Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

341–350 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#341
post #308
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

Do you really need such strong security? Or after the FBI forced Apple to apply their best engineering minds to crack your phone, they'd just find a grocery shopping list and pictures of your cats? Because this sounds a bit like Tesla's "operating room air quality" - something that might be useful 0.001% of the customers, and it's just marketing for the remaining 99.999%

Yes. Because I've got plenty to lose from criminals too.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#342
post #316

Earlier quoted context omitted.

Two things come to mind. First an equivalent of the secure enclave. Second a single company that is willing to go this far to protect its users. For Samsung this is complicated because both Google and Samsung are involved, and Samsung is not a US company so I'd expect them to cave in under pressure from the US govt more easily. Edit: a Nexus device bought directly from Google with the right hw may address both points…

> For Samsung this is complicated because both Google and Samsung are involved, and Samsung is not a US company so I'd expect them to cave in under pressure from the US govt more easily. Why? I'd expect just the opposite.

> Why? I'd expect just the opposite.

To many Americans, Apple is the example of American innovation and entrepreneurial spirit, and a proof that the American model works. Apple employs 10s of thousands of Americans directly, and probably provides jobs for 100s of thousands indirectly. Going too aggressive on Apple, e.g. at the level where executives could be charged in court, or products embargoed, would be a decidedly unpopular move with many voters and politicians. Samsung is a much easier target here.

Also as an American company, Apple can legitimately enter the democratic debate, see the calls it makes to congress. Samsung can't really do that. Imagine Samgsung putting out press release quoting the founding fathers or referring to the first amendment. That would not be credible.

Edit: grammar

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#343

Earlier quoted context omitted.

Corporate email profiles on BYOD phones often enforce a long passcode requirement, so you've got a lot of Fortune 500 sales guys to screen out if you're stopping and searching anybody with a suspiciously long password.

I'm at a loss as to how alphabet agency can determine a weak passcode vs strong passcode was used. how does a pin get stored on the phone? surely, not plain text of a 4 digit pin. if they do any encryption to the 4 digit pin, how would it appear any different than a significantly stronger passcode?

It uses a different screen. If you have a 4 digit pin, the entry screen looks a lot like the phone dialer, with the numbers 0-9.

If you have a stronger passcode, you see a full keyboard instead.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#344
post #66
post #20

Earlier quoted context omitted.

Probably not. If you're dead, they probably have your fingers. If you're alive, they can compel you to unlock the device with your fingerprint. The only point I'm making is that Apple already designed a cryptosystem that resists court-ordered coercion: as long as your passcode is strong (and Apple has allowed it to be strong for a long time), the phone is prohibitively difficult to unlock even if Apple cuts a special…

Using a strong pin is pretty annoying, and a relatively visible signal when using the phone on the street etc, So it can be a good filter(maybe via street cams) to filter suspicious people - which isn't a bad goal for law enforcement.

People who desire to be secure in their electronic papers and effects are not and should not be considered "suspicious people".

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#345

Earlier quoted context omitted.

Which, ironically, is exactly what Apple is protecting here. DRM.

DRM for your own data is called privacy.

Apple, a 3rd-party, holds the master keys, and you don't.

So no, that's not DRM for your own data.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#346
post #297

Earlier quoted context omitted.

How does a 3rd-party researcher find the next heartbleed if they can't even decrypt the binaries for analysis?

Binaries can be converted back to assembly and quite often even back to equivalent C; bugs are most often found by fuzzing (intentional or not) which does not require source code. The difference between open and closed source is that open is more often analysed by white hats who rather publish vulnerabilities and help fixing them, while closed by black hats who rather sell or exploit them in secret.

You misunderstand; if you can't even decrypt the binary, you can't disassemble, much less run a decompiler over it.

As someone who has done quite a bit of reverse engineering work, I have no idea how I'd identify and isolate a vulnerability found by fuzzing without the ability to even look at the machine code.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#347

Earlier quoted context omitted.

It's encrypted against an effectively random 128 bit AES key. Unlimited time is not enough.

Unless there is weakness in the PRNG/RNG that creates the fused key in the secure enclave itself. Which is not out of question. I am not sure why FBI didn't ask apple politely how these keys are generated in the first place.

That seems excessively unlikely to me. The phone itself wouldn't have anything to seed a PRNG with, so the random number would need to come from an embedded hardware generator or a dedicated random number device in the factory, and both of those options would have huge amounts of engineering oversight.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#348
post #326

Earlier quoted context omitted.

Sorry but "unbreakable crypto" is the only right crypto.

Of course. And 11000 meters waterproof is the only waterproof acceptable for a watch. And operating room clean air is the only clean air. And obsidian blades are the only ones that deserve to be used in your kitchen. And triple malt, 60 years aged whiskey is the only whiskey. Etc.

That argument doesn't hold water.

If you're using a breakable crypto , you're not protected at any given time.

If you're using a watch that's waterproof up to 100m, you're safe up to 100 meters.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#349
This is all just theatre. The real motivation is to control the platform: to ship a piece of hardware that dictates who can install stuff on it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access.

Since 197X, people had home computers (and institutional computers for two decades before that) on which the FBI could install anything they want, if that equipment fell into their hands. This fact never made news headlines; it was taken for granted that the computer is basically the digital equivalent of a piece of stationery, written in pencil.

There is nothing wrong with that situation, and on such equipment, you can secure your data just fine.

No machine can be trusted if it fell under someone's physical access. Here is a proof: if I get my hands on your device, I can replace it with a physically identical device which looks exactly like yours, but is actually a man-in-the-middle (MITM). (I can put the fake device's board into your original plastic and glass, so it will have the same scratches, wear, grime pattern and whatever other markings that distinguish the device as yours.) My fake device will collect the credentials which you enter. Those are immediately sent to me and I play them against the real device to get in.

Apple are trying to portray themselves as a champion of security, making clueless users believe that the security of a device rests in the manufacturer's hands. This could all be in collaboration with the FBI, for all we know. Two versions of Big Brother are playing the "good guy/bad guy" routine, so you would trust the good guy, who is basically just one of the faces of the same thing.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#350
post #315
post #310

Earlier quoted context omitted.

How can you ask a question like this? Define "so strong" in this context? It's similar to asking "do you need so free speech". We're not talking about anything special here beyond a standard expectation of reasonable security. The fact that apple is trying to make it "so secure even they can't hack it" is just a means for them to protect themselves that happens to align with the interests of the user.

General, unbreakable crypto security applied to all contents is a feature that very few people ever needed or even tried to achieve. Until a few years ago you were perfectly content with keeping an agenda in your pocket and pictures in your living room's drawer. A minimum of privacy is of course needed and welcome; however, unless you're planning a major terror attack, or strategic war plans, or you have incredibly v…

you forgot about freedom of the press. Typical FUD:

"If you aren't doing anything wrong, what do you have to fear."

"If you do want something private then you must be doing something wrong, ARE YOU A TERRORIST!?!?!?!"

Post reply on HN