Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

21–30 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#22
post #9

that's the endgame of government surveillance requests: it's increasingly in a company's best interest to have the best security possible so they can't be compelled to hack their own devices.

Surely it is a company's best interests to have 'good enough' looking security to serve their PR purposes while also secretly providing government access to maximise government kudos and all the benefits that would entail?

Not really.

For many customers of hardware and software trust is what is being sold.

As trust is eroded 'good enough' is no longer good enough. The only way to continue to be trusted is to be more secure, and as the grandparent points out the endgame there is that the encryption puts the software and hardware beyond the reach of the company that produced it.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#23
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

>If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right?

That probably also means removing most debugging connections from the physical chip, and making extra sure you can't modify secure enclave memory even if you desolder the phone.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#24
post #7

Don't they just need to tell people to switch away from 4 or 6 digit pins and use longer passwords?

I wish Apple would start pushing passphrases. Easy enough to remember, plenty strong, already usable with the current system on iphones.

Nobody would adopt them. It's annoying enough to deal with 4 digits when it's cold and I'm wearing gloves and I just want to change the song I'm listening to.

Passphrases suck enough whenever you have to log back in. Are people really gonna put up with that every time they want to use their phone?

On the other hand, if there were a convenient way to toggle between passphrases and 4-digit unlock, (especially if you had to use the passphrases to toggle back to 4-digit) then I would be all for it.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#25
post #17

The problem with software is that none have been 100% secure yet... I doubt that Apple will be able to achieve that in the near future. Someone should send a phone to John Mcafee at the very least [1][2] ... 1. http://www.pcgamer.com/john-mcafee-on-his-fbi-iphone-hack-of... 2. http://arstechnica.com/staff/2016/02/mcafee-will-break-iphon... edit: added source #2; see Google for additional sources...

What an awful article. And it isn't even the real article.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#26
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

> if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone Is this true even if you use Touch ID?

If they have access to a live finger for the TouchID, sure they can bypass - but they could do that with the $5 guaranteed coercion method as well [1].

Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer.

All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode).

[1] https://xkcd.com/538/ [2] https://blog.lookout.com/blog/2013/09/23/why-i-hacked-apples...

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#27
post #7

Don't they just need to tell people to switch away from 4 or 6 digit pins and use longer passwords?

I wish Apple would start pushing passphrases. Easy enough to remember, plenty strong, already usable with the current system on iphones.

maybe if i only needed to use it on boot or daily. inputing a long passphrase is pretty onerous to do all the time.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#28
post #5

What is to stop the DOJ from requiring them to produce a phone that has a hardware backdoor? If they are required to produce a software backdoor then building an iphone which is immune to such vulnerabilities seemingly solves that problem but I don't see the leap towards compelling Apple to build vulnerabilities into hardware as a large one. I'm not well versed in security so excuse me for my ignorance but what if th…

The thing to look out for is Congress taking up legislation to compel such capabilities, not the DOJ.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#29
post #5

What is to stop the DOJ from requiring them to produce a phone that has a hardware backdoor? If they are required to produce a software backdoor then building an iphone which is immune to such vulnerabilities seemingly solves that problem but I don't see the leap towards compelling Apple to build vulnerabilities into hardware as a large one. I'm not well versed in security so excuse me for my ignorance but what if th…

What if another agency already has an NSL in place requiring exactly the same (backdoor, weak crypto params, weak by design secure enclave) and they simply are under a gag order to talk about?

Yea NO. NSL's can't do that. At worst they will tell you to release and data that you have and your private keys. At best they will tell you to make sure you archive everything and don't permanently destroy records in case they are required in the future. They cannot force you to add backdoors or create a weak crypto , although they can indirectly suggest you to do that and its then on the company if they do so.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#30
post #26

Earlier quoted context omitted.

> if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone Is this true even if you use Touch ID?

If they have access to a live finger for the TouchID, sure they can bypass - but they could do that with the $5 guaranteed coercion method as well [1]. Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer. All bets are off if the iPhone is power-cycled. Best bet i…

> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode).

Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.

Post reply on HN