https://www.schneier.com/blog/archives/2015/07/back_doors_wo...
Re: Your iPhone just got less secure. Blame the FBI
#13It always amazes me when people get on their high horse and start complaining about something when the remedy is quite simple - don't use the iphone. Get an Android phone, or an Ubuntu phone, or a Blackphone or a Windows phone. There's plenty of other devices that haven't been cracked by the FBI.
There's irony in the fact Apple resisted the FBI attempts to crack the phone and now this vulnerability will go unpatched and the FBI now has a zero-day exploit they can use whenever they want.
Re: Your iPhone just got less secure. Blame the FBI
#14If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.
Re: Your iPhone just got less secure. Blame the FBI
#15Re: Your iPhone just got less secure. Blame the FBI
#16If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.
Re: Your iPhone just got less secure. Blame the FBI
#17Re: Your iPhone just got less secure. Blame the FBI
#18Your iphone just got less secure - so don't use iphones anymore. It always amazes me when people get on their high horse and start complaining about something when the remedy is quite simple - don't use the iphone. Get an Android phone, or an Ubuntu phone, or a Blackphone or a Windows phone. There's plenty of other devices that haven't been cracked by the FBI. There's irony in the fact Apple resisted the FBI attempts…
Re: Your iPhone just got less secure. Blame the FBI
#19The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Basically, if your phone supports Apple Pay, you're good.
And if it's the case, it was a design decision rather than a bug. The secure hardware wasn't ready for consumer use when those devices were designed (and even then, the first generation of iPhone fingerprint readers was pretty bad). Apple knew a desoldering attack could be successful, but such attacks are very expensive, require long-term physical possession of the phone, and are impossible to pull off covertly. There may be another way to pull off a direct hardware access attack without actually needing to desolder the flash memory, but that would still only be effective in the absence of a hardware security module. The only defense against this type of attack is a secure hardware encryption module like the one Apple included to support Apple Pay (because the banks likely insisted on this level of security).
Re: Your iPhone just got less secure. Blame the FBI
#20The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in question had a short passcode set. I'd bet dollars to donuts that whatever attack they used would not work against my phone with a secure passphrase.
I'm usually a fan of Schneier, but I think he really missed with this one.