Live data from Hacker News

Justice Department Wants Data from About 12 Other iPhones

wsj.com

1–10 of 101 posts

Re: Justice Department Wants Data from About 12 Other iPhones

#4
post #2

I think the fear is that those 12 will lead to the other 700 million iPhones.

That's not a justified fear. Requiring Apple to backdoor all phones is not similar at all to requiring Apple to help hack particular phones, that they have the capability to hack, in response to court orders.

Re: Justice Department Wants Data from About 12 Other iPhones

#5

there's quite a few more than are involved in probably about 9 innocent deaths PER DAY. http://www.huffingtonpost.com/2015/06/08/dangers-of-texting-... Does the justice dept want those unlocked too?

Comey said the FBI wants the ability to do this even for car accidents, so a qualified "yes."

Re: Justice Department Wants Data from About 12 Other iPhones

#6
post #2

I think the fear is that those 12 will lead to the other 700 million iPhones.

That's not a justified fear. Requiring Apple to backdoor all phones is not similar at all to requiring Apple to help hack particular phones, that they have the capability to hack, in response to court orders.

You haven't been paying attention. Please explain how a security hole can only be exploited by Apple+FBI and no one else.

Re: Justice Department Wants Data from About 12 Other iPhones

#7
post #2

I think the fear is that those 12 will lead to the other 700 million iPhones.

That's not a justified fear. Requiring Apple to backdoor all phones is not similar at all to requiring Apple to help hack particular phones, that they have the capability to hack, in response to court orders.

You're telling me you would trust that software to remain in the hands of trusted actors? In 2015, alone, the IRS was breached, LastPass, the director of the CIA, Hacking Team, even Kaspersky Labs was breached! There can be no absolute guarantee that this backdoor would remain safe indefinitely. That is just the most blatant problem, not to mention the overt displays of cynicism and misuse of authority by the NSA as revealed by the Snowden leaks. Consider the political climate in the US at the moment. Now imagine a truly evil actor came into power, being handed over control of organizations with unheard-of amounts of surveillance power. I don't mean to seem paranoid, but in this case the feeling is completely warranted.

Re: Justice Department Wants Data from About 12 Other iPhones

#8
Question for HN in general: Is it possible in principle (for Apple or someone else) to construct a smartphone that can accept software/firmware updates, but that Apple cannot push malware to at some later time?

E.g. can we implement all security functionality in hardware/burn it into the silicon? Or accomplish the same ends by some other means?

Intuition says "no," because "security functionality" is sort of nebulous. But it would be great if a device could be constructed in such a way that all such future demands for collusion by hostile actors such as governments could be rendered preemptively impossible.

Re: Justice Department Wants Data from About 12 Other iPhones

#9
post #8

Question for HN in general: Is it possible in principle (for Apple or someone else) to construct a smartphone that can accept software/firmware updates, but that Apple cannot push malware to at some later time? E.g. can we implement all security functionality in hardware/burn it into the silicon? Or accomplish the same ends by some other means? Intuition says "no," because "security functionality" is sort of nebulous…

It should be completely possible for them to not accept any software updates unless the phone is unlocked. They may not wish to do this for various reasons, but it is definitely technically possible.

Re: Justice Department Wants Data from About 12 Other iPhones

#10
post #8

Question for HN in general: Is it possible in principle (for Apple or someone else) to construct a smartphone that can accept software/firmware updates, but that Apple cannot push malware to at some later time? E.g. can we implement all security functionality in hardware/burn it into the silicon? Or accomplish the same ends by some other means? Intuition says "no," because "security functionality" is sort of nebulous…

It is possible, with caveats. The user has to be able to decide whether to accept an update or not, and signal their assent or rejection with their password. And the software has to be open source, so that the user can inspect a proposed software update and decide whether it is malware or not (or let others inspect it and know they have the same thing). In practice this is imperfect, because trustworthy volunteers willing to audit software are scarce.
Post reply on HN