Earlier quoted context omitted.
"To be fair - the only reason he's doing it is because it would cause a significant drop in sales for Apple devices." That's not being fair at all. To say the only reason he is doing it is to protect iPhone sales doesn't speak to Tim's character. Of course he cares about sales, but he also cares about privacy.
Normally people on HN are much more skeptical about airy promises and assertions from corporate executives. I don't see what behavior on Tim Cook's part has indicated he's more to be trusted than anyone else.
A Message to Our Customers
641–650 of 1001 posts
Re: A Message to Our Customers
#642Re: A Message to Our Customers
#643Re: A Message to Our Customers
#644Good one Tim! I mean how long did the LE think they can abuse constitution, put spy devices on people's cars without warrant, use stingrays and do all sort of other crazy stuff including planning and executing white-flag attacks without any consequences whatsoever?? I mean, at some point, we the people - for a good reason - will lose all and any trust we have in them! And that's what Tim is saying in this one sentence that with overwhelming evidence, the US Gov would have hard time arguing against!
Re: A Message to Our Customers
#645There's a simple way to defeat Apple's argument. The judge could simply ask Apple to flash the new firmware on that phone, let the FBI run the brute force under their supervision and obtain the contents they need, and then flash back a non-compromised version of the OS. The government would never have access to a phone with a compromised version of an OS that they could use to repeat this trick. Rather, the governmen…
The problem is that once created, it would be easier for future warrants to ask Apple to simply re-perform the same trick it's done in the past. Apple's core argument is that allow this once opens the door to doing it repeatedly because right now Apple doesn't have the toolchain to do this. Once the toolchain exists, its deployment is trivial.
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
Upon probable cause, the government may issue warrants. The US government, backed by the people of the United States, have a right to compel a private corporation to comply with reasonable searches and seizures on probable cause with a warrant.
The government is not asking Apple to deploy nuclear weapons, nor ship all iPhones with a hack. They are specifically asking for help with one vulnerable phone, an iPhone 5C. They may be asked to do this multiple times, but they can keep whatever engineers and tools they use internally private.
I mean, let's get real for a second. The toolchain already exists. Apple has the source code, hardware simulators, debugging harnesses, and the original engineers. There's no magic. As long as those things exist, the danger of a hack getting public is real, especially if the source for iOS is ever stolen, or one of the core engineers goes rogue. If Apple's own internal security can't keep a more polished tool under wraps, they won't be able to keep the subcomponents of it under wraps.
There's a reasonable middle ground between "government has a backdoor and can scan and read everything" and "it's impossible for the government to even obtain legal warrants on probable cause for a very targeted piece of information" What's being discussed in this case is not Snowden-level drag-net snooping. We're not even talking about a wire-tap. We're literally talking about the government finding a Safe/Vault inside the house of a murderer, and talking to the manufacturer of the Safe/Vault to get them to pick the lock without destroying the evidence inside. The Vault-maker in this scenario doesn't even have to give over the blueprints of the proprietary lock mechanism, they just need to open this one vault.
Re: A Message to Our Customers
#646Earlier quoted context omitted.
I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.
I'm not sure you can draw the conclusion that Apple can push OS updates to a locked phone. What Tim Cook wrote is that > "install it on an iPhone recovered during the investigation." > "the potential to unlock any iPhone in someone’s physical possession." So the FBI has the physical phone already. They can deliver to Apple who can disassemble it and either use a JTAG/Flash programmer on an internal connector to manua…
The newer devices run a special L4 kernel on the secure enclave. It is not updateable without providing the existing passcode. It enforces the attempt rate limiting and key deletion on too many attempts (if enabled). Special limited communication channels allow the CPU to talk to the SE. In production devices the SE has JTAG disabled. Encryption and decryption of the master keys happen inside the SE with its own private AES engine so even oracle/timing attacks on the main CPU are useless.
Why doesn't Apple just help hack this phone but wash their hands of newer devices and tell customers to upgrade? Because if the FBI and this court get away with using the All Writs act to compel Apple to write new software they'll eventually be forced to add a backdoor to SE-equipped devices too. Courts won't understand or care about the differences.
If the government forced them, Apple could insert a backdoor into the next major version of iOS or the hardware; then everyone inputs their passcode during the upgrade and the backdoor is deployed. Their primary defense against that so far (and the only real one you can have as a corporation) is to never build the capability in the first place. This judge's order is telling them to go build the capability (in theory for this one phone). The fact that you can't retroactively build the backdoor for 5S and newer devices isn't the main issue.
Better to fight every step of the way and draft as many pro-privacy people as possible into the fight to apply political pressure.
Re: A Message to Our Customers
#647Earlier quoted context omitted.
iTunes recovery mode? It allows to restore the OS, but also gives you other means to manipulate the device. Imagine if they simply hot-patch the lockscreen to allow any number of tries of password?
Recovery mode with DFU and the like results in a device wipe. There are many ways to redo the firmware, but every single one of them, by design, requires wiping the phone to implement.
Re: A Message to Our Customers
#648Earlier quoted context omitted.
".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…
In a lot of consumer devices, JTAG is at least partially disabled (sometimes they can throw a fuse that only lets you do boundary scan for manufacturing). I would not be surprised at all that Apple's internal 'backdoor' (if you can call it that) is just resetting the security enclave, essentially erasing everything on the NAND. That'd be fine for refurb/manufacturing, desirable even as that guarantees that full syste…
Most ICs can be completely erased to remove the limitations on access, but this usually requires a 'mass erase', where the entire non-volatile memory is erased (taking any codes, passwords, and encryption keys with it).
source: I am an embedded software engineer who works with these settings in bootloaders and application software.
Re: A Message to Our Customers
#649Earlier quoted context omitted.
"To be fair - the only reason he's doing it is because it would cause a significant drop in sales for Apple devices." That's not being fair at all. To say the only reason he is doing it is to protect iPhone sales doesn't speak to Tim's character. Of course he cares about sales, but he also cares about privacy.
Why would it cause a significant drop? Where would those people go?
Re: A Message to Our Customers
#650Earlier quoted context omitted.
"To be fair - the only reason he's doing it is because it would cause a significant drop in sales for Apple devices." That's not being fair at all. To say the only reason he is doing it is to protect iPhone sales doesn't speak to Tim's character. Of course he cares about sales, but he also cares about privacy.
Normally people on HN are much more skeptical about airy promises and assertions from corporate executives. I don't see what behavior on Tim Cook's part has indicated he's more to be trusted than anyone else.
We should be careful about plainly stating what someone else's motivations are when it contradicts their own story.
Edit: s/it's/his reasons include/ for clarification.