Live data from Hacker News

Your iPhone just got less secure. Blame the FBI

washingtonpost.com

91–100 of 255 posts

Re: Your iPhone just got less secure. Blame the FBI

#91
This is awful reporting.

For weeks, the experts in security had been saying that FBI does not in fact need Apple's help to get into that phone; that they are just posturing in order to obtain a back door.

This was posted on the ACLU website:

https://www.aclu.org/blog/free-future/one-fbis-major-claims-...

The FBI can simply remove this chip from the circuit board (“desolder” it), connect it to a device capable of reading and writing NAND flash, and copy all of its data. It can then replace the chip, and start testing passcodes. If it turns out that the auto-erase feature is on, and the Effaceable Storage gets erased, they can remove the chip, copy the original information back in, and replace it. If they plan to do this many times, they can attach a “test socket” to the circuit board that makes it easy and fast to do this kind of chip swapping.

Maybe the FBI has a secret new exploit --- or maybe they just did the above method, getting the "third party" help with the desoldering and the attachment of a socket, and hardware for reading NAND.

It's just speculation.

Even if the FBI are exploiting some hole, that is better than them having a back door, which is essentially a security hole put in by design.

The article is speculating, and it's conflating security holes with back doors.

Re: Your iPhone just got less secure. Blame the FBI

#92
post #55

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

I agree with you, and I think this will eventually lead to a world where governments are unable to exert meaningful influence on large corporations. We're already starting to get there; I have a feeling that if the supreme court had forced Apple to write a custom version of iOS that things could have gotten really messy very quickly -- there were rumors that Apple's entire iOS engineering team was ready to resign if…

> It's plausible to see a scenario where Apple says "You know what? Fuck it, we're based in Ireland now."

Maybe, but I think you're putting the cart before the horse. We're not at that stage right now. Right now we can turn the tables on the FBI and demand they contribute back to our own ability to secure ourselves. It's not too tough to describe the issue to the general public.

The FBI would ordinarily help businesses identify security vulnerabilities in their products, such as a flaw in a bank vault, because it makes the public more safe to enable the bank to secure itself. Law enforcement regularly recommends certain bike locks, car systems (note their recent notification about remote exploits [1]), etc. over others. In this case, due to disagreement about how to keep the public safe, the FBI is refusing to cooperate with the general public who own iPhones.

[1] http://www.ic3.gov/media/2016/160317.aspx

Re: Your iPhone just got less secure. Blame the FBI

#93
post #45
post #19

This is bad reporting. The iPhone did not get less secure. It has always had this security hole. I, like many others here on HN, believe the vulnerability to be related to the lack of a secure hardware biometric / encryption module. If this is the case, then your iPhone probably did not get less secure -- such exploits would only work on iPhones prior to the 5S (I think? The 6 series phones are covered for sure). Bas…

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

>take the Monty Hall problem

It amazing how many people still don’t get the Monty Hall problem. Its lesson is that the probabilities do NOT change – until we make a choice!. That’s why it’s better to switch once we see the goat behind door 1. The probability of our having made a good choice, initially (1 in 3), has NOT changed even though there are now only two ‘choices’. But they are not REALLY choices because we’ve ALREADY chosen. The probability can only change if we make a NEW choice, because the ‘probability’ that we’re discussing is the probability that our choice, at the time it was made, would produce a result that we wanted. The iPhone 5 is clearly no less secure now than it was then. But we can switch.

Re: Your iPhone just got less secure. Blame the FBI

#94
post #62
post #45

Earlier quoted context omitted.

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…

> I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies.

Is this view particular to software defects? For example, do government inspectors have an obligation to report food safety violations that they've discovered? In either case, the problem puts the public at risk.

Re: Your iPhone just got less secure. Blame the FBI

#95
post #62

Earlier quoted context omitted.

> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…

> I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. So I take it then you don't believe in a government "for the people"? Like it or not, Apple is legally a person, and even tossing that aside, we know that many of Apple's customers are American citizens, and this whole idea of "keeping knowledge from you…

Agents who handle secret or otherwise restricted data should not be handling it on a mobile device. Those devices should be sanitized.

Presuming security is what gets people compromised (and in some cases in political trouble as one US presidential candidate is coming to realize).

Re: Your iPhone just got less secure. Blame the FBI

#96
post #65

Earlier quoted context omitted.

What might it be? I assumed the code is just 4 digits long but judging by the quick downvotes people aren't even considering this to be a possibility.

There's a mechanism that wipes the device after too many incorrect code attempts. Disabling this mechanism was the entire point of the FBI/Apple lawsuit.

I am pretty sure a reboot bypasses that mechanism.

Re: Your iPhone just got less secure. Blame the FBI

#97
post #79
post #62

Earlier quoted context omitted.

> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obliga…

> I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. Interesting. What obligations do governments have? On the one hand we have government agencies (the CPA, e.g.) whose entire function is to protect consumer…

Here's the oath stated by FBI agents when they join [1],

> I [name] do solemnly swear (or affirm) that I will support and defend the Constitution of the United States against all enemies, foreign and domestic; that I will bear true faith and allegiance to the same; that I take this obligation freely, without any mental reservation or purpose of evasion; and that I will well and faithfully discharge the duties of the office on which I am about to enter. So help me God.

[1] https://www2.fbi.gov/publications/leb/2009/september2009/oat...

Re: Your iPhone just got less secure. Blame the FBI

#99
post #55

The FBI's refusal to detail the flaw will just add to the pile of miscommunications between technologists and the government. That hurts the government's ability to advance their own technological capabilities and understanding. Every day, they're getting better at shooting themselves in the foot and widening that communication gap. I see nobody out there capable of bridging it. Not Tim Cook, not the EFF, not Obama,…

I agree with you, and I think this will eventually lead to a world where governments are unable to exert meaningful influence on large corporations. We're already starting to get there; I have a feeling that if the supreme court had forced Apple to write a custom version of iOS that things could have gotten really messy very quickly -- there were rumors that Apple's entire iOS engineering team was ready to resign if…

> These companies are the size of governments -- if Apple decided it wanted to hire a bunch of mercenaries and take over a small country, it could probably do so

Is this anything new though? I once heard the Dutch West India Company described as "Exxon Mobil with guns."

Re: Your iPhone just got less secure. Blame the FBI

#100
post #45

Earlier quoted context omitted.

Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier. However, I'll defend his point: take the Monty Hall problem [ https://en.wikipedia.org/wiki/Monty_Hall_problem ]. The probabilities change, even when a door you didn't pick [and doesn't hold the prize] is opened. I think this is a fair analogy. We've now gained knowledge about the existence of a vulnerability…

>take the Monty Hall problem It amazing how many people still don’t get the Monty Hall problem. Its lesson is that the probabilities do NOT change – until we make a choice!. That’s why it’s better to switch once we see the goat behind door 1. The probability of our having made a good choice, initially (1 in 3), has NOT changed even though there are now only two ‘choices’. But they are not REALLY choices because we’ve…

It's much easier to understand when you realize that Monty never reveals that one of the closed doors contained the car.

That asymmetry of action leads to the asymmetry of probabilities; your initial choice constrained his choices when he takes action.

Post reply on HN