Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

371–380 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#371
post #315
post #310

Earlier quoted context omitted.

How can you ask a question like this? Define "so strong" in this context? It's similar to asking "do you need so free speech". We're not talking about anything special here beyond a standard expectation of reasonable security. The fact that apple is trying to make it "so secure even they can't hack it" is just a means for them to protect themselves that happens to align with the interests of the user.

General, unbreakable crypto security applied to all contents is a feature that very few people ever needed or even tried to achieve. Until a few years ago you were perfectly content with keeping an agenda in your pocket and pictures in your living room's drawer. A minimum of privacy is of course needed and welcome; however, unless you're planning a major terror attack, or strategic war plans, or you have incredibly v…

I am not sure why this comment (and all Udik's comments) is being downvoted into oblivion. This is the view of the US government and quite likely a vast majority of citizens here (and, I would guess, in many countries).

This morning I was having a conversation with my fiancee, who said "if the US government gets a warrant they can open your mail, they can tap your phone calls, they can come into your house and search -- why should your phone be some sort of zone they cannot search even with a warrant?"

I happen not to agree but this is not some wacko view.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#372
post #298

Earlier quoted context omitted.

Is it that hard to have the phone display an encryption key and have the user copy it to dead tree? As above, not a good idea for a default, but don't see why it wouldn't be technically viable for opt-in protection.

The hardware key is designed to be impossible to extract from the device. That's part of the security, so you can't simply transfer the data to a phone where protections against brute-forcing the user key have been removed.

> An encryption key

To spell it out (1) request new encryption key from device (let's call it key4cloud); (2) encryption key generated, displayed for physical logging by the user, & stored in the secure enclave; (3) all normal backups to iCloud are now encrypted via key4cloud; (4) user loses phone; (5) user purchases new phone; (6) new phone downloads data; (7) user enters key4cloud from physical notes & decrypts backup

Yes, it requires paper and a pencil and user education (hence the opt-in). But it's also incredibly resistant to "Give us all iCloud data on User Y."

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#373
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

I wonder if Microsoft came out with Palladium ( https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi... ) today, if it would be hailed as a great development for privacy or would still garner lots of criticism as it did 10 years ago. Of Palladium, Bruce Scheier said: > "There's a lot of good stuff in Pd, and a lot I like about it. There's also a lot I don't like, and am scared of. My fear is that Pd will lead…

Wait, are you saying you trust apple yet not Microsoft or more than?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#374
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

I wonder if Microsoft came out with Palladium ( https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi... ) today, if it would be hailed as a great development for privacy or would still garner lots of criticism as it did 10 years ago. Of Palladium, Bruce Scheier said: > "There's a lot of good stuff in Pd, and a lot I like about it. There's also a lot I don't like, and am scared of. My fear is that Pd will lead…

I thought that's the opposite of what Palladium did. Doesn't it make it so the apps and data on your computer aren't actually yours? Like Microsoft would have total control over what you put on your computer? I was under the impression it didn't do anything to protect your privacy: instead it actually put backdoors in your computer that Microsoft could access any time they wanted?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#375
post #311

Earlier quoted context omitted.

Anything specifically missing on android side except the PR? Seriously asking if I'm missing something. The nexus series has comparable crypto hw and similar options for encryption + wiping.

https://news.ycombinator.com/item?id=10250803 I'll repost a snippet from a post by merhdada that hints at the root of one of the problems with android security: "This can happen only because of a design flaw in the security architecture of Android (L). Unlike iOS and like traditional PCs, the disk encryption key is always in memory when the device is booted and nothing is really protected if you get a device in that…

Yeah, the problem is that Google's whole business model depends on uploading all your unencrypted data to their cloud, whereas Apple could probably decide to encrypt everything in iCloud so not even they could read it if any government/hacker came looking.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#376
post #326

Earlier quoted context omitted.

Of course. And 11000 meters waterproof is the only waterproof acceptable for a watch. And operating room clean air is the only clean air. And obsidian blades are the only ones that deserve to be used in your kitchen. And triple malt, 60 years aged whiskey is the only whiskey. Etc.

