Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

111–120 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#111
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

> When someone passes away, for example, it would be a terrible compounding tragedy if all their photos from their whole life passed away along with them, because they didn't tell anyone their password or where they kept the backup key. So Apple wants and needs to provide an alternative way to recover the account. (For example, they will provide access to a deceased person's account if their spouse can obtain a court…

That is also an interesting point. It certainly comes up often when next-of-kin go through the private physical possessions of the deceased and discover secret love letters, diaries, etc. They probably wanted those to stay private.

But for bank account records, most photos, etc., you probably don't want those to disappear in the event of your death. You want those to pass on.

Given the choice between the two defaults, it makes a lot of sense for Apple to make "accessible to next of kin" the default, and "dies with you" the opt-in.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#113
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

I actually intend for my private data to die with me. I have gone out of my way to guarantee that it will. In my view, if I haven't published it, then it shouldn't be accessible. I have absolutely nothing to hide. I have simply always treated my privacy as something that was valuable in it of itself. Perhaps even more valuable than the photos I clearly opted to not share with others, to go off your example. I also do…

Since you're responding to me I'm assuming you mean me, but I have no problem conceptualizing non-malicious things you would want to keep private.

The problem here is that a lot of the stuff stored on phones falls somewhere between "dies with me" private and "should pass on to my family" private. Or "should be recoverable if I lose my key" private.

Strong encryption makes it impossible to recover in the event of a lost key or pass on to family in the event of your death. So that's not necessarily a great default for, say, decades of family photos. It would be a huge tragedy if that was lost.

The good news is that Apple does provide tools to opt-in to stronger security, rather easily. For example, the Notes app was recently upgraded with note-level strong encryption. That might be a good solution for your most private notes, without endangering the survivability of your digital memories and assets.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#114
The original story has changed its title to "Apple Is Said to Be Trying to Make It Harder to Hack iPhones".

I was a bit surprised by the clickbait-y nature of the HN title, but we can see in the nytimes URL that this "Apple Is Said to Be Working on an iPhone Even It Can’t Hack" was the original title, eh.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#115
They can have perfect hardware crypto, but they can always send a new OS update to every phone with "if your account id is in top 100 wanted, send a copy of everything to x.y.z". Nobody would ever know (until it's too late, at least)

(of course if the phone is not in use anymore it doesn't apply)

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#116

Any device that relies on hiding secrets inside the silicon itself is subject to hacking. Several secure-enclave like chips have been hacked in the past by using electron microscopes and direct probes on the silicon. If BlackHat conference independent security researchers have the resources to pull this off, Apple and the NSA certainly can. Exfiltrating the Enclave UID could be done by various mechanisms at the chip…

> You just need to disable the mechanism that wipes the device

Sure, to resist microscopic attacks, an IC must assert logical integrity to itself i.e. that the gates & wires are not compromised by a microscopic attack.

But just because you and I haven't imagined it, doesn't mean some kind of internal canary can't exist. Your naive code (below) of a counter might instead be based on quantum cryptography, or on intrinsic properties of a function or algorithm which if compromised the SE cannot function at all.

The existence of one-time password schemes like S/KEY gives me hope, since it is a sequence generator that simply doesn't function without input of the correct next value (technically the previous value from the hash function). S/KEY itself is not the answer (wrong UX and no intrinsically escalating timer), but I wanted to illustrate that you can generate a self-validating sequence without tracking integer position.

Apple apparently has a motive and the warchest for the R&D. If they're hiring cryptographers (has anyone checked?), they're acting on it.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#117
post #109

The article doesn't cite a source. It doesn't even say that it is anonymously sourced from someone close to Apple (who presumably is leaking). That makes me wonder if the real source of this info is Apple-approved, and sort of an indirect way of engaging policymakers. I get the sense that Apple is picking a fight b/c the DOJ has violating an unwritten agreement, basically that Apple will provide all the help requeste…

That's normal style in mainstream journalism, weird as it is. If you read a lot of sports journalism for example, you'll see a ton of articles which are literally just a summarized transcript of a phone call a reporter got from an agent, written as if it's just pure factual information that appeared from thin air. At least in those cases it's trivial to guess who the source actually is. Again, it is objectively very…

Yeah, standard practice maybe. I guess I'm more interested to know if this story is sourced from Apple (unofficially) or is it based on a more indirect rumor that's going around...

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#118
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

They're not anywhere near 99% of the way there; they've destroyed the heterogeneous decentralized ecosystem that broad security requires. Locking themselves out of the Secure Enclave isn't anywhere near sufficient. As long as the device software and trust mechanisms are totally opaque and centrally controlled by Apple, the whole thing is just a facade. There's almost nothing Apple can't push to the phone, and the aud…

I think from the context it's pretty clear that "hack" in this case is referring to "being forced to unlock". Yes, they could still deliberately break encryption for future OSes and phones, but the same could be said of any software, open or closed source.

I don't think acting like an open ecosystem is the be-all and end-all of security is productive. Most organizations (let alone individuals) don't have the resources to vet every line in every piece of software they run. Software follows economies of scale, and for hard problems (IE, TLS, font rendering, etc) will only have one or two major offerings. How hard would it be to introduce another heartbleed into one of those?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#119
post #66
post #20

Earlier quoted context omitted.

Probably not. If you're dead, they probably have your fingers. If you're alive, they can compel you to unlock the device with your fingerprint. The only point I'm making is that Apple already designed a cryptosystem that resists court-ordered coercion: as long as your passcode is strong (and Apple has allowed it to be strong for a long time), the phone is prohibitively difficult to unlock even if Apple cuts a special…

Using a strong pin is pretty annoying, and a relatively visible signal when using the phone on the street etc, So it can be a good filter(maybe via street cams) to filter suspicious people - which isn't a bad goal for law enforcement.

Corporate email profiles on BYOD phones often enforce a long passcode requirement, so you've got a lot of Fortune 500 sales guys to screen out if you're stopping and searching anybody with a suspiciously long password.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#120

Any device that relies on hiding secrets inside the silicon itself is subject to hacking. Several secure-enclave like chips have been hacked in the past by using electron microscopes and direct probes on the silicon. If BlackHat conference independent security researchers have the resources to pull this off, Apple and the NSA certainly can. Exfiltrating the Enclave UID could be done by various mechanisms at the chip…

>You may not need to crack the OS, or even upload a new firmware. You just need to disable the mechanism that wipes the device and delays how many wrong tries you get. So for example, if you can manage to corrupt, or patch the part of the system that does that, then you can try thousands of PINs without worrying about triggering the timer or wipe, and without needing to upload a whole new firmware.

I disagree. The pin validation is done within the secure enclave. You can't do it outside the secure enclave because the pin is combined with a secret that is burned into the silicon of it. The secure enclave can and will enforce timeouts for repeated failures, as well as refuse to process any pin entries after too many attempts. Disabling the wipes or bypassing the timer won't do you any good when you only have a few attempts.

https://blog.trailofbits.com/2016/02/17/apple-can-comply-wit...

Post reply on HN