Live data from Hacker News

The StingRay Is Why the 4th Amendment Was Written (2017)

fee.org

31–40 of 155 posts

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#31
Between this example and “no knock” warrants (where people get killed, including police) I think it seems obvious that people have forgotten what the point of a warrant is.

A warrant is suppose to prevent either of the two cases from resulting in lengthy court battles or death from confusion, and it’s very simple:

YOU SHOW THE PERSON BEING SEARCHED THE WARRANT IN ADVANCE!

That is how you gain authorization... somehow people are being searched and the warrant is either kept secret entirely or not shown to them prior to the search!

That’s literally the fundamental purpose of a constitutional warrant!

Things are so backwards now, search then warrant, shoot first then ask questions, execution before trial...

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#32
post #30

Earlier quoted context omitted.

iOS's only security issue is users not updating and being vulnerable to well known vulnerabilities. Neither iOS nor Android will survive a truly targeted nation state attack, but for most people 0-days aren't worth protecting against. The only exception to this is the checkm8 vulnerability, which can be performed on an A11 and older chips (so iPhone XR/XS/XS+ and 11/11 pro/11 pro max aren't vulnerable) from DFU mode,…

Right. I guess that phones can't update without direct cellular or WiFi connectivity. But I don't know. Is that true? Could one somehow enable updates through pure TCP/IP?

You can update iOS devices through iTunes via USB, or buy an ethernet adapter.

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#34
post #15
post #3

Earlier quoted context omitted.

Encryption does not fix this completely even if you assume all texts and voice calls are encrypted. The metadata is equally important: - your location in time and space - the numbers you contacted - the duration of contact

Metadata is useful but it's a stretch to call it equally important as actual call content. If you were spying on someone, what would you rather know: all the above metadata you listed, or a full recording of all their calls?

> If you were spying on someone, what would you rather know: all the above metadata you listed, or a full recording of all their calls?

That depends entirely on the purpose of the spying.

If you're spying with a goal of assassination, the location data from their morning commute might be far more valuable.

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#35
post #32
post #30

Earlier quoted context omitted.

Right. I guess that phones can't update without direct cellular or WiFi connectivity. But I don't know. Is that true? Could one somehow enable updates through pure TCP/IP?

You can update iOS devices through iTunes via USB, or buy an ethernet adapter.

Cool. So you could take the phone/tablet totally offline, except for external router via USB.

Maybe same for Android?

Except that you'd arguably want to update it locally with the Copperhead OS.

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#36

Seems like a strong case for encryption. Why is it even possible for these devices to read your info?

As I understand it, cellphone infrastructure is intentionally simplistic so that it works the same everywhere. If the US implemented some kind of end to end encryption or authentication, Canada might not, and then everyone who crosses the border would have a brick.

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#37

Seems like a strong case for encryption. Why is it even possible for these devices to read your info?

It’s actually more a case for authentication. Why don’t our phones authenticate cell towers when connecting to them? Why are providers so lax at enforcing that?

Even if your phone insisted that each cell tower authenticate itself as an authentic Verizon Tower(TM), then Verizon would just provide 500 extra authentic tower keys to various police agencies for their use. shrug emoji

You can't trust cell companies to help you against the government.

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#38

Seems like a strong case for encryption. Why is it even possible for these devices to read your info?

As I understand it, cellphone infrastructure is intentionally simplistic so that it works the same everywhere. If the US implemented some kind of end to end encryption or authentication, Canada might not, and then everyone who crosses the border would have a brick.

It’s designed to minimize billing issues. User privacy or in transit security aren’t significant business requirements.

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#39
post #30

Earlier quoted context omitted.

iOS's only security issue is users not updating and being vulnerable to well known vulnerabilities. Neither iOS nor Android will survive a truly targeted nation state attack, but for most people 0-days aren't worth protecting against. The only exception to this is the checkm8 vulnerability, which can be performed on an A11 and older chips (so iPhone XR/XS/XS+ and 11/11 pro/11 pro max aren't vulnerable) from DFU mode,…

Right. I guess that phones can't update without direct cellular or WiFi connectivity. But I don't know. Is that true? Could one somehow enable updates through pure TCP/IP?

Carrier updates might have some power i'm not aware of on iOS (they pop up saying "do you want to update carrier settings" with simple yes/no options), but regular iOS software updates do require connection to Apple servers and the firmware itself also has to be signed by Apple.

The carrier setting thing hasn't ever been use for a jailbreak exploit AFAIK so chances are it's not a good attack vector.

From your other comment:

> But it mentions the option of wiping baseband firmware

iOS also has signature verification for its baseband, since trying to load an incompatible one during a downgrade[0] breaks Face ID / Touch ID.

But ya, this is all "trust apple to not do anything". They've made a good stance with refusing the FBI request[1], but the FBI got into the phone anyways[2].

0: https://github.com/tihmstar/futurerestore

1: https://news.ycombinator.com/item?id=11116274

2: https://venturebeat.com/2016/03/28/u-s-government-gains-acce...

Re: The StingRay Is Why the 4th Amendment Was Written (2017)

#40
post #30

Earlier quoted context omitted.

Right. I guess that phones can't update without direct cellular or WiFi connectivity. But I don't know. Is that true? Could one somehow enable updates through pure TCP/IP?

Carrier updates might have some power i'm not aware of on iOS (they pop up saying "do you want to update carrier settings" with simple yes/no options), but regular iOS software updates do require connection to Apple servers and the firmware itself also has to be signed by Apple. The carrier setting thing hasn't ever been use for a jailbreak exploit AFAIK so chances are it's not a good attack vector. From your other c…

I guess that a key question is whether one can trust iOS airplane mode to fully take the phone offline.

And under what circumstances does the phone leave airplane mode, and go back online.

But even if that were solid, you'd still be ~unable to install apps that Apple doesn't provide. Unless you play the developer game, and I gather that's limited in app number, and how long they'll stay functional.

Post reply on HN