Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

211–220 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#211
post #153

Earlier quoted context omitted.

Wiping the phone doesn't help you. Using the strong password renders the information inaccessible, at least as inaccessible as your phone backup is. Touch ID isn't re-enabled until the phone's passcode is used. Presumably if the authorities have access to your phone's memory they also have access to your laptops, and neither will do them any damn good. And it's paranoia if there's a legitimate threat, that's just cal…

Could the "code equivalent" of your fingerprint be stolen by a rogue app if it's allowed to read it? I don't have a touchId phone but have wondered what would happen if your "print" is stolen -- passwords can at least be changed.

Speaking as an App Developer, we cannot touch stuff like that. We're allowed to ask Touch ID to verify things and process the results, but we don't actually get to use the Touch ID system. It's similar to how the shared keychain is used: We can ask iOS to do things, but then must handle any one of many possible answers. We don't actually see your fingerprint in any way.

Now Cydia and 3rd party stuff? I have no clue.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#212
post #131
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

Why would they have made the Secure Enclave allow updates on a locked device without wiping the key in the first place? Either they didn't think it through, assumed they would never be compelled to use it as a backdoor, or perhaps they were afraid some bug could end up having catastrophic consequences of locking a billion people out of their phones with no way to fix it? Do we even know for certain that the Secure En…

As I understand it, Secure Enclave firmware is just a signed blob of code on main flash storage that's updated along with the rest of iOS, which can be done via DFU without pin entry. I assume DFU updates are very low level, with no knowledge of the Secure Enclave or ability to prompt the user to enter their pin.

Making the DFU update path more complex increases the risk of bugs and thus the risk of permanently bricking phones.

You could imagine an alternative where on boot the Secure Enclave runs some code from ROM which checks that a hash of the SE firmware matches a previously signed hash, which is only updated by the Secure Enclave if the user entered their pin during the update. If it doesn't match, either wipe the device or don't boot until the previous firmware is restored.

This way Secure Enclave firmware updates and updates via DFU are still possible, but not together without wiping the device.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#213
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

> Farook disabled the iCloud backup six weeks prior to the attack

http://6abc.com/news/senior-official-stresses-feds-need-to-u...

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#214

A lot of the comments on that article burn me up. People in the U.S. really think there's a terrorism problem here. The only problem is that government spending so much money on a non-issue! Politicians love to "debate" it because they know it is one of those things that looks good to the naive citizens but they really don't have to do anything because there's nothing to be done.

Indeed. Even Bernie doesn't make this point (or at least, I haven't heard him make it). To stand up and say, "Actually, terrorism isn't a big threat to the US, especially compared to ..." would be political suicide. Why? Because terrorism isn't about any real threat, it's about hurt pride, outrage at being vulnerable, outrage at being hated, and underlying it all a cultural animosity that ranges from dispassionate co…

> Even Bernie doesn't make this point (or at least, I haven't heard him make it). To stand up and say, "Actually, terrorism isn't a big threat to the US, especially compared to ..." would be political suicide.

Sanders has expressly argued that climate change is a bigger national security threat than terrorism (or anything else) -- and did so in one the Democratic debates, in response to a question on national security threats. While that may not be directly minimizing terrorism, it certainly is explicitly placing it behind other problems in terms of need for focus.

> (And in another twist of irony I am positive that the American Revolutionaries were called terrorists by the British.)

They absolutely were not; the term "terrorists" was first applied to the leaders of the regime of the Reign of Terror in the French Revolution (shortly after the American Revolution), and it was quite a long time after that before the term was applied to actors other than state leaders applying terror as a weapon to control their subject population.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#215

Earlier quoted context omitted.

It was in the leak on mobile OS's. They not only found iPhone vulnerable but mocked their users.

Could you be more specific? I've followed the NSA leaks with some interest, but not particularly closely, so I'd be really interested in seeing the actual presentation/document/whatever. For reference I've googled every combination of "nsa apple mobile OS leak" I could think of and couldn't find a primary source.

