Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

171–180 of 217 posts

Re: Apple – Privacy – Government Information Requests

#171

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

The quote is extremely misleading. Sure, it's encrypted by your passcode, and that's great. It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy. http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...

It's not quite milliseconds. According to https://www.documentcloud.org/documents/1302613-ios-security... they've increased the iteration count somewhat:

“The passcode is entangled with the device’s UID, so brute-force attempts must be performed on the device under attack. A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 milliseconds.”

This is still an argument for using a longer length code, however, since a simple 4-digit number would only take 800 seconds to brute force.

Re: Apple – Privacy – Government Information Requests

#172
post #69

Earlier quoted context omitted.

Often it seems like the people want businesses to take up the fight for privacy, rather than the people themselves.

Explain to me how businesses aren't people ?

Business are made of people, but a business is not a person in and of itself. That's why we have the saying "design by committee", because a group of people doing something will not lead to the same result of one person doing something.

Re: Apple – Privacy – Government Information Requests

#173

Here's an observation, and an idea for testing Apple's claims on iMessage privacy: China seems quite determined to block IM systems which do not cooperate with the authorities and permit monitoring of communications. Most recently, both Line and the Korean KakaoTalk were blocked [1]. Skype remains useable in China, presumably because Skype permits efficient monitoring [2]. It seems unlikely that China would tolerate…

It is interesting you are the only one who has mentioned China. The other side of the coin is Apple being worried about being locked out of China for not being secure enough. http://www.reuters.com/article/2014/07/11/us-apple-china-idU...

Re: Apple – Privacy – Government Information Requests

#174
post #57

Earlier quoted context omitted.

Apple has directly addressed the PRISM diclosures, last year: https://www.apple.com/apples-commitment-to-customer-privacy/ In addition the new section launched today includes a page on government information requests, including "National Security Orders from the U.S. government." One sentence summary: they provide data to the government when required to by law. PRISM itself is a program that is structured as a reques…

> The initial report of PRISM implied that the NSA and FBI had direct, unfettered access to providers' "central servers", but that has been since walked back a bit. Really? I haven't been able to follow every report, as the Snowden leaks generated a lot of content over the past year. Can you give a source to where PRISM's central server access has been "walked back a bit"?

http://www.forbes.com/sites/jonathanhall/2013/06/07/washingt...

Re: Apple – Privacy – Government Information Requests

#175

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

>"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" Too bad they (and other phone manufacturers) don't protect phone calls with some kind of end-to-end encryptio…

There's not much one company can do about the standards. [1] They can only control their own output.

Apple asserts that Facetime and Facetime Audio are end-to-end encrypted. And Google claims Hangouts are encrypted as well.

I don't know whether there are caveats (or how many) to either of those claims. But that's about as much as one could hope for in the current climate. [2]

[1] Particularly upstart computer companies dealing with the telecom oligopoly. Long cozy with governments and law-enforcement, if not an explicit part of government.

[2] It's a serious bummer that FaceTime never developed into the open standard they claimed at introduction. I've been curious about where that fell apart. (Competitor disinterest, patent liability, carrier terms, etc)

Re: Apple – Privacy – Government Information Requests

#176
post #57

Earlier quoted context omitted.

Apple has directly addressed the PRISM diclosures, last year: https://www.apple.com/apples-commitment-to-customer-privacy/ In addition the new section launched today includes a page on government information requests, including "National Security Orders from the U.S. government." One sentence summary: they provide data to the government when required to by law. PRISM itself is a program that is structured as a reques…

> The initial report of PRISM implied that the NSA and FBI had direct, unfettered access to providers' "central servers", but that has been since walked back a bit. Really? I haven't been able to follow every report, as the Snowden leaks generated a lot of content over the past year. Can you give a source to where PRISM's central server access has been "walked back a bit"?

The Wikipedia page is up to date and contains a lot of links to external sources.

http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%2...

The press report that most directly addresses the issue is probably this one:

http://www.cnet.com/news/no-evidence-of-nsas-direct-access-t...

Incidentally the author of that story is doing a startup now, visits HN, and actually has posted in this thread! Username is "declan."

Essentially, it seems there are a number of NSA programs that we can now distinguish from one another.

PRISM uses the FBI and FISA court orders to directly request records from hosted application providers like Google, Yahoo, Apple, etc.

But there are also other programs that claim to be authorized under the FISA law that target network infrastructure companies like Verizon and AT&T, apparently sucking up and storing huge amounts of raw traffic directly from network infrastructure. This would be the famous "secret room" at AT&T network building in California. These could suck up Apple traffic (or anyone else) but Apple would not be aware because it's at the network layer.

Then there is MUSCULAR, in which the NSA helped the British GCHQ hack into the internal networks of Google (without Google's knowledge) to suck data out of the unencrypted connections between Google servers.

Re: Apple – Privacy – Government Information Requests

#177

Earlier quoted context omitted.

The government has your fingerprint.

If you grew up in the US, they already have it. Every elementary school kid in the US gets fingerprinted. EDIT: It appears I was wrong, this was only in LA county.

Uh, what? Neither I nor my children have had such an experience in public school.

Re: Apple – Privacy – Government Information Requests

#178
post #173

Here's an observation, and an idea for testing Apple's claims on iMessage privacy: China seems quite determined to block IM systems which do not cooperate with the authorities and permit monitoring of communications. Most recently, both Line and the Korean KakaoTalk were blocked [1]. Skype remains useable in China, presumably because Skype permits efficient monitoring [2]. It seems unlikely that China would tolerate…

It is interesting you are the only one who has mentioned China. The other side of the coin is Apple being worried about being locked out of China for not being secure enough. http://www.reuters.com/article/2014/07/11/us-apple-china-idU...

...where by "not being secure enough" means that location data ends up on US servers. I'd be surprised to see the same sort of statement if location data was collected and kept nationally.

Nonetheless, Apple's relationship to China is a interesting case:

• On one hand, China is posed to be the largest market for Apple in just a handful of years.

• On the other hand, it's hard to imagine China approving of e.g. un-snoopable instant messaging in the hands of the populace.

Re: Apple – Privacy – Government Information Requests

#179

I don't need to read this. Everything on the iPhone is proprietary software. As it has been proven countless times, there is an 100% probability that there are backdoors everywhere on this device. This entire blog post is a lie.

And software built by volunteers, like OpenSSL, has proven to be so much more secure. It's not like heartbleed left practically the entire internet vulnerable to abuse. Oh wait, yes it did.

Re: Apple – Privacy – Government Information Requests

#180

Earlier quoted context omitted.

What's keeping government agencies from putting keylogging code on the SIM card or baseband processor (whichever has the best access to host cpu/memory) via the carriers to obtain the passcode? Not much I guess. Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?

Some very knowledgable iOS security people have told me how hard it is to break iOS. You need quite a few chained exploits to do anything meaningful. Browsers are pretty much the only things with Read/Write/Execute memory. Security is always a convenience/security trade-off. iOS is about as good as you can get before inconvenience will turn people to less secure devices.

[deleted]
Post reply on HN