Earlier quoted context omitted.
They would have to update the OS on the device first. And that's definitely not something that can be done silently. I'm assuming here that the OS already doesn't have the ability to suppress the popup, and I think that's a safe assumption because Apple doesn't want to have this ability.
>They would have to update the OS on the device first. And that's definitely not something that can be done silently. how do we know that the iMessage protocol doesn't already have support for a "silent" flag, which, if set, will not cause the message to appear?
Why can't Apple decrypt your iPhone?
121–130 of 132 posts
Re: Why can't Apple decrypt your iPhone?
#122Earlier quoted context omitted.
They would have to update the OS on the device first. And that's definitely not something that can be done silently. I'm assuming here that the OS already doesn't have the ability to suppress the popup, and I think that's a safe assumption because Apple doesn't want to have this ability.
> that's definitely not something that can be done silently. I hate to sound so paranoid, but what reason do you have to believe this?
Re: Why can't Apple decrypt your iPhone?
#123There's another technical surveillance method here that I feel more people should be talking about: monitoring iMessage communication. iMessage is extremely secure[1], except for the fact that Apple controls the device list for iCloud accounts. The method would simply be for Apple to silently add another device to a target's account which is under law enforcement's control. I say "silently" in that they would need to…
Whenever you add a device to your pool of iMessage devices, all of the other devices get a popup message telling them. This is the step where each of the other devices get the decryption key for that device. My hunch is that Apple doesn't have a way to prevent the popup messages so if they were forced to add a law enforcement iPhone to an iMessage pool then the target would notice an extra device was added.
Whenever an iMessage client wants to message the target, it gets a list of target device public encryption keys from Apple. It then sends a separately-encrypted copy of each message to each of those recipients.
What Apple could do is to "bug" the lists that are sent to the devices wanting to sending something to the target, without modifying the list that the target device sees. So all incoming messages to the target would get cc'd to law enforcement. This could probably be done completely server-side.
As for outgoing messages, Apple could do the same thing in reverse: whenever the target device asks for the list of recipient devices, just add the monitoring device to it. Again, all by simply modifying the device directory server, no client changes.
The bigger point here is that Apple claims their hands are tied due to the design of the encryption. But as long as the directory service is still under their central control, there is still a technical means for complying with law enforcement requests to monitor iMessage communication.
Perhaps law enforcement just needs to get more specific with their demand. Don't demand "decryption" anymore.. demand a wiretap.
Re: Why can't Apple decrypt your iPhone?
#124Earlier quoted context omitted.
> And that's definitely not something that can be done silently. Can you link me to a technical analysis about this? It would be one of the few phones where the baseband/SIM couldn't make changes to the system.
iMessage has nothing at all to do with the baseband or SIM. And carriers definitely can't push updates to the OS. Only Apple has the technical capability to produce updates to the OS, if for no other reason than the fact that all OS code must be codesigned with Apple's certificate, and only Apple has the keys. But since the baseband can't update the OS anyway, that's a moot point. I don't have a link for a technical…
Similarly, the conjectured scenario is that the government is trying to get in to your phone secretly: it's hardly unreasonable to think they could compel both Apple and your carrier to assist them, in the form of Apple generating a custom wiretap update and your carrier silently pushing it.
> It would in fact be incredibly dangerous to update the OS without explicit action, if for no other reason than the fact that this would not give the user the chance to back up their phone in case something goes wrong.
Again, we're talking about responding to a sealed court order to aid in tapping a telephone, and not about what makes good business sense under normal conditions.
Re: Why can't Apple decrypt your iPhone?
#125Earlier quoted context omitted.
Android requires root privilege and/or system-level app to take screenshots. iOS is probably similar. I don't think an app could spy like this without user enabling it (which is a valid but separate concern about how knowledgeable the average rooter/jailbreaker is.) [0] http://android.stackexchange.com/questions/10930/why-do-we-n...
Maybe I'm not fully understanding here but the last two phones I've used do not require root or any app to take screenshots. Nexus 5 and Moto X.
Re: Why can't Apple decrypt your iPhone?
#126There's another technical surveillance method here that I feel more people should be talking about: monitoring iMessage communication. iMessage is extremely secure[1], except for the fact that Apple controls the device list for iCloud accounts. The method would simply be for Apple to silently add another device to a target's account which is under law enforcement's control. I say "silently" in that they would need to…
Re: Why can't Apple decrypt your iPhone?
#127Earlier quoted context omitted.
There is an argument against using the fingerprint access and that is that a user gives up the right of consent while in custody. If law enforcement gets a judicial order to forcibly press the prisoner's finger to the sensor to unlock the device, then he or she has little recourse as the right to remain silent is not implicated. One cannot be similarly physically compelled to disclose a code only held in his or her m…
If you have the ability to lawyer it enough, I think you'd have a few layers of court required to sort out whether this is allowed (assuming they don't have proof you have something on the phone). You are basically forcing self-incrimination, a violation of the Fifth Amendment. I totally agree that, if you are really concerned about this, fingerprint is a bad idea, but the legal ramifications are interesting. Not qui…
Evidence is not covered by the Fifth Amendment. If you have papers that would incriminate you, and a warrant is issued for those papers, you cannot refuse to surrender them. If you destroy them having received the warrant, you'll be prosecuted for obstructing justice.
