Earlier quoted context omitted.
call me a cynic, but I'm not buying "somebody at the county screwed up"
Indeed, "The County was working cooperatively with the FBI when it reset the iCloud password at the FBI's request." https://twitter.com/CountyWire/status/700887823482630144
Apple Is Said to Be Working on an iPhone Even It Can’t Hack
281–290 of 415 posts
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#282Earlier quoted context omitted.
The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…
Naive quedtion perhaps, bit why wouldn't they be able to employ the same hardware on icloud than on the phone?
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#283They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…
>If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? That probably also means removing most debugging connections from the physical chip, and making extra sure you can't modify secure enclave memory even if you desolder the phone.
You decap the chip to expose the die with HF, and then use Focused Ion Beams and a million dollar microscope setup, you can rearrange the circuits. So, if the NSA absolutely had to have the data on the chip they could modify it to make it sing. So, if say they know an iPhone had the location of Bin Laden on it, they could get the goods without Apple.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#284This is one of those moments I wish Jobs was still here. Had he lost to the DOJ, here is what would (might) have happened: - he would gladly unlocked this phone and bill DOJ for the time spent on redesigning IOS - going forward, he would label each phone's box in red letters: CONTAINS GOVERNMENT-REQUIRED BACKDOOR (I doubt Gov can forbid him from doing that) - he would then stop selling devices in Apple stores directl…
And then Jobs would find himself for a long long prison term after the DOJ decides to go full power with him for something otherwise unrelated or small. You commit a lot of federal offenses by just existing in the USA. Or every other country. There is always something that they can nail you for.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#285Earlier quoted context omitted.
You only need the strong alphanumeric pass phrases on device startup, then you can use TouchID. I bought an iPhone 6 for exactly this reason (employer required strong passphrase, was too annoying to type in on the Android device I had at the time).
In a way, that's even worse. You're more likely to forget a complicated passphrase when you only have to type it in very seldomly.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#286They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…
The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#287Earlier quoted context omitted.
> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.
If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.
its not trivial, but its sure easy to do in this day and age.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#288Earlier quoted context omitted.
Could you be more specific? I've followed the NSA leaks with some interest, but not particularly closely, so I'd be really interested in seeing the actual presentation/document/whatever. For reference I've googled every combination of "nsa apple mobile OS leak" I could think of and couldn't find a primary source.
I Googled "nsa leak iOS" and found the first one: http://www.spiegel.de/international/world/how-the-nsa-spies-... Helps to type in just what you want and what will specifically have your answer. Mobile will give you garbage most of the time. Apple as well. A technical document will usually reference iOS. Also, you can use quotes to ensure something appears. Interesting enough, me typing what you typed into Google sti…
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#289Earlier quoted context omitted.
The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…
Naive quedtion perhaps, bit why wouldn't they be able to employ the same hardware on icloud than on the phone?
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#290Earlier quoted context omitted.
Since you're responding to me I'm assuming you mean me, but I have no problem conceptualizing non-malicious things you would want to keep private. The problem here is that a lot of the stuff stored on phones falls somewhere between "dies with me" private and "should pass on to my family" private. Or "should be recoverable if I lose my key" private. Strong encryption makes it impossible to recover in the event of a lo…
That's what a last will is for: "...and the passphrase for my inheritable private stuff is 12345; it's the file named Blah.xyzzy.foo on my desktop, decryptable using BazBarFoo (installed)."
It would be better to opt-in to auto-destruct-when-i-die, not opt-out. It's more of a special case. E.g. create encrypted notes for super secret stuff you want to die with you, but let the default security for photos and documents be "private but recoverable in the event of death or forgotten key."
Not to mention, writing that password down in a will would be pretty bad from a security standpoint while you're alive.