Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

61–70 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#61
post #17

Is this just FUD? Simply confirming the vulnerability seems likely to lead to it being plugged, whether or not the FBI reveals their methods, in effect doing the opposite of what the title suggests.

They confirmed a method to get in existed, but did not reveal

- what the scope of its usefulness is (particular kinds of hardware or software revisions)

- whether it still works on modern platforms

Without even a vague idea where to look or whether it's still there, it's a guarantee that _something_ existed, sometime.

Re: Your iPhone just got less secure. Blame the FBI

#62
post #45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier.

I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obligation to create vulnerabilities for the governments to exploit (on the contrary; the companies have an obligation to find and fix the holes in their products).

> It doesn't matter that the vulnerability "has always been there" if nobody knew about it.

There's no guarantee that nobody knew about it, and that's the problem. Information asymmetry is a bitch, but the safest assumption is that someone else did indeed know about it, and then told the FBI. If someone was willing to tell the FBI, it's a safe bet the security community knows about this exploit.

Also, if I was the FBI I would intentionally try to obfuscate my capabilities as much as I can. I would want people to think I can hack every iPhone at any time, even if I can't.

Re: Your iPhone just got less secure. Blame the FBI

#63
post #52

Schneier has never had a strong intuition for how software vulnerabilities work. In the 2000s, he wrote articles in his newsletter blaming eEye (a security research firm then the home of Derek Soeder, Barnaby Jack, Ryan Permeh, and the like) for publishing their vulnerability research. He is at turns anti-disclosure, pro-disclosure, and all points in between.

My understanding is that “disclosure” is a nuanced thing, time-wise: responsible disclosure is to mention the vulnerability to someone who can and is intent to fix it first, give them the time to write, test and send a patch, and then publish it. Publishing it earlier sound very unreasonable, especially before handing the details to the manufacturer.

I am not familiar with what Schneier said 15 years ago, though. He might have chastised someone for doing that; he might have changed his mind. If he hasn’t in a decade and a half, I’d be shocked.

I realised this morning that 15 years ago, I was proud of using SAS, “the most powerful analytics software there [was]”. I changed.

Re: Your iPhone just got less secure. Blame the FBI

#64
post #56
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

> This is bad reporting. I felt the same way when I hit the article link, but changed by mind when Bruce Schneier made the more nuanced argument. Of course the vulnerability already existed. That's not what he has a problem with: the problem is that now there is a commercially-known but secret vulnerability. Which is a different thing than an unknown vulnerability. Newer hardware revisions, etc etc, but the biggest i…

I guess the part I disagree with him on is that I actually expect the US government to act like malware authors. They've shown an affinity for the tactics before (using surveillance software, stingrays, etc) so it's at least perfectly consistent.

I have no expectations that the relationship between law enforcement and technology companies will improve. I guess I've just accepted this situation as the "new normal".

Re: Your iPhone just got less secure. Blame the FBI

#65
post #24

I am sure they just hired some interns to code = 0000 While code_is_valid not true: enter code reboot device code++ Edit: I am pretty sure there's a delay in code execution registering a wrong pin hence by rebooting the phone, the wrong pins won't get detected.

Good one, though I can see there is a problem with this "algorithm"! haha :-)

What might it be?

I assumed the code is just 4 digits long but judging by the quick downvotes people aren't even considering this to be a possibility.

Re: Your iPhone just got less secure. Blame the FBI

#66

Schneier knows this, and this is a particularly idealistic op-ed, but this is just how the exploit market works and while it would be nice if law enforcement would take the white-hat road, the hazard here is still vastly better than some kind of legal precedent for requiring backdoors. The good thing about the exploit market is that it is naturally self-limiting: you don't burn a zero-day on a dragnet; you limit its…

> ...you don't burn a zero-day on a dragnet;

A for-profit entity shouldn’t.

I’m not sure the FBI has the same objectives. If they do, I’m sure Apple would be happy to pay market-prices for that vulnerability.

Re: Your iPhone just got less secure. Blame the FBI

#67
post #58
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

I believe that his point is that the non-disclosure affects the security of other similar devices, especially those that can still be patched.

That's the entire purpose of the FBI not disclosing this information though. Government agencies engage in game theory as well, and information asymmetry is a powerful tool.

Re: Your iPhone just got less secure. Blame the FBI

#68

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

It seems to me that Tim Cook and the FBI understand each other very well. They just don't care about the same things. Former CIA and NSA Director Michael Hayden clearly understands the issues. I saw an interview where he stated that the FBI was correct to want access (it makes their job easier) and that we shouldn't give it to them (he understands that a backdoor will be used in ways other than intended). The point b…

Public officials answer to a different standard than private citizens who run companies. The oath of the FBI is not to make their own jobs easier. It is to maintain public security. If the Director of the FBI cannot do that effectively, then that is a blemish on the record of President Obama who appointed Comey.

There's a definite need for someone to step up and say that on balance, we are more secure without trying to guarantee government access to encrypted data, or vice versa. So far nobody has taken that high level view and been able to convince any of the early major players in this debate.

Lindsey Graham's statement during his questioning of Lynch is the closest we got to a high level player changing sides, demonstrating an understanding of both positions [1].

[1] https://youtu.be/uk4hYAwCdhU?t=6m53s

Re: Your iPhone just got less secure. Blame the FBI

#69
post #45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

[deleted]

Re: Your iPhone just got less secure. Blame the FBI

#70
post #62
post #45

Earlier quoted context omitted.

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…

> I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obligation to create vulnerabilities for the governments to exploit (on the contrary; the companies have an obligation to find and fix the holes in their products).

How do you determine if a vulnerability was there because it was overlooked in development, or if it was there because the government demanded it from the company but used the law to impose a gag order on the company preventing the public from finding out about it?

Post reply on HN