Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

391–400 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#391
post #305

I've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want…

I wonder if Microsoft came out with Palladium ( https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi... ) today, if it would be hailed as a great development for privacy or would still garner lots of criticism as it did 10 years ago. Of Palladium, Bruce Scheier said: > "There's a lot of good stuff in Pd, and a lot I like about it. There's also a lot I don't like, and am scared of. My fear is that Pd will lead…

> I think his fears have come true to some extent in iOS, but knowing what we know now about government surveillance of everybody, it may no longer seem like too great a price to pay.

We're already paying that price, essentially. An iPhone won't run arbitrary code, a replacement OS, or accept code from arbitrary sources. It's already an exclusively vendor-curated platform. If you're already going to buy into that model, I don't see the point in not going for the greatest amount of protection that you can get. (OK, yes, a dev can compile their own code and push it to their own device. I'm actually not sure why I don't hear about this happening more often as a way to run "unacceptable" programs on iOS devices).

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#392
post #358

Earlier quoted context omitted.

>it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access. How do you plan to flash all the HDD/USB/Network controllers? Not to mention the CPU/GPU microcode, and countless other random chips inside your computer that are executing firmware you have no access to. We're already hosed. Its just a matter of whats considered a 'reasonable' barrier.

If I have no access to the firmware, but neither does anyone else, then it's just a part of the hardware. That is okay. I don't care whether a given processor is microcoded via a tiny ROM, or whether it is all hard-wired gates; the difference is just in the instruction execution timings. We are not "hosed" in any way by this. As soon as the microcode is writable, then we have questions: can anyone write any arbitrary…

>If [...] but neither does anyone else, then it's just a part of the hardware

That has never been the case, for practical manufacturing reasons.

>As soon as the microcode is writable, then we have questions:

It has been writable for more than a decade I think.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#393
post #389

Earlier quoted context omitted.

Any watch can be breached by water, given enough time and pressure. Most watches would not survive very long at the bottom of the Marianas Trench. Similarly, most watches would not survive a few centuries in a shallow pool, even if rated for much deeper immersion. Although no watch can be absolutely waterproof, not even at a given depth, there are levels of risk one can accept. A watch you can use at 100m for several…

Your comment (and its sibling) substantially agree with what I wrote - there isn't absolutely unbreakable cryptography, only reasonably secure. Therefore the parent doesn't make sense. Now, is a cryptography that can't be broken by anyone except maybe (that hasn't even happened yet) through a specific court order signed by a judge, reasonably secure? I think it qualifies as such. If you need even more security, I'm s…

Strictly, it is not the cryptography being broken in this case. The FBI want to guess a (possibly) six-digit pin. The iPhone might have been configured to erase its data on 10 failed PIN attempts, so the current odds are not good. To this end, the FBI want Apple to produce a version of iOS that bypasses this restriction, and install it on the phone.

Assuming I agree that a security system that can be turned off remotely by its vendor is reasonably secure, it is only a specific court order now. If Apple are successfully compelled to produce a version of iOS that bypasses PIN security, it will be much easier for the FBI to request that it be deployed on phones in the future - after all, that version of iOS will already exist then.

If Apple do make it, I am certain there will quickly be a slew of court orders regarding other iDevices that the authorities have in their possession, all of which are likely to be harder to defeat than the court order they would just have failed to defeat.

However, I don't agree that a security system that can be turned off remotely by its vendor is reasonably secure, anyway. There is nothing technically requiring Apple to wait for a court order: the phone will accept their new software whether or not it comes with a court order. Apple could decide to make PIN cracking available to anyone who can prove they own a given iPhone. Given their attitude, they probably won't, but the actual security mechanism is reliant on their goodwill for it to remain unbroken. I don't consider that reasonable.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#394
post #389

Earlier quoted context omitted.

Your comment (and its sibling) substantially agree with what I wrote - there isn't absolutely unbreakable cryptography, only reasonably secure. Therefore the parent doesn't make sense. Now, is a cryptography that can't be broken by anyone except maybe (that hasn't even happened yet) through a specific court order signed by a judge, reasonably secure? I think it qualifies as such. If you need even more security, I'm s…

Strictly, it is not the cryptography being broken in this case. The FBI want to guess a (possibly) six-digit pin. The iPhone might have been configured to erase its data on 10 failed PIN attempts, so the current odds are not good. To this end, the FBI want Apple to produce a version of iOS that bypasses this restriction, and install it on the phone. Assuming I agree that a security system that can be turned off remot…

> If Apple are successfully compelled to produce a version of iOS that bypasses PIN security

this would seem a rather scary precedent of forced, unwilling labor. i wonder if it could be construed as "involuntary servitude".

