Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

171–180 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#171

Earlier quoted context omitted.

Corporate email profiles on BYOD phones often enforce a long passcode requirement, so you've got a lot of Fortune 500 sales guys to screen out if you're stopping and searching anybody with a suspiciously long password.

I'm at a loss as to how alphabet agency can determine a weak passcode vs strong passcode was used. how does a pin get stored on the phone? surely, not plain text of a 4 digit pin. if they do any encryption to the 4 digit pin, how would it appear any different than a significantly stronger passcode?

The prompt is different based on the type of code you use.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#172

Earlier quoted context omitted.

Corporate email profiles on BYOD phones often enforce a long passcode requirement, so you've got a lot of Fortune 500 sales guys to screen out if you're stopping and searching anybody with a suspiciously long password.

I'm at a loss as to how alphabet agency can determine a weak passcode vs strong passcode was used. how does a pin get stored on the phone? surely, not plain text of a 4 digit pin. if they do any encryption to the 4 digit pin, how would it appear any different than a significantly stronger passcode?

The grandparent post was about determining the complexity of a PIN/Passcode by watching it being entered - more screen interaction = more complex.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#173
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

They're not anywhere near 99% of the way there; they've destroyed the heterogeneous decentralized ecosystem that broad security requires. Locking themselves out of the Secure Enclave isn't anywhere near sufficient. As long as the device software and trust mechanisms are totally opaque and centrally controlled by Apple, the whole thing is just a facade. There's almost nothing Apple can't push to the phone, and the aud…

Then again, nobody is suing over android phone crypto, and as recently as last November bugs have been discovered that sookmg things like entering an excessively long password allows you to bypass the lock screen.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#174

Earlier quoted context omitted.

The DoJ doesn't really have the power to do that. They can get a judge to issue a warrant to search an existing device, and the judge can in some circumstances compel other parties to cooperate in that search. But generally any requirement that Apple insert a generalized backdoor into a product will need to come from new legislation.

Actually the FBI's current argument is very close to saying that the All Writs Act has no limits, and can compel literally anything the FBI thinks would "help" them with investigations.

I'm not a lawyer so obviously I'm not exhaustively well read on the law but in the case that All Writs did allow any action to be demanded to help with an investigation it would still require there to be an investigation in the first place.

To preemptively demand a back door is almost akin to guilty until proven innocent, youre assuming that there will be an investigation in the future where a governments ability to hack a device is required.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#175
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

"These devices were already fenced off from the DOJ, as long as their operators were savvy about opsec."

I hate to be that guy, but if you have an op and you have any opsec, you aren't even carrying a phone.

Right ?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#176
post #175
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

"These devices were already fenced off from the DOJ, as long as their operators were savvy about opsec." I hate to be that guy, but if you have an op and you have any opsec, you aren't even carrying a phone. Right ?

Like literally every other type of security, OpSec is not binary.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#177

My last write-up on smartphone risks applies to this discussion. https://news.ycombinator.com/item?id=10906999 Apple is far from having a secure phone right now. NSA certainly has ways to bypass this based on my attack framework and their prior work. They just don't want them to be known. They pulled the same stuff in the past where FBI talked about how they couldn't beat iPhones but NSA had them in the leaks & was p…

> They pulled the same stuff in the past where FBI talked about how they couldn't beat iPhones but NSA had them in the leaks & was parallel constructing to FBI. Do you have a link to a leak that shows this? I couldn't find anything with a simple google search.

It was in the leak on mobile OS's. They not only found iPhone vulnerable but mocked their users.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#178

Earlier quoted context omitted.

The DoJ doesn't really have the power to do that. They can get a judge to issue a warrant to search an existing device, and the judge can in some circumstances compel other parties to cooperate in that search. But generally any requirement that Apple insert a generalized backdoor into a product will need to come from new legislation.

Actually the FBI's current argument is very close to saying that the All Writs Act has no limits, and can compel literally anything the FBI thinks would "help" them with investigations.

The FBI's argument doesn't come anywhere close to saying that. What the FBI's motion actually says[1] is:

Pursuant to the All Writs Act, the Court has the power, "in aid of a valid warrant, to order a third party to provide nonburdensome technical assistance to law enforcement officers."

The most important limitation here is that nobody, including the FBI, is claiming the All Writs Act grants the court any power at all in the absence of a search warrant. Nobody really disputes the statement above, or the validity of the warrant in question.

Again: if the FBI wants Apple to preemptively insert a generalized backdoor into their products they'll need to lobby to have new legislation passed. They've tried that and it hasn't gone much of anywhere. In my opinion lets try and keep it that way.

[1] http://www.wired.com/wp-content/uploads/2016/02/SB-shooter-M...

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#179
post #49

Any device that relies on hiding secrets inside the silicon itself is subject to hacking. Several secure-enclave like chips have been hacked in the past by using electron microscopes and direct probes on the silicon. If BlackHat conference independent security researchers have the resources to pull this off, Apple and the NSA certainly can. Exfiltrating the Enclave UID could be done by various mechanisms at the chip…

A couple issues: * Decapping and feature extraction even from simpler devices is error prone; you can destroy the device in the process. You only get one bite at the apple; you can't "image" the hardware and restore it later. Since the government is always targeting one specific phone, this is a real problem. * There's no one byte you can write to bypass all the security on an iPhone, because (barring some unknown re…

Is there anything preventing them from imaging the parts of the device that store data? The data in the image would be encrypted, of course, but wouldn't this give them essentially unlimited (or up to their budget) attempts at getting to the data?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#180
post #49

Earlier quoted context omitted.

A couple issues: * Decapping and feature extraction even from simpler devices is error prone; you can destroy the device in the process. You only get one bite at the apple; you can't "image" the hardware and restore it later. Since the government is always targeting one specific phone, this is a real problem. * There's no one byte you can write to bypass all the security on an iPhone, because (barring some unknown re…

Is there anything preventing them from imaging the parts of the device that store data? The data in the image would be encrypted, of course, but wouldn't this give them essentially unlimited (or up to their budget) attempts at getting to the data?

It's encrypted against an effectively random 128 bit AES key. Unlimited time is not enough.
Post reply on HN