Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

221–230 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#221
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

One of the "knock it out of the park" features of icloud is that it lets you trivially share photostreams (It's the one service that I've found close to flawless) - so all those shared pictures are still available to the family who you shared them with should you pass away. I certainly don't know if Apple should, without a court order, share any of my data that I haven't explicitly shared with next of kin if I passed…

They do require a court order, reportedly.

The problem with requiring explicit sharing is that a lot of people don't realize they need to do it to properly navigate these future events. Just look at how many people fail to write wills. You wouldn't want real-world assets to automatically get destroyed because you failed to write a will, even though there may be some things in there you didn't want to pass down. The "failsafe" mechanism there is, a court figures it out. So that's apparently what Apple is doing.

But keep in mind this is not just about next-of-kin. It's also about the ability for you to recover your life if you forget your password. That is why Apple will always have a "backdoor" into iCloud.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#222

Earlier quoted context omitted.

> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

There's a reason Google decided to encrypt all communication between machines inside their datacenters.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#223

Earlier quoted context omitted.

You seem to make the assumption that corrupting the secure enclave firmware is easy, or that its RAM is exposed of chip. The entire point of an secure enclave is to completely enclose all the hardware and software needed to generate encryption keys in a single lump of silicon. This means that all of its processing requirements (it's a complete co-processor) are on chip, it's RAM is on chip (not shared with it the mai…

I don't make that assumption, I worked on developing TPM modules myself in the 90s at research labs, and our prototypes had even more anti-tampering than so far revealed about Secure Enclave/Trustzone: we had micro-wire-meshes in the packaging to self-destruct on drilling or decapping, we had anti-ultrasonic and anti-TEMPEST shielding. I'm pretty familiar. The point is that state actors have vast resources to pull of…

> If the NSA really wanted to crack the Secure Enclave, I have very little doubt about their ability to carry it out.

Well they certainly really want to crack the Secure Enclave, so maybe this case is moot.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#224
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

Does Apple owning the iCloud data center have an impact?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#225
post #79

Earlier quoted context omitted.

> "Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer." You get plenty of tries to perfect the technique, before using it on the actual device. You acquire identical hardware and "dead finger countermeasures" (does the iphone employ any? Some readers look for pu…

There's also a 48 hour window and touch ID doesn't work initially after booting. https://support.apple.com/en-us/HT204587 Great design.

Not only the amount of work, technology and thought that have gone into this, but also how well this has been implemented is mind-blowing.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#226
post #21

This is excellent, but unfortunately it will not protect any data on the millions of iPhones that already exist.

It would be a huge middle finger for Apple to design this new iPhone as a free upgrade for all current iPhone users. With their cash reserve, it would be a huge PR spin.

There are however those pesky share holders to keep happy.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#227
post #122
post #62

Earlier quoted context omitted.

> Touch ID isn't re-enabled until the phone's passcode is used. Do the docs confirm that there is no way around this? I'd guess generating the encryption key requires the passcode, which is discarded immediately, and Touch ID can only "unlock" a temporarily re-encrypted version which never leaves ephemeral storage?

From the iOS Security Guide - How Touch ID unlocks an iOS device; If Touch ID is turned off, when a device locks, the keys for Data Protection class Complete, which are held in the Secure Enclave, are discarded. The files and keychain items in that class are inaccessible until the user unlocks the device by entering his or her passcode. With Touch ID turned on, the keys are not discarded when the device locks; instea…

[deleted]

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#228
post #139

A lot of the comments on that article burn me up. People in the U.S. really think there's a terrorism problem here. The only problem is that government spending so much money on a non-issue! Politicians love to "debate" it because they know it is one of those things that looks good to the naive citizens but they really don't have to do anything because there's nothing to be done.

What really burns me is that this strategy is so well known. 1984 was written almost 70 years ago, and yet we have millions of people begging for persistent, unavoidable surveillance by authorities as part of a never-ending war with an ambiguous enemy that our own policies are strengthening.

Referencing 1984 is childish in this context, we're talking about obtaining a warrant for known suspects or already convicted persons. The enemy isn't ambiguous, you're purposely muddying their image.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#229

Earlier quoted context omitted.

> getting a John Yoo to write an executive memo The memos didn't provide de iure indemnity. There is no constitutional basis, in fact the proposition that a memo can supersede the Constitution is idiotic on its face. The failure is the de facto doctrine of absolute executive immunity. It has two prongs: 1. "When the president does it, that means that it is not illegal." 2. When the perpetrator follows president's ord…

The memos didn't provide de iure indemnity. There is no constitutional basis, in fact the proposition that a memo can supersede the Constitution is idiotic on its face. Yes, and that's what I meant by "let the courts sort it out later." The Constitution's not much help either way, being full of imprecise, hand-waving language and vague terms like "cruel and unusual." It was anticipated by the Constitution's authors t…

I would disagree. The Constitution is a bulwark against tyranny. The US have successfully prosecuted waterboarding in the past.

It usually only happens when the rule of law is suspended and then resumed. You're a young country, so maybe it hasn't happened before. Robert H. Jackson was an American, though ;-)

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#230

Earlier quoted context omitted.

As I understand it, Secure Enclave firmware is just a signed blob of code on main flash storage that's updated along with the rest of iOS, which can be done via DFU without pin entry. I assume DFU updates are very low level, with no knowledge of the Secure Enclave or ability to prompt the user to enter their pin. Making the DFU update path more complex increases the risk of bugs and thus the risk of permanently brick…

Let us direct our attention to the superhero Mike Ash and his latest post on secure enclave. https://www.mikeash.com/pyblog/friday-qa-2016-02-19-what-is-... Honestly, this is really the shit..

Yeah, the key question is how Secure Enclave firmware updates work, and whether they can be prevented without pin entry. One former Apple security engineer thinks they are not subject to pin entry: https://twitter.com/JohnHedge/status/699892550832762880
Post reply on HN