Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

131–140 of 217 posts

Re: Apple – Privacy – Government Information Requests

#131
post #41

Earlier quoted context omitted.

I am no lawyer. While lower court decisions have gone both ways, according to wikipedia, in United States v. Doe, the United States Court of Appeals for the Eleventh Circuit ruled on 24 February 2012 that forcing the decryption of one's laptop violates the Fifth Amendment [1] So there is hope. Perhaps a more practical problem is even with a 5 digit pin, it's entirely possible to simply try all combinations. You proba…

> even with a 5 digit pin, it's entirely possible to simply try all combinations Given a long time. Don't forget iOS slows your brute-force attempts down substantially. I'd be curious how long a brute-force attack would take given the current behavior of the OS.

Is there no way to duplicate the whole filesystem onto a computer and try decrypting that? I didn't think they would actually be thumbing in every password combination...

Re: Apple – Privacy – Government Information Requests

#132

Earlier quoted context omitted.

You get the government you vote for.

You get the government the majority of voters vote for.

Minus that whole lobbying, "corps are people (only when convenient)", and gerrymandering thing, exactly!

Re: Apple – Privacy – Government Information Requests

#133
post #116

Earlier quoted context omitted.

> is far beyond the scope of anything that a US court can order a private party to do. They could order Apple to disclose signing keys so that the government can install spyware themselves. See http://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_orde... for a case where they have done something similar before.

>the government can install spyware themselves It would have to be an OS update since applications don't have access to that stuff, even if signed with an apple key.

That's probably not quite true. Take an app that the user is already likely to have given access to their photos, like Facebook. Create a malicious app with the same app identifiers, sign, and push to the user. At that point, the phone thinks it's Facebook, and should allow access.

That said, it'd be kind of unsubtle, and they'd probably get caught.

Re: Apple – Privacy – Government Information Requests

#134

So the US is now a country where mainstream companies market it as a competitive advantage that they will try to minimize what they will release to the government. I'm glad companies are doing this, but I'm sad that they even have to.

This is hardly a unique situation for the US. There are lots of countries where the state is surveilling their own citizens en masse, some for much more nefarious purposes, and it's not all tiny dictatorships either - plenty of large Western countries are doing it. From my perspective (as someone in the UK) it's actually really refreshing that in the US, some companies are pushing this as a competitive advantage. That means people actually care about it and will make decisions based on it, which is far better than the total apathy I'm surrounded by here. Companies having to work to minimise what is released to the government is not unique to the US; the fact that they are however is relatively rare.

Re: Apple – Privacy – Government Information Requests

#135

Earlier quoted context omitted.

>the government can install spyware themselves It would have to be an OS update since applications don't have access to that stuff, even if signed with an apple key.

That's probably not quite true. Take an app that the user is already likely to have given access to their photos, like Facebook. Create a malicious app with the same app identifiers, sign, and push to the user. At that point, the phone thinks it's Facebook, and should allow access. That said, it'd be kind of unsubtle, and they'd probably get caught.

Ahh yes, I assumed we were talking about messages.

Re: Apple – Privacy – Government Information Requests

#136

Earlier quoted context omitted.

And then NSA forces Apple I to issue the OS update that breaks all your efforts.

That sort of order is out of scope of anything a US court can order, and I believe that an Apple employee would leak it before they complied with such an order.

> That sort of order is out of scope of anything a US court can order

How do you know that? Secret court orders are secret. "National security" trumps everything these days.

LavaBit chose to shut down rather to insert a backdoor that was forced on them. I doubt Apple will shut down over that.

And thanks to Snowden we know Apple's products have been backdoored already.

http://www.spiegel.de/international/world/catalog-reveals-ns...

http://www.infoworld.com/article/2609310/hacking/apple--cisc...

Re: Apple – Privacy – Government Information Requests

#137
post #121

Earlier quoted context omitted.

The government has your fingerprint.

Which doesn't help them much because the fingerprint will only reveal the passcode if they gain physical access to the device's "secure element" and its contents (which is reportedly hard).

It is really surprising how much HN turns a blind eye to / lacks imagination for potential security issues just because it's Apple.

Well, actually it isn't surprising at all.

Re: Apple – Privacy – Government Information Requests

#138
post #101

Earlier quoted context omitted.

Well, I think whatever Apple says, you will find a "loophole" in the wording that supposedly allows them to do evil things. Try it: pretend you are Apple and just try writing a statement that you would consider acceptable and that you wouldn't call "word games, deception and legalese". Myself, I think they did fairly well, certainly the best of any tech company out there today.

> Try it: pretend you are Apple and just try writing a statement that you would consider acceptable and that you wouldn't call "word games, deception and legalese". Ok. "We're enabling custom encryption key management. You may now generate and use your own encryption keys. In addition to ensuring the device data is encrypted, nothing in your iCloud account can be recovered if you lose your key because it is all pre-e…

I don't see any promise there that they won't somehow store your encryption key in a place where they can access it. I see a huge line saying "we invite you to try and catch us and if so we will try to find another way that you haven't yet found out about". So I think you failed on your premise.

Re: Apple – Privacy – Government Information Requests

#140
post #85
post #69

Earlier quoted context omitted.

Often it seems like the people want businesses to take up the fight for privacy, rather than the people themselves.

And why not? Businesses, through lobbying, essentially control the US government. It's not unreasonable that American citizens might feel more empowered voting with their dollars than with ballot papers.

People don't care about privacy or they wouldn't be using Android.
Post reply on HN