Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

51–60 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#51
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. The problem here is that we're all just speculating. We suspect this to be the case, but we can't be sure. And we probably never will be. To take this a step further, the FBI has also learned the lesson to never take this public again. If you are worried about law enforcement attacks against any device protected by…

> And we probably never will be.

Investigation is either made completely public after the fact or partially marked secret for certain years. Now if someone intentionally hide the investigation details, well, that's a whole different story and I wouldn't be surprised at all. Writer chooses what to write in their investigation log reports.

Anyway, we really don't know what method they used to gather the information and what kind of information they pulled off for sure.

Re: Your iPhone just got less secure. Blame the FBI

#52
Schneier has never had a strong intuition for how software vulnerabilities work. In the 2000s, he wrote articles in his newsletter blaming eEye (a security research firm then the home of Derek Soeder, Barnaby Jack, Ryan Permeh, and the like) for publishing their vulnerability research. He is at turns anti-disclosure, pro-disclosure, and all points in between.

Re: Your iPhone just got less secure. Blame the FBI

#54
post #45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

That was an excellent analogy.

Re: Your iPhone just got less secure. Blame the FBI

#55

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

I agree with you, and I think this will eventually lead to a world where governments are unable to exert meaningful influence on large corporations. We're already starting to get there; I have a feeling that if the supreme court had forced Apple to write a custom version of iOS that things could have gotten really messy very quickly -- there were rumors that Apple's entire iOS engineering team was ready to resign if the case went the wrong way. It's plausible to see a scenario where Apple says "You know what? Fuck it, we're based in Ireland now."

Ultimately, I don't think governments are designed to deal with corporations that make as much money as a company like Apple does. These companies are the size of governments -- if Apple decided it wanted to hire a bunch of mercenaries and take over a small country, it could probably do so (if it didn't mind getting embargoed by whoever was friendly to the country they took over).

I wouldn't be surprised to see corporate sovereignty become a big international issue in our lifetimes. International law is a huge grey area, and I expect companies to exploit that to their advantage to avoid enforcement actions by individual nations.

Re: Your iPhone just got less secure. Blame the FBI

#56
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

> This is bad reporting.

I felt the same way when I hit the article link, but changed by mind when Bruce Schneier made the more nuanced argument.

Of course the vulnerability already existed. That's not what he has a problem with: the problem is that now there is a commercially-known but secret vulnerability. Which is a different thing than an unknown vulnerability.

Newer hardware revisions, etc etc, but the biggest issue he takes is that the US government is supporting this practice (and in doing so basically acting like malware authors). Again, that may be realpolitik, but isn't something that we should support as a policy position.

Re: Your iPhone just got less secure. Blame the FBI

#57
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

>The iPhone did not get less secure. It has always had this security hole. Although given the fact that it was made public that they found a security hole, won't that change the behavior of malicious actors? Now that it's known that a hole exists, more people will start looking for it, reducing security through obscurity.

A concrete example of this happening would be when the NSA's catalog of implants and general descriptions of what they could do was released, and a large flurry of public (and probably private) activity surrounding rediscovering the wheel ensued.

It's a lot easier to build something when you have a loosely-constrained search space and a guarantee that it's possible, than to discover something entirely new.

Re: Your iPhone just got less secure. Blame the FBI

#58
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

I believe that his point is that the non-disclosure affects the security of other similar devices, especially those that can still be patched.

Re: Your iPhone just got less secure. Blame the FBI

#59

Your iphone just got less secure - so don't use iphones anymore. It always amazes me when people get on their high horse and start complaining about something when the remedy is quite simple - don't use the iphone. Get an Android phone, or an Ubuntu phone, or a Blackphone or a Windows phone. There's plenty of other devices that haven't been cracked by the FBI. There's irony in the fact Apple resisted the FBI attempts…

I don't believe even for a second that Android devices are any more secure than iPhones. And I use an android phone. But let's be honest - with dozens of manufacturers there isn't a single one who dedicated the same amount of work to securing their devices or engineering things like the secure enclave in iPhones. I use a Sony phone but I'm sure Sony wouldn't have the guts to stand up to FBI, or that FBI would even ne…

Apparently Windows Mobile is getting some attention for being quite secure:

Windows Phone security is top notch, says Kaspersky - http://betanews.com/2015/06/11/windows-phone-security-is-top...

Microsoft may have the most secure smartphone OS in Windows Phone - http://www.neowin.net/news/microsoft-may-have-the-most-secur...

Windows Phone is the most secure mobile OS says white hat hacker - http://www.techworm.net/2015/11/windows-phone-is-the-most-se...

Re: Your iPhone just got less secure. Blame the FBI

#60

To be clear, the FBI isn't compelling Apple to leave the vulnerability open, are they? My understanding is they simply found/were informed of a vulnerability that existed in this model of the phone, and are not informing Apple of it. If Apple themselves finds the vulnerability and patches it, the FBI can't do anything about it.

Correct. And to be fair, the FBI could have received the vulnerability from a foreign state that is also opposed to terrorism but did not want their identity or methods known.

ie they may have reasons for not disclosing the vulnerability, and it's a shame that there's so much mistrust of the government [caused by actions of the government] so that we can't assume the best.

Post reply on HN