Earlier quoted context omitted.
We do not even know if the FBI knows the vulnerability. The phone could have been attacked by a contractor working for the FBI without the contractor sharing the tools.
This is a great point. Cellebrite's known for their black box approach. Law enforcements and Courts can send their locked iPhone and get it back unlocked. They'll just get the job done without knowing what was actually performed on the phone. This might as well be the case here.
Your iPhone just got less secure. Blame the FBI
221–230 of 255 posts
Re: Your iPhone just got less secure. Blame the FBI
#222Earlier quoted context omitted.
We do not even know if the FBI knows the vulnerability. The phone could have been attacked by a contractor working for the FBI without the contractor sharing the tools.
This is a great point. Cellebrite's known for their black box approach. Law enforcements and Courts can send their locked iPhone and get it back unlocked. They'll just get the job done without knowing what was actually performed on the phone. This might as well be the case here.
Re: Your iPhone just got less secure. Blame the FBI
#223Earlier quoted context omitted.
We do not even know if the FBI knows the vulnerability. The phone could have been attacked by a contractor working for the FBI without the contractor sharing the tools.
This is a great point. Cellebrite's known for their black box approach. Law enforcements and Courts can send their locked iPhone and get it back unlocked. They'll just get the job done without knowing what was actually performed on the phone. This might as well be the case here.
Re: Your iPhone just got less secure. Blame the FBI
#224Earlier quoted context omitted.
It seems to me that Tim Cook and the FBI understand each other very well. They just don't care about the same things. Former CIA and NSA Director Michael Hayden clearly understands the issues. I saw an interview where he stated that the FBI was correct to want access (it makes their job easier) and that we shouldn't give it to them (he understands that a backdoor will be used in ways other than intended). The point b…
But I think we could craft a talking point version of this argument that unsubtle busy people could understand. "The FBI is trying to compromise your data security, for the sake of their job security."
Re: Your iPhone just got less secure. Blame the FBI
#225Earlier quoted context omitted.
I don't see why the other door has 99x more probability of being correct. It's still 50/50, original door or remaining door, the other 98 don't change the odds.
Let's play a game to make this more clear. I'm thinking of a number between 1 and 1000. First, guess what it is.
Re: Your iPhone just got less secure. Blame the FBI
#226Earlier quoted context omitted.
I agree with you, and I think this will eventually lead to a world where governments are unable to exert meaningful influence on large corporations. We're already starting to get there; I have a feeling that if the supreme court had forced Apple to write a custom version of iOS that things could have gotten really messy very quickly -- there were rumors that Apple's entire iOS engineering team was ready to resign if…
> Fuck it, we're based in Ireland now Apple has an enormous investment in their design team in Cupertino. It would be an enormous impact to their product development capability to start over somewhere else. It's not enough to say "HQ is over here bro," court orders still work in California. Then again this whole All Writs effort to "build me a tool to help my investigation" seems to break new ground. Maybe it wouldn'…
There are already state level bills proposing this in CA and NY [1]. Those bills would fine manufacturers $2,500 for every phone sold in those states that isn't capable of providing decrypted data. The language originally comes from a white paper by Manhattan DA Cyrus Vance. Feinstein-Burr are working on a similar federal bill which was supposed to be released late last year, then this month [2]. It has obviously been delayed by the public's response to the SB Apple case.
[1] https://www.techdirt.com/articles/20160122/06200833403/calif...
[2] http://www.politico.com/tipsheets/morning-cybersecurity/2016...
Re: Your iPhone just got less secure. Blame the FBI
#227Earlier quoted context omitted.
Let's play a game to make this more clear. I'm thinking of a number between 1 and 1000. First, guess what it is.
2
Keep in mind I made my choice before we started, and it hasn't changed.
Do you want to change your guess to 437, or stick with 2?
Re: Your iPhone just got less secure. Blame the FBI
#228Earlier quoted context omitted.
I find it clearer if you have 100 doors. Pick one. The host eliminates 98 doors [with no prize behind them]. Do you switch? Or do you stick with your original guess? As the parent mentioned, switching gives you a 99/100 chance of being correct, staying gives you a mere 1/100 chance.
I don't see why the other door has 99x more probability of being correct. It's still 50/50, original door or remaining door, the other 98 don't change the odds.
Re: Your iPhone just got less secure. Blame the FBI
#229Earlier quoted context omitted.
> As devices become more secure, Apple will no longer be able to unlock them. That is only true if revoking trust is the only thing left to do to increase iphone security against every potential bad actor. That isn't the case, and that leaves plenty of time to pester Apple with unlocking phones collected in every investigation from now until then. > If you put a backdoor into your phones, you should expect to have to…
I don't think labor should be forced, but data should be accessible. Apple had the keys to use the backdoor, and they should have been forced to choose between using them to sign software, or handing them over and letting the FBI sign it themselves. Apple would prefer to sign it themselves, so they can effectively be forced to do so. I disagree that they can force the inclusion of a backdoor using the same logic. The…
This is the most important part of the whole thing. Where do you draw the line, is everybody legally obligated to comply with such demands? Well obviously those directly involved with whatever crime is being investigated are exposed to such compulsion, but so are third party service providers. But in the case of these third parties, there are a lot of laws dictating their part in great detail. For its part as a service provider, Apple supplied the user data it had. What the FBI has done is declare loud and clear that they'd like to expand those subject to compulsion to include anyone it designates, for any purpose that isn't explicitly illegal, thanks to All Writs. Now in this case they say, for the victims, they're being exhaustive in pursuing what is most likely a dry hole. But what is to stop them from wielding such authority over every manufacturer of everything that the subject of the investigation touched? How about compelling every luckless individual who lives along the subject's morning commute to turn over all video and image files because it might help them in their investigation. For as crazy as that sounds, consider the fact that there is no logical distinction between any of those scenarios.
> I don't think labor should be forced ... they should have been forced to choose...
You can't believe both of those, because compulsion eliminates choice. That would be like saying "I'm not forcing you to run, it is your choice, but if you don't then I'll kill you".
> ...they want from Apple is information, I.e. the key.
No, they want on demand access - they don't care about any key. Even if Apple were to get rid of the key, there is historical precedent for the state pulling some insane precrimes logic in order to expand authority - see the commerce clause. I'll explain that reference briefly: the federal government has explicitly defined authority over commerce that occurs between states, but it was reasoned that commerce within a state could potentially result in the absence of interstate commerce, therefor the federal government has authority over all commerce... Now imagine that reasoning being applied to a manufacturer who doesn't have the capability to, but could if it wanted, respond to a court order. Oh, and lets not forget the clipper chip, a nice indicator of the state's position on forcing manufacturers to backdoor consumer products in the interested of potential investigations.
Re: Your iPhone just got less secure. Blame the FBI
#230Earlier quoted context omitted.
The government isn't a single entity with a single goal. There already exist federal agencies with the goal of increasing security (see http://csrc.nist.gov/groups/ST/toolkit/ ), while others like the FBI have vested interest in increasing their powers of investigation. The executive branch has already made their stance clear, weakening encryption should not be the goal of any federal agency: "We recommend that, rega…
It just seems like federal folks working on security are currently outgunned by the federal folks working on access. For example where were the pro-security quotes from NIST in all the FBI-Apple stories? I'm sort of kidding--obviously there weren't any--but the reality is that NIST can't stand up to the FBI and that's not their role anyway. They set standards not executive priorities. If we think of the federal govt…
I'm not the least bit happy about this, but it's been that way for the entirety of the computer age -- it's not a new development.