If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.
Because FBI spent taxpayer's money to find a vulnerability in a device used by millions of people - it should release that information so that apple can fix it. Simple as that.
Your iPhone just got less secure. Blame the FBI
71–80 of 255 posts
Re: Your iPhone just got less secure. Blame the FBI
#72Earlier quoted context omitted.
Good one, though I can see there is a problem with this "algorithm"! haha :-)
What might it be? I assumed the code is just 4 digits long but judging by the quick downvotes people aren't even considering this to be a possibility.
Re: Your iPhone just got less secure. Blame the FBI
#731. If the vulnerability the FBI used worked because the device was an iPhone without a secure enclave, Apple probably knows how they did it, but they can't really fix devices that have already shipped without the security features. While this obviously hurts users of those phones, every phone going forward won't have this issue, and this won't be replicable on a mass scale.
2. Because this was a vulnerability that was found, not intentionally created, there is a high likelihood that the bug will be found again by security researchers, or at the very least paid for handsomely by Apple. This isn't necessarily true (Heartbleed existed for 2 years without being noticed), but it means that the vulnerability has a timetable that rapidly closes. This is far different from an _introduced_ backdoor/vulnerability, where Apple knows exactly what can be used to get into a device, but has their hands tied by the government, which would _unilaterally_ make our phones less secure. I don't like buying a door lock if I know there's a master key that can open any of the doors of that brand.
3. The author I feel is misleading when he says things like "A vulnerability in Windows 10, for example, affects all of us who use Windows 10". Even if a piece of software has a vulnerability, that vulnerability could perhaps only be exploitable under certain conditions, like software running on certain hardware (eg: without a secure enclave), or under certain conditions (passcodes of less than 4 digits). It also can be highly theoretical or impractical to do on any sort of scale -- if the vulnerability involves reading data off a hard drive using an electron microscope to check for magnetic signatures, I'm not going to be too worried that it will be abused, as the man hours to have it work for a single case would be astronomical and only feasible in the most extreme circumstances.
It's probably very frustrating on Apple's part that the FBI found a vulnerability that they (likely) don't know about, and in an ideal world, governments would disclose those vulnerabilities to make us more secure. But as long as the software and hardware continue to get more secure and not intentionally crippled, any benefit they derived feels short lived at best.
Re: Your iPhone just got less secure. Blame the FBI
#74Earlier quoted context omitted.
Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…
> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…
So I take it then you don't believe in a government "for the people"? Like it or not, Apple is legally a person, and even tossing that aside, we know that many of Apple's customers are American citizens, and this whole idea of "keeping knowledge from you for your own good" just reeks of the patronizing oligarchy that the US government has become known for.
Lest you jump to the argument that this would endanger operations, I would still point out two very salient facts: this information is not intelligence data, and as Schneier pointed out, this attack can be used against many in the US government, including FBI agents in the field. Getting it fixed is the right thing to do.
Re: Your iPhone just got less secure. Blame the FBI
#75What amaze me is the tendency for our society to call for more privacy that favors the more powerful, hence the more likely to be corrupted.
If we want make it easy for our leaders to be corrupted I definitively would call for more cryptography.
Me except the normal "shameful" stuff from the common people I want privacy to. Like anyone I have stuff I want to hide. But, it is okay if I get _caught_. I will not say everything I did is okay, because, I still have hurt indirectly people. There are stuff I want to hide to protect myself from the intolerant crowd.
But guess what, I have as much as I could went to present my excuses, and took responsibility for my own shitty actions. And for the stuff I should not be ashamed of, I don't see the need to hide it, in a democracy we have the freedom to fight for our opinions.
None of my stupid stuff requiring privacy have been leading to blood being shed, exploitation, or making the market noncompetitive.
With greater power/wealth should come greater transparency. And iPhone are definitively more expensive than most phones.
So let's remember that is often the look from the others that makes us more virtuous, and let us all accept to live in an house made of glass (except for the bathroom, and the bedrooms).
In a fair competitive market access to information is symmetrical. In a real democracy government are expected to be openly enforcing the choices of the voters.
In a world tending towards virtue, there is no need for more privacy.
Re: Your iPhone just got less secure. Blame the FBI
#76> We don’t know what the method is, or which iPhone models it applies to. Where is the proof? there is no proof.
How do you prove something you don't know?
Re: Your iPhone just got less secure. Blame the FBI
#77Earlier quoted context omitted.
There's a bit of irony to this, too. If Apple had been more cooperative earlier, law enforcement probably would've taken the white hat approach. Apple protected users from the FBI, but is now potentially unable to protect them from organised crime.
There is absolutely no proof of that. What they where asking for was keys to every lock in the world. It would have given them unprecedented power to do whatever they wanted. Apple did the right thing. Users should always come first especially when privacy is at stake.
Re: Your iPhone just got less secure. Blame the FBI
#78Earlier quoted context omitted.
> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…
> I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obligation to create vulnerabilities for the governments to exploit (on the contrary; the companies have an obligati…
You don't; but that's possible today with the way the gag orders and FISA courts work. That's a real problem around transparency in our legal system; which IMO is a different issue from transparency around security issues relating to privately-developed products.
Re: Your iPhone just got less secure. Blame the FBI
#79Earlier quoted context omitted.
Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…
> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…
Interesting. What obligations do governments have? On the one hand we have government agencies (the CPA, e.g.) whose entire function is to protect consumers from bad products and marketing. On the other hand there's the many regulatory and standards bodies, which are to ensure orderly marketplaces and discourage anti-competition. Then there's an agency that protects the environment, one that administers health, education....yet there's no obligation to disclose security vulnerabilities? Hmmppf. I'm stumped.
Re: Your iPhone just got less secure. Blame the FBI
#80This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…
Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…
It would also be remiss to think that people aren't looking for the vulnerabilities, people like Stefan Esser have plenty of research documenting the security mechanisms and flaws in iOS, and in the hardware. People have crawled over the hardware and software documenting everything, looking for bugs. People have bugs we haven't heard about because they put the time in to go down the avenues that lead nowhere in order to find them. The people that would find these bugs have a deep knowledge and understanding of the internals of the devices in question, and some suspicion of how they would be applied in this situation. They are not people who would go from zero knowledge to chasing 0day without at least a decent lead as to what the FBI's third party did.
The thing is, the FBI are not obligated to hand over their bugs, nor are the third party. It's the third party's trick, they found it, if they want to keep it it's their right to do so.
Asserting that somehow because someone has specific 0day (designed to bypass unlocks when the phone is in their physical possession for an extended period of time) and doesn't want to share makes us all less secure is incredibly ingenuous and a logical fallacy at best.