Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

351–360 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#351
post #120

Earlier quoted context omitted.

>You may not need to crack the OS, or even upload a new firmware. You just need to disable the mechanism that wipes the device and delays how many wrong tries you get. So for example, if you can manage to corrupt, or patch the part of the system that does that, then you can try thousands of PINs without worrying about triggering the timer or wipe, and without needing to upload a whole new firmware. I disagree. The pi…

The state representing the number of attempts must be stored somewhere, and thus a determined adversary could eventually corrupt it. Look, there's a big difference between trusting known ciphers that have been well studied by the world's top cryptographers, and a proprietary TPM chip that relies on security-through-obscurity. The history of embedding secrets into black boxes is a history of them being broken. This is…

The question is not whether a determined adversary could corrupt the counter. The question is whether they can corrupt the counter before they corrupt something else that causes total data loss.

Physical defenses are not security through obscurity, and why you assuming they don't use known ciphers?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#352
post #311
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

Anything specifically missing on android side except the PR? Seriously asking if I'm missing something. The nexus series has comparable crypto hw and similar options for encryption + wiping.

https://news.ycombinator.com/item?id=10250803

I'll repost a snippet from a post by merhdada that hints at the root of one of the problems with android security:

"This can happen only because of a design flaw in the security architecture of Android (L). Unlike iOS and like traditional PCs, the disk encryption key is always in memory when the device is booted and nothing is really protected if you get a device in that state. It's an all-or-nothing proposition."

Please read the entire thread, and check the links referenced in that thread, for information on how issues like these are mitigated.

That's only one issue though. There are a few more.

But none of that even matters a lot of times ... you really won't need to hack an android phone... because the data is also on corporate servers. So the FBI could get at it in any case most of the time.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#354
post #326

Earlier quoted context omitted.

Of course. And 11000 meters waterproof is the only waterproof acceptable for a watch. And operating room clean air is the only clean air. And obsidian blades are the only ones that deserve to be used in your kitchen. And triple malt, 60 years aged whiskey is the only whiskey. Etc.

That argument doesn't hold water . If you're using a breakable crypto , you're not protected at any given time. If you're using a watch that's waterproof up to 100m, you're safe up to 100 meters.

If you're using a watch that's waterproof up to 100m, you're safe up to 100 meters.

To be pedantic, that's not exactly what is meant by 100m Water Resistant, but your point is valid.

https://en.wikipedia.org/wiki/Water_Resistant_mark

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#355

Earlier quoted context omitted.

The NSA cracking the Secure Enclave is not the same as the FBI cracking the Secure Enclave.

If the NSA can't crack the Secure Enclave in a terrorism case, it's not super useful that the NSA can crack the Secure Enclave.

Perhaps the NSA is savvy enough to know that a heroic effort isn't needed, and that the FBI is mostly looking to set precedent rather than find anything worth the cost and risk of chip-hacking.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#356

This is all just theatre. The real motivation is to control the platform: to ship a piece of hardware that dictates who can install stuff on it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access. Since 197X, people had home computers (and institutional computers for two decades before that) on which the FBI could install anything they want, if that equ…

> This is all just theatre. The real motivation is to control the platform: to ship a piece of hardware that dictates who can install stuff on it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access.

This is already the case. Right now, only firmware signed by Apple can be installed. The next logical step is to build a system where the unit that deals with PINs cannot be updated at all, or at least not without wiping all keys. This would prevent any non-invasive attempts of bypassing the rate-limiting of PIN attempts or auto-wipe.

> There is nothing wrong with that situation, and on such equipment, you can secure your data just fine.

Again, this is also true for an iPhone with a sufficiently complex passphrase, Because Crypto™. Secure Enclave is just an additional layer that protects against everyone not in a position to get custom firmware signed by Apple.

> No machine can be trusted if it fell under someone's physical access. Here is a proof: if I get my hands on your device, I can replace it with a physically identical device which looks exactly like yours, but is actually a man-in-the-middle (MITM). (I can put the fake device's board into your original plastic and glass, so it will have the same scratches, wear, grime pattern and whatever other markings that distinguish the device as yours.) My fake device will collect the credentials which you enter. Those are immediately sent to me and I play them against the real device to get in.

The scenario here isn't an Evil Maid Attack. It's about protecting locked devices while someone else has physical access to them. Right now, you're fairly safe from most attackers in this scenario. In the future, with a read-only Secure Enclave, you're also safe from Apple and anyone who could force Apple to sign firmware. The fact that Evil Maid Attacks are harder to pull off because of this is just a nice extra.

> Apple are trying to portray themselves as a champion of security, making clueless users believe that the security of a device rests in the manufacturer's hands. This could all be in collaboration with the FBI, for all we know. Two versions of Big Brother are playing the "good guy/bad guy" routine, so you would trust the good guy, who is basically just one of the faces of the same thing.

This doesn't make sense. There's no crypto backdoor. The worst case scenario for their current security architecture is that it falls back to how FDE works on a desktop system - i.e., it's completely dependent on your passphrase complexity.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#357
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

Of course it's a short-term marketing benefit. But , if the encryption is secure, then the marketing benefit is matching up with the customer benefit, so hey.

It's not clear that it IS a short-term benefit. Poll results are mixed (although the wording has a significant impact on the results) and a leading presidential candidate is calling for a boycott of their products. Marketing campaigns tend to be less polarizing. Also, I would imagine that losing the case would negatively impact sales more than if they had quietly complied.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#358

This is all just theatre. The real motivation is to control the platform: to ship a piece of hardware that dictates who can install stuff on it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access. Since 197X, people had home computers (and institutional computers for two decades before that) on which the FBI could install anything they want, if that equ…

>it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access.

How do you plan to flash all the HDD/USB/Network controllers? Not to mention the CPU/GPU microcode, and countless other random chips inside your computer that are executing firmware you have no access to.

We're already hosed. Its just a matter of whats considered a 'reasonable' barrier.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#359

Earlier quoted context omitted.

Has Apple even given access of someone's iCloud account to next-of-kin after they died? I've never heard of this, and I don't expect Apple to be responsible to preserve photos. You already can have shared photo streams, and there are many solutions for other data that could be potentially lost that don't involve Apple getting directly involved in these cases.

The idea of Apple (or some other big corporation) providing my protected personal data to my next-of-kin is more frightening than the idea that the government has the ability to spy on me while I'm alive. It's the most morbid kind of subliminal marketing that could possibly exist. "Hey, we're really sorry about fluxquanta's passing. Here is his private data which he may or may not have wanted you to see (but we'll ju…

That's pretty standard, though: once you no longer exist, all your private data, all your private money, all your private goods become part of your estate, to be disposed of by your executor according to your will.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#360
post #342

Earlier quoted context omitted.

> For Samsung this is complicated because both Google and Samsung are involved, and Samsung is not a US company so I'd expect them to cave in under pressure from the US govt more easily. Why? I'd expect just the opposite.

> Why? I'd expect just the opposite. To many Americans, Apple is the example of American innovation and entrepreneurial spirit, and a proof that the American model works. Apple employs 10s of thousands of Americans directly, and probably provides jobs for 100s of thousands indirectly. Going too aggressive on Apple, e.g. at the level where executives could be charged in court, or products embargoed, would be a decided…

You are right to a certain extent! But lets not forget that Samsung is a huge company too and is registered as per US norms. So the American executives of Samsung would be very much comfortable referring to either of them.
Post reply on HN