Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

141–150 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#141

Earlier quoted context omitted.

> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

What data is likely on someone's phone that is not also in the cloud one way or another?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#142
Could Apple not push an OS update that can compromise everything they are doing to make the iPhone unhackable? As long as user has to trust Apple there's always going to be the possibility that FBI/NSA/Whoever force Apple to update a target's iPhone to enable tracking/recording of whatever information.

It's not an attainable goal in practice. Today they generate a per device customized update that can be installed without user intervention. Even if they tomorrow enforce user intervention they still retain the capability to push a targeted update for a specific device on law enforcement/court order. The user has no way of telling what the update did.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#143

Could Apple not push an OS update that can compromise everything they are doing to make the iPhone unhackable? As long as user has to trust Apple there's always going to be the possibility that FBI/NSA/Whoever force Apple to update a target's iPhone to enable tracking/recording of whatever information. It's not an attainable goal in practice. Today they generate a per device customized update that can be installed wi…

I think they could do all the stuff that makes it unhackable in hardware, and/or they could make it so updates aren't installed while the phone is locked.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#144

Could Apple not push an OS update that can compromise everything they are doing to make the iPhone unhackable? As long as user has to trust Apple there's always going to be the possibility that FBI/NSA/Whoever force Apple to update a target's iPhone to enable tracking/recording of whatever information. It's not an attainable goal in practice. Today they generate a per device customized update that can be installed wi…

It's very difficult, especially since they aren't open source. However, they could attain a state where to compromise a device requires the user accepting a malicious update, which would make the FBI's current request moot.

(although there's a whole separate set of legal attacks unexplored)

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#145

Earlier quoted context omitted.

> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

If you're paranoid, you don't have a cell phone.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#146

Earlier quoted context omitted.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

What data is likely on someone's phone that is not also in the cloud one way or another?

I wonder this too. The only personal data on my phone are my text and email messages. I'm not sure how other data would get onto the phone.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#147
What I want is a service that deletes all my online presence after I die. A deadswitch. All texts, messages, emails, facebook posts, pictures anywhere, everything.

I want it all to go when I do. Hell, I want some of it to go now.

After I'm gone, I want to leave no part of my existence on the internet.

I realize that's not possible. But I want to minimize my footprint.

It is totally possible for a local device. I have a deadswitch on all my computers. If I don't log in and set an alive flag via the command line in any of my computers for more than a week, that computer securely wipes itself.

Let it be known, I have nothing to hide. I just think this is the best way to do things.

Edit: My reason for this is the frequency with which I encounter people who are no longer alive. It's a harsh thing to look at a link to someone who said something, and you used to know and then suddenly realize, "Oh shit. He's dead. And I used to be his best friend."

I know facebook has memorial pages, but those are difficult to get.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#148
post #131
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

Why would they have made the Secure Enclave allow updates on a locked device without wiping the key in the first place? Either they didn't think it through, assumed they would never be compelled to use it as a backdoor, or perhaps they were afraid some bug could end up having catastrophic consequences of locking a billion people out of their phones with no way to fix it? Do we even know for certain that the Secure En…

From what's been said, it seems like it was made to be updated so that Apple could easily issue security updates. They've already increased the delay between repeated attempts at password entry. Probably they were worried about vulnerabilities or bugs that hadn't been found and wanted to maintain debugging connections to make repairs easier. A tamper-resistant self-destruct mechanism with no possibility of recovery introduces extra points of failure, and it seems that until now, they didn't think it was necessary.

Look at the controversy over the phone not booting with third-party fingerprint reader repairs as an example. People were upset when they found out that having their device worked on could make it unbootable, but Apple was able to easily fix it with a software update. If it had been designed more securely, it might have wiped data when it detected unauthorized modifications, which would have meant even more upset people. Now that this has become a public debate, there will be a very different response to making it more secure.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#149
post #131
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

Why would they have made the Secure Enclave allow updates on a locked device without wiping the key in the first place? Either they didn't think it through, assumed they would never be compelled to use it as a backdoor, or perhaps they were afraid some bug could end up having catastrophic consequences of locking a billion people out of their phones with no way to fix it? Do we even know for certain that the Secure En…

> or perhaps they were afraid some bug could end up having catastrophic consequences of locking a billion people out of their phones with no way to fix it?

That basically happened (at a smaller scale) just last week. When Apple apologized and fixed the "can't use iPhone if it's been repaired by a 3rd party" thing, the fix required updating phones which were otherwise bricked. It's not an unreasonable scenario.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#150
post #78

Earlier quoted context omitted.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

Well, yeah, if you back it up with a 3rd party backup tool, you are trusting the 3rd party. I recommend you make a backup to your laptop, which you then encrypt manually. That way the trust model is: you trust yourself. Then you can do whatever you want with the encrypted file. Apple's iCloud is perfectly fine at this point. The real challenge is to find a way to restore that backup, because you have to be on a compu…

> I recommend you make a backup to your laptop, which you then encrypt manually.

You mean your laptop that was manufactured by a 3rd party, with a network card that was manufactured by a 3rd party? And you're using encryption software that, even if it's open source, you probably aren't qualified to code review. I'm not downplaying the benefit of being careful, but unfortunately you can keep doing that pretty much forever.

Post reply on HN