Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

231–240 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#231

Earlier quoted context omitted.

2

Well, before you finalize your guess, I'll give you a hint: it's either 2, or 437. It's not any other number. Keep in mind I made my choice before we started, and it hasn't changed. Do you want to change your guess to 437, or stick with 2?

This is a nice reinterpretation.

Re: Your iPhone just got less secure. Blame the FBI

#232
post #45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

a "renowned security researcher" or a "renowned academic cryptographer"?

Re: Your iPhone just got less secure. Blame the FBI

#233
post #218

Earlier quoted context omitted.

I don't think labor should be forced, but data should be accessible. Apple had the keys to use the backdoor, and they should have been forced to choose between using them to sign software, or handing them over and letting the FBI sign it themselves. Apple would prefer to sign it themselves, so they can effectively be forced to do so. I disagree that they can force the inclusion of a backdoor using the same logic. The…

> ...but data should be accessible. This is the most important part of the whole thing. Where do you draw the line, is everybody legally obligated to comply with such demands? Well obviously those directly involved with whatever crime is being investigated are exposed to such compulsion, but so are third party service providers. But in the case of these third parties, there are a lot of laws dictating their part in g…

>Where do you draw the line, is everybody legally obligated to comply with such demands?

If I have a warrent, I can force you to hand over all information allowed by the warrent. That's how warrents work.

They're able to get any data a judge agrees with.

I don't think they're able to compel labor.

>How about compelling every luckless individual who lives along the subject's morning commute to turn over all video and image files because it might help them in their investigation.

If a judge thinks there's probable cause, they can require this, so far as I know.

>You can't believe both of those, because compulsion eliminates choice.

They have the ability to compel Apple to hand over data. They don't have the ability to compel Apple to perform labor unrelated to producing data.

>No, they want on demand access - they don't care about any key.

The FBI explicitly asked for the key at one point in the case.

Could you explain how your commerce example is in any way precedent?

Re: Your iPhone just got less secure. Blame the FBI

#234

Earlier quoted context omitted.

It wouldn't set a legal precedent unless a court ruled on it. It would only have come to that if Apple continued to decline the FBI's request.

Again, victim blaming. How is that any different from the false choice "We can do this the hard way, or the easy way"? Have you considered what will happen to the number of such requests as devices continue to become more secure?

That's not blaming anyone. It's objectively the circumstance under which a precedent would be created. My understanding of your point was that Apple shouldn't comply in this case because it would set precedent. My point is that choosing to comply was actually one of the ways they could've avoided setting precedent.

Re: Your iPhone just got less secure. Blame the FBI

#235

Earlier quoted context omitted.

2

Well, before you finalize your guess, I'll give you a hint: it's either 2, or 437. It's not any other number. Keep in mind I made my choice before we started, and it hasn't changed. Do you want to change your guess to 437, or stick with 2?

I've always flip-flopped on grasping the Monty Hall thing (sometimes I'd think I understand, other times not so much)... but this little guessing game really clarified it for me, once and for all. Thanks!

Re: Your iPhone just got less secure. Blame the FBI

#236
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. The problem here is that we're all just speculating. We suspect this to be the case, but we can't be sure. And we probably never will be. To take this a step further, the FBI has also learned the lesson to never take this public again. If you are worried about law enforcement attacks against any device protected by…

Dont forget Genode project https://genode.org/ and Crash safe http://www.crash-safe.org/

Re: Your iPhone just got less secure. Blame the FBI

#237
post #233

Earlier quoted context omitted.

> ...but data should be accessible. This is the most important part of the whole thing. Where do you draw the line, is everybody legally obligated to comply with such demands? Well obviously those directly involved with whatever crime is being investigated are exposed to such compulsion, but so are third party service providers. But in the case of these third parties, there are a lot of laws dictating their part in g…

>Where do you draw the line, is everybody legally obligated to comply with such demands? If I have a warrent, I can force you to hand over all information allowed by the warrent. That's how warrents work. They're able to get any data a judge agrees with. I don't think they're able to compel labor. >How about compelling every luckless individual who lives along the subject's morning commute to turn over all video and…

> If I have a warrent...

> If a judge thinks there's probable cause...

> They have the ability to compel Apple to hand over data.

Warrants aren't golden tickets, if a warrant exceeds the court's authority then it isn't worth anything. That is exactly what was going to be resolved here, a court ordered Apple to do something that Apple thought exceeded the state's authority - thanks to the FBI the question remain unresolved (which the DOJ prefers to a precedent going against them).

> I don't think they're able to compel labor.

Subpoena to appear immediately comes to mind, NSLs might reach that level as well - they certainly exceed "hand over data". But the point isn't really about court orders during discovery, it is the final interpretation of an existing law that will determine the nature of forced labor. There are plenty of laws that compel labor.

> The FBI explicitly asked for the key at one point in the case.

No, they presented it as an alternative after they met resistance (aka threatened).

> Could you explain how your commerce example is in any way precedent?

"historical precedent" (an example, a demonstration of disposition), not a legal precedent. I'm disappointed that you focused on that and overlooked the point - the use of "precrimes", "potential" and "clipper chip" is the hint.

Re: Your iPhone just got less secure. Blame the FBI

#238
post #230

Earlier quoted context omitted.

It just seems like federal folks working on security are currently outgunned by the federal folks working on access. For example where were the pro-security quotes from NIST in all the FBI-Apple stories? I'm sort of kidding--obviously there weren't any--but the reality is that NIST can't stand up to the FBI and that's not their role anyway. They set standards not executive priorities. If we think of the federal govt…

> It just seems like federal folks working on security are currently outgunned by the federal folks working on access. I'm not the least bit happy about this, but it's been that way for the entirety of the computer age -- it's not a new development.

I agree. But I think that as computing makes its way into more and more of our lives, it becomes less and less excusable.

Re: Your iPhone just got less secure. Blame the FBI

#239

Earlier quoted context omitted.

Again, victim blaming. How is that any different from the false choice "We can do this the hard way, or the easy way"? Have you considered what will happen to the number of such requests as devices continue to become more secure?

That's not blaming anyone. It's objectively the circumstance under which a precedent would be created. My understanding of your point was that Apple shouldn't comply in this case because it would set precedent. My point is that choosing to comply was actually one of the ways they could've avoided setting precedent.

> It would only have come to that if Apple continued to decline the FBI's request.

> That's not blaming anyone.

I guess I misunderstood you because you left out the other potential scenarios, like instead of "Apple continued" the "FBI ceased" - or the "DOJ never attempted to compel Apple under the All Writs act in the first place". Apple had no control over the situation outside appeasing the FBI, the state controlled every other aspect.

> My understanding of your point...

You think it wouldn't come up further down the road as the FBI demands more and more, after they've already built the tools to meet prior demands?

Re: Your iPhone just got less secure. Blame the FBI

#240
post #219

Earlier quoted context omitted.

This is a great point. Cellebrite's known for their black box approach. Law enforcements and Courts can send their locked iPhone and get it back unlocked. They'll just get the job done without knowing what was actually performed on the phone. This might as well be the case here.

Doesn't this approach cast doubt on the legitimacy of any evidence obtained from the device?

Don't think so, it's basically like lock picking a suspect's apartment with a warrant. What is found should be valid evidence, no? Law enforcement can break the door or call a locksmith and pay him for his service. In this case Cellebrite's the locksmith.
Post reply on HN