Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

21–30 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#21

NPR was playing this story up as if it's a blow for Apple - is it really? Isn't the vulnerability the fact that the phone has no secure enclave, and so the timeout/wipe can be worked around by external access to the flash? Isn't that the whole reason the newer phones were upgraded? Older device fails, newer device with improved security doesn't. That's not a blow to Apple, that's the way the world works.

You are exactly right: If the vulnerability does exist, and the FBI did contract it out, this just shows that the vulnerability is very expensive and only available to major state actors. In fact, a single government - the U.S. - couldn't do it alone.

It's possible this is a actually script-kiddie exploitable vuln, but I highly doubt it.

All that we have learned is what we suspected: Some "outdated"/older phones are infinitesimally less secure in a way that only internationally collaboration between some of the world's most powerful hackers can break. And it's not really the FBI's fault. They're not sharing it with anyone. (Probably).

So it's not a blow to Apple at all. They already moved on before this. This phone/vuln was a stepping stone for them that is already obsolete. In fact, this is a boon to Apple, bc people will be scared into upgrading. (Except for the hopeless sheeple who "have nothing to hide" and perfer to share their personal info with the world's gubmints).

Re: Your iPhone just got less secure. Blame the FBI

#22
post #17

Is this just FUD? Simply confirming the vulnerability seems likely to lead to it being plugged, whether or not the FBI reveals their methods, in effect doing the opposite of what the title suggests.

FUD or not, if it's from the Washington Post, you can almost guarantee it's not a good source.

Re: Your iPhone just got less secure. Blame the FBI

#24
I am sure they just hired some interns to

    code = 0000

    While code_is_valid not true:

        enter code

        reboot device

        code++
Edit: I am pretty sure there's a delay in code execution registering a wrong pin hence by rebooting the phone, the wrong pins won't get detected.

Re: Your iPhone just got less secure. Blame the FBI

#25

Schneier knows this, and this is a particularly idealistic op-ed, but this is just how the exploit market works and while it would be nice if law enforcement would take the white-hat road, the hazard here is still vastly better than some kind of legal precedent for requiring backdoors. The good thing about the exploit market is that it is naturally self-limiting: you don't burn a zero-day on a dragnet; you limit its…

> ...you don't burn a zero-day on a dragnet;

That depends entirely upon the nature of the vulnerability. Every TLS vulnerability publicly disclosed and then patched comes to mind. The NSA can use that all day long without anybody knowing - see parallel reconstruction.

Re: Your iPhone just got less secure. Blame the FBI

#26

If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.

If I find a vulnerability and exploit someone's device, it's not okay under law. Why is a government institution exempt from law in a supposedly exemplary democracy?

Re: Your iPhone just got less secure. Blame the FBI

#27

Your iphone just got less secure - so don't use iphones anymore. It always amazes me when people get on their high horse and start complaining about something when the remedy is quite simple - don't use the iphone. Get an Android phone, or an Ubuntu phone, or a Blackphone or a Windows phone. There's plenty of other devices that haven't been cracked by the FBI. There's irony in the fact Apple resisted the FBI attempts…

[deleted]

Re: Your iPhone just got less secure. Blame the FBI

#28

NPR was playing this story up as if it's a blow for Apple - is it really? Isn't the vulnerability the fact that the phone has no secure enclave, and so the timeout/wipe can be worked around by external access to the flash? Isn't that the whole reason the newer phones were upgraded? Older device fails, newer device with improved security doesn't. That's not a blow to Apple, that's the way the world works.

As far as I've been able to figure out, the Secure Enclave does not have its own storage. The proposed attack of cloning the phone's flash memory would work just as well on a new iPhone 6s. A lot of people are assuming that the Secure Enclave would prevent this attack, but I've not yet been able to find any basis for that assumption.

The main security advantage of newer phones in this context is that Touch ID makes it practical to set a more complex passphrase. The flash cloning attack only works if you have a short passcode set, because it relies on brute force. If your passphrase is complex enough that it can't be brute forced even when the software controls are removed, then you're still safe.

I'd wager that when the iPhone 7 ships this fall, it will have an upgraded Secure Enclave with internal storage that can prevent this attack entirely.

Re: Your iPhone just got less secure. Blame the FBI

#29
I think this just feeds off the myth that the iPhone was invulnerable to exploit. The average washington post reader isnt going to know the intricacies of mobile security. NPR and to some extent this article makes it seem like the iPhone was previously secure, and now less so. There is no data supporting either hypothesis, but its likely that this was not a new exploit found that the FBI used.

I am curious, however, as to whether this affects only the 5c or if it affects the newer 6/6+/s/s+

Re: Your iPhone just got less secure. Blame the FBI

#30
post #20

I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it. The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in questio…

Sad to see this downvoted, it's as far as I can see absolutely accurate.
Post reply on HN