Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

261–270 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#261
post #210
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

> The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. Q: Can't I already encrypt my iCloud data via a keychain?

Quite the opposite: your keychain is stored as part of your iCloud data.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#262

Earlier quoted context omitted.

I actually intend for my private data to die with me. I have gone out of my way to guarantee that it will. In my view, if I haven't published it, then it shouldn't be accessible. I have absolutely nothing to hide. I have simply always treated my privacy as something that was valuable in it of itself. Perhaps even more valuable than the photos I clearly opted to not share with others, to go off your example. I also do…

Since you're responding to me I'm assuming you mean me, but I have no problem conceptualizing non-malicious things you would want to keep private. The problem here is that a lot of the stuff stored on phones falls somewhere between "dies with me" private and "should pass on to my family" private. Or "should be recoverable if I lose my key" private. Strong encryption makes it impossible to recover in the event of a lo…

That's what a last will is for: "...and the passphrase for my inheritable private stuff is 12345; it's the file named Blah.xyzzy.foo on my desktop, decryptable using BazBarFoo (installed)."

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#264
post #225

Earlier quoted context omitted.

There's also a 48 hour window and touch ID doesn't work initially after booting. https://support.apple.com/en-us/HT204587 Great design.

Not only the amount of work, technology and thought that have gone into this, but also how well this has been implemented is mind-blowing.

It really shows the staggering difference between having a Samsung phone with fingerprint security versus an iPhone.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#265
post #252

Earlier quoted context omitted.

I don't understand the whole debate about Apple security: - Apple is required to have backdoors, at least on iPhones sold in foreign countries, isn't it? - Even if the SE were completely secure, a rogue update of iOS could intercept the fingerprint or passcode whenever it is typed, and replay it to unlock the SE when spies ask for it. As far as I know, the on-screen keyboard is controlled by software which isn't in t…

Apple is not required by any country to have a backdoor and I am not aware of any agreement from Apple to install such a back door for anyone

[deleted]

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#266
post #49

Earlier quoted context omitted.

A couple issues: * Decapping and feature extraction even from simpler devices is error prone; you can destroy the device in the process. You only get one bite at the apple; you can't "image" the hardware and restore it later. Since the government is always targeting one specific phone, this is a real problem. * There's no one byte you can write to bypass all the security on an iPhone, because (barring some unknown re…

No, the chief protection against the PIN code hacking comes from the retry counter. The FBI doesn't need the crypto keys, it just needs the PIN code. So it needs to brute force about 10,000 PIN codes. Any mechanism that prevents the application processor from either a) remembering it incremented the count b) corrupts the count or c) patches the logic that handles a retry count of 10, is sufficient to attack the phone…

Small nit but probably more like 1000000 codes since apple moved to 6-digit pins.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#267

Earlier quoted context omitted.

Referencing 1984 is childish in this context, we're talking about obtaining a warrant for known suspects or already convicted persons. The enemy isn't ambiguous, you're purposely muddying their image.

I believe the GP was making a generality and not talking about just this specific scenario. "Terrorism" is an ambiguous enemy and while the number of deaths to terrorism is disheartening, it pales in comparison to many other problems (e.g. car accidents or heart disease).

Let's not forget that because terrorism is ambiguous, our own government can create mock attacks and blame them on 3rd parties. Furthering their own agendas. Invoking fear and loathing in the citizens.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#268
post #234

"Impossible for security agency to hack" Nothing is 100% proof, crypto certainly isn't. It's going from child's play to "you actually need to knowledge" to "this is actually hard now" (but.. not impossible).

Perhaps "infeasible" is a better word: "possible, but it would take about 300 years."

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#270
post #123

Earlier quoted context omitted.

I'm speaking the case of the San Bernardino killers. Using strong alphanumeric pass phrases are anti-usability, the vast majority of people won't use them. Hell, the vast majority of people don't even have strong alphanumeric passwords on desktop services. So it falls to either 2-factor or biometric to avoid PINs. Biometric of course has it's own problems. Perhaps people should really carry around a Secure Enclave on…

You only need the strong alphanumeric pass phrases on device startup, then you can use TouchID. I bought an iPhone 6 for exactly this reason (employer required strong passphrase, was too annoying to type in on the Android device I had at the time).

In a way, that's even worse. You're more likely to forget a complicated passphrase when you only have to type it in very seldomly.
Post reply on HN