Live data from Hacker News

A Message to Our Customers

apple.com

491–500 of 1001 posts

Re: A Message to Our Customers

#491

Earlier quoted context omitted.

+1. If it is possible to push software updates to a "locked" phone then is this not tantamount to remote code execution with root privileges, and hence the BACKDOOR ALREADY EXISTS? "Locked" seems like an improper term for such a scenario. I applaud apple for appealing this case to the public however there is a HUGE HUGE difference between "we can't unlock" and "we shouldn't unlock". This distinction will likely be lo…

No. The word "remote" is not applicable to an attack that only works with physical possession of the device. As far as I'm aware there is no known technique to prevent someone with physical access, a bunch of engineers, and the code signing keys from replacing firmware.

"locked" is a relative term. Anything encrypted can be broken with enough effort. But that is the semantic difference between leveraging a back door and brutally busting open the front door. I want a device where there is no back door. I hope you can appreciate that difference.

Re: A Message to Our Customers

#492
Maybe I am missing something here, but the Washinton Post says "Federal prosecutors stated in a memo accompanying the order that the software would affect only the seized phone". What is so wrong with that? If they just use it only on this phone? Or is that the weapon has been created and could be used?

Re: A Message to Our Customers

#494

Maybe I am missing something here, but the Washinton Post says "Federal prosecutors stated in a memo accompanying the order that the software would affect only the seized phone". What is so wrong with that? If they just use it only on this phone? Or is that the weapon has been created and could be used?

" Or is that the weapon has been created and could be used?"

I'm pretty sure it's this. Once it's created it's only a matter of time until it's leaked and anyone can use it.

Re: A Message to Our Customers

#495
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

The government wants Apple to disable the auto-erase after so many unlock attempts. Apple argues in this letter that with modern computing power, this amounts to a backdoor. The details of the gov't request are in another story on the HN front page https://www.techdirt.com/articles/20160216/17393733617/no-ju...

[deleted]

Re: A Message to Our Customers

#496
post #464

Earlier quoted context omitted.

Pretty sure you can upgrade the OS on a locked phone if you have physical access to it.

Negative. You need the passcode.

If you lose the PIN on an iPhone you need to do a wipe and restore it from backup. You had better hope you remembered the backup password. You can't make a backup of a locked phone either.

The backup is probably easier to attack if you have it, since it doesn't have hardware imposed timeouts on password guesses. It may not be current however.

Re: A Message to Our Customers

#499
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

The government wants Apple to disable the auto-erase after so many unlock attempts. Apple argues in this letter that with modern computing power, this amounts to a backdoor. The details of the gov't request are in another story on the HN front page https://www.techdirt.com/articles/20160216/17393733617/no-ju...

The encryption key used on the root filesystem is too hard to brute force. It's not based on some crappy password that a human created, it's some hash value stored in the hardware. In a scenario like that it is easy to create a key that would require all of the computers working till the heat death of the universe to crack.
Post reply on HN