Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

111–120 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#111
post #88
post #45

Earlier quoted context omitted.

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

> The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. That's the common misunderstanding of the problem. Most people think that the probabilities go fro 1/3, 1/3, 1/3 to 1/2, 1/2, after choosing a door and having Monty Hall open one of the others. The probabilities don't change. The probabilities are 1/3, 1/3, 1/3 at the start. After you choose a door, they're still 1/3,…

This assumes you always open a door, that door never holds the prize, and there is exactly 1 prize.

You could run (ed:a similar game with different rules) such that the odds go 1/3,1/3,1/3 to 1/2, 1/2 if you flipped a coin to chose the second door and sometimes show the prize. Alternatively, if you chose when to open the second door, you could make swapping a very good (100%) or very poor choice (0%).

Worse, you could swap what's behind the doors after they chose.

Which IMO is why people find this so confusing. In the real world the odds presented may or may not line up with the actual odds. aka unknown unknowns.

Re: Your iPhone just got less secure. Blame the FBI

#112
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

>The iPhone did not get less secure. It has always had this security hole. Although given the fact that it was made public that they found a security hole, won't that change the behavior of malicious actors? Now that it's known that a hole exists, more people will start looking for it, reducing security through obscurity.

Security by obscurity is an antipractice.

Re: Your iPhone just got less secure. Blame the FBI

#113
post #20

I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it. The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in questio…

If phones are no less secure when the existence of a vulnerability is disclosed, why do we prefer security researchers to notify the manufacturer before disclosing the vulnerability? And perhaps the vulnerability in question wouldn't work against your iPhone, but how many millions of iPhones still use a short passcode? This vulnerability could still affect all of those phones.

Disclosing vulnerabilities makes us more secure, that's why we want people to do it. That doesn't imply that failing to disclose them makes us less secure. Not doing anything leaves us where we started.

Re: Your iPhone just got less secure. Blame the FBI

#114
post #88
post #45

Earlier quoted context omitted.

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

> The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. That's the common misunderstanding of the problem. Most people think that the probabilities go fro 1/3, 1/3, 1/3 to 1/2, 1/2, after choosing a door and having Monty Hall open one of the others. The probabilities don't change. The probabilities are 1/3, 1/3, 1/3 at the start. After you choose a door, they're still 1/3,…

>> The probabilities change

> That's the common misunderstanding of the problem...

You've got a choice here... you can either interpret "The probabilities change" as meaning the probabilities of a given door being correct at the start (which would be a misunderstanding) or you could interpret it from the pragmatic angle; the probability of success if you switch doors after one is taken away.

Given the context I'm inclined to believe that wrsh07 intended the latter.

Re: Your iPhone just got less secure. Blame the FBI

#115
post #20

I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it. The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in questio…

If phones are no less secure when the existence of a vulnerability is disclosed, why do we prefer security researchers to notify the manufacturer before disclosing the vulnerability? And perhaps the vulnerability in question wouldn't work against your iPhone, but how many millions of iPhones still use a short passcode? This vulnerability could still affect all of those phones.

Bruce Schneier is an advocate of full disclosure. He does not believe that companies should be notified first.

Re: Your iPhone just got less secure. Blame the FBI

#116

I completely disagree with the premise here. This is Tim Cook's fault and it should fall completely on Apple. I've been using Apple products my whole life, and I think security and privacy are great, but I don't believe for one second that Apple is the holy savior of our privacy. They fought the FBI because of marketing and profits, not out of a sense of duty to protect our privacy. I also don't buy the rhetorical co…

You're certainly right about one thing: the people want privacy and will reward a company handsomely for delivering.

In theory government is supposed to also be responsive to the will of the people especially with regards to things like privacy from government searches so I guess it's up to the reader to decide for themselves which side they're on here.

Re: Your iPhone just got less secure. Blame the FBI

#117
post #35

Schneier knows this, and this is a particularly idealistic op-ed, but this is just how the exploit market works and while it would be nice if law enforcement would take the white-hat road, the hazard here is still vastly better than some kind of legal precedent for requiring backdoors. The good thing about the exploit market is that it is naturally self-limiting: you don't burn a zero-day on a dragnet; you limit its…

There's a bit of irony to this, too. If Apple had been more cooperative earlier, law enforcement probably would've taken the white hat approach. Apple protected users from the FBI, but is now potentially unable to protect them from organised crime.

If Apple had done as requested, the FBI would not have hired a contractor and we would not know that a contractor capable of this existed.

Re: Your iPhone just got less secure. Blame the FBI

#118
post #88
post #45

Earlier quoted context omitted.

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

> The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. That's the common misunderstanding of the problem. Most people think that the probabilities go fro 1/3, 1/3, 1/3 to 1/2, 1/2, after choosing a door and having Monty Hall open one of the others. The probabilities don't change. The probabilities are 1/3, 1/3, 1/3 at the start. After you choose a door, they're still 1/3,…

I only started to understand how to look at this problem once I realized the host was going to eliminate a bad door _no matter what was chosen_. Of course if you have already selected a bad door he won't eliminate it.

Another useful exercise is to stretch the number of doors to some large N and suppose the choice was posed repeatedly with a decreasing number of doors. If you can have anywhere from 2 to N guesses and as N decreases the number of bad doors decreases, it seems more obvious that you should always switch.

Re: Your iPhone just got less secure. Blame the FBI

#119
post #45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

According to the article, the vulnerability was known. All that changed is the FBI got somebody to use it.

I would agree with the "less secure" bit if the FBI had uncovered the vulnerability, or asked some third party to do it. But since they just used something that was already known, the "less secure" statement makes no sense to me.

Re: Your iPhone just got less secure. Blame the FBI

#120
post #63
post #52

Schneier has never had a strong intuition for how software vulnerabilities work. In the 2000s, he wrote articles in his newsletter blaming eEye (a security research firm then the home of Derek Soeder, Barnaby Jack, Ryan Permeh, and the like) for publishing their vulnerability research. He is at turns anti-disclosure, pro-disclosure, and all points in between.

My understanding is that “disclosure” is a nuanced thing, time-wise: responsible disclosure is to mention the vulnerability to someone who can and is intent to fix it first, give them the time to write, test and send a patch, and then publish it. Publishing it earlier sound very unreasonable, especially before handing the details to the manufacturer. I am not familiar with what Schneier said 15 years ago, though. He…

There is no such thing as "responsible disclosure". That's a term invented by vendors to coerce independent researchers into doing free work for them. Semantic drift has somewhat legitimized the term, but I think it's important we remember why it was conjured in the first place.
Post reply on HN