Live data from Hacker News

A Message to Our Customers

apple.com

891–900 of 1001 posts

Re: A Message to Our Customers

#891
post #861

Earlier quoted context omitted.

Save people like me a trip to the Google: NSL = A national security letter (NSL) is an administrative subpoena issued by the United States federal government to gather information for national security purposes. NSLs do not require prior approval from a judge.

Not only do NSLs not require approval from a judge, they also include a very intimidating gag order that prevents you from discussing the issue with anyone else (including even your own family). One of the big problems with NSLs is that you can't let anyone know that you've received or acted on one, so there's very little accountability. Hence the recent trend of some companies including a warrant canary on their web…

I think deleting something would be considered an active action. The trick with a canary is that you're choosing not to do something, so it can't compel you to act (as compared to, for example, telling you you can't delete the canary).

So for it to work, you need to issue a statement every month that says you haven't been issued a NSL, and then simply not issue a statement the month you finally were issued a NSL. That would then require the government to actually compel speech (compel you to post a new notice saying you didn't receive a canary).

Of course, the above should make it blatantly obvious how absolutely absurd the blanket gag order on NSLs are.

Re: A Message to Our Customers

#892

Earlier quoted context omitted.

That doesn't explain how they would get the update on to a locked and encrypted device, even if it existed.

It seems like it would be easy enough to crack it open and replace the OS boot data. That being said, I really WANT the data in this case. I hope Apple finds a compromise where they can help get this specific data without risking leaking a compromised OS.

> I hope Apple finds a compromise where they can help get this specific data without risking leaking a compromised OS.

I want pharmaceuticals without side effects, and real doughnuts that don't make you fat.

Seriously, you are asking for "A" and "not-A" in one sentence. Take your pick. Are you willing to get this one phone unlocked so badly that you would be OK with nobody having security? Because that's what you're asking for, whether you realize it or not.

Re: A Message to Our Customers

#893
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

I'm afraid I'm too skeptical to get the same assurances as you. Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor . This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.

I thought the same thing when I read it. If Apple can do this, then it's already a backdoor, and all the publicity of "Even Apple can't hack your phone" was false. But it turns out this is an older 5C, not the new 5S and up. So those old phones were effectively backdoored.

I agree that Tim Cook has spun it as if it's not a backdoor when clearly it is. Still quite a hard-to-use one though. It seems like they need the physical phone and maybe Apple's private key for signing updates.

The idea that the act of writing software makes it insecure is silly though. The security doesn't come from no-one having made the appropriate changes to iOS. If it was, that would be security through obscurity and any motivated hacker or the FBI could modify iOS themselves. It must be about signing the update so that it can actually be installed.

Re: A Message to Our Customers

#894
post #881

Earlier quoted context omitted.

I know it requires Tim Cook to be willing to martyr himself, but do we really see Obama whisking the CEO of Apple Computer off to Guantanamo or some supermax prison? I'd maybe call the bluff, and take my political stand.

Cook wouldn't have to go that far. The court order specified Apple, not Tim Cook personally. He can simply resign instead of following the court order. For that matter, so can the engineers that Apple would need to work on this project.

That's interesting.

IANAL but seems like you're missing something.

Apple can simply let Employee B take Employee A's place after A quits. When the authorities come for B, B can quit, and Apple can re-hire A.

Apple never has to comply.

Re: A Message to Our Customers

#895

Earlier quoted context omitted.

Nothing. Bringing a bunch of special agents along with you to a meeting is intimidating, though. I suppose in their defense, they may be the particular agents working on the San Bernadino case, who arrived to explain exactly why they need the access or whatever.

> Bringing a bunch of special agents along with you to a meeting is intimidating Again, what is intimidating about that? The agency they were dealing with was the FBI, right? And that's the correct agency to deal with this matter, right? Well in the FBI, 'special agent' simply means any worker who does investigatory work.

Special agents who wear earpieces are people who have been trained to respond swiftly and decisively when violence is called for. That's what the earpiece is for, to coordinate tactical action if necessary. Having a swarm of them show up at your place of business is obviously intimidating even if they're not actually planning or expecting violence.

Re: A Message to Our Customers

#896
post #891
post #861

Earlier quoted context omitted.

Not only do NSLs not require approval from a judge, they also include a very intimidating gag order that prevents you from discussing the issue with anyone else (including even your own family). One of the big problems with NSLs is that you can't let anyone know that you've received or acted on one, so there's very little accountability. Hence the recent trend of some companies including a warrant canary on their web…

I think deleting something would be considered an active action. The trick with a canary is that you're choosing not to do something, so it can't compel you to act (as compared to, for example, telling you you can't delete the canary). So for it to work, you need to issue a statement every month that says you haven't been issued a NSL, and then simply not issue a statement the month you finally were issued a NSL. Tha…

Interestingly, if you accept that code can be copyrighted, and that only things that are expressions (speech) are eligible for copyright ("A copyrighted work must be an original work of authorship which is fixed in a tangible medium of expression"), then code == speech.

