Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

381–390 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#381
post #315
post #310

Earlier quoted context omitted.

How can you ask a question like this? Define "so strong" in this context? It's similar to asking "do you need so free speech". We're not talking about anything special here beyond a standard expectation of reasonable security. The fact that apple is trying to make it "so secure even they can't hack it" is just a means for them to protect themselves that happens to align with the interests of the user.

General, unbreakable crypto security applied to all contents is a feature that very few people ever needed or even tried to achieve. Until a few years ago you were perfectly content with keeping an agenda in your pocket and pictures in your living room's drawer. A minimum of privacy is of course needed and welcome; however, unless you're planning a major terror attack, or strategic war plans, or you have incredibly v…

> Until a few years ago you were perfectly content with keeping an agenda in your pocket and pictures in your living room's drawer.

only because they weren't (thought to be) subject to casual perusal by unknown entities. this is a silly thing to even mention.

> unless you're planning a major terror attack

ah, the "if you don't have anything to hide" rhetoric. do you really buy that?

> a level of security that he won't need

unless there is some nontrivial cost or burden associated, it's a red herring to belabor whether it's "too strong" or "more than needed".

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#382

Earlier quoted context omitted.

> iCloud backups can be secured so not even Apple can get in... I'm sure they are working on it, but it is nontrivial. There is no way they are working on this. It is an intentional design decision that Apple offers an alternative way to recover your data if you lose your password. Or if you die without telling your next-of-kin your password. Most people do not actually want all of their family photos to self-destruc…

Has Apple even given access of someone's iCloud account to next-of-kin after they died? I've never heard of this, and I don't expect Apple to be responsible to preserve photos. You already can have shared photo streams, and there are many solutions for other data that could be potentially lost that don't involve Apple getting directly involved in these cases.

Yes. http://www.cnet.com/news/widow-says-apple-told-her-to-get-co...

Shared photo streams are only a solution if they are used. Most people don't even write wills.

If you fail to write a will should the state just burn all your assets, assuming that's what you meant? No, that's the wrong default. Burn-when-I-die should be opt-in for specific assets, not the default.

And the good news is Apple is providing opt-in options like secure notes. Perhaps even backups too (3rd parties already do). But only after presenting the user with a big disclaimer informing them of the severe consequences of losing the password.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#383
post #222

Earlier quoted context omitted.

There's a reason Google decided to encrypt all communication between machines inside their datacenters.

Are you sure it's not just communication between data centres?

Probably not. FB is doing the same thing. In most cases your app or service does not actually know if the remote service it is talking to is local or in another DC. Yes, you can find out if you need to, but that requires contacting another service and introduces some delay and latency. Use a service router to try to keep the calls local to a rack or a DC, but you know that if there are problems with local cells you might get routed across the country so start with the assumption that _all_ connections get encrypted even if the connection is to localhost.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#384

Earlier quoted context omitted.

Has Apple even given access of someone's iCloud account to next-of-kin after they died? I've never heard of this, and I don't expect Apple to be responsible to preserve photos. You already can have shared photo streams, and there are many solutions for other data that could be potentially lost that don't involve Apple getting directly involved in these cases.

The idea of Apple (or some other big corporation) providing my protected personal data to my next-of-kin is more frightening than the idea that the government has the ability to spy on me while I'm alive. It's the most morbid kind of subliminal marketing that could possibly exist. "Hey, we're really sorry about fluxquanta's passing. Here is his private data which he may or may not have wanted you to see (but we'll ju…

The thing is, you can opt in to destroy-when-I-die security. You can encrypt notes or use a zero-knowledge backup provider (backblaze offers this). But for most people that's the wrong default for things like decades of family photos.

In absence of a will it would be terrible to assume that a person meant to have all their assets destroyed instead of handed down. It should be an explicit opt-in. The default should be, your stuff is recoverable and inheritable.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#385
post #358

This is all just theatre. The real motivation is to control the platform: to ship a piece of hardware that dictates who can install stuff on it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access. Since 197X, people had home computers (and institutional computers for two decades before that) on which the FBI could install anything they want, if that equ…

>it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access. How do you plan to flash all the HDD/USB/Network controllers? Not to mention the CPU/GPU microcode, and countless other random chips inside your computer that are executing firmware you have no access to. We're already hosed. Its just a matter of whats considered a 'reasonable' barrier.

If I have no access to the firmware, but neither does anyone else, then it's just a part of the hardware. That is okay.

I don't care whether a given processor is microcoded via a tiny ROM, or whether it is all hard-wired gates; the difference is just in the instruction execution timings.

We are not "hosed" in any way by this.

