Live data from Hacker News

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

404media.co

531–540 of 565 posts

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#531

Earlier quoted context omitted.

I'll bite. Why is it so terrible? I'm browsing this site right now on my phone and don't see the horror.

Phone networks by design track you more precisely than possible over a conventional internet connection to facilitate the automatic connection to the nearest available network. Also, for similar reasons it requires the phone network to know that it is your phone

The phone network already needs to know where your phone is to be able to route incoming calls.

Also, I don't get how the situation with your home internet connection changes much. Your ISP knows exactly where you are because your house doesn't move.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#532
post #531

Earlier quoted context omitted.

Phone networks by design track you more precisely than possible over a conventional internet connection to facilitate the automatic connection to the nearest available network. Also, for similar reasons it requires the phone network to know that it is your phone

The phone network already needs to know where your phone is to be able to route incoming calls. Also, I don't get how the situation with your home internet connection changes much. Your ISP knows exactly where you are because your house doesn't move.

Right, but for most people you can reasonably be expected to be in your house so it isn't that big of a security risk

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#533

Earlier quoted context omitted.

> faulty fingerprint sensor The fingerprint sensor does not make access control decisions, so the fault would have to be somewhere else (e.g. the software code branch structure that decides what to do with the response from the secure enclave).

If you're interested in this in more detail, check this out: https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/

This is a great read, but note that it's specific to Windows and Dell/Lenovo/Microsoft.

Apple does it different(ly), and I'd argue more securely. Being able to specify the full chain of hardware, firmware, and software always has its advantages.

Apple's fingerprint readers do not perform authentication locally -- instead the data read from the sensor (or derivatives thereof) is compared to a reference which is stored in the secure enclave in the Apple silicon (Ax Tx or Mx) of the Mac or iOS device itself.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#534

Earlier quoted context omitted.

They can refuse, and they have refused. See San Bernardino and the concept of "compelled work".

That was the old US law, not the one where Tim Cook delivered gold bars to Trump

It remains the US law, and you are wrong about everything in your short sentence.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#535
post #420

Earlier quoted context omitted.

[flagged]

> The US taxpayer has no moral obligation to send welfare "around the world". I mean, by way of the atrocities we've committed around the world, we kinda do. Even if we buy your thesis, foregoing morals, geopolitics, and history, it's a useful soft power strategy... I'm not saying fund USAID before healthcare for all in america. I'm saying of all the insane things our government wastes money on, USAID was far down on…

>I mean, by way of the atrocities we've committed around the world, we kinda do.

I've committed no atrocities. Going to guess that you've committed no atrocities. What atrocities did occur, most of those who committed those are dead, the rest are senile in nursing homes. I have no guilt and certainly feel no guilt for those events.

>it's a useful soft power strategy.

Sure, if you're some sort of tyrant. I thought the left was against colonialism... but you guys really just one a more clever, subtle colonialism eh? Figures.

>I'm saying of all the insane things our government wastes money on, USAID was far down on the list of most egregious.

What you're saying is that no cuts can or should be made, unless they are your favorite cuts first. And maybe after you get those, no others need be made at all.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#536

Earlier quoted context omitted.

Is the knowledge of which finger to use protected as much as a passcode? Law enforcement might have the authority to physically hold the owner's finger to the device, but it seems that the owner has the right to refuse to disclose which finger is the right one. If law enforcement doesn't guess correctly in a few tries, the device could lock itself and require the passcode. Another reason to use my dog's nose instead…

I really wish Apple would offer a pin option on macos. For this reason, precisely. Either that, or an option to automatically disable touchid after a short amount of time (eg an hour or if my phone doesn't connect to the laptop)

I often see people use a "pin" on Windows and I never got it. What is the purpose of a pin makes it different from a password?

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#537
post #408

Earlier quoted context omitted.

I'd be wary of trying this as it reeks of "one neat trick" thinking applied to law based on a small technicality where law is often subject to the spirit instead of strictly hewing to the most favorable interpretation the exact wording for the citizen. The warrant can just state you're required to unlock the system not simply "make your fingers available". It's fun to try to find places where the rules seem to leave…

No, it's literally based on existing boilerplate language that's already commonly associated with these warrants based on previous litigation. Making your body parts available is not testimonial, answering "Which finger?" undoubtedly is.

> answering "Which finger?" undoubtedly is.

Unless that's already established in your circuit you're counting on the court agreeing with your interpretation because the cops/courts certainly think they can compel that.

All I'm doing is cautioning you and anyone else reading against DIY legal interpretations. Have a lawyer.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#538

Earlier quoted context omitted.

https://www.bleepingcomputer.com/news/legal/man-who-refused-...

It took 4 years. What is your point?

That you don't want to be in jail for 4 years for not providing the key?

I personally don't want to say "oh but my liberty", in a jail cell. Whatever floats your boat though.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#539
post #537

Earlier quoted context omitted.

No, it's literally based on existing boilerplate language that's already commonly associated with these warrants based on previous litigation. Making your body parts available is not testimonial, answering "Which finger?" undoubtedly is.

> answering "Which finger?" undoubtedly is. Unless that's already established in your circuit you're counting on the court agreeing with your interpretation because the cops/courts certainly think they can compel that. All I'm doing is cautioning you and anyone else reading against DIY legal interpretations. Have a lawyer.

From the warrant:

>During the execution of the search of HANNAH NATANSON as described in Attachment A-3, law enforcement personnel are authorized to (1) press or swipe the fingers (including thumbs) of HANNAH NATANSON to the fingerprint scanner of the device; (2) hold a device found during the search in front of the face of HANNAH NATANSON and activate the facial recognition feature, for the purpose of attempting to unlock the device in order to search the contents as authorized by this warrant.

>While attempting to unlock the device by use of the compelled display of biometric characteristics pursuant to this warrant, law enforcement is not authorized to demand that an occupant state or otherwise provide the password or identify the specific biometric characteristics (including the unique fingers) or other physical features), that may be used to unlock or access the device(s). Nor does the warrant authorize law enforcement to use the fact that the warrant allows law enforcement to obtain the display of any biometric characteristics to compel an occupant to state or otherwise provide that information. However, the voluntary disclosure of such information by an occupant is permitted. To avoid confusion on that point, if agents in executing the warrant ask an occupant for the password to any device(s), or to identify which biometric characteristic (including the unique fingers) or other physical features) unlocks any device(s), the agents will not state or otherwise imply that the warrant requires the person to provide such information, and will make clear that providing any such information is voluntary and that the person is free to refuse the request.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#540
post #481

Earlier quoted context omitted.

Good idea, but this is why you image devices.

Sorry I explained it poorly and emphasized the wrong thing. The way it would work is not active destruction of data just a different view of data that doesn’t include any metadata that is encrypted in second profile. Data would get overwritten only if you actually start using the fallback profile and populating the "free" space because to that profile all the data blocks are simply unreserved and look like random dat…

The main point is logging in to the fake profile does not do anything different from logging in to the main profile. If you image the whole thing and somehow completely bypass secure enclave (but let's assume you can't actually bruteforce the PIN because it's not feasible) then you enter the distress PIN in controlled environment and you look at what writes/reads it does and to where, even then you would not be able to tell you are in the fake profile. Nothing gets deleted eagerly, just the act of logging in is destructive to overlapping profiles. This is the only different thing in the main profile. It know which data belongs to fallback profile and will not allocate anything in those blocks. However it's possible to set up the device without fallback profile so you don't know if you are in the fallback profile or just on device without one set up.

Hopefully I explained it clearly. I haven't seen this idea anywhere else so I would be curious if someone smarter actually tried something like that already.

Post reply on HN