Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

271–280 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#271
If Congress does pass such laws, I would love it if Apple considered security so important to it's product vision that they'd be willing to use their cash reserves to restructure the company and engineering and moving it's security engineering to a country that pledges never to force it to compromise on security. Apple is no stranger to keeping internal secrets and keeping concerns isolated. I have no doubt that they could find a way to guarantee security. IMHO governments are security bugs to be patched.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#272
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

There's an easy way Apple could offer a true cryptographically secure cloud backup service - support local backups with a physical keystore. Make it an advanced option but use it as an excuse to sell users a Time Machine backup unit with RFID built in to read a security key.

Apple could make truly secure systems user friendly if they wanted to. It seems they may see some value in doing so.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#273
post #252
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

I don't understand the whole debate about Apple security: - Apple is required to have backdoors, at least on iPhones sold in foreign countries, isn't it? - Even if the SE were completely secure, a rogue update of iOS could intercept the fingerprint or passcode whenever it is typed, and replay it to unlock the SE when spies ask for it. As far as I know, the on-screen keyboard is controlled by software which isn't in t…

If the person knowing the passcode is around and you can fool them into using their passcode then yes, you could capture their passcode. Touch ID is even less of a problem because taking someone's fingerprints is a lot easier than taking a passcode out of their head.

But in both those situations the weakness is in the person, not the device. Apple devices still potentially have security weaknesses which the FBI is asking Apple to exploit for them. Apple wants to fix these weaknesses, to stop Apple being forced to exploit them.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#275
post #26

Earlier quoted context omitted.

If they have access to a live finger for the TouchID, sure they can bypass - but they could do that with the $5 guaranteed coercion method as well [1]. Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer. All bets are off if the iPhone is power-cycled. Best bet i…

It is not a good bet if you're pulled over by the authorities to be doing something with your hands that they can't reliably identify as different from preparing a weapon. Particularly if not white.

This would prevent people from recording police abuse ...

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#276

Earlier quoted context omitted.

> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

Well you can make an encrypted Backup via iTunes (that would involve firing up iTunes though shudders)

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#277
post #222

Earlier quoted context omitted.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

There's a reason Google decided to encrypt all communication between machines inside their datacenters.

Are you sure it's not just communication between data centres?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#278
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

Naive quedtion perhaps, bit why wouldn't they be able to employ the same hardware on icloud than on the phone?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#279

Hmmm... this absolutest attitude by Apple begs the question for me, are we SURE we want to have phones that absolutely cannot be unlocked when the owner is no where to be found/dead? It's such a grey area and I will probably get down voted for commenting this way. I 100% agree that the power, in the wrong hands, is horrible, but can't we talk about this in a way where there's some kind of middle ground? All I've been…

If I die I don't want anyone accessing my phone.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#280
post #123

Earlier quoted context omitted.

You only need the strong alphanumeric pass phrases on device startup, then you can use TouchID. I bought an iPhone 6 for exactly this reason (employer required strong passphrase, was too annoying to type in on the Android device I had at the time).

In a way, that's even worse. You're more likely to forget a complicated passphrase when you only have to type it in very seldomly.

You have to enter it every 48 hours.
Post reply on HN