I Googled "nsa leak iOS" and found the first one:

http://www.spiegel.de/international/world/how-the-nsa-spies-...

Helps to type in just what you want and what will specifically have your answer. Mobile will give you garbage most of the time. Apple as well. A technical document will usually reference iOS. Also, you can use quotes to ensure something appears.

Interesting enough, me typing what you typed into Google still led to same leak and others showing potential backdoors. Hmmm.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#216
post #131

Earlier quoted context omitted.

Why would they have made the Secure Enclave allow updates on a locked device without wiping the key in the first place? Either they didn't think it through, assumed they would never be compelled to use it as a backdoor, or perhaps they were afraid some bug could end up having catastrophic consequences of locking a billion people out of their phones with no way to fix it? Do we even know for certain that the Secure En…

As I understand it, Secure Enclave firmware is just a signed blob of code on main flash storage that's updated along with the rest of iOS, which can be done via DFU without pin entry. I assume DFU updates are very low level, with no knowledge of the Secure Enclave or ability to prompt the user to enter their pin. Making the DFU update path more complex increases the risk of bugs and thus the risk of permanently brick…

Let us direct our attention to the superhero Mike Ash and his latest post on secure enclave. https://www.mikeash.com/pyblog/friday-qa-2016-02-19-what-is-...

Honestly, this is really the shit..

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#217
post #210
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

> The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. Q: Can't I already encrypt my iCloud data via a keychain?

I'm not exactly sure what you mean. iCloud data is reportedly encrypted at rest. The issue is that Apple has the decryption key. And they keep it in order to recover you from a lost password event, so that is likely to always be true forever.

Having said that, you can add another layer of your own encryption to certain data that is stored in iCloud, like for example the latest Notes app in iOS 9.3. Apple won't have that key.. but the app warns you the data will be lost if you lose it. You could also encrypt files you store in iCloud Drive using an encryption app. But you wouldn't be able to do this with other data that is managed by iOS like iCloud backups or photo libraries.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#218

Earlier quoted context omitted.

I actually intend for my private data to die with me. I have gone out of my way to guarantee that it will. In my view, if I haven't published it, then it shouldn't be accessible. I have absolutely nothing to hide. I have simply always treated my privacy as something that was valuable in it of itself. Perhaps even more valuable than the photos I clearly opted to not share with others, to go off your example. I also do…

Since you're responding to me I'm assuming you mean me, but I have no problem conceptualizing non-malicious things you would want to keep private. The problem here is that a lot of the stuff stored on phones falls somewhere between "dies with me" private and "should pass on to my family" private. Or "should be recoverable if I lose my key" private. Strong encryption makes it impossible to recover in the event of a lo…

Yes, It's different for everyone. I didn't mean to accuse of being one of those people, I was speaking generally there. I'm sorry if my phrasing was bad. My main concern is that people are scared to admit they use the best, because they will be accused of being criminals. The stigma is harmful.

Imagine if somebody is writing down there dreams, writing there intimate deep thoughts, tracking symptoms of a medicine, using drugs recreationally...etc. These things might be very very private and be totally abusable outside of context.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#219
post #206
post #203

Earlier quoted context omitted.

It's not 99%; adoption of iCloud backups is not nearly that high.

Uhh, well it's probably pretty high. Considering their adoption rate for new software is sitting somewhere around 95%. iCloud backups default to on - just like automatic updates - when the user sets up their phone. Not to mention most Geniuses would ask to turn on iCloud backup when upgrading the device for convenience.

Well the specific phone that started this controversy didn't have any iCloud backups, so regardless of the percentage it doesn't pertain here.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#220
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

If the device has a manufacturer's key and the user's key, then it's basically down to simple Boolean logic: does the innermost trusted layer allow something to be installed or altered if it is authorized by the manufacturer's key OR your key? Or the manufacturer's key AND your key? Or just your key? (With a warning if it has no other key?)
Post reply on HN