Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

301–310 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#301
post #300

Earlier quoted context omitted.

They did not even attempt to get it to send a fresh backup to iCloud before they reset it making it impossible. [0] http://daringfireball.net/2016/02/san_bernardino_password_re...

On the other hand, "turn it on and let it do its thing" is a terrible idea from a forensics standpoint. You want to lock the account down ASAP to prevent potential accomplices from remote wiping your evidence.

In an alternate universe it may have been a plausible deliberate measure, but in this universe, it was a fuckup.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#302

Earlier quoted context omitted.

That's what a last will is for: "...and the passphrase for my inheritable private stuff is 12345; it's the file named Blah.xyzzy.foo on my desktop, decryptable using BazBarFoo (installed)."

Most people don't write wills. Their assets shouldn't be lost forever as a result. That would be terrible. It would be better to opt-in to auto-destruct-when-i-die, not opt-out. It's more of a special case. E.g. create encrypted notes for super secret stuff you want to die with you, but let the default security for photos and documents be "private but recoverable in the event of death or forgotten key." Not to mentio…

Yes, autodestruct should probably be opt-in.

Most people don't stick their wills to their monitors with post-its (there are other secrets in there after all, and many people would like to know those); the legal system has mature tools that are surprisingly good at keeping such secrets secret until the release conditions are met. A will is a Solved Problem, with highly reliable solutions - consider the ways to prove that it is indeed to be opened. Contrast with most computerized solutions and "solutions" thereof, mostly hinging on some form of dead man's switch.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#303

Earlier quoted context omitted.

The real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore…

> iCloud backups can be secured so not even Apple can get in... I'm sure they are working on it, but it is nontrivial. There is no way they are working on this. It is an intentional design decision that Apple offers an alternative way to recover your data if you lose your password. Or if you die without telling your next-of-kin your password. Most people do not actually want all of their family photos to self-destruc…

Has Apple even given access of someone's iCloud account to next-of-kin after they died? I've never heard of this, and I don't expect Apple to be responsible to preserve photos. You already can have shared photo streams, and there are many solutions for other data that could be potentially lost that don't involve Apple getting directly involved in these cases.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#304
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

If the device has a manufacturer's key and the user's key, then it's basically down to simple Boolean logic: does the innermost trusted layer allow something to be installed or altered if it is authorized by the manufacturer's key OR your key? Or the manufacturer's key AND your key? Or just your key? (With a warning if it has no other key?)

Underrated post.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#305
I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this.

The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want to believe, that this is actually driven by company values and not a short-term marketing benefit.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#308
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

Do you really need such strong security? Or after the FBI forced Apple to apply their best engineering minds to crack your phone, they'd just find a grocery shopping list and pictures of your cats? Because this sounds a bit like Tesla's "operating room air quality" - something that might be useful 0.001% of the customers, and it's just marketing for the remaining 99.999%

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#309
post #280

Earlier quoted context omitted.

In a way, that's even worse. You're more likely to forget a complicated passphrase when you only have to type it in very seldomly.

You have to enter it every 48 hours.

Only if you don't unlock the phone in these 48 hours, no?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#310
post #308
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

Do you really need such strong security? Or after the FBI forced Apple to apply their best engineering minds to crack your phone, they'd just find a grocery shopping list and pictures of your cats? Because this sounds a bit like Tesla's "operating room air quality" - something that might be useful 0.001% of the customers, and it's just marketing for the remaining 99.999%

How can you ask a question like this? Define "so strong" in this context? It's similar to asking "do you need so free speech". We're not talking about anything special here beyond a standard expectation of reasonable security. The fact that apple is trying to make it "so secure even they can't hack it" is just a means for them to protect themselves that happens to align with the interests of the user.
Post reply on HN