Live data from Hacker News

A Message to Our Customers

apple.com

991–1000 of 1001 posts

Re: A Message to Our Customers

#991
post #956
post #886

Earlier quoted context omitted.

Fighting will probably impact the bottom line. As in, improve it. Tim Cook is probably more popular than Obama (and surely is WRT this issue.) Apple is about a thousand times more popular than the NSA and blessed with almost infinitely deep pockets and a very, very good marketing team. Not to mention the fact that most of the people who use computers and phones don't even live in the USA.

Unfortunately, the NSA/FBI likely have far more money than Apple, and if Apple spends too much, their shareholders can demand that leadership backs down. Tim Cook is responsible to his BoD and shareholders.

The NSA has an annual budget of ~10B, the FBI even less.

In comparison, Apple had a net income of ~50B in 2015.

Let that sink in for a moment.

Re: A Message to Our Customers

#992

Earlier quoted context omitted.

The current implementation is done this way indeed: even Apple cannot decrypt without using the right password. The right password can be obtained by either knowing it, or by guessing it. As an additional security measure, the software shipped with the phone prevents brute force attacks by wiping the device after a given number of failed attempts. Apple has been asked to modify the software so that it won't wipe the…

I'm really curious as I have been hearing this many times. "even Apple cannot decrypt without using the right password." Could you please explain?

You can read more about it in this well written article: https://www.mikeash.com/pyblog/friday-qa-2016-02-19-what-is-...

Re: A Message to Our Customers

#993

Earlier quoted context omitted.

The code which decrypts the system (and is responsible for wiping the drive on repeated failures) is definitely not encrypted. How would it be able to take the input in order to decrypt the drive.

Their security PDF says that the system has a chain of trust established, anchored at an immutable loader residing inside the chip, and each step verifies the digital signature of the next step against the hardcoded Apple CA certificate.

So to clarify you're saying that you can't just nop instructions, or it's not as simple as that, right?

Re: A Message to Our Customers

#994
post #892

Earlier quoted context omitted.

It seems like it would be easy enough to crack it open and replace the OS boot data. That being said, I really WANT the data in this case. I hope Apple finds a compromise where they can help get this specific data without risking leaking a compromised OS.

> I hope Apple finds a compromise where they can help get this specific data without risking leaking a compromised OS. I want pharmaceuticals without side effects, and real doughnuts that don't make you fat. Seriously, you are asking for "A" and "not-A" in one sentence. Take your pick. Are you willing to get this one phone unlocked so badly that you would be OK with nobody having security? Because that's what you're…

Perhaps you're not technically deep enough to see other solutions.

Perhaps you are trying to disagree with a point by conflating it.

Re: A Message to Our Customers

#995
post #350

Earlier quoted context omitted.

Was going to point out that you spelt "prosecutors"as "persecutors", but then realised you might have genuinely meant that spelling!

I'm not a native english speaker and that actually was just a typo.

Don't worry about it. Your misspelling is actually quite apt!

Re: A Message to Our Customers

#996
post #976

Earlier quoted context omitted.

> The best Apple could do is sign a malicious update to the Secure Enclave firmware that either removes the time delays or dumps the keys. Dumping the Secure Enclave would not result in the keys necessary to read the files on the filesystem. Each file has a unique key, which is wrapped by a class key, and for some classes, the class key is wrapped by a key derived from the passcode. If you don't have the passcode, yo…

You could bruteforce the passcode.

Yes, if you could recover the SE key (or factory-burned SoC key for older phones), you could crack the passcode on your own cluster rather than being limited to what the phone hardware/software can do.

Re: A Message to Our Customers

#997
post #976

Earlier quoted context omitted.

You could bruteforce the passcode.

Yes, if you could recover the SE key (or factory-burned SoC key for older phones), you could crack the passcode on your own cluster rather than being limited to what the phone hardware/software can do.

> for older phones

To my knowledge, all keys are still wrapped with the UID, and the UID is still a factory-burned SoC key (not accessible to any firmware). Possible to extract, but not easy to do at scale.

Re: A Message to Our Customers

#998

A friend of mine at Apple reported multiple Black Vehicles (Lincoln Town Cars and Escalades) with at least one having MD License Plates at the Apple Executive Briefing Center this morning between 11AM and Noon. Occupants had ear pieces and sun glasses and were accompanied by a CHP (California Highway Patrol) cruiser and three motorcycle escorts. I suppose it's possible this was a quick (less than 1 hour) VIP stop but…

Just a follow-up to correct the record as much as possible. I believe this motorcade was related to the Prime Minister of Malaysia's visit to Apple per the following tweet. Hat tip to the redditor @frenvedd over on r/apple for this information!

https://twitter.com/DelFazli/status/700133655444746241

Post reply on HN