Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

121–130 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#121

Earlier quoted context omitted.

>take the Monty Hall problem It amazing how many people still don’t get the Monty Hall problem. Its lesson is that the probabilities do NOT change – until we make a choice!. That’s why it’s better to switch once we see the goat behind door 1. The probability of our having made a good choice, initially (1 in 3), has NOT changed even though there are now only two ‘choices’. But they are not REALLY choices because we’ve…

It's much easier to understand when you realize that Monty never reveals that one of the closed doors contained the car. That asymmetry of action leads to the asymmetry of probabilities; your initial choice constrained his choices when he takes action.

Well, Monty doesn't know (or care about) your choice. He's 'constrained' by the fact that his 'probability' is 100%: he knows where the goats and car are.

Re: Your iPhone just got less secure. Blame the FBI

#122

If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.

Because FBI spent taxpayer's money to find a vulnerability in a device used by millions of people - it should release that information so that apple can fix it. Simple as that.

Apple probably should have considered their own fallibility and the value of a working relationship with the FBI before launching a scorched-earth PR campaign.

If the FBI could rely on Apple to provide assistance when presented with a court order, they would have no reason to keep such a method private -- or to even find and use it in the first place.

Tim Cook does not come across as a sufficiently prescient CEO in this boondoggle.

Re: Your iPhone just got less secure. Blame the FBI

#123
post #111
post #88

Earlier quoted context omitted.

> The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. That's the common misunderstanding of the problem. Most people think that the probabilities go fro 1/3, 1/3, 1/3 to 1/2, 1/2, after choosing a door and having Monty Hall open one of the others. The probabilities don't change. The probabilities are 1/3, 1/3, 1/3 at the start. After you choose a door, they're still 1/3,…

This assumes you always open a door, that door never holds the prize, and there is exactly 1 prize. You could run (ed:a similar game with different rules) such that the odds go 1/3,1/3,1/3 to 1/2, 1/2 if you flipped a coin to chose the second door and sometimes show the prize. Alternatively, if you chose when to open the second door, you could make swapping a very good (100%) or very poor choice (0%). Worse, you coul…

This is incorrect.

Flipping a coin to "to chose the second door and sometimes show the prize." has no impact on the probabilities. The parent is correct - there is a 2/3 chance the prize exists under one of the other two doors, and if one of them is shown not to have the prize (through random flipping, deliberate selection, whatever) - then the final door now has a 2/3 chance to have the prize.

Re: Your iPhone just got less secure. Blame the FBI

#124
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

>and even then, the first generation of iPhone fingerprint readers was pretty bad Hunh? The iPhone 5s and the iPhone 6 both contained the first gen fingerprint reader, and it was universally regarded as one of the best consumer fingerprint readers available on any device. That is largely irrelevant though, as the secure enclave is not in the fingerprint reader. TouchID is one way to access it, but the secure element…

Note that the Secure Element is not the same as the Secure Enclave. The Secure Enclave is a walled-off section of the main CPU, running a custom L4 microkernel, which handles the device encryption. The Secure Element is a separate chip running Java Card which handles payments. The devices (including the watch) have both.

Re: Your iPhone just got less secure. Blame the FBI

#125

I completely disagree with the premise here. This is Tim Cook's fault and it should fall completely on Apple. I've been using Apple products my whole life, and I think security and privacy are great, but I don't believe for one second that Apple is the holy savior of our privacy. They fought the FBI because of marketing and profits, not out of a sense of duty to protect our privacy. I also don't buy the rhetorical co…

Yeah, the "trade liberty for security" line is applied selectively, as far as I can tell. It tends to be trotted out frequently in discussions about data encryption.

I don't see that line used nearly so often against traffic laws, driver's license laws, state medical board doctor licensing laws, laws banning the sale of guns to minors, compulsory education laws, childhood vaccination laws, laws banning lead in gasoline, building codes requiring the use of twelve-gauge wire in certain circuits, laws requiring carbon monoxide detectors in our bedrooms and kitchens, etc.

The government is applying constraints to our lives and freedoms literally _all the time_ in the name of securing us against threats to life and health.

Most people accept those trade offs. But those same people actually _do_ deserve both liberty and security.

Re: Your iPhone just got less secure. Blame the FBI

#126
post #45

Earlier quoted context omitted.

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

>take the Monty Hall problem It amazing how many people still don’t get the Monty Hall problem. Its lesson is that the probabilities do NOT change – until we make a choice!. That’s why it’s better to switch once we see the goat behind door 1. The probability of our having made a good choice, initially (1 in 3), has NOT changed even though there are now only two ‘choices’. But they are not REALLY choices because we’ve…

The iPhone 5 is now less secure because attackers now know that there is a vulnerability, and they will find it. If, previously, they had thought there wasn't a vulnerability, they might have invested fewer resources in hacking it. That is now no longer the case.

Increasing the number of people who will find exploits on a device, will reduce the security of that device.

Put another way - a platform that no (talented) engineers are attempting to find exploits for is more secure than the same platform if many talented engineers put their time into finding exploits for it.

Re: Your iPhone just got less secure. Blame the FBI

#127
post #77
post #47

Earlier quoted context omitted.

There is absolutely no proof of that. What they where asking for was keys to every lock in the world. It would have given them unprecedented power to do whatever they wanted. Apple did the right thing. Users should always come first especially when privacy is at stake.

They were willing to hand over the phone to Apple and allow all work to take place on Apple premises. How does that affect other phones?

So have you not heard that this would set a legal precedent? Apple would get pestered until they finally create an automatic gateway for turn key security breaking, not unlike the wiretap portals setup by telecoms - or the frequently abused youtube DMCA mechanisms.

Re: Your iPhone just got less secure. Blame the FBI

#129

Earlier quoted context omitted.

It's much easier to understand when you realize that Monty never reveals that one of the closed doors contained the car. That asymmetry of action leads to the asymmetry of probabilities; your initial choice constrained his choices when he takes action.

Well, Monty doesn't know (or care about) your choice. He's 'constrained' by the fact that his 'probability' is 100%: he knows where the goats and car are.

What? Of course his action is based on your choice.

If a has the car and b and c have goats, and you pick b, he opens c. And if you pick c, he opens b...

Re: Your iPhone just got less secure. Blame the FBI

#130

NPR was playing this story up as if it's a blow for Apple - is it really? Isn't the vulnerability the fact that the phone has no secure enclave, and so the timeout/wipe can be worked around by external access to the flash? Isn't that the whole reason the newer phones were upgraded? Older device fails, newer device with improved security doesn't. That's not a blow to Apple, that's the way the world works.

For all we know, it was because the device was owned by San Bernadino government (despite the FBI screwing that up) that allowed them to access it.

This is all smoke and no fire.

Post reply on HN