Earlier quoted context omitted.
Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.
> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)
A Message to Our Customers
131–140 of 1001 posts
Re: A Message to Our Customers
#132What im reading is that apple can remote install an update that disable encryption. They dont want to do it. But that they have the capability is a bit scary.
It doesn't say anything about remote install - in fact it says "physical possession" several times.
Re: A Message to Our Customers
#133Earlier quoted context omitted.
That is hard, we know. But it is not impossible for those with time, resources and willingness to think outside the box. For instance, signing keys can and have been stolen, on the principle of "if you can't brute-force it, hack in and take it". http://arstechnica.com/security/2013/02/cooks-steal-security... http://blogs.adobe.com/security/2012/09/inappropriate-use-of... http://www.androidauthority.com/ssl-added-remo…
That is hard, we know. But it is not impossible for those with time, resources and willingness to think outside the box. I assume that Apple has a hardware security module for key generation and storage, perhaps even custom-designed and built, to prevent key extraction/copying. Of course, in the end you have to trust Apple that only a limited number of employees have access to such hardware, that they have proper aud…
Re: A Message to Our Customers
#1340) Find some errata. Apple presumably knows as much as anyone except NSA. Have plausible deniability/parallel construction.
1) OS level issues, glitching, etc. if the device is powered on (likely not the case). Power stuff seems like a particularly profitable attack on these devices.
2) Get Apple, using their special Apple key, to run a special ramdisk to run "decrypt" without the "10 tries" limit. Still limited by the ~80ms compute time in hardware for each try.
(vs. an iPhone 5S/6/6S with the Secure Enclave:)
3) Using fairly standard hardware QA/test things (at least chip-level shops; there are tens/hundreds in the world who can do this), extract the hardware key. Run a massively parallel cluster to brute force a bunch of passphrases and this hw key, in parallel. I'd bet the jihadizen is using a shortish weak passphrase, but we can do 8-10 character passphrases, too. They may have info about his other passphrases from other sources which could be useful.
While I'm morally against the existence of #3, I'm enough of a horrible person, as well as interested in the technical challenge of #3, that I'd be willing to do it for $25mm, as long as I got to do it openly and retained ownership. In secret one-off, $100mm. I'd then spend most of the profits on building a system which I couldn't break in this way.
Re: A Message to Our Customers
#135Earlier quoted context omitted.
What it sounds like is they've been asked to prepare a new OS release that allows an unlimited number of attempts to enter the passphrase via some network link. The press release is written to sound like without a software release, it wouldn't be possible to mount this kind of attack, however attacks like this are generally possible regardless of having some specially modified and signed OS image: for example, by cut…
> with the exception that providing an easy means to brute force a phone to the authorities sets a horrible precedent This is the entire concern (in my opinion and in my reading of Tim Cook's opinion). If the government can force Apple to backdoor this one iPhone (because terrorist), then they can force Apple to backdoor any iPhone for any person given a valid warrant, subpoena or otherwise granted power. Once the fl…
Re: A Message to Our Customers
#136This is quite unlike Apple. Is this the same company that insists on keeping its source proprietary and is always against FOSS? The idea that you care for your users' privacy and still like to keep control on them by not giving them the freedom to modify source-code is not what I buy.
Re: A Message to Our Customers
#137Earlier quoted context omitted.
Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.
> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)
Basebands aside, the rest of the device is somewhat feasible to see being open.
Re: A Message to Our Customers
#138[0] https://en.wikipedia.org/wiki/File:PRISM_Collection_Details....
Re: A Message to Our Customers
#139It makes sense for them. If they put a backdoor in iPhone for US government, they are effectively thrown out of Chinese market. Interesting enough, what will Apple do if Chinese government demand they to decrypt/put backdoor in exchange of staying in the market?
I was about to mention the Chinese case, the Chinese government asking foreign companies to install means of control and access in their products. Does that mean that apple will not provide such means or disable security for phones sold on the Chinese market? That would be surprising given the potential size of this market.
Re: A Message to Our Customers
#140Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…
> Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. Why against hope?