Earlier quoted context omitted.
I think from the context it's pretty clear that "hack" in this case is referring to "being forced to unlock". Yes, they could still deliberately break encryption for future OSes and phones, but the same could be said of any software, open or closed source. I don't think acting like an open ecosystem is the be-all and end-all of security is productive. Most organizations (let alone individuals) don't have the resource…
> don't have the resources to vet every line in every piece of software they run For the same reason I do not independently vet every line of source code I run, but still reasonably trust my system magnitudes more than anyone could - and I argue, nobody can - trust proprietary systems. And that is because while I personally may not take initiative to inspect my sources, I know many other people will, and that if I we…
Apple Is Said to Be Working on an iPhone Even It Can’t Hack
291–300 of 415 posts
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#292It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…
There's an easy way Apple could offer a true cryptographically secure cloud backup service - support local backups with a physical keystore. Make it an advanced option but use it as an excuse to sell users a Time Machine backup unit with RFID built in to read a security key. Apple could make truly secure systems user friendly if they wanted to. It seems they may see some value in doing so.
It's just not an option that your average person would want for their family photos.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#293They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…
The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…
There is no way they are working on this. It is an intentional design decision that Apple offers an alternative way to recover your data if you lose your password.
Or if you die without telling your next-of-kin your password. Most people do not actually want all of their family photos to self-destruct when they die because they didn't plan for their death "correctly". That would be a further tragedy for the family. (Most people don't even write wills and a court has to figure things out.)
Making data self-destruct upon forgetting a password (or dying) is not a good default. It's definitely something people should be able to opt-in to in particular situations, but only when they understand the consequences. So it's great news that in iOS 9.3 the Notes app will let you encrypt specific notes with a key that only you know. But it's opt-in, not the default.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#294Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#295Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#296Earlier quoted context omitted.
If you're paranoid, making a complete copy of all your secrets on some remote Apple or Google "cloud" where the government can get at it trivially is the exact opposite of what you want to be doing.
If you're paranoid, you don't have a cell phone.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#297Earlier quoted context omitted.
I think from the context it's pretty clear that "hack" in this case is referring to "being forced to unlock". Yes, they could still deliberately break encryption for future OSes and phones, but the same could be said of any software, open or closed source. I don't think acting like an open ecosystem is the be-all and end-all of security is productive. Most organizations (let alone individuals) don't have the resource…
How does a 3rd-party researcher find the next heartbleed if they can't even decrypt the binaries for analysis?
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#298Earlier quoted context omitted.
Naive quedtion perhaps, bit why wouldn't they be able to employ the same hardware on icloud than on the phone?
Uploading the encrypted content has no value as backup, if you don't have keys that can decrypt it. If the keys are backed up as well, all security is gone.
As above, not a good idea for a default, but don't see why it wouldn't be technically viable for opt-in protection.
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#299Earlier quoted context omitted.
Indeed, "The County was working cooperatively with the FBI when it reset the iCloud password at the FBI's request." https://twitter.com/CountyWire/status/700887823482630144
The "screwup" grandparent is suggesting is that the county didn't think to disable the setting that would let employees turn off iCloud backups for their devices, however many months or years ago, not that they've messed up during the investigation now.
"One of the strongest suggestions we [Apple] offered was that they pair the phone to a previously joined network, which would allow them to back up the phone and get the data they are now asking for. Unfortunately, we learned that while the attacker’s iPhone was in FBI custody the Apple ID password associated with the phone was changed. Changing this password meant the phone could no longer access iCloud services."
Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack
#300Earlier quoted context omitted.
> Farook disabled the iCloud backup six weeks prior to the attack http://6abc.com/news/senior-official-stresses-feds-need-to-u...
They did not even attempt to get it to send a fresh backup to iCloud before they reset it making it impossible. [0] http://daringfireball.net/2016/02/san_bernardino_password_re...