Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

291–300 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#291
post #208
post #118

Earlier quoted context omitted.

I think from the context it's pretty clear that "hack" in this case is referring to "being forced to unlock". Yes, they could still deliberately break encryption for future OSes and phones, but the same could be said of any software, open or closed source. I don't think acting like an open ecosystem is the be-all and end-all of security is productive. Most organizations (let alone individuals) don't have the resource…

> don't have the resources to vet every line in every piece of software they run For the same reason I do not independently vet every line of source code I run, but still reasonably trust my system magnitudes more than anyone could - and I argue, nobody can - trust proprietary systems. And that is because while I personally may not take initiative to inspect my sources, I know many other people will, and that if I we…

C is not a problem -- you can make a bug in every language. Even with memory safety and a perfect compiler, bug may direct the flow in bad direction (bypassing auth for instance) or leak information via side-channel.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#292
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

There's an easy way Apple could offer a true cryptographically secure cloud backup service - support local backups with a physical keystore. Make it an advanced option but use it as an excuse to sell users a Time Machine backup unit with RFID built in to read a security key. Apple could make truly secure systems user friendly if they wanted to. It seems they may see some value in doing so.

Local backups are not cloud backups. But there's already at least one 3rd party cloud backup provider that provides zero-knowledge encrypted backup as an option, with the caveat that the data will be forever lost if you lose the key (or die, etc.) [1]

It's just not an option that your average person would want for their family photos.

[1] https://www.backblaze.com/business-security.html

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#293
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

> iCloud backups can be secured so not even Apple can get in... I'm sure they are working on it, but it is nontrivial.

There is no way they are working on this. It is an intentional design decision that Apple offers an alternative way to recover your data if you lose your password.

Or if you die without telling your next-of-kin your password. Most people do not actually want all of their family photos to self-destruct when they die because they didn't plan for their death "correctly". That would be a further tragedy for the family. (Most people don't even write wills and a court has to figure things out.)

Making data self-destruct upon forgetting a password (or dying) is not a good default. It's definitely something people should be able to opt-in to in particular situations, but only when they understand the consequences. So it's great news that in iOS 9.3 the Notes app will let you encrypt specific notes with a key that only you know. But it's opt-in, not the default.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#295
post #246

If you want to keep a secret, you must also hide it from yourself" - George Orwell, 1984 - Apple, 2016

Just a nitpick, but 1984 by G. Orwell was first published in 1949 what makes it even more impressive.

That was intentional

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#296
post #145

Earlier quoted context omitted.

If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.

If you're paranoid, you don't have a cell phone.

Or you have several, and send them on trips without you, etc.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#297
post #118

Earlier quoted context omitted.

I think from the context it's pretty clear that "hack" in this case is referring to "being forced to unlock". Yes, they could still deliberately break encryption for future OSes and phones, but the same could be said of any software, open or closed source. I don't think acting like an open ecosystem is the be-all and end-all of security is productive. Most organizations (let alone individuals) don't have the resource…

How does a 3rd-party researcher find the next heartbleed if they can't even decrypt the binaries for analysis?

Binaries can be converted back to assembly and quite often even back to equivalent C; bugs are most often found by fuzzing (intentional or not) which does not require source code. The difference between open and closed source is that open is more often analysed by white hats who rather publish vulnerabilities and help fixing them, while closed by black hats who rather sell or exploit them in secret.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#298

Earlier quoted context omitted.

Naive quedtion perhaps, bit why wouldn't they be able to employ the same hardware on icloud than on the phone?

Uploading the encrypted content has no value as backup, if you don't have keys that can decrypt it. If the keys are backed up as well, all security is gone.

Is it that hard to have the phone display an encryption key and have the user copy it to dead tree?

As above, not a good idea for a default, but don't see why it wouldn't be technically viable for opt-in protection.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#299
post #281
post #254

Earlier quoted context omitted.

Indeed, "The County was working cooperatively with the FBI when it reset the iCloud password at the FBI's request." https://twitter.com/CountyWire/status/700887823482630144

The "screwup" grandparent is suggesting is that the county didn't think to disable the setting that would let employees turn off iCloud backups for their devices, however many months or years ago, not that they've messed up during the investigation now.

No, they're probably referring to this, from the second letter,

"One of the strongest suggestions we [Apple] offered was that they pair the phone to a previously joined network, which would allow them to back up the phone and get the data they are now asking for. Unfortunately, we learned that while the attacker’s iPhone was in FBI custody the Apple ID password associated with the phone was changed. Changing this password meant the phone could no longer access iCloud services."

http://www.apple.com/customer-letter/answers/

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#300

Earlier quoted context omitted.

> Farook disabled the iCloud backup six weeks prior to the attack http://6abc.com/news/senior-official-stresses-feds-need-to-u...

They did not even attempt to get it to send a fresh backup to iCloud before they reset it making it impossible. [0] http://daringfireball.net/2016/02/san_bernardino_password_re...

On the other hand, "turn it on and let it do its thing" is a terrible idea from a forensics standpoint. You want to lock the account down ASAP to prevent potential accomplices from remote wiping your evidence.
Post reply on HN