Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

191–200 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#191
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

The Secure Enclave which amongst others prevents tampering with the microkernel and related modules of iOS was introduced with the A7 SoC.

So basically only the iPhone 5 and older models are easy to compromise, with iPhone 5S and newer it gets a _lot_ harder.

Details here, from the mothership itselves: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Re: Your iPhone just got less secure. Blame the FBI

#192

I find myself divided on this article, as a person who values security very strongly. 1. If the vulnerability the FBI used worked because the device was an iPhone without a secure enclave, Apple probably knows how they did it, but they can't really fix devices that have already shipped without the security features. While this obviously hurts users of those phones, every phone going forward won't have this issue, and…

I am sure Apple knows exactly what they did, it's their system and their own hacking team likely finds stuff like this. The key is if anyone else in the US is able to purchase this hack to unlock a phone: if they do and try to reference evidence based on that a judge will require the process be disclosed.

Re: Your iPhone just got less secure. Blame the FBI

#193

Earlier quoted context omitted.

The specific point of bridging is that technology corporations and the federal government should both care deeply about making consumer and corporate technology as secure as possible, given how much of the nation depends on it. On paper, the right federal agency for this should be the Department of Homeland Security. In reality they have neither the technical expertise nor the political "juice" to compete with the in…

The government isn't a single entity with a single goal. There already exist federal agencies with the goal of increasing security (see http://csrc.nist.gov/groups/ST/toolkit/ ), while others like the FBI have vested interest in increasing their powers of investigation. The executive branch has already made their stance clear, weakening encryption should not be the goal of any federal agency: "We recommend that, rega…

It just seems like federal folks working on security are currently outgunned by the federal folks working on access.

For example where were the pro-security quotes from NIST in all the FBI-Apple stories? I'm sort of kidding--obviously there weren't any--but the reality is that NIST can't stand up to the FBI and that's not their role anyway. They set standards not executive priorities.

If we think of the federal govt as a multi-armed see-saw, where points of view oppose one another from various agencies, then right now the arms in favor of access have a lot more "weight", so the overall system tilts toward them. This was visible in what the Presdient said at SXSW.

What do we see? Pro-encryption messages come from private groups, but pro-access messages come from federal executives. Why wasn't there a senior federal appointee telling Congress that hacking the iPhone was a bad idea? That the FBI had not fully considered all that consequences? Who would that be? The head of NIST?

Re: Your iPhone just got less secure. Blame the FBI

#194

Earlier quoted context omitted.

I don't see why the other door has 99x more probability of being correct. It's still 50/50, original door or remaining door, the other 98 don't change the odds.

Your initial pick has a 1/100 chance of being right. If you switch, and you were right, you lose. On the other hand, your initial pick has a 99/100 chance of being wrong, and if you were wrong, and you switch, you win. So switch.

[deleted]

Re: Your iPhone just got less secure. Blame the FBI

#195
post #165
post #88

Earlier quoted context omitted.

> The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. That's the common misunderstanding of the problem. Most people think that the probabilities go fro 1/3, 1/3, 1/3 to 1/2, 1/2, after choosing a door and having Monty Hall open one of the others. The probabilities don't change. The probabilities are 1/3, 1/3, 1/3 at the start. After you choose a door, they're still 1/3,…

This is a great clarification of how this problem works. I STILL can't grasp why you'd switch. Since you have no idea which door it is, couldn't the 2/3 probability be applied to either his door or your door? For all you know, the one that he removed was just one random one of the goat doors. Your chance of picking the car was 1/3 before, if you could have the car already, why would it be better to switch now that he…

The table here [1] helped me understand it when I first heard of this problem.

[1] https://en.wikipedia.org/wiki/Monty_Hall_problem#Simple_solu...

Re: Your iPhone just got less secure. Blame the FBI

#196
post #79

Earlier quoted context omitted.

> I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. Interesting. What obligations do governments have? On the one hand we have government agencies (the CPA, e.g.) whose entire function is to protect consumer…

Here's the oath stated by FBI agents when they join [1], > I [name] do solemnly swear (or affirm) that I will support and defend the Constitution of the United States against all enemies, foreign and domestic; that I will bear true faith and allegiance to the same; that I take this obligation freely, without any mental reservation or purpose of evasion; and that I will well and faithfully discharge the duties of the…

And here's what their "about" page says:

"Our mission is to help protect you, your children, your communities, and your businesses from the most dangerous threats facing our nation—from international and domestic terrorists to spies on U.S. soil…from cyber villains to corrupt government officials…from mobsters to violent street gangs…from child predators to serial killers."

Our mission is to help protect ... your businesses ... from cyber villains. The FBI acknowledges right on their home page that they have an obligation to share security vulnerabilities with companies.

https://www.fbi.gov/about-us

Re: Your iPhone just got less secure. Blame the FBI

#197
post #95

Earlier quoted context omitted.

> I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. So I take it then you don't believe in a government "for the people"? Like it or not, Apple is legally a person, and even tossing that aside, we know that many of Apple's customers are American citizens, and this whole idea of "keeping knowledge from you…

Agents who handle secret or otherwise restricted data should not be handling it on a mobile device. Those devices should be sanitized. Presuming security is what gets people compromised (and in some cases in political trouble as one US presidential candidate is coming to realize).

Presuming security is when someone says "restricted data should not be [handled] on a mobile device". Spills happen, intentionally or otherwise. This security hole should be fixed before a field agent gets his iPhone hacked by the Chinese.

Re: Your iPhone just got less secure. Blame the FBI

#198

Earlier quoted context omitted.

There is no such thing as "responsible disclosure". That's a term invented by vendors to coerce independent researchers into doing free work for them. Semantic drift has somewhat legitimized the term, but I think it's important we remember why it was conjured in the first place.

How would you call Google Project Zero's 90 day policy?

It is imposed by Google, not the vendor of the broken software.

Re: Your iPhone just got less secure. Blame the FBI

#199
post #62

Earlier quoted context omitted.

> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…

> I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. So I take it then you don't believe in a government "for the people"? Like it or not, Apple is legally a person, and even tossing that aside, we know that many of Apple's customers are American citizens, and this whole idea of "keeping knowledge from you…

> Apple is legally a person

it's not government "for the persons"

Re: Your iPhone just got less secure. Blame the FBI

#200
post #55

Earlier quoted context omitted.

I agree with you, and I think this will eventually lead to a world where governments are unable to exert meaningful influence on large corporations. We're already starting to get there; I have a feeling that if the supreme court had forced Apple to write a custom version of iOS that things could have gotten really messy very quickly -- there were rumors that Apple's entire iOS engineering team was ready to resign if…

> Fuck it, we're based in Ireland now Apple has an enormous investment in their design team in Cupertino. It would be an enormous impact to their product development capability to start over somewhere else. It's not enough to say "HQ is over here bro," court orders still work in California. Then again this whole All Writs effort to "build me a tool to help my investigation" seems to break new ground. Maybe it wouldn'…

I imagine most of the engineers would respond well to "can you please relocate closer to the giant pile of money in ireland"
Post reply on HN