Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

191–200 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#191
post #129

Earlier quoted context omitted.

Depends on if they're at a border crossing or in the interior of the country. Laws apply to citizens and non-citizens alike. If you haven't been admitted to the country, about the most they can do is turn you away at the border checkpoint and put you on the next flight back to your home country.

and if you're a citizen of the country you're trying to enter...

Then the TSA drops a paper clip while you bend over and pick it up

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#192
This marks a very interesting time in my opinion. We have corporations with more money with governments making (or at least attempting to make) certain social decisions once reserved for only public sector government officials. If Apple is successful here, it will usher in a new era of what a private company can do.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#193
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

Can the SE be updated on a locked phone? Because Apple's docs give the impression that it can't.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#195
post #78

Earlier quoted context omitted.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

Well, yeah, if you back it up with a 3rd party backup tool, you are trusting the 3rd party. I recommend you make a backup to your laptop, which you then encrypt manually. That way the trust model is: you trust yourself. Then you can do whatever you want with the encrypted file. Apple's iCloud is perfectly fine at this point. The real challenge is to find a way to restore that backup, because you have to be on a compu…

All laptops and cameras entering the US are subject to search and seizure.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#196
post #120

Any device that relies on hiding secrets inside the silicon itself is subject to hacking. Several secure-enclave like chips have been hacked in the past by using electron microscopes and direct probes on the silicon. If BlackHat conference independent security researchers have the resources to pull this off, Apple and the NSA certainly can. Exfiltrating the Enclave UID could be done by various mechanisms at the chip…

>You may not need to crack the OS, or even upload a new firmware. You just need to disable the mechanism that wipes the device and delays how many wrong tries you get. So for example, if you can manage to corrupt, or patch the part of the system that does that, then you can try thousands of PINs without worrying about triggering the timer or wipe, and without needing to upload a whole new firmware. I disagree. The pi…

The state representing the number of attempts must be stored somewhere, and thus a determined adversary could eventually corrupt it.

Look, there's a big difference between trusting known ciphers that have been well studied by the world's top cryptographers, and a proprietary TPM chip that relies on security-through-obscurity.

The history of embedding secrets into black boxes is a history of them being broken. This isn't a theoretical concern, it's a very practical one.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#197

Earlier quoted context omitted.

That's not really true; as evidence, I give you Room 641A: https://en.wikipedia.org/wiki/Room_641A "Room 641A is a telecommunication interception facility operated by AT&T for the U.S. National Security Agency" As long as you have a backdoor, and Apple does, shady government agencies can and do come knocking. We've got plenty of shady government agencies, and can never guarantee that we won't have more in the future.

That was most likely a backdoor deal between AT&T and the NSA. There was no legislation enacted. AT&T was not REQUIRED to install that room.

We still don't know what the deal was. Arguing the nature of what we know about NSLs is a bit pointless when things like 641A are happening.

Our interpretation of already unconstitutional NSLs guarantees nothing.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#198

Earlier quoted context omitted.

Actually the FBI's current argument is very close to saying that the All Writs Act has no limits, and can compel literally anything the FBI thinks would "help" them with investigations.

The FBI's argument doesn't come anywhere close to saying that. What the FBI's motion actually says[1] is: Pursuant to the All Writs Act, the Court has the power, "in aid of a valid warrant, to order a third party to provide nonburdensome technical assistance to law enforcement officers." The most important limitation here is that nobody, including the FBI, is claiming the All Writs Act grants the court any power at a…

If the proposed help here isn't "burdensome", then nothing would be.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#199
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

Can the SE be updated on a locked phone? Because Apple's docs give the impression that it can't.

The only statement I could find from Apple was from the iOS security guide that states, "it utilizes its own secure boot and personalized software update separate from the application processor." I think we can both agree that's a pretty vague statement, if you have a better source I'd like to see it.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#200
post #82

Earlier quoted context omitted.

We wrote about this in our border search guide and concluded that there is a risk of being refused admission to the U.S. in this case (in the border search context) because the CBP agents performing the inspection have extremely broad discretion on "admissibility" of non-citizens and non-permanent residents, and refusing to cooperate with what they see as a part of the inspection could be something that would lead th…

" they don't obviously get to impose penal sanctions on people for saying no" I wonder if there is any negative effects associated with being refused entry by a CBP? Could it be the case that if you are refused entry once, that in the future they will be more likely to refuse you entry? If so, that's a fairly significant penalty/power that the CBP person has.

> I wonder if there is any negative effects associated with being refused entry by a CBP? Could it be the case that if you are refused entry once, that in the future they will be more likely to refuse you entry? If so, that's a fairly significant penalty/power that the CBP person has.

Yes, some categories of non-citizen visitors (I don't remember which) are asked on the form if they have ever been refused entry to the U.S. (and are required to answer yes or no). If they're using the same passport number as before, CBP likely also has access to a computerized record of the previous interaction.

Post reply on HN