2 ms·
> This is just huge hypocrisy and full of lies. First of all, Apple CAN attempt to brute force the password. Compiling whatever new firmware is needed and signi
by voidpointer 11y ago
> This is just huge hypocrisy and full of lies. First of all, Apple CAN attempt to brute force the password. Compiling whatever new firmware is needed and signing it with their keys will not introduce any new backdoor like they claimed and lied to the public - the backdoor is already there, and it is their private keys. Just like that "backdoor" somehow end up at some bad guy's hand, so could their private keys.
Thank you! This is the most important technical point about this whole thing. All the talking about the SE (fascinating as it may be) is irrelevant. All strong crypto that is based on a private key being kept in a secure vault at some corporation does have a backdoor. The keeper of the key can be compelled to use it to sign something.
This is exactly why this would be such a dangerous precedent. Government giving software specifications that are signed with a vendors public key. In this case, it's a one off but it's a step into the direction of "upload a screen-shot of the phone's display every minute to ftp.nsa.gov with your next iOS update". And no SecureEnclave will protect against that. It will just be a OS update signed by Apple.