Live data from Hacker News

Apple’s dangerous game

washingtonpost.com

11–20 of 113 posts

Re: Apple’s dangerous game

#11

The article asks: > How is the public interest served by a policy that only thwarts lawful search warrants? Perhaps the answer is that judges act as rubber stamps now, authorizing way too many search warrants. The author assumes that the judges are fairly applying the 4th amendment.

Not only that, but they're issued in secret by secret courts.

This article is very disturbing.

Re: Apple’s dangerous game

#12
I agree it's odd that they're actually marketting it as anti-law enforcement.

There are certainly other reasons to appreciate secure encryption though. But "not even a disgruntled apple employee, or one paid by your business competitor" brings up questions that are not good marketting to put in people's heads. Even "not even a hacker, cause we used actual secure crypto" is not what they want people to think about.

Now, personally, I include "not even law enforcement" in my list of attackers I'd like to defend from, and there's nothing wrong with that (and there's not supposed to be in America, the 4th ammendment and all). But the fact that it's actually good marketting generally (or at least they're betting on it) -- well, we have Snowden to thank for that. And I doubt it will last.

Also, of course, there are a variety of reasons the iphone crypto as a system isn't all that secure -- including but not limiting to the fact that we still have trust apple (we can't see the code, or the code in the updates pushed out regularly).

Not that I disagree that it's a benefit to make it harder for law enforcement

Re: Apple’s dangerous game

#15
Apple's architecture decision proves a quiet point - that Apple feels it has been illegally pressured by the government (notably the NSA) to crack too many cell-phones, and that their own business and the rights of their users are at risk from an overly aggressive government. I interpret Apple's move as a self-defense mechanism to attempt to stop the immoral actions of a government over-stepping it's bounds, and to protect the people that Apple cares about most - their users.

Re: Apple’s dangerous game

#16
post #10

"The first question is whether the government can lawfully compel the telephone’s owner to divulge the passcode. I believe the answer is that yes, a person can in fact face punishment for refusal to enter in the password to decrypt his own phone. If the government obtains a subpoena ordering the person to enter in the passcode, and the person refuses or falsely claims not to know the passcode, a person can be held in…

This actually isn't entirely settled law. Some argue that the 5th ammendment protection from self-incrimination would give someone the right not to give up their passcode. But different courts have ruled differently in differnet situations/jurisdictions, so far.

Re: Apple’s dangerous game

#18
While I do understand the situation the law enforcement is dealing with, it is not an excuse to not allow us to have complete privacy and full encryption support on our digital devices. Nobody including governments has any rights to have any access to my personal data. If I don't share it with anybody, it's mine just as my personal thoughts in my head.

I agree with what Apple is doing and I want them to do more. There are still some remaining holes that need to be closed up and all users should be encouraged to enable 2FA with the mandated switch in a few years.

Re: Apple’s dangerous game

#19
Is this actually new in iOS 8? I thought this has been the design of iMessage from the beginning -- namely that Apple does not have the decryption keys.

What Apple does have is the directory of recipient public keys that your device should use to encrypt its messages. (Background: iMessage encrypts each message separately for every recipient device, which shows just how far Apple went to protect key security. Not only does Apple not have the keys, private keys never have to be exchanged among devices ever.)

But technically speaking -- I have no idea if they actually do this -- that gives them a way to insert a "wiretap" of sorts in the form of an additional, silent recipient that you don't know about. Think of it as adding another device to your iCloud account, only it's not yours. Still, this could at least be discovered by monitoring the size of the outgoing data to see if it matches the expected number of recipients.

Re: Apple’s dangerous game

#20
The arguments in this article are hinged on one crucial premise: Apple stills owns your device even after selling it to you. This is different from gmail where your data is on servers owned by google. The analogy to this premise is that the producers of a safe that they sell to you must be able to provide the government a key to the safe. This clearly does not make sense, and neither does requiring Apple to always have a backdoor to your device.
Post reply on HN