Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

201–210 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#201
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring.

iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore to a new device), and it would significantly complicate iCloud password changes. I'm sure they are working on it, but it is nontrivial.

That (software) problem is the real reason 99% of users are still exposed, as you say the hardware and secure enclave holes are basically closed.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#202
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

One of the "knock it out of the park" features of icloud is that it lets you trivially share photostreams (It's the one service that I've found close to flawless) - so all those shared pictures are still available to the family who you shared them with should you pass away.

I certainly don't know if Apple should, without a court order, share any of my data that I haven't explicitly shared with next of kin if I passed away.

I'm wondering though - what happens if I stop paying my $2.99/month for 200 GB - will any of my existing photos be wiped out of shared photostreams?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#203
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

It's not 99%; adoption of iCloud backups is not nearly that high.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#204

Earlier quoted context omitted.

Can the SE be updated on a locked phone? Because Apple's docs give the impression that it can't.

The only statement I could find from Apple was from the iOS security guide that states, "it utilizes its own secure boot and personalized software update separate from the application processor." I think we can both agree that's a pretty vague statement, if you have a better source I'd like to see it.

A former Apple engineer said on Twitter:

"@AriX I have no clue where they got the idea that changing SPE firmware will destroy keys. SPE FW is just a signed blob on iOS System Part"

https://twitter.com/johnhedge/status/699882614212075520

Then Apple seems to confirm it:

"The executives — speaking on background — also explicitly stated that what the FBI is asking for — for it to create a piece of software that allows a brute force password crack to be performed — would also work on newer iPhones with its Secure Enclave chip"

http://techcrunch.com/2016/02/19/apple-executives-say-new-ip...

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#205

A lot of the comments on that article burn me up. People in the U.S. really think there's a terrorism problem here. The only problem is that government spending so much money on a non-issue! Politicians love to "debate" it because they know it is one of those things that looks good to the naive citizens but they really don't have to do anything because there's nothing to be done.

Indeed. Even Bernie doesn't make this point (or at least, I haven't heard him make it). To stand up and say, "Actually, terrorism isn't a big threat to the US, especially compared to ..." would be political suicide. Why? Because terrorism isn't about any real threat, it's about hurt pride, outrage at being vulnerable, outrage at being hated, and underlying it all a cultural animosity that ranges from dispassionate concern to visceral hatred. American's are very much doers and they want to "win the war on terror". Which of course is stupid since terrorism has always been around, and will always be around. (And in another twist of irony I am positive that the American Revolutionaries were called terrorists by the British.)

Anyway, a rational politician would have a tremendous uphill battle against both Pride and Ignorance. He or she would have to have tremendous skill as a teacher and a leader, not to mention the emotional fortitude of a Buddha to endure the onslaught of hatred.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#206
post #203

Earlier quoted context omitted.

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

It's not 99%; adoption of iCloud backups is not nearly that high.

Uhh, well it's probably pretty high. Considering their adoption rate for new software is sitting somewhere around 95%. iCloud backups default to on - just like automatic updates - when the user sets up their phone. Not to mention most Geniuses would ask to turn on iCloud backup when upgrading the device for convenience.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#207
post #66
post #20

Earlier quoted context omitted.

Probably not. If you're dead, they probably have your fingers. If you're alive, they can compel you to unlock the device with your fingerprint. The only point I'm making is that Apple already designed a cryptosystem that resists court-ordered coercion: as long as your passcode is strong (and Apple has allowed it to be strong for a long time), the phone is prohibitively difficult to unlock even if Apple cuts a special…

Using a strong pin is pretty annoying, and a relatively visible signal when using the phone on the street etc, So it can be a good filter(maybe via street cams) to filter suspicious people - which isn't a bad goal for law enforcement.

Nobody cares that you're using an alphanumeric passcode on your iPhone.

Some corps require or strongly encourage it. My employer does.

And most parents I know use alphanumeric to keep their kids from wiping their phones and iPads just by tapping the numbers. (A four digit number code auto-submits on the 4th tap, so all it takes is 40 toddler taps. An alphanumeric code can be any length and won't submit unless the actual submit button is tapped.)

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#208
post #118

Earlier quoted context omitted.

They're not anywhere near 99% of the way there; they've destroyed the heterogeneous decentralized ecosystem that broad security requires. Locking themselves out of the Secure Enclave isn't anywhere near sufficient. As long as the device software and trust mechanisms are totally opaque and centrally controlled by Apple, the whole thing is just a facade. There's almost nothing Apple can't push to the phone, and the aud…

I think from the context it's pretty clear that "hack" in this case is referring to "being forced to unlock". Yes, they could still deliberately break encryption for future OSes and phones, but the same could be said of any software, open or closed source. I don't think acting like an open ecosystem is the be-all and end-all of security is productive. Most organizations (let alone individuals) don't have the resource…

> don't have the resources to vet every line in every piece of software they run

For the same reason I do not independently vet every line of source code I run, but still reasonably trust my system magnitudes more than anyone could - and I argue, nobody can - trust proprietary systems. And that is because while I personally may not take initiative to inspect my sources, I know many other people will, and that if I were suspicious of anything I could investigate.

Bugs like Heartbleed just demonstrated... well, several things:

1. Software written in C is often incredibly unsafe and dangerous, even when you think you know what you are doing. 2. Implementing hard problems is not the whole story, because you also need people who comprehend said problems, the sources implementing them, and have reason to do so in the first place.

Which I guess relates back to C in many ways.

I look forward to Crypto implemented in Rust and other memory / concurrency / resource safe languages. There is always a surface vector of a mistake being made that can compromise any level of security - if you move the complexity into the programming language the burden falls on your compiler. But in the same way you can only trust auditable in production heavily used sources, nothing is going to be more heavily used and scrutinized, at least by those interested, than languages themselves.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#209

Earlier quoted context omitted.

> They pulled the same stuff in the past where FBI talked about how they couldn't beat iPhones but NSA had them in the leaks & was parallel constructing to FBI. Do you have a link to a leak that shows this? I couldn't find anything with a simple google search.

It was in the leak on mobile OS's. They not only found iPhone vulnerable but mocked their users.

Could you be more specific? I've followed the NSA leaks with some interest, but not particularly closely, so I'd be really interested in seeing the actual presentation/document/whatever.

For reference I've googled every combination of "nsa apple mobile OS leak" I could think of and couldn't find a primary source.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#210
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

> The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments.

Q: Can't I already encrypt my iCloud data via a keychain?

Post reply on HN