Live data from Hacker News

A Message to Our Customers

apple.com

751–760 of 1001 posts

Re: A Message to Our Customers

#751

Earlier quoted context omitted.

But this all hinges on the naive assumptions that this is a one off and will never happen again, and that later generation devices are immune from any circumvention attempt. History says this isn't how this plays out. If you crack the encryption once you'll get orders to crack it again and again, and in much lower profile and lower stake cases. Look at the prevalence of espionage tactics such as Stingrays and "parall…

Both Paris and SB were great examples of the terrorists basically not bothering with using encryption, if they had actually used and benefited from encryption we'd be discussing how to get cryptography re-legalized. I doubt there's even anything on the phone the FBI don't have from other sources. The reason they're using the All Writs Act with this case is because of the publicity of the case so they can point to App…

We're already in the woodshed. We've been there for 15 years.

Re: A Message to Our Customers

#752

Earlier quoted context omitted.

The current implementation is done this way indeed: even Apple cannot decrypt without using the right password. The right password can be obtained by either knowing it, or by guessing it. As an additional security measure, the software shipped with the phone prevents brute force attacks by wiping the device after a given number of failed attempts. Apple has been asked to modify the software so that it won't wipe the…

Why doesn't the FBI simply clone the current device, make brute force attempts and then clone again if locked out? Yes, lots of work but also doesn't force Apple to participate.

Each device has a device-specific AES key (UID) burned into it such that you cannot clone devices (or move flash chips between them).

Everything is encrypted with a derivative of this UID, and extracting the UID is not a thing you can do without destroying the device.

Re: A Message to Our Customers

#753

If it is possible to build the requested OS, then it can be said that the iPhone already has a backdoor. If the device were truely locked down, there would be no aftermarket solution to unlock it. My understanding is that Apple was asked to supply software that would prevent their software from destroying evidence on a particular device. They should comply with this order, especially given the device in question.

That's true for the iPhone 5 and earlier but for the iPhone 5S and later Apple actually made it impossible (see secure enclave). But it's not about that but rather the legal implications this has - it would set a precedent allowing the government to basically compel any company to provide keys to decrypt information which is a huge blow to privacy.

Re: A Message to Our Customers

#754
Is it possible for a human just to try all 9999 passcode combinations? Assuming the 10-failure erasure is switched off -- a bad assumption, I know. Is there an additional slowdown after a lot of failed attempts?

Re: A Message to Our Customers

#756

Earlier quoted context omitted.

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

> That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security. No, they can't. A quick update to recent hardware practices: modern SoCs like Apple's have something called "Secure Enclave Processor" that's on-die. This is the first thing to start when the c…

To play devil's advocate: If they can be compelled to produce de-novo firmware for the purpose of data extraction they could also be compelled to design the means necessary to extract the data from the secure enclave, e.g. by prying the chips open and putting it under a scanning tunneling microscope.

Re: A Message to Our Customers

#757
"For years, cryptologists and national security experts have been warning against weakening encryption. Doing so would hurt only the well-meaning and law-abiding citizens who rely on companies like Apple to protect their data. Criminals and bad actors will still encrypt, using tools that are readily available to them."

Sounds just like gun control :)

Re: A Message to Our Customers

#759
post #327

Earlier quoted context omitted.

I think the question is less about whether or not a "correct / valid use" of this new technology is acceptable. The problem is that it's impossible (once it exists) to guarantee it won't be used in malicious ways.

Right, but isn't "impossible" too high a bar? Or is the ability to comply with a warrant worth nothing? It's not like iOS is impossible to hack now and it would be terrible that it becomes possible. There are other aspects of the system that allow malicious exploits more easily than this theoretical threat. So it doesn't make sense to preserve at all costs (e.g. making warrants unenforceable) an "impossibilty" that n…

> Right, but isn't "impossible" too high a bar?

No, not really.

> Or is the ability to comply with a warrant worth nothing?

What if I issued a warrant for you to give me a 3 headed dog? Is your inability to comply with a warrant worth nothing?

Re: A Message to Our Customers

#760
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

".. what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security…

>>> I am really glad that one of the most valuable companies in the world is drawing a bright line in the sand. So I really support Tim's position on this one.

Tim's position today might not be apple's position tomorrow. Apple is a large publicly traded company. They owe a duty only to shareholders. Fighting this fight will probably impact the bottom line. Tim's continuation may turn on the outcome.

Cooperation may see Apple hurt. The perception of cooperation was part of RIM's fall from grace. Non-cooperation may also cause issues. Through it's various agencies, the US government is Apple's largest customer, as it is Microsoft's. Large contracts might be on the line should Apple not play ball. Either way, this order has probably wounded Apple.

Post reply on HN