So, by compelling Apple to code something that doesn't exist, the government would indeed actually be compelling speech.

Re: A Message to Our Customers

#897

Earlier quoted context omitted.

Save people like me a trip to the Google: NSL = A national security letter (NSL) is an administrative subpoena issued by the United States federal government to gather information for national security purposes. NSLs do not require prior approval from a judge.

IANAL, but how is it a subpoena if it doesn't originate from the judiciary?

https://en.wikipedia.org/wiki/Administrative_subpoena

Re: A Message to Our Customers

#898

Earlier quoted context omitted.

So? At least in American jurisdiction, the 4th Amendment doesn't guarantee the right to unbreakable crypto. It says: "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the p…

> I mean, let's get real for a second. The toolchain already exists. Apple has the source code, hardware simulators, debugging harnesses, and the original engineers. There's no magic. As long as those things exist, the danger of a hack getting public is real, especially if the source for iOS is ever stolen, or one of the core engineers goes rogue. If Apple's own internal security can't keep a more polished tool under…

No, I'm saying Apple shouldn't hand over their encryption keys. I'm saying the FBI should hand over the iPhone, and Apple hands back the files, but doesn't give them any hacked phone.

In a paperless world, and unbreakable encryption, what is the point of warrants or regulations at all?

If a company that say, committed crimes, financial or criminal, has a warrant served on them, what if the response is, "Hey, we'd love to give you our emails, but all employees use end to end encryption, and every desktop has unbreakable filesystem crypto, and our IT department can't unlock anything, so you must compel the users to hand over keys?"

Can that be a defense against all warrants and crimes? If politicians are suspected of accepting bribes with strong probable cause, do we simply accept that their phones and email communications with lobbyists and corrupt bribers can't be accessed?

What does society resort to then, rubber hose cryptanalysis? Imprisonment on lack of evidence until they turn over the keys?

Transparent democracy is on a crash course with cryptoanarchy. The same people who are chanting for absolute unbreakable cryptography are some of the same people supporting Bernie Sanders and would rail against offshore Cayman or swiss financial obfuscation by the mega rich.

If we want non-corrupt government and industry, we need a way to investigate serious crimes. In the past, this meant seizing papers, letters, and records under warrant. Nowadays, it may be possible for the entire digital crime trail to be unbreakable with no recourse except catching people in the act. However, when the FBI entraps people with sting operations "in the act", civil libertarians decry that too.

So how do we police the bad? If you look at many third world countries with trouble advancing, a lot of is due to corruption. Is the danger of the government subpoenaing your email worse than the danger of tens of thousands of corrupt businesses spreading financial risk all over the economy and political system?

Re: A Message to Our Customers

#899
post #894

Earlier quoted context omitted.

Cook wouldn't have to go that far. The court order specified Apple, not Tim Cook personally. He can simply resign instead of following the court order. For that matter, so can the engineers that Apple would need to work on this project.

That's interesting. IANAL but seems like you're missing something. Apple can simply let Employee B take Employee A's place after A quits. When the authorities come for B, B can quit, and Apple can re-hire A. Apple never has to comply.

Employee A doesn't have to actually quit, they just have to credibly threaten to. Say, by signing an open letter that says that they'd quit before helping backdoor the iPhone. Apple can then claim that they cannot bring together a team that is willing and able to backdoor that iPhone.

When you break down the process of having a private company comply with an order to create a particular piece of software, there's many failure points.

The counter from the governmental side is "we will give your company massive fines until and unless your company complies".

As a note, the actual text of the court order (https://www.documentcloud.org/documents/2714001-SB-Shooter-O...) explicitly says that Apple can appeal it on grounds that it is an unreasonable request. Uncooperative engineers can make it an unreasonable request, and have the legal right to be as uncooperative as they want to be in this case. And, they're on the same side as the CEO of Apple ethically, so it isn't career suicide.

Re: A Message to Our Customers

#900
post #896
post #891

Earlier quoted context omitted.

I think deleting something would be considered an active action. The trick with a canary is that you're choosing not to do something, so it can't compel you to act (as compared to, for example, telling you you can't delete the canary). So for it to work, you need to issue a statement every month that says you haven't been issued a NSL, and then simply not issue a statement the month you finally were issued a NSL. Tha…

Interestingly, if you accept that code can be copyrighted, and that only things that are expressions (speech) are eligible for copyright ("A copyrighted work must be an original work of authorship which is fixed in a tangible medium of expression"), then code == speech. So, by compelling Apple to code something that doesn't exist, the government would indeed actually be compelling speech.

Court processes involve compelled speech all the time. Heck, compelling witness testimony, which is one of the most well-established parts of the court process, is nothing but compelling speech.

So, I'm not sure what the value is of a clever argument that compelling Apple to comply with the order here is "compelling speech" is supposed to be (likewise, the upthread one about NSL canaries.)

Post reply on HN