Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

281–290 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#281
post #254

Earlier quoted context omitted.

call me a cynic, but I'm not buying "somebody at the county screwed up"

Indeed, "The County was working cooperatively with the FBI when it reset the iCloud password at the FBI's request." https://twitter.com/CountyWire/status/700887823482630144

The "screwup" grandparent is suggesting is that the county didn't think to disable the setting that would let employees turn off iCloud backups for their devices, however many months or years ago, not that they've messed up during the investigation now.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#282

Earlier quoted context omitted.

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

Naive quedtion perhaps, bit why wouldn't they be able to employ the same hardware on icloud than on the phone?

It can be the same hardware but I believe that not usually meant with "hardware based encryption". The point is that the private keys never leave the hardware of the phone, thus making it secure. So they could employ the same hardware but the hardware does not have the necessary keys.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#283
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

>If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? That probably also means removing most debugging connections from the physical chip, and making extra sure you can't modify secure enclave memory even if you desolder the phone.

No one has been talking about the fact that you can rebuild transistors on an existing chip. It's very high tech stuff, the sort that Intel uses to repair early engineering samples painstakingly, but it is used.

You decap the chip to expose the die with HF, and then use Focused Ion Beams and a million dollar microscope setup, you can rearrange the circuits. So, if the NSA absolutely had to have the data on the chip they could modify it to make it sing. So, if say they know an iPhone had the location of Bin Laden on it, they could get the goods without Apple.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#284

This is one of those moments I wish Jobs was still here. Had he lost to the DOJ, here is what would (might) have happened: - he would gladly unlocked this phone and bill DOJ for the time spent on redesigning IOS - going forward, he would label each phone's box in red letters: CONTAINS GOVERNMENT-REQUIRED BACKDOOR (I doubt Gov can forbid him from doing that) - he would then stop selling devices in Apple stores directl…

And then Jobs would find himself for a long long prison term after the DOJ decides to go full power with him for something otherwise unrelated or small. You commit a lot of federal offenses by just existing in the USA. Or every other country. There is always something that they can nail you for.

This is quite horrible but, if his diagnosis had come after such a middle finger... I wonder if he would care.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#285
post #123

Earlier quoted context omitted.

You only need the strong alphanumeric pass phrases on device startup, then you can use TouchID. I bought an iPhone 6 for exactly this reason (employer required strong passphrase, was too annoying to type in on the Android device I had at the time).

In a way, that's even worse. You're more likely to forget a complicated passphrase when you only have to type it in very seldomly.

[deleted]

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#286
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

The exact reason i simply just don't use the iCloud backup.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#287

Earlier quoted context omitted.

> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

backup ==> zip/rar => encrypt with pgp or whatever => split => upload various parts to different cloud storage providers => wipe device => pass checkpoint => download => combine => decrpy => uncompress => restore.

its not trivial, but its sure easy to do in this day and age.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#288

Earlier quoted context omitted.

Could you be more specific? I've followed the NSA leaks with some interest, but not particularly closely, so I'd be really interested in seeing the actual presentation/document/whatever. For reference I've googled every combination of "nsa apple mobile OS leak" I could think of and couldn't find a primary source.

I Googled "nsa leak iOS" and found the first one: http://www.spiegel.de/international/world/how-the-nsa-spies-... Helps to type in just what you want and what will specifically have your answer. Mobile will give you garbage most of the time. Apple as well. A technical document will usually reference iOS. Also, you can use quotes to ensure something appears. Interesting enough, me typing what you typed into Google sti…

If you are asked for a source it doesn't look great to begin your answer with: "I googled …" About the linked article: out of date (2013, mentions iOS 4.3.3). Very thin on actual information. 90% of article is about Blackberry but insinuates same risks for iOS. As a German I wouldn’t trust Der Spiegel anyway: when it come to IT issues my fellow countrymen are often fueled by longstanding anti-americanism and technophobia :/

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#289

Earlier quoted context omitted.

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

Naive quedtion perhaps, bit why wouldn't they be able to employ the same hardware on icloud than on the phone?

Uploading the encrypted content has no value as backup, if you don't have keys that can decrypt it. If the keys are backed up as well, all security is gone.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#290

Earlier quoted context omitted.

Since you're responding to me I'm assuming you mean me, but I have no problem conceptualizing non-malicious things you would want to keep private. The problem here is that a lot of the stuff stored on phones falls somewhere between "dies with me" private and "should pass on to my family" private. Or "should be recoverable if I lose my key" private. Strong encryption makes it impossible to recover in the event of a lo…

That's what a last will is for: "...and the passphrase for my inheritable private stuff is 12345; it's the file named Blah.xyzzy.foo on my desktop, decryptable using BazBarFoo (installed)."

Most people don't write wills. Their assets shouldn't be lost forever as a result. That would be terrible.

It would be better to opt-in to auto-destruct-when-i-die, not opt-out. It's more of a special case. E.g. create encrypted notes for super secret stuff you want to die with you, but let the default security for photos and documents be "private but recoverable in the event of death or forgotten key."

Not to mention, writing that password down in a will would be pretty bad from a security standpoint while you're alive.

Post reply on HN