Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

51–60 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#51
post #7

Don't they just need to tell people to switch away from 4 or 6 digit pins and use longer passwords?

Does anyone know if it re-encryptes the data after I change my passphrase? In other words, am I immediately more secure if I switch from a 6 digit pin to a passphrase?

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#52
post #9

Earlier quoted context omitted.

Surely it is a company's best interests to have 'good enough' looking security to serve their PR purposes while also secretly providing government access to maximise government kudos and all the benefits that would entail?

The counter-argument would be that that opens you up to catastrophic exposure when Snowden 2.0 releases the data.

So the backdoor is built in such a way that Apple could have strong deniability. The NSA already did this with EC-DRBG.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#53
post #26

Earlier quoted context omitted.

If they have access to a live finger for the TouchID, sure they can bypass - but they could do that with the $5 guaranteed coercion method as well [1]. Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer. All bets are off if the iPhone is power-cycled. Best bet i…

Is it only five fails on TouchID to delete data? I don't have the option to delete the data enabled on my iPhone... but it often takes more than five tries to just get it to work on my finger that is legitimately registered in touchID.

No, it's five fails before Touch ID stops working until after a passcode is entered again.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#54
post #16

Earlier quoted context omitted.

If the has been switched off or if >48h passed since the last unlock. Also remember that rubber-hose cryptanalysis is always an option.

Can you be convicted in the US based on evidence obtained with physical torture? Edit: Looks like the answer is it depends and not a resounding no http://www.nolo.com/legal-encyclopedia/evidence-obtained-thr...

No, you cannot. Evidence derived from facts learned from torture is also excludable.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#55
post #26

Earlier quoted context omitted.

If they have access to a live finger for the TouchID, sure they can bypass - but they could do that with the $5 guaranteed coercion method as well [1]. Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer. All bets are off if the iPhone is power-cycled. Best bet i…

Is it only five fails on TouchID to delete data? I don't have the option to delete the data enabled on my iPhone... but it often takes more than five tries to just get it to work on my finger that is legitimately registered in touchID.

After five failures the you cannot use Touch ID to unlock and will instead need the passcode to access the phone again. This means that any approach to fooling the fingerprint reader will need to be done within five tries.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#56

Any device that relies on hiding secrets inside the silicon itself is subject to hacking. Several secure-enclave like chips have been hacked in the past by using electron microscopes and direct probes on the silicon. If BlackHat conference independent security researchers have the resources to pull this off, Apple and the NSA certainly can. Exfiltrating the Enclave UID could be done by various mechanisms at the chip…

I upvoted because I think you are absolutely correct. Better security could be had with a two-factor system -- plug the phone into a cryptobox to decrypt. Having everything in one place is vulnerable.

If you need to plug the phone into the cryptobox to decrypt it, they're going to be in one place anyway.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#57
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

> When someone passes away, for example, it would be a terrible compounding tragedy if all their photos from their whole life passed away along with them, because they didn't tell anyone their password or where they kept the backup key.

Would you really expect Apple to recover the data in this scenario for the next of kin? I certainly wouldn't, and I wouldn't want them to.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#58
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

>If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? That probably also means removing most debugging connections from the physical chip, and making extra sure you can't modify secure enclave memory even if you desolder the phone.

A lot of that stuff was already in the original threat model for the Secure Enclave ("assume the whole AP is owned up").

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#59

Earlier quoted context omitted.

I wish Apple would start pushing passphrases. Easy enough to remember, plenty strong, already usable with the current system on iphones.

Nobody would adopt them. It's annoying enough to deal with 4 digits when it's cold and I'm wearing gloves and I just want to change the song I'm listening to. Passphrases suck enough whenever you have to log back in. Are people really gonna put up with that every time they want to use their phone? On the other hand, if there were a convenient way to toggle between passphrases and 4-digit unlock, (especially if you ha…

Not really. Have the option to set both a long passphrase and a PIN code.

The long passphrase is used to mount the encrypted file system upon startup, and the PIN code is used merely as a "screen lock", as a casual deterrent from your friends and casual thieves from swiping through your photos before you can catch them.

The file system can be automatically unmounted after a set period of inactivity, or if the user wants to unmount it on demand. After the file system is unmounted, the data is secure again and the long passphrase will once again be needed before anything can be done with the phone.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#60
post #47

Earlier quoted context omitted.

No, although I'd love to see a HealthKit app that uses your Apple Watch as a dead man's switch, and disables Touch ID or powers the phone off in the event the watch is removed or your pulse is no longer detected.

That wouldn't work well with loose wrists and other similar edge cases.

Then those people could turn it off. But it would be a nice option.
Post reply on HN