Live data from Hacker News

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

404media.co

281–290 of 565 posts

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#281
post #4

[flagged]

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

[deleted]

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#282
Don't be idiots. The FBI may say that whether or not they can get in:

1. If they can get in, now people - including high-value targets like journalists - will use bad security.

2. If the FBI (or another agency) has an unknown capability, the FBI must say they can't get in or reveal their capabilities to all adversaries, including to even higher-profile targets such as counter-intelligence targets. Saying nothing also risks revealing the capability.

3. Similarly if Apple helped them, Apple might insist that is not revealed. The same applies to any third party with the capability. (Also, less significantly, saying they can't get in puts more pressure on Apple and on creating backdoors, even if HN readers will see it the other way.)

Also, the target might think they are safe, which could be a tactical advantage. It also may exclude recovered data from rules of handling evidence, even if it's unusable in court. And at best they haven't got in yet - there may be an exploit to this OS version someday, and the FBI can try again then.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#284
post #103

Earlier quoted context omitted.

"Don't secure your phone it might mess up JavaScript" is not something I had on my 2026 bingo card.

I mean I tried it for a bit and I have to say it was a significant compromise. All kinds of random things don't work.

I find all kinds of random things already don't work on mobile Safari - the web is effectively unusable without an adblocker, and over the past few months I've seen an explosion in the use of sites using "AdShield" which, if they detect ad-blocking, breaks websites (and lies to the user about the cause). Desktop browsers are able to handle this still, but on mobile Safari it just results in a bunch of the web being broken.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#286

Earlier quoted context omitted.

Absolutely every aspect of it? What’s so hard about adding a feature that effectively makes a single-user device multi-user? Which needs the ability to have plausible deniability for the existence of those other users? Which means that significant amounts of otherwise usable space needs to be inaccessibly set aside for those others users on every device—to retain plausible deniability—despite an insignificant fractio…

Android has work profiles, so that could be done in Android. iPhone still does not.

Police ask: give me pass for work profile. If you don’t: prison.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#287

Earlier quoted context omitted.

Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. What’s so hard to make 2-3 pins and each to access different logged in apps and files. If Apple/android was serious about it would implement it, but from my research seems to be someone that it’s against it, as it’s too good. I don’t want to remove my Banking apps when I go travel or in “dangerous”…

> Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. > What’s so hard to make 2-3 pins and each to access different logged in apps and files. Besides the technical challenges, I think there's a pretty killer human challenge: it's going to be really hard for the user to create an alternate account that looks real to someone who's paying attention. Su…

Just use an account for “regular” stuff. And only use the “secret” account as needed.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#288
post #23

Earlier quoted context omitted.

Serious question: What are the "valid concerns" about people securing their computing devices against third parties?

Lockdown mode significantly effects the usability of the phone. It completely disables JIT js in Safari for example.

I do have it enabled and webbrowsing is still fine, the things I use are or websites or simple web apps that aren't javascript heavy anyway...

when I want to do something for longer I will pickup my MacBook anyway.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#289

Earlier quoted context omitted.

> Still go to prison for not showing. So until devices have multiple pins for plausible deniability we are still screwed. > What’s so hard to make 2-3 pins and each to access different logged in apps and files. Besides the technical challenges, I think there's a pretty killer human challenge: it's going to be really hard for the user to create an alternate account that looks real to someone who's paying attention. Su…

But at that point it turns from "the person refused to unlock the device" to "we think the person has unlocked the device into a fake account".

That’s what plausible deniability. How can you even tell?

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#290

Earlier quoted context omitted.

Indeed, likely as secure as the VPNs run by intelligence contractors. 1. iOS has well-known poorly documented zero-click exploits 2. Firms are required to retain your activity logs for 3 months 3. It is illegal for a firm to deny or disclose sealed warrants on US soil, and it is up to 1 judge whether to rummage through your trash. If I recall it was around 8 out of 18000 searches were rejected. It is only about $23 t…

> 1. iOS has well-known poorly documented zero-click exploits PoC || GTFO, to use the vernacular. If you're talking about historical bugs, don't forget the update adoption curves.

No one will hand over the several $1m 0-day as PoC for free, as there are grey-market products based on the same tired exploits.

"Not My Circus, Not My Monkeys" as they say. =3

Post reply on HN