Live data from Hacker News

Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

latimes.com

81–90 of 129 posts

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#81
Can anyone find any actual citation for Apple wanting "the FBI to reveal" anything? There's quotes from an AVG spokesperson in the article, and the paragraph "Attorneys for Apple are researching legal tactics to compel the government..." but no specific sources.

The author, on Twitter, said that "last week" Apple said they wanted to know what the exploit was, but the announcement about a successful exploit was only two days ago.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#82
post #64

Earlier quoted context omitted.

>Now, it's the FBI sending a giant "screw you" to Apple by not only letting them know they were able to hack into the phone without Apple's help but at the same time, making a mockery of Apple's entire security claims. >it's pretty obvious that Apple has been outsmarted by a government agency. I disagree with this assessment. It's not very surprising that the FBI was able to hack into a particular iPhone by focusing…

An interesting twist would be for Apple to encourage someone to sue Apple for having a hackable phone and then having Apple supply a legal request to require the FBI to disclose the hack in order to "defend" the lawsuit. Not sure this would work but you need a legal reason to force disclosure.

Let's find out.

As an iPhone user, I presume I have standing and could argue some form of damages. Now, is there a lawyer out there interested in discussing whether there is really any merit to bringing a suit forward?

Would / could this be a class action, or in this case, is it better to seek an individual out come?

Hypothetically speaking, of course, until there are proven grounds to stand on.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#83
post #18
post #4

Ask these guys, not the feds: http://www.cellebrite.com/Pages/cellebrite-solution-for-lock... You are welcome Apple.

The San Bernadino phone was running iOS 9. (It's reasonable to assume that if there was a vulnerability in 8.x, Apple would want to have fixed it in 9.)

But the San Bernardino phone did not have the secure enclave that new iOS 9 devices have. If the vulnerability is unworkable on devices with the secure enclave, well, they've already fixed it.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#84

Earlier quoted context omitted.

Because it's possible that they actually do think this is the right way to keep the public safe, and it is possible that domestic law enforcement's understanding of tech is a lot worse than we imagine. The NSA and the FBI are very different in their understanding of tech. Former NSA director Hayden already said he thinks the FBI's plan is no good. He also said he understands why Comey is pursuing this path. He did no…

I don't care what Hayden says. They lied about the motivation for the case, and they lied about a software update from Apple being the only means of recovering the data.

A good portion of the public still believes James Comey. That includes lower level law enforcement officers. I want them to do their jobs well. Depending on access to encrypted communications residing in the phones of terrorists isn't going to cut it in the future.

It'd be nice if they realized this future is coming very soon. We pay the FBI to be good at maintaining public safety.

On top of that, the polls about this issue showed there is somewhere between 40 and 50 percent of the public who sides with the FBI in the SB case. If backdoor legislation is introduced following a terrorist attack, there is a chance it could pass. We're better off educating the public now about how encryption works and where it is used.

The people we want to convince already trust the government. They will not listen if you include "the FBI lied about everything" in your argument. I think they could understand that backdoor-less encryption tech is better for our safety than backdoored encryption, given some explanation that one weakness exposes all devices. And, I think they could understand the impracticalities of enforcing what the government wants, given some discussion about how encryption is used in both commercial and free and open source messaging apps.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#85

Earlier quoted context omitted.

What lock do you have on your door? Something standard like this: http://goo.gl/cuIenh (Image of lock)? That can be opened easily in a number of seconds without damaging the lock with at least 2 well known techniques. Yet that is the lock installed on new doors on peoples homes. They don't care, people don't want/need actual security they just want to keep the idiot burglars out and be able to claim the value of thei…

Where do you live, that new homes have locks like those? Because here new houses pretty much require class C anti-burglar doors (which roughly means, they should be impenetrable in less than 10 minutes) - they have non-standard keys and complicated locking mechanisms, door-frame is locked into concrete etc. etc. Otherwise cost of your insurance will go through the roof.

Where do you live? "Here" could mean South Africa, in which case you'd have a point. But it's also very much a special circumstance, as anyone from that part of the world would attest.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#86

Earlier quoted context omitted.

