Live data from Hacker News

Why Apple's iPhone encryption won't stop NSA

siliconexposed.blogspot.com

61–70 of 71 posts

Re: Why Apple's iPhone encryption won't stop NSA

#61
post #4

I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…

While the NSA could probably figure out how to attack Apple's key management infrastructure [...], doing so for all the people would, in principle, be fairly noticeable to Apple.

Maybe that's why Apple's warrant canary has disappeared[1].

[1] https://gigaom.com/2014/09/18/apples-warrant-canary-disappea...

Re: Why Apple's iPhone encryption won't stop NSA

#63

Earlier quoted context omitted.

I can't think of any reason why its "best" for Apple to keep LEO happy. LEO don't pay them anything and actively increase the difficulty they face running their business as well as reduce the trust the people who do pay them (ie their customers) have for their products, actively hurting their business. The big fear is that pissing off LEO will result in harmful regulation, and, while that is certainly possible, histo…

"I can't think of any reason why...": http://www.businessinsider.com/the-story-of-joseph-nacchio-a...

The amount of money Apple makes from (US) government contracts is utterly insignificant compared to what they make from selling directly to consumers. Which revenue stream do you think they would be least likely to gamble with?

Re: Why Apple's iPhone encryption won't stop NSA

#64
post #4

I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…

Disk encryption will only stop a targeted attack (someone physically gets their hands on your phone) anyway. All this does is raise the cost by a bit.

Or move the attack.

If it's encrypted at rest you look at attack in transit or via social engineering or whatever.

I think sometimes we get too hung up about the technology around security. For a targeted attack, going for the technology often won't be the best route.

Re: Why Apple's iPhone encryption won't stop NSA

#65
post #57

Earlier quoted context omitted.

> I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA) Great point and one that I think typical computer savvy users already do. It is in the security-expert-fantasy-world that the perfect quickly becomes the enemy of the good. For example, using SSL to send sensitive data li…

It has numerous higher costs, from special email software to the social pain of getting your friends to also use it. With 'special email software' do you mean not-webmail? Outlook is still around in many companies, where your colleagues are already connected. IIRC there's a PGP plugin.

A PGP plugin is special software.

Re: Why Apple's iPhone encryption won't stop NSA

#67
I didn't get the impression that Apple was trying to tell us our data was safe from other people snooping because of their new encryption practices. Instead, Apple is removing themselves from the list of corporations who are forced to turn over our data because they no longer have access to it.

In other words, trust Apple not to betray you because they no longer have the ability. That's the message I think they are trying to send.

Re: Why Apple's iPhone encryption won't stop NSA

#68
post #3

I'm sorry, but this is just plain wrong. Let's take "since the key is physically burned in"... You don't need to burn it in, it could easily be stored in a few bytes of on-die sram. As for the assertion that a de-powered chip can't wipe itself? You can just go out and buy a self wiping chip ... you don't need to be either Apple or the NSA, just have a credit card.

If the key is kept across a battery replacement or repair procedure, then it's going to be hard-wired/fused into the chip. SRAM needs to be powered constantly to retain data. Credit cards/smartcards include self-destructs that will erase the nonvolatile memory (flash) in certain cases if power is applied while a tamper signal is asserted. They cannot erase data while in the "off" state. One of the problems with fuse-…

Just so I understand - this process of dumping the keys off the iPhone would typically something that the owner would notice? Is it feasible to take someone's phone, dump the silicon, and then return the phone to them?

Re: Why Apple's iPhone encryption won't stop NSA

#69
post #60
post #14

Earlier quoted context omitted.

> I think the crux of the matter is that this crypto scheme is not designed to stop the NSA I think the NSA has so many tools available when it comes to hack into people's data, it doesn't really matter how you secure yourself, there are many ways for the NSA to spy on people if they really want to. Right now I don't think anyone can really pretend to secure their data from the NSA. It might make it harder for them,…

Not least of which is using 210 to ask your nuts for your password...

What's 210?
Post reply on HN