Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

41–50 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#41
post #34

Earlier quoted context omitted.

If I find a vulnerability and exploit someone's device, it's not okay under law. Why is a government institution exempt from law in a supposedly exemplary democracy?

Because it's not someone's device anymore. It's government evidence?

It was the county's device to start with, too. Not the shooter's.

Re: Your iPhone just got less secure. Blame the FBI

#42
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module.

The problem here is that we're all just speculating. We suspect this to be the case, but we can't be sure. And we probably never will be.

To take this a step further, the FBI has also learned the lesson to never take this public again. If you are worried about law enforcement attacks against any device protected by they signing keys of a US company, it is only prudent for you to ASSUME that a FISA court has or will soon compromise the signing keys of your device. Jonathan Zdziarski has already shown the enclave to be useless in this case of compromised keys.

At this point, the work being done by Joanna Rutkowska, Coreboot, Purism, and others are our only hope now. And even there, we'll never own our chipsets, ethernet controllers, or CPUs.

May as well give up, we've already lost.

Re: Your iPhone just got less secure. Blame the FBI

#43

Why did the FBI drop the lawsuit against Apple in the first place? They both made it sound like the stake was much higher than unlocking the one device. Or, the FBI managed to unlock this phone and so they can unlock any other devices too, now-and-forever? They don't need a backdoor any more? Wouldn't the logical next step from Apple's side be to protect their users in their future devices? Wouldn't then the FBI have…

It's a writ. It is legally only valid if there is necessity and the court must be informed if that changes.

Re: Your iPhone just got less secure. Blame the FBI

#44

Your iphone just got less secure - so don't use iphones anymore. It always amazes me when people get on their high horse and start complaining about something when the remedy is quite simple - don't use the iphone. Get an Android phone, or an Ubuntu phone, or a Blackphone or a Windows phone. There's plenty of other devices that haven't been cracked by the FBI. There's irony in the fact Apple resisted the FBI attempts…

I just found out the other day that if you use any "Accessibility features" on an android phone, your device's encryption password changes to a default, effectively disabling encryption until you turn those features off again.

Furthermore, it's not immediately clear that you're disabling encryption when you do that.

So all in all, and for other reasons listed, I believe iPhone is probably the better bet at the moment for secure hardware.

Re: Your iPhone just got less secure. Blame the FBI

#45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier.

However, I'll defend his point: take the Monty Hall problem [https://en.wikipedia.org/wiki/Monty_Hall_problem]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened.

I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability, and that knowledge makes everyone's device less secure [for a variety of reasons -- eg others know to look for the vulnerability, others know it can be bought, etc]. It doesn't matter that the vulnerability "has always been there" if nobody knew about it.

Re: Your iPhone just got less secure. Blame the FBI

#46

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

It seems to me that Tim Cook and the FBI understand each other very well. They just don't care about the same things.

Former CIA and NSA Director Michael Hayden clearly understands the issues. I saw an interview where he stated that the FBI was correct to want access (it makes their job easier) and that we shouldn't give it to them (he understands that a backdoor will be used in ways other than intended). The point being that people on the government side aren't just naive, ignorant administrators.

I think the problem with a lot of national issues isn't the players lacking an understanding of the nuances, it's that people in general aren't very receptive to nuance. That makes it a losing strategy to try to address it.

Re: Your iPhone just got less secure. Blame the FBI

#47
post #35

Schneier knows this, and this is a particularly idealistic op-ed, but this is just how the exploit market works and while it would be nice if law enforcement would take the white-hat road, the hazard here is still vastly better than some kind of legal precedent for requiring backdoors. The good thing about the exploit market is that it is naturally self-limiting: you don't burn a zero-day on a dragnet; you limit its…

There's a bit of irony to this, too. If Apple had been more cooperative earlier, law enforcement probably would've taken the white hat approach. Apple protected users from the FBI, but is now potentially unable to protect them from organised crime.

There is absolutely no proof of that. What they where asking for was keys to every lock in the world. It would have given them unprecedented power to do whatever they wanted. Apple did the right thing. Users should always come first especially when privacy is at stake.

Re: Your iPhone just got less secure. Blame the FBI

#48
post #20

I find this rather silly. iPhones didn't get less secure because the FBI used a known vulnerability to break into one. iPhones were that insecure all along, and the only thing that changed is that we now know it. The article further states, "There’s no such thing as a vulnerability that affects only one device." Except that I'm pretty sure that whatever attack the FBI used relied on the fact that the phone in questio…

This is pedantic in my opinion. The main point of the article was that the FBI found a vulnerability. So before it was likely an unknown vulnerability, now it is known by law enforcement. The whole point of the article was that responsible organizations disclose vulnerabilities so that companies can make their software/hardware more secure. In this case the FBI is sitting on it, so they can continue to use it. Last week the FBI couldn't break into my iPhone. Now they /might/ be able to (it's a 6, so who knows if it is fixed). And Apple can't fix what they don't know about. Therefore, my confidence in the security of my iPhone has diminished, and it may be less secure than it was last week.

Re: Your iPhone just got less secure. Blame the FBI

#49
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

>The iPhone did not get less secure. It has always had this security hole.

Although given the fact that it was made public that they found a security hole, won't that change the behavior of malicious actors? Now that it's known that a hole exists, more people will start looking for it, reducing security through obscurity.

Re: Your iPhone just got less secure. Blame the FBI

#50
post #17

Is this just FUD? Simply confirming the vulnerability seems likely to lead to it being plugged, whether or not the FBI reveals their methods, in effect doing the opposite of what the title suggests.

How can it be plugged, if Apple doesn't know what it is?
Post reply on HN