8 ms·
Apple Has Not Unlocked 70 iPhones for Law Enforcement
- Overtonwindow 11y agoI wonder what Apple's PR machine is doing on this front to support their position. The more articles I see about what Apple can, cannot, will not, or could not do, makes me suspect Apple's PR team is behind some of those articles.
- marcoperaza 11y agoTLDR for what follows: Mandated backdoors must be a red line, but this is not a request for a backdoor and actually seems pretty reasonable. Trying to argue that the tech industry shouldn't help, even in this case, is not only the wrong position in my book, but a sure way to lose the bigger debate. My views on the general encryption controversy are: 1. Everyone must be free to make their technology as secure as they possibly can. There can be no mandated weakening of security, back-doors, or other requirements to make the information more easily accessible by law enforcement. On newer iPhones, Apple has patched up the flaw that the FBI wants their help with exploiting. They must continue to be allowed to do that. 2. The government must be able to demand, with a court order predicated on probable cause, that companies provide any and all information that they have that could be useful in circumventing their security features. This can be everything from technical specifications and threat-model analyses, to lists of unpatched vulnerabilities and code-signing keys. 3. It seems to me that American companies have a moral obligation that goes beyond the legal obligations in point #2. They should be actively assisting the government in recovering information, especially when concerning issues of national security. In extreme circumstances, like total war, this should definitely be legally mandated. I'm undecided as to what the policy should be generally. On a practical level, it's probably not feasible for the government to, e.g. start hacking around the iOS codebase themselves, so just information might not be enough. I'm not too troubled by this court order, especially given the particular circumstances. The right to make products as secure as you can, even from yourself and the government, is what's really important to defend. Trying to argue that the tech industry shouldn't help, even in this case, is not only the wrong position in my book, