Live data from Hacker News

Apple Is Said to Be Working on an iPhone Even It Can’t Hack

nytimes.com

91–100 of 415 posts

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#91
post #17

The problem with software is that none have been 100% secure yet... I doubt that Apple will be able to achieve that in the near future. Someone should send a phone to John Mcafee at the very least [1][2] ... 1. http://www.pcgamer.com/john-mcafee-on-his-fbi-iphone-hack-of... 2. http://arstechnica.com/staff/2016/02/mcafee-will-break-iphon... edit: added source #2; see Google for additional sources...

This is why the FBI's argument and that of those who say "they just want balance" is such nonsense.

"Balanced" compared to what? To the 80% insecurity we have now? And "balance" for what protocol? For all existing protocols? For all future protocols? What if hackers learn how to exploit that "balance" in a massive way? Will companies be allowed to fix it by improving the security or will they be "impeding law enforcement"?

It's unbelievable to me how hard the government is fighting against basic security.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#92
post #70

Earlier quoted context omitted.

> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.

Can non-US citizens be coerced into giving up their passcode?

Depends on if they're at a border crossing or in the interior of the country. Laws apply to citizens and non-citizens alike. If you haven't been admitted to the country, about the most they can do is turn you away at the border checkpoint and put you on the next flight back to your home country.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#93
post #51
post #7

Don't they just need to tell people to switch away from 4 or 6 digit pins and use longer passwords?

Does anyone know if it re-encryptes the data after I change my passphrase? In other words, am I immediately more secure if I switch from a 6 digit pin to a passphrase?

Short answer: yes.

Longer answer: There's a key that encrypts the actual data, and that key is stored on disk, but encrypted with your passcode along with a hardware key. The hardware key cannot be read, only used to decrypt. Changing your code just changes the key stored to disk, but not the encryption key, so it's quick, but preserves security.

Longest and most accurate answer: https://www.apple.com/business/docs/iOS_Security_Guide.pdf from page 10.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#94

Earlier quoted context omitted.

Nobody would adopt them. It's annoying enough to deal with 4 digits when it's cold and I'm wearing gloves and I just want to change the song I'm listening to. Passphrases suck enough whenever you have to log back in. Are people really gonna put up with that every time they want to use their phone? On the other hand, if there were a convenient way to toggle between passphrases and 4-digit unlock, (especially if you ha…

I'd love to have a long passphrase that has to be entered after booting and every 48 hours, and then a 4-digit pin that's usable when TouchID is for when I'm unlocking my phone with my nose.

Exactly. Short passwords/longish pins suffice for short durations if they are random (i.e. not guessable), particularly if the device requires external hardware to brute force due to attempt duration scaling.

I currently use a generated long password on my Android phone and have adapted to the extra work, but having the option to enter a password once a day and a pin or shorter password throughout that day would be a welcome convenience option, and it's not really significantly more onerous than just a pin.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#95
post #26

Earlier quoted context omitted.

If they have access to a live finger for the TouchID, sure they can bypass - but they could do that with the $5 guaranteed coercion method as well [1]. Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer. All bets are off if the iPhone is power-cycled. Best bet i…

Is it only five fails on TouchID to delete data? I don't have the option to delete the data enabled on my iPhone... but it often takes more than five tries to just get it to work on my finger that is legitimately registered in touchID.

You should overtrain your TouchID: http://www.imore.com/touch-id-not-working-you-heres-fix

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#96
post #2

They're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your pas…

They're not anywhere near 99% of the way there; they've destroyed the heterogeneous decentralized ecosystem that broad security requires.

Locking themselves out of the Secure Enclave isn't anywhere near sufficient. As long as the device software and trust mechanisms are totally opaque and centrally controlled by Apple, the whole thing is just a facade. There's almost nothing Apple can't push to the phone, and the audibility of the device is steadily trending towards "none at all".

If the NSA pulls a Room 641A, we'd never know. If Apple management turns evil, again, we'll never know. If a foreign state use some crazy tempest attack to acquire Apple's signing keys ... again, we'll never know.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#97
post #50

It's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherw…

[deleted]

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#99
post #5

What is to stop the DOJ from requiring them to produce a phone that has a hardware backdoor? If they are required to produce a software backdoor then building an iphone which is immune to such vulnerabilities seemingly solves that problem but I don't see the leap towards compelling Apple to build vulnerabilities into hardware as a large one. I'm not well versed in security so excuse me for my ignorance but what if th…

Congress can do it. It's happened before: https://en.wikipedia.org/wiki/Communications_Assistance_for_...

This is something Apple practically guaranteed by using platform DRM to turn themselves into a critical single point of failure.

CALEA was extended to ISPs once ISPS consolidated enough; now that Apple has consolidated central control of mobile devices in a similar fashion, it seems quite likely that extending CALEA to cover smart phones will be on the table.

I'd be extremely surprised if Apple's management wasn't very aware of the CALEA precedent, but they chose to go down this road anyway. I find that rather unsettling.

Re: Apple Is Said to Be Working on an iPhone Even It Can’t Hack

#100
post #54

Earlier quoted context omitted.

Can you be convicted in the US based on evidence obtained with physical torture? Edit: Looks like the answer is it depends and not a resounding no http://www.nolo.com/legal-encyclopedia/evidence-obtained-thr...

No, you cannot. Evidence derived from facts learned from torture is also excludable.

Sure, you can. It all depends on who gets to define "torture."

If they can find a judge who believes the iron maiden isn't torture while the anal pear is, then guess what... the government will use the iron maiden.

Even if they can't find such a pliable jurist, they'll have no problem getting a John Yoo to write an executive memo that justifies whatever they want to do to you, and let the courts sort it out later. There's no downside from their point of view.

Post reply on HN