I think you're reading this completely wrong. The FBI asked for access, Apple said no (because they knew the case was about precedent rather than capabilities). Apple knows the older phones had vulnerabilities (see this faux-apple computer - https://youtu.be/zsjZ2r9Ygzw?t=15m50s commercial). This is the follow-up from Apple saying "oh, you needed our help to crack it huh? How did you suddenly find a way to do it on y…

The VEP seems to be policy rather than legislation. Meaning that there is no legal obligation for the US Government to abide by it. If anything, the question is whether the US Government is morally obliged to reveal the vulnerability, given that the risk of not doing so is much higher than the value the government gets from exploiting it as a tool against terrorism. That, I believe, is the EFF's strategy – getting pu…

So the same company that didn't want to help investigate somebody who killed 14 people because of privacy concerns believes the government has a moral obligation to help them debug their software / hardware platforms. Yup, that makes sense.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#87
post #86

Earlier quoted context omitted.

The VEP seems to be policy rather than legislation. Meaning that there is no legal obligation for the US Government to abide by it. If anything, the question is whether the US Government is morally obliged to reveal the vulnerability, given that the risk of not doing so is much higher than the value the government gets from exploiting it as a tool against terrorism. That, I believe, is the EFF's strategy – getting pu…

So the same company that didn't want to help investigate somebody who killed 14 people because of privacy concerns believes the government has a moral obligation to help them debug their software / hardware platforms. Yup, that makes sense.

You seem to think holding both positions is incoherent, but I have no idea why.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#88
post #58

Earlier quoted context omitted.

You think Apple should have lied to the public?

I assume he means this would be the best strategy (if kept under wraps) for Apple's reputation; the public's interests notwithstanding. Regardless, grandstanding twice just looks foolish for everyone except the FBI.

You think this case makes the FBI look good? It took a month long media circus, made Apple look like the good guys, pissing off most of the tech community—all to unlock a single phone that likely has no useful data on it. If they had wanted to advertise their ability to unlock iPhones, they would have just done it, and done a press conference about how they unlocked it and got lots of good information. Instead, they look like they were desperately scrambling, before some "Canadian girlfriend" showed up at the last minute and saved them from looked even more foolish.

Sure, from Apple's side, it would have been better had it gone to court and been established that the government isn't allowed to do what it was trying to do, but... I don't see the FBI trying the same tactic again, and, here's the kicker—if they can't establish the authority to force Apple to unlock phones on non-secure enclave machines, then when they need a secure enclave equipped phone unlocked, it's going to be a lot harder to use the All Writs Act to force Apple's hand.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#89
post #88
post #58

Earlier quoted context omitted.

I assume he means this would be the best strategy (if kept under wraps) for Apple's reputation; the public's interests notwithstanding. Regardless, grandstanding twice just looks foolish for everyone except the FBI.

You think this case makes the FBI look good? It took a month long media circus, made Apple look like the good guys, pissing off most of the tech community—all to unlock a single phone that likely has no useful data on it. If they had wanted to advertise their ability to unlock iPhones, they would have just done it, and done a press conference about how they unlocked it and got lots of good information. Instead, they…

I'm specifically talking about Apple asking for the hacking info. The FBI doesn't look anything (yet) because it's just the recipient of the request and AFAIK hasn't yet responded.

Re: Apple wants the FBI to reveal how it hacked the San Bernardino killer's iPhone

#90

Earlier quoted context omitted.

What lock do you have on your door? Something standard like this: http://goo.gl/cuIenh (Image of lock)? That can be opened easily in a number of seconds without damaging the lock with at least 2 well known techniques. Yet that is the lock installed on new doors on peoples homes. They don't care, people don't want/need actual security they just want to keep the idiot burglars out and be able to claim the value of thei…

Where do you live, that new homes have locks like those? Because here new houses pretty much require class C anti-burglar doors (which roughly means, they should be impenetrable in less than 10 minutes) - they have non-standard keys and complicated locking mechanisms, door-frame is locked into concrete etc. etc. Otherwise cost of your insurance will go through the roof.

Where do you live such that those things are required to get a decent insurance rate? My insurance never mentioned a single one of those requirements.
Post reply on HN