Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

81–90 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#81
post #56
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

> This is bad reporting. I felt the same way when I hit the article link, but changed by mind when Bruce Schneier made the more nuanced argument. Of course the vulnerability already existed. That's not what he has a problem with: the problem is that now there is a commercially-known but secret vulnerability. Which is a different thing than an unknown vulnerability. Newer hardware revisions, etc etc, but the biggest i…

>> now there is a commercially-known but secret vulnerability.

Exactly, and not only that, but (potentially) unknown to Apple.

Re: Your iPhone just got less secure. Blame the FBI

#82
post #17

Is this just FUD? Simply confirming the vulnerability seems likely to lead to it being plugged, whether or not the FBI reveals their methods, in effect doing the opposite of what the title suggests.

How can it be plugged, if Apple doesn't know what it is?

Because Apple being the OEM of the hardware and software involved, things tend to get back to them, even if in rumor form.

And them knowing their software so well gives them intimate knowledge when tracking down vulnerabilities.

Re: Your iPhone just got less secure. Blame the FBI

#83

If Apple refused to comply with the FBI's request, why should the FBI owe Apple a disclosure of this vulnerability they found? Keep the downvotes coming, lads! They're meant for burying spam and junk comments, not expressing disagreement, but I enjoy them anyway.

If I find a vulnerability and exploit someone's device, it's not okay under law. Why is a government institution exempt from law in a supposedly exemplary democracy?

Because they're a law enforcement agency with a warrant. It's also illegal for me to enter your home without your permission, but the police don't need your permission when they have a search warrant.

Re: Your iPhone just got less secure. Blame the FBI

#84

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

The specific point of bridging is that technology corporations and the federal government should both care deeply about making consumer and corporate technology as secure as possible, given how much of the nation depends on it.

On paper, the right federal agency for this should be the Department of Homeland Security. In reality they have neither the technical expertise nor the political "juice" to compete with the intelligence and law enforcement agencies--who care much more about access than security.

Until this balance is corrected at the federal level, it's going to be a mess. On balance, the government essentially WANTS technology to be insecure right now, so that intelligence and law enforcement staff can do their jobs more easily.

Re: Your iPhone just got less secure. Blame the FBI

#85
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. The problem here is that we're all just speculating. We suspect this to be the case, but we can't be sure. And we probably never will be. To take this a step further, the FBI has also learned the lesson to never take this public again. If you are worried about law enforcement attacks against any device protected by…

I suppose you have the option to use older/legacy hardware which has had more time to be vetted.

Re: Your iPhone just got less secure. Blame the FBI

#86
post #62

Earlier quoted context omitted.

> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…

> I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. So I take it then you don't believe in a government "for the people"? Like it or not, Apple is legally a person, and even tossing that aside, we know that many of Apple's customers are American citizens, and this whole idea of "keeping knowledge from you…

> Lest you jump to the argument that this would endanger operations, I would still point out two very salient facts: this information is not intelligence data, and as Schneier pointed out, this attack can be used against many in the US government, including FBI agents in the field. Getting it fixed is the right thing to do.

I agree with you that given the facts we know today, notifying Apple is the right thing to do. But I also think the FBI should have some latitude in deciding what is in its best interest; and if they're making their own agents vulnerable to an exploit they know exists -- well, that's dumb and I hope it bites them in the ass.

Re: Your iPhone just got less secure. Blame the FBI

#87

Earlier quoted context omitted.

It seems to me that Tim Cook and the FBI understand each other very well. They just don't care about the same things. Former CIA and NSA Director Michael Hayden clearly understands the issues. I saw an interview where he stated that the FBI was correct to want access (it makes their job easier) and that we shouldn't give it to them (he understands that a backdoor will be used in ways other than intended). The point b…

Public officials answer to a different standard than private citizens who run companies. The oath of the FBI is not to make their own jobs easier. It is to maintain public security. If the Director of the FBI cannot do that effectively, then that is a blemish on the record of President Obama who appointed Comey. There's a definite need for someone to step up and say that on balance, we are more secure without trying…

Ok, sub in that it would be a valuable tool in carrying out their mission for the making their job easier. The point is that it isn't extraordinary for law enforcement to want investigative powers.

If you watch some interviews with Michael Hayden, you'll see him saying just what you want, and I think someone who is a former director of both the CIA and NSA counts as a high level player. Autoplay video, but read the text:

http://www.usatoday.com/story/news/2016/02/21/ex-nsa-chief-b...

Re: Your iPhone just got less secure. Blame the FBI

#88
post #45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

> The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened.

That's the common misunderstanding of the problem. Most people think that the probabilities go fro 1/3, 1/3, 1/3 to 1/2, 1/2, after choosing a door and having Monty Hall open one of the others. The probabilities don't change.

The probabilities are 1/3, 1/3, 1/3 at the start. After you choose a door, they're still 1/3, 1/3, 1/3. Or a put a different way: 1/3 (your choice) 2/3 (what you didn't choose). When Monty Hall opens one of the other doors, the probabilities don't change. It's still 1/3 (your choice) 2/3 (what you didn't choose).

However, because he's removed one of the doors from the problem, the 2/3 probability is now applied to the remaining door.

That can be viewed as "probabilities changing" for the remaining door, but it's better described as the probabilities being shared between the doors you didn't choose.

Re: Your iPhone just got less secure. Blame the FBI

#90
post #64
post #56

Earlier quoted context omitted.

> This is bad reporting. I felt the same way when I hit the article link, but changed by mind when Bruce Schneier made the more nuanced argument. Of course the vulnerability already existed. That's not what he has a problem with: the problem is that now there is a commercially-known but secret vulnerability. Which is a different thing than an unknown vulnerability. Newer hardware revisions, etc etc, but the biggest i…

I guess the part I disagree with him on is that I actually expect the US government to act like malware authors. They've shown an affinity for the tactics before (using surveillance software, stingrays, etc) so it's at least perfectly consistent. I have no expectations that the relationship between law enforcement and technology companies will improve. I guess I've just accepted this situation as the "new normal".

I actually expect the US government to act like malware authors.

The main point is, that this should not be acceptable.

Post reply on HN