Live data from Hacker News

A Message to Our Customers

apple.com

501–510 of 1001 posts

Re: A Message to Our Customers

#501

Earlier quoted context omitted.

iCloud backups are 100% encrypted. Only some iTunes backups are not, and only if the option to use encryption to protect the backup is not selected.

They are, but apple have the keys : https://thehackernews.com/2016/01/apple-icloud-imessages.htm... So basically, they could be in clear text, it's pretty much the same.

[deleted]

Re: A Message to Our Customers

#503

Maybe I am missing something here, but the Washinton Post says "Federal prosecutors stated in a memo accompanying the order that the software would affect only the seized phone". What is so wrong with that? If they just use it only on this phone? Or is that the weapon has been created and could be used?

Apple is sayong that the federal prosecutors are wrong in this assertion.

Apple is saying that any solution that is applied to specifically this phone can trivially be generalized to all other iPhones (or, at least other iPhone 5cs). Further, unlocking this phone in response to this order establishes a precedent that this is okay. You are much better off legally if you fight the first request than if you fight the thousandth request.

Re: A Message to Our Customers

#504

I'm surprised that nobody on this thread has commented on the real substance of this response. It has nothing to do with Apple brute forcing iPhones for the police (which it has done for years, with a simple court order) - but instead, is Apple making it abundantly clear, that if they comply (or are forced to comply) with the All Writs Act of 1789 to create this particular back door, then that opens the floodgate mov…

And it'd seem to open the floodgates for certificate authorities to be compromised as well. What's to stop the FBI from compelling a CA to create a special MITM certificate for a criminal investigation of a Yahoo user?

What makes you think the FBI, or a certain assisting agency, don't already have CAs in their pocket? They only need one. The 'rogue CA' threat that encouraged the development of HPKP covers this scenario. Hell, DNS TLSA records (which are a part of the now dead DANE concept) let you pin to any combination of PKI CA, public key, or certificate. One day we'll regret not deploying this stuff.

Re: A Message to Our Customers

#506

Earlier quoted context omitted.

Negative. You need the passcode.

There is no way to recover a phone if you lose the passcode?

If you have access to the iTunes account you can do a physical backup with iTunes and then erase and restore that backup. It won't be pin protected.

Re: A Message to Our Customers

#507
post #163

Earlier quoted context omitted.

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

They didn't make any mention of how feasible it would be, just that they wouldn't even try because it would threaten the security of their users.

Let me correct it for you. "Perceived security of their users".

A lot of it about PR.

Re: A Message to Our Customers

#508
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

I'm afraid that I have to agree with you here. But Apple (and the FBI) recognize that this is the first salvo in a battle that will rage for MANY years. These early skirmishes could dis-proportionally affect the outcome - hence the ensuing PR battle.

Re: A Message to Our Customers

#510
post #159

Earlier quoted context omitted.

Once they build that in for one device then they have opened pandora's box. Then it becomes a precedent in the courts that Apple has this ability so they will issue court orders to make them comply for every single case where a phone is encrypted.

One way around that is for Apple to make it extremely costly for courts to issue many of such orders, because after all Apple are free to charge whatever they like for doing this service.

I think US govt would be kinda ok with that idea if Apple didn't park their profit overseas to avoid paying tax...
Post reply on HN