This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…
Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…
Your iPhone just got less secure. Blame the FBI
101–110 of 255 posts
Re: Your iPhone just got less secure. Blame the FBI
#102I also don't buy the rhetorical come-back about those who would trade liberty for security deserve neither. There is a line between the two, and each side must give and take. If the FBI found a way to do it without Apple, bravo. Let Apple figure it out if they want.
This is Apple's fault and they should not get a pass for spinning the PR in their favor.
Re: Your iPhone just got less secure. Blame the FBI
#103Earlier quoted context omitted.
Public officials answer to a different standard than private citizens who run companies. The oath of the FBI is not to make their own jobs easier. It is to maintain public security. If the Director of the FBI cannot do that effectively, then that is a blemish on the record of President Obama who appointed Comey. There's a definite need for someone to step up and say that on balance, we are more secure without trying…
Ok, sub in that it would be a valuable tool in carrying out their mission for the making their job easier. The point is that it isn't extraordinary for law enforcement to want investigative powers. If you watch some interviews with Michael Hayden, you'll see him saying just what you want, and I think someone who is a former director of both the CIA and NSA counts as a high level player. Autoplay video, but read the t…
Sure. Then I'd just circle back to my original point which is there is disagreement over how to keep the public safe. That's the cause of the problem, and we're missing someone who can bridge that communication gap.
> If you watch some interviews with Michael Hayden, you'll see him saying just what you want, and I think someone who is a former director of both the CIA and NSA counts as a high level player.
I've watched several. The one you cite is actually a bit old. In more recent interviews, he sides even more with Apple.
Hayden definitely brings a lot of credibility to Apple's side. Unfortunately he's not in a position to call a meeting between the tech industry and the DOJ plus Obama to settle their differences. In fact, nobody is except the public. The public will ultimately decide this through their voice and vote. If we sit back and do nothing, I imagine we would see backdoor legislation pass quickly. So far, we've been vocal enough to prevent Feinstein's bill from being released. Let's keep it that way and start pushing back against the DOJ. We can play offense too by asking the FBI to share its technique with Apple.
Re: Your iPhone just got less secure. Blame the FBI
#104I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it. The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in questio…
This is pedantic in my opinion. The main point of the article was that the FBI found a vulnerability. So before it was likely an unknown vulnerability, now it is known by law enforcement. The whole point of the article was that responsible organizations disclose vulnerabilities so that companies can make their software/hardware more secure. In this case the FBI is sitting on it, so they can continue to use it. Last w…
I agree that the FBI should inform Apple of the vulnerability they used. I just don't think that failing to do so makes iPhones less secure. Failing to do so leaves them as they are, and informing Apple would make iPhones more secure.
I don't see this as pedantic, because it's the difference between the FBI actively harming us and the FBI merely not helping us.
Re: Your iPhone just got less secure. Blame the FBI
#105This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…
Hunh? The iPhone 5s and the iPhone 6 both contained the first gen fingerprint reader, and it was universally regarded as one of the best consumer fingerprint readers available on any device.
That is largely irrelevant though, as the secure enclave is not in the fingerprint reader. TouchID is one way to access it, but the secure element can exist without touchID (as on the watch).
Re: Your iPhone just got less secure. Blame the FBI
#106Earlier quoted context omitted.
> I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. So I take it then you don't believe in a government "for the people"? Like it or not, Apple is legally a person, and even tossing that aside, we know that many of Apple's customers are American citizens, and this whole idea of "keeping knowledge from you…
> Lest you jump to the argument that this would endanger operations, I would still point out two very salient facts: this information is not intelligence data, and as Schneier pointed out, this attack can be used against many in the US government, including FBI agents in the field. Getting it fixed is the right thing to do. I agree with you that given the facts we know today, notifying Apple is the right thing to do.…
Re: Your iPhone just got less secure. Blame the FBI
#107Re: Your iPhone just got less secure. Blame the FBI
#108The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…
I agree with you, and I think this will eventually lead to a world where governments are unable to exert meaningful influence on large corporations. We're already starting to get there; I have a feeling that if the supreme court had forced Apple to write a custom version of iOS that things could have gotten really messy very quickly -- there were rumors that Apple's entire iOS engineering team was ready to resign if…
Re: Your iPhone just got less secure. Blame the FBI
#109I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it. The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in questio…
And perhaps the vulnerability in question wouldn't work against your iPhone, but how many millions of iPhones still use a short passcode? This vulnerability could still affect all of those phones.
Re: Your iPhone just got less secure. Blame the FBI
#110Earlier quoted context omitted.
Ok, sub in that it would be a valuable tool in carrying out their mission for the making their job easier. The point is that it isn't extraordinary for law enforcement to want investigative powers. If you watch some interviews with Michael Hayden, you'll see him saying just what you want, and I think someone who is a former director of both the CIA and NSA counts as a high level player. Autoplay video, but read the t…
> Ok, sub in that it would be a valuable tool in carrying out their mission for the making their job easier. The point is that it isn't extraordinary for law enforcement to want investigative powers. Sure. Then I'd just circle back to my original point which is there is disagreement over how to keep the public safe. That's the cause of the problem, and we're missing someone who can bridge that communication gap. > If…