As soon as the microcode is writable, then we have questions: can anyone write any arbitrary microcode and put it in place? Or is there some tamper-proof layer containing that only accepts signed microcode, and who has the keys?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#386
post #376

Earlier quoted context omitted.

That argument doesn't hold water . If you're using a breakable crypto , you're not protected at any given time. If you're using a watch that's waterproof up to 100m, you're safe up to 100 meters.

I'm sorry, I might be wrong here, but I thought that any cryptographic system is breakable, given enough time and resources. If this is true, then, according to your statement, you're never protected. Therefore you can just transmit and store plain data without any cryptography, isn't it the same?

There's an idea used in crypto commonly called "reasonable security". Anything is possible given an computationally unbounded adversary, but the point of strong crypto is to make it such that cracking the crypto takes an "unfeasible amount" of time. Crypto isn't some spectrum like waterproofing is, it's binary: either broken or it's "will be broken".

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#387
post #376

Earlier quoted context omitted.

That argument doesn't hold water . If you're using a breakable crypto , you're not protected at any given time. If you're using a watch that's waterproof up to 100m, you're safe up to 100 meters.

I'm sorry, I might be wrong here, but I thought that any cryptographic system is breakable, given enough time and resources. If this is true, then, according to your statement, you're never protected. Therefore you can just transmit and store plain data without any cryptography, isn't it the same?

Any watch can be breached by water, given enough time and pressure. Most watches would not survive very long at the bottom of the Marianas Trench. Similarly, most watches would not survive a few centuries in a shallow pool, even if rated for much deeper immersion.

Although no watch can be absolutely waterproof, not even at a given depth, there are levels of risk one can accept. A watch you can use at 100m for several hours a day is effectively waterproof if that's the harshest treatment the watch will receive.

Similarly, although no cryptographic system is absolutely unbreakable^, there are levels of risk one can accept. And, unlike with watches, we can design cryptographic systems which, except in the face of unforeseen mathematical breakthroughs, or bugs (or backdoors) in their implementation, cannot be broken in the next few hundred years even by a nation state-level attacker.

I think is it reasonable to describe a cryptographic system that can't be broken within the lifetime of anyone alive today as "unbreakable".

^ Except maybe one-time-pads, depending upon how "unbreakable" is defined.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#388
post #357

Earlier quoted context omitted.

It's not clear that it IS a short-term benefit. Poll results are mixed (although the wording has a significant impact on the results) and a leading presidential candidate is calling for a boycott of their products. Marketing campaigns tend to be less polarizing. Also, I would imagine that losing the case would negatively impact sales more than if they had quietly complied.

Polls say whatever the poll-maker wants. Ask people if they support government surveillance, they say "Sure." Ask if they want the government to be able to access their Dick-Pics and the answer is a resounding NO[1]. Apple is on the right side of history here. [1] https://www.youtube.com/watch?v=XEVlyP4_11M

Right, but the question here is of the obvious short-term marketing benefit, which to me is not that obvious. I think that in the short term Apple has more to lose financially by not aiding the FBI in an emotionally-charged request than if they had silently complied, particularly if they end up losing the case.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#389
post #376

Earlier quoted context omitted.

I'm sorry, I might be wrong here, but I thought that any cryptographic system is breakable, given enough time and resources. If this is true, then, according to your statement, you're never protected. Therefore you can just transmit and store plain data without any cryptography, isn't it the same?

Any watch can be breached by water, given enough time and pressure. Most watches would not survive very long at the bottom of the Marianas Trench. Similarly, most watches would not survive a few centuries in a shallow pool, even if rated for much deeper immersion. Although no watch can be absolutely waterproof, not even at a given depth, there are levels of risk one can accept. A watch you can use at 100m for several…

Your comment (and its sibling) substantially agree with what I wrote - there isn't absolutely unbreakable cryptography, only reasonably secure. Therefore the parent doesn't make sense.

Now, is a cryptography that can't be broken by anyone except maybe (that hasn't even happened yet) through a specific court order signed by a judge, reasonably secure? I think it qualifies as such. If you need even more security, I'm sure you can use specialized software to achieve it - I'm not saying you shouldn't be allowed to.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#390
post #376

Earlier quoted context omitted.

I'm sorry, I might be wrong here, but I thought that any cryptographic system is breakable, given enough time and resources. If this is true, then, according to your statement, you're never protected. Therefore you can just transmit and store plain data without any cryptography, isn't it the same?

There's an idea used in crypto commonly called "reasonable security". Anything is possible given an computationally unbounded adversary, but the point of strong crypto is to make it such that cracking the crypto takes an "unfeasible amount" of time. Crypto isn't some spectrum like waterproofing is, it's binary: either broken or it's "will be broken".

Please see the reply to your comment's sibling, they say substantially the same thing.
Post reply on HN