Live data from Hacker News

A Message to Our Customers

apple.com

71–80 of 1001 posts

Re: A Message to Our Customers

#71
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

Why wold Google and Facebook get behind this? They store their customers data in a way they can access and subsequently have to give it to persecuters when there's a court order

Re: A Message to Our Customers

#72
Huge respect to Tim Cook for standing up for the personal information security of Apples users around the world. When a non tech demands something as stupid as a back door, they do not acknowledge how weak they make data security.

Re: A Message to Our Customers

#73
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.

Not too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.

Re: A Message to Our Customers

#74

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

What you're saying sound like a win-win situation for Apple and its customers. So whatever the reason is for them to speak out, it's a good thing that they do speak out. Isn't it?

Re: A Message to Our Customers

#75

This is interesting: "Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession." Am I reading this right? Apple, if they chose to, ca…

See other comment: https://news.ycombinator.com/item?id=11116439

Potentially, Apple cannot circumvent their own protections on some models (in software anyway), and could in others.

Re: A Message to Our Customers

#76

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

We've seen that bad that comes of corporations chasing a bottom line, perhaps this is the good.

And honestly I don't mind if my digital rights are defended as an advertisment.

Re: A Message to Our Customers

#77

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

I don't see why it couldn't be both - seems to me like they both believe in protecting privacy and (possibly even therefore?) follow a business model which deeply respects privacy.

Seems to me both of those things are worthy of respect in today's society.

Re: A Message to Our Customers

#78

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

You are right. What you say about Facebook is true, but Google's Android is open source, so there is no way they can plant a privacy-invading code and get away with that.

Re: A Message to Our Customers

#79

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

So, their motivation is even better and more effective than idealism.

Re: A Message to Our Customers

#80

Earlier quoted context omitted.

The security here is Apple's signing key that is used to sign updates. If you believe RSA is safe (which I assume is being used) and the key has a reasonable length, throwing a couple of millions at it won't bring you much. I guess what the FBI wants is a backdoored iOS version and to have Apple sign it with their signing key (which means that the FBI can use it over and over again).

That is hard, we know. But it is not impossible for those with time, resources and willingness to think outside the box. For instance, signing keys can and have been stolen, on the principle of "if you can't brute-force it, hack in and take it". http://arstechnica.com/security/2013/02/cooks-steal-security... http://blogs.adobe.com/security/2012/09/inappropriate-use-of... http://www.androidauthority.com/ssl-added-remo…

That is hard, we know. But it is not impossible for those with time, resources and willingness to think outside the box.

I assume that Apple has a hardware security module for key generation and storage, perhaps even custom-designed and built, to prevent key extraction/copying.

Of course, in the end you have to trust Apple that only a limited number of employees have access to such hardware, that they have proper auditing procedures, etc.

But the probability of a compromise can never be 0, unless you design and produce your hardware yourself, write all code that this hardware runs yourself, and never leave your computing device unattended. Since that is not practical for most people, you have to put trust in some third party.

Post reply on HN