Live data from Hacker News

Why can't Apple decrypt your iPhone?

blog.cryptographyengineering.com

1–10 of 132 posts

Re: Why can't Apple decrypt your iPhone?

#4
post #3

And what about a backdoor? Code is not open-source. Just saying..

I'm skeptical as well. Seems to me that so many things on your phone are talking to Apple (and other 3rd parties) anyways, that this might not even matter?

Although the FBI seems to be not very happy about this (if it's not just "for show" that is)[1]. The FBI is using the age-old "Save/Protect the children" argument, literally.

[1] http://www.washingtonpost.com/business/technology/2014/09/25...

Re: Why can't Apple decrypt your iPhone?

#5
post #4
post #3

And what about a backdoor? Code is not open-source. Just saying..

I'm skeptical as well. Seems to me that so many things on your phone are talking to Apple (and other 3rd parties) anyways, that this might not even matter? Although the FBI seems to be not very happy about this (if it's not just "for show" that is)[1]. The FBI is using the age-old "Save/Protect the children" argument, literally. [1] http://www.washingtonpost.com/business/technology/2014/09/25...

Never mind that none of this matters if you have unlocked the phone and it's on (default protection policy is protect until first unlock, which happens right after turnup). That's gotta be 99.9% of cases. Once the police or apple have a locked phone, all bets are off. Apple can just install an app remotely that gets them past the lockscreen, and unless this is from a cold boot, you have access to all apps and all data. This includes access to e.g. The logs of any configured skype session, the company mails ...

Add to that the usual closed software problems. Apple says they don't have a specific backdoor anymore (!), and they won't let you audit anything.

Re: Why can't Apple decrypt your iPhone?

#6

   1. [...]
   2. [...]
   3. [...]
   4. [...]
   5. The manufacturer of the A7 chip stores every UID for
      every chip.
I'm a total layman, but the UID has to be created at some point and so it can be known by someone. Wouldn't it be the easiest way to just record it for every chip? Apple wouldn't even have know about it.

Re: Why can't Apple decrypt your iPhone?

#9

1. [...] 2. [...] 3. [...] 4. [...] 5. The manufacturer of the A7 chip stores every UID for every chip. I'm a total layman, but the UID has to be created at some point and so it can be known by someone. Wouldn't it be the easiest way to just record it for every chip? Apple wouldn't even have know about it.

This is the fundamental problem: unless you are rolling your own silicon, at some point you have to take some big corporation's word for it that a chip does what they say it does. This fundamental problem is the reason that nuclear launch codes are protected by a relatively low-tech solution:

http://en.wikipedia.org/wiki/Gold_Codes

Post reply on HN