Live data from Hacker News

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

404media.co

271–280 of 565 posts

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#271
post #4

[flagged]

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

Assuming the rule of law is still functioning, there are multiple protections for journalists who refuse to divulge passwords in the USA. A journalist can challenge any such order in court and usually won't be detained during the process as long as they show up in court when required and haven't tried to destroy evidence.

Deceiving investigators by using an alternate password, or destroying evidence by using a duress code on the other hand is almost always a felony. It's a very bad idea for a journalist to do that, as long as the rule of law is intact.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#272

Earlier quoted context omitted.

That's not what we're discussing here, you can't just say "I plead the fifth" and walk away if the people in charge decided you wouldn't walk away, no matter what's right or "legal" Francis Rawls stayed 4 years in jail despite pleading the fifth all day long

That case also established 18 months as an upper limit. If you are in that situation it is usually better to simply jot divulge. Especially if there is incriminating evidence. Or you are a journalist being harassed by the DOJ. It can only bring you more pain. They will always find something.

Yeah well that's what I'm saying... "just plead the fifth" is nice on paper, in practice you're going to suffer for a long time.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#273

Earlier quoted context omitted.

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

“Plausible deniability” is a public relations concept. It doesn’t confer any actual legal protection.

It absolutely offers some legal protection. If it is implemented correctly, no legal framework for it is required. Government forces you to enter your password. You comply and enter "a" password. The device shows contents. You did what you were asked to do. If there is no way for the government to prove that you entered a decoy password that shows decoy contents, you are in the clear. Done correctly (in device and OPSEC) government can't prove you entered your decoy password so you can't be held in contempt. And that is the entire point. It is not like asking the government to give your "plausible deniability" rights. It is about not potentially incriminating yourself against people that abuse the system to force you to incriminate yourself.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#274
post #142
post #7

> Natanson said she does not use biometrics for her devices, but after investigators told her to try, “when she applied her index finger to the fingerprint reader, the laptop unlocked.” Curious.

Why is this curious?

There appear to be a relatively few possibilities.

* The reporter lied.

* The reporter forgot.

* Apple devices share fingerprint matching details and another device had her details (this is supposed to be impossible, and I have no reason to believe it isn't).

* The government hacked the computer such that it would unlock this way (probably impossible as well).

* The fingerprint security is much worse than years of evidence suggests.

Mainly it was buried at the very end of the article, and I thought it worth mentioning here in case people missed it.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#275
post #4

[flagged]

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

Even if this worked (which would be massively expensive to implement) the misconfiguration possibilities are endless. It wouldn't be customer-centric to actually release this capability.

Better for the foreseeable future to have separate devices and separate accounts (i.e. not in the same iCloud family for instance)

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#276

It seems unfortunate that enhanced protection against physically attached devices requires enabling a mode that is much broader, and sounds like it has a noticeable impact on device functionality. I never attach my iPhone to anything that's not a power source. I would totally enable an "enhanced protection for external accessories" mode. But I'm not going to enable a general "Lockdown mode" that Apple tells me means…

> I would totally enable an "enhanced protection for external accessories" mode.

Anyone can do this for over a decade now, and it's fairly straightforward:

- 2014: https://www.zdziarski.com/blog/?p=2589

- recent: https://reincubate.com/support/how-to/pair-lock-supervise-ip...

This goes beyond the "wired accessories" toggle.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#277
post #4

[flagged]

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

There is no plausible deniability here, that's only relevant in a rule-of-law type of situation, but then you wouldn't need it as you can't be legally compelled to do that anyway. "We don't see any secret source communication on your work device = you entered the wrong pin = go think about what your behavior in jail"

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#278
post #257
post #225

Earlier quoted context omitted.

Not sure if you know the history behind it, but look up Paul Le Roux Also would recommend the book called The Mastermind by Evan Ratliff

imo Paul Le Roux has nothing to do with TrueCrypt

He wrote the code base that it is based on in combination with code he stole. The name is also based on an early name he chose for the software.

Whether he was involved in the organization and participated in it, is certainly up for debate, but it's not like he would admit it.

https://en.wikipedia.org/wiki/E4M

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#279
post #119

Earlier quoted context omitted.

Fourth and Fifth amendments disagree

People are jailed for contempt of court for failing to provide passwords. https://reason.com/2017/05/31/florida-man-jailed-180-days-fo...

Wow, so US judges are just making it up as they go along, huh? It's like every case is a different judgement with no consistent criterion.

>Doe vs. U.S. That case centered around whether the feds could force a suspect to sign consent forms permitting foreign banks to produce any account records that he may have. In Doe, the justices ruled that the government did have that power, since the forms did not require the defendant to confirm or deny the presence of the records.

Well, what if the defendant was innocent of that charge but guilty of or involved in an unrelated matter for which there was evidence in the account records?

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#280

Sadly, they still got to her Signal on her Desktop – her sources might still be compromised. It's sadly inherent to desktop applications, but I'm sad that a lot more people don't know that Signal for Desktop is much, much less secure against adversaries with your laptop.

If people don't have Signal set to delete sensitive messages quickly, then they may as well just be texting.

That's a strong statement. Also imho it's important that we use Signal for normal stuff like discussing where to get coffee tomorrow - no need for disappearing messages there.
Post reply on HN