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#395

Earlier quoted context omitted.

The idea of Apple (or some other big corporation) providing my protected personal data to my next-of-kin is more frightening than the idea that the government has the ability to spy on me while I'm alive. It's the most morbid kind of subliminal marketing that could possibly exist. "Hey, we're really sorry about fluxquanta's passing. Here is his private data which he may or may not have wanted you to see (but we'll ju…

The thing is, you can opt in to destroy-when-I-die security. You can encrypt notes or use a zero-knowledge backup provider (backblaze offers this). But for most people that's the wrong default for things like decades of family photos. In absence of a will it would be terrible to assume that a person meant to have all their assets destroyed instead of handed down. It should be an explicit opt-in. The default should be…

> But for most people that's the wrong default for things like decades of family photos.

That seems like a weird assumption, that there'd be a single person with access to an account containing the only copies of decades of family photos. If someone else has account access or if there are copies of the photos elsewhere, then "destroy-when-I-die" isn't a big problem.

On the other hand, it also violates the way that I think things would usually work in the physical world. That is, if there's a safe that only the deceased had the combination to, I can still drill it to access the contents.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#396

Earlier quoted context omitted.

The only statement I could find from Apple was from the iOS security guide that states, "it utilizes its own secure boot and personalized software update separate from the application processor." I think we can both agree that's a pretty vague statement, if you have a better source I'd like to see it.

A former Apple engineer said on Twitter: "@AriX I have no clue where they got the idea that changing SPE firmware will destroy keys. SPE FW is just a signed blob on iOS System Part" https://twitter.com/johnhedge/status/699882614212075520 Then Apple seems to confirm it: "The executives — speaking on background — also explicitly stated that what the FBI is asking for — for it to create a piece of software that allows a…

I understand that the boot chain is the only way Apple may modify the behaviour of the Enclave but how would the update be forced? DFU wipes the class key, making any attempt at trying to brute force the phone, useless. If debug pinout access is available, then why does FBI needs Apple to access the phone at all?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#397

A lot of the comments on that article burn me up. People in the U.S. really think there's a terrorism problem here. The only problem is that government spending so much money on a non-issue! Politicians love to "debate" it because they know it is one of those things that looks good to the naive citizens but they really don't have to do anything because there's nothing to be done.

> People in the U.S. really think there's a terrorism problem here

out of curiosity, what evidence is there that there isn't?

perhaps i should ask what you mean by "a terrorism problem" as well.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#398
post #371
post #315

Earlier quoted context omitted.

General, unbreakable crypto security applied to all contents is a feature that very few people ever needed or even tried to achieve. Until a few years ago you were perfectly content with keeping an agenda in your pocket and pictures in your living room's drawer. A minimum of privacy is of course needed and welcome; however, unless you're planning a major terror attack, or strategic war plans, or you have incredibly v…

I am not sure why this comment (and all Udik's comments) is being downvoted into oblivion. This is the view of the US government and quite likely a vast majority of citizens here (and, I would guess, in many countries). This morning I was having a conversation with my fiancee, who said "if the US government gets a warrant they can open your mail, they can tap your phone calls, they can come into your house and search…

It might not be the most constructive way of doing things, but people tend to downvote comments they disagree with.

As to why they disagree: HN's audience is not representative of the general citizenry. We're better informed about technical security matters (or we like to think we are, at least). I suspect that correlates with being less willing to trust security to the goodwill of third parties.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#400

Earlier quoted context omitted.

Oh, OK. That makes more sense. As I said to other commenter, I'm not doing enough research to figure out how they're hacking it directly. There's so many published hacks of hardware and firmware that were designed for secure operation that it would be a miracle if they didn't have something on iPhones. It's more a "insecure-by-default" if it doesn't address what's on my list of attack vectors. I know it doesn't becau…

Gotcha. I agree that there are a lot of potential security issues present on the iPhone, and if I was a terrorist (or my name was Edward Snowden) I would definitely act as if they were already hacked by the NSA/FBI/whomever. However, your original comment made it sound like we had direct confirmation of that fact. I hadn't heard that before, which is why I was interested.

I figured that's what you were wondering. Nah, it would take new leaks for us to know about that. Gets less likely as they put their people under more intense scrutiny.
Post reply on HN