Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

131–140 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#131

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

> That hurts the government's ability to advance their own technological capabilities and understanding.

I take it that nobody in The White House uses an iPhone, or at least I hope not. Institutionalized ignorance to the degree of shooting oneself in the foot is concerning - far more concerning than the existence of this specific vulnerability.

Re: Your iPhone just got less secure. Blame the FBI

#132
post #78

Earlier quoted context omitted.

> I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obligation to create vulnerabilities for the governments to exploit (on the contrary; the companies have an obligati…

> How do you determine if a vulnerability was there because it was overlooked in development, or if it was there because the government demanded it from the company but used the law to impose a gag order on the company preventing the public from finding out about it? You don't; but that's possible today with the way the gag orders and FISA courts work. That's a real problem around transparency in our legal system; wh…

That's a really interesting viewpoint. Thanks for sharing it.

In my opinion the government should be obliged to share the vulnerability for the purposes of the keeping the rest of the users safe from the same exploit, whether executed by the government or executed by somebody else.

In summary, I disagree with you but I'm glad I took the time to ask you about your view since I learned something new.

Re: Your iPhone just got less secure. Blame the FBI

#133
TBH there have been so many security holes in the iOS software... this software did not "get less secure", it has been there all along. If you're an iPhone user, you notice the CONSTANT iOS security updates... most of them are because someone found a hole and patched it up! I just hope that the FBI lets Apple know of this hole once the case is over (but I doubt that will happen), or Apple figures out how they did it. If Apple can't find out, it won't be very easy for others to get into iPhones either... but it's still possible.

Re: Your iPhone just got less secure. Blame the FBI

#134

Earlier quoted context omitted.

> Ok, sub in that it would be a valuable tool in carrying out their mission for the making their job easier. The point is that it isn't extraordinary for law enforcement to want investigative powers. Sure. Then I'd just circle back to my original point which is there is disagreement over how to keep the public safe. That's the cause of the problem, and we're missing someone who can bridge that communication gap. > If…

It's not a communication gap. The sides understand each other just fine.

The FBI brought this to court and demanded, quite vehemently in their last brief [1], what they wanted. They chose to bypass the option of further discussing the issue with Apple outside of a court room. Whether you feel Apple or the FBI was being stubborn, that is not good communication.

In my opinion, the government needs to make some deposits into its emotional bank account with technologists to make up for the damage it has done.

[1] https://www.techdirt.com/articles/20160310/18161233865/we-re...

Re: Your iPhone just got less secure. Blame the FBI

#136
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

How secure something is doesn't only depends on itself but also on its environment. There's a vulnerability known by some which isn't going to be fixed. The moment this vulnerability was disclosed to the FBI, the iPhone became effectively less secure.

More generally, any given version of a piece of software if becoming less and less secure with time, because vulnerabilities are found, although it's the same piece of software.

Re: Your iPhone just got less secure. Blame the FBI

#137

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

> That hurts the government's ability to advance their own technological capabilities and understanding. I take it that nobody in The White House uses an iPhone, or at least I hope not. Institutionalized ignorance to the degree of shooting oneself in the foot is concerning - far more concerning than the existence of this specific vulnerability.

Tons do. Watch the Congressional hearing [1]. Some representatives hold theirs up when they begin talking.

[1] https://youtu.be/g1GgnbN9oNw

Re: Your iPhone just got less secure. Blame the FBI

#138
post #111

Earlier quoted context omitted.

This assumes you always open a door, that door never holds the prize, and there is exactly 1 prize. You could run (ed:a similar game with different rules) such that the odds go 1/3,1/3,1/3 to 1/2, 1/2 if you flipped a coin to chose the second door and sometimes show the prize. Alternatively, if you chose when to open the second door, you could make swapping a very good (100%) or very poor choice (0%). Worse, you coul…

This is incorrect. Flipping a coin to "to chose the second door and sometimes show the prize." has no impact on the probabilities. The parent is correct - there is a 2/3 chance the prize exists under one of the other two doors, and if one of them is shown not to have the prize (through random flipping, deliberate selection, whatever) - then the final door now has a 2/3 chance to have the prize.

If one of the doors is shown to not have the prize, the odds are now 1/2 when the choice of reveal door is made randomly. That's because 1/3 of the time, you're not even offered the chance to switch, since it's pointless.

I'll run the trials here. Assume the first two doors have the goat, and the third door has the car.

   Pick  Reveal  Switch?  Outcome
   ----  ------  -------  -------
     1      2      Y 3    Car
     2      1      Y 3    Car
     3      1      N 3    Car
     3      2      N 3    Car

     1      2      N 1    Goat
     2      1      N 2    Goat  
     3      1      Y 2    Goat
     3      2      Y 1    Goat

     1      3       -     No chance to switch      
     1      3       -     No chance to switch
     2      3       -     No chance to switch
     2      3       -     No chance to switch
Meaning, given that you've made it to the point that an offer to switch doors is presented, there is no advantage to do so (or not do so).

Re: Your iPhone just got less secure. Blame the FBI

#140

This is awful reporting. For weeks, the experts in security had been saying that FBI does not in fact need Apple's help to get into that phone; that they are just posturing in order to obtain a back door. This was posted on the ACLU website: https://www.aclu.org/blog/free-future/one-fbis-major-claims-... The FBI can simply remove this chip from the circuit board (“desolder” it), connect it to a device capable of read…

Yes. I'm not worried if the police seize a locked safe from someone and hire a safecracker to open it. That doesn't mean that I shouldn't use that safe. It may still be, in fact, the best safe for me to use.
Post reply on HN