Orin Kerr's interpretation[1] is that a phone is evidence, and contains evidence in the form of digital data. The only need for testimony is to establish that the phone is actually yours. You can't be forced to admit "yes that is my phone." But if the fact that it is your phone can be established in other ways (say, with the testimony of your wireless provider), then you can be forced to unlock it.
You can't be beaten or tortured until you type it in, of course, at least within the U.S. But you can be jailed for contempt of court for your refusal. And the limits of contempt imprisonment seem to be pretty murky.
[1] http://www.washingtonpost.com/news/volokh-conspiracy/wp/2014...
Edit: to clarify the source of my argument
Re: Why can't Apple decrypt your iPhone?
#128Earlier quoted context omitted.
iMessage has nothing at all to do with the baseband or SIM. And carriers definitely can't push updates to the OS. Only Apple has the technical capability to produce updates to the OS, if for no other reason than the fact that all OS code must be codesigned with Apple's certificate, and only Apple has the keys. But since the baseband can't update the OS anyway, that's a moot point. I don't have a link for a technical…
"It's obvious that neither of the other two processors in your phone with DMA could update your OS" is a statement that needs more justification than "it's obvious". Quite a number of backdoors from the baseband to the actual processor of the phone have been discovered over the last few years, including commands that seem to indicate that it could possibly write arbitrary memory under the right conditions. Similarly,…
Every single one is a security vulnerability, not an intentional blessed mechanism by which the OS can be updated. And every single one is patched as soon as Apple learns of it.
> it's hardly unreasonable to think they could compel both Apple and your carrier to assist them, in the form of Apple generating a custom wiretap update and your carrier silently pushing it.
Except a) any known mechanisms by which this could be done would have already been patched, and b) I find it highly implausible that the government could compel Apple into deliberately breaking the fundamental security architecture of their product. If Apple already had the keys to decrypt the message, they could be compelled to hand them over, but that's very different than compelling them to actually modify their end-user software.
If the government did have the power to compel Apple to do something to aid wiretapping, it would be to compel them to add the ability to suppress the popup into a future OS update. It would certainly not be to compel them into creating and installing an OS update on the fly to a specific phone. Security implications aside, installing custom OS updates to specific phones would also have tremendous consequences on a lot of other stuff, including future OS updates (installing an OS update certainly can't brick the phone even if it's running an unknown custom OS), customer support (what if the target brings their phone in to an apple store?), even their internal build process.
That said, I don't believe the government can compel Apple to deliberately violate the advertised security guarantees of their product. Especially when such tampering is potentially visible to the target (which this would be; people have reverse-engineered the iMessage protocol, which means it's possible to intercept and analyze the traffic, which means it would be possible to write a tool to dump out the keys that your message is going to, which can be used to detect when new keys are added even if the OS doesn't alert you).
> Again, we're talking about responding to a sealed court order to aid in tapping a telephone
No we're not. iMessage isn't a telephone. The fact that the device you're using iMessage on almost certainly also has phone capabilities is irrelevant (and of course you can use iMessage without a telephone, by using a Mac or an iPod Touch).
Re: Why can't Apple decrypt your iPhone?
#129Earlier quoted context omitted.
"It's obvious that neither of the other two processors in your phone with DMA could update your OS" is a statement that needs more justification than "it's obvious". Quite a number of backdoors from the baseband to the actual processor of the phone have been discovered over the last few years, including commands that seem to indicate that it could possibly write arbitrary memory under the right conditions. Similarly,…
> Quite a number of backdoors from the baseband to the actual processor of the phone have been discovered over the last few years Every single one is a security vulnerability, not an intentional blessed mechanism by which the OS can be updated. And every single one is patched as soon as Apple learns of it. > it's hardly unreasonable to think they could compel both Apple and your carrier to assist them, in the form of…
Well I don't know what news you've been reading the past year, but personally I've been given the impression that your NSA will try and compel whoever to do whatever they please, be it through court order, economic/political pressure and/or psy-ops.
> If Apple already had the keys to decrypt the message, they could be compelled to hand them over, but that's very different than compelling them to actually modify their end-user software.
It's also very different from the NSA actively hacking into, breaking security infrastructure of their ALLIES. Which is what they've done repeatedly.
It's also been shown that the NSA doesn't (can't or won't) really make a very fine distinction between who/what exactly are enemy, allied or US-targets. In particular if they really really want certain information that can be considered of high tactical value in their pursuit of foreign targets. Such as, say, private encryption keys for OS updates or whatnot.
While this is not proof that this happened or is happening, I'm arguing that there is very little stopping the NSA if they wanted to.
Re: Why can't Apple decrypt your iPhone?
#130Earlier quoted context omitted.
> Quite a number of backdoors from the baseband to the actual processor of the phone have been discovered over the last few years Every single one is a security vulnerability, not an intentional blessed mechanism by which the OS can be updated. And every single one is patched as soon as Apple learns of it. > it's hardly unreasonable to think they could compel both Apple and your carrier to assist them, in the form of…
> I find it highly implausible that the government could compel Apple into deliberately breaking the fundamental security architecture of their product. Well I don't know what news you've been reading the past year, but personally I've been given the impression that your NSA will try and compel whoever to do whatever they please, be it through court order, economic/political pressure and/or psy-ops. > If Apple alread…