That argument doesn't hold water . If you're using a breakable crypto , you're not protected at any given time. If you're using a watch that's waterproof up to 100m, you're safe up to 100 meters.

I'm sorry, I might be wrong here, but I thought that any cryptographic system is breakable, given enough time and resources. If this is true, then, according to your statement, you're never protected. Therefore you can just transmit and store plain data without any cryptography, isn't it the same?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#377

Earlier quoted context omitted.

Sorry, maybe I should have been a little more specific. I was looking for a primary source that shows this part: "FBI talked about how they couldn't beat iPhones but NSA had them in the leaks & was parallel constructing to FBI." The link you posted only talks about "hacking" iPhones, but nothing about parallel construction. Additionally, it only talks about how the NSA is making use of the device's (local) backup. As…

Oh, OK. That makes more sense. As I said to other commenter, I'm not doing enough research to figure out how they're hacking it directly. There's so many published hacks of hardware and firmware that were designed for secure operation that it would be a miracle if they didn't have something on iPhones. It's more a "insecure-by-default" if it doesn't address what's on my list of attack vectors. I know it doesn't becau…

Gotcha. I agree that there are a lot of potential security issues present on the iPhone, and if I was a terrorist (or my name was Edward Snowden) I would definitely act as if they were already hacked by the NSA/FBI/whomever.

However, your original comment made it sound like we had direct confirmation of that fact. I hadn't heard that before, which is why I was interested.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#378
post #325
post #322

Earlier quoted context omitted.

For me it's not really about my personal security because, you're right, there's nothing interesting on my phone. My issue is with one entity having access to ALL of our phones. Have you read 1984? Because that's what that sounds like. It's too much power for the government to have.

I think I missed the part where anybody asked Apple to build a backdoor into every phone that could be accessed without appropriate control from the authorities and without passing through Apple each time. Of course I'm not saying that your data should be uploaded daily to a government's server for anybody with a badge and free time to spare to look through.

The FBI here only represents the 'legal' government and not the world of secret courts and the NSA.

The NSA did infact try to build backdoors into important hardware and software standards. They did push companies into using worse crypto. The do massiv port scanning and build themself botnets from where thet attack other nation states. And thats just a tiny fraction of what they do.

So yes, I absolutly do need computer hardware and software that even the manufacturer cant break. Low level security for boot and authentification is only the first in many, many steps that we have to take all the way up to imroving usability in end user applications to make it hard to do the wrong thing.

The FBI are not the o ly player, all governments want such control, all governments have things like the NSA. Even private actors are getting better and better.

We do need better security to protect the integrety of all our data, this includes all our communication and even, if possible metadata that we produce.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#379
post #359

Earlier quoted context omitted.

That's pretty standard, though: once you no longer exist, all your private data, all your private money, all your private goods become part of your estate, to be disposed of by your executor according to your will.

Things like money and personal physical property, sure, I understand that. But I feel like personal protected (encrypted) data should be treated differently. I'm thankful Google at least has options[0] available for their ecosystem, but I guess I'm going to need a will to cover the rest. [0] https://support.google.com/accounts/answer/3036546?hl=en

Historical, pre-digital precedent:

In the case of sudden death, there would not have been any way to securely dispose of any private "data". So your private information, diaries, works you purposefully didn't publish, unfinished manuscripts you abandoned - everything was handed down to your estate, and more often than not used against your intent.

I'm not entirely clear whether your will could specify such disposal to be done, or could prohibit people from at least publishing these private notes and letters if not reading them, in any kind of binding and permanent way.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#380

Earlier quoted context omitted.

I wonder if Microsoft came out with Palladium ( https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi... ) today, if it would be hailed as a great development for privacy or would still garner lots of criticism as it did 10 years ago. Of Palladium, Bruce Scheier said: > "There's a lot of good stuff in Pd, and a lot I like about it. There's also a lot I don't like, and am scared of. My fear is that Pd will lead…

Wait, are you saying you trust apple yet not Microsoft or more than?

I do trust Apple more than Microsoft.
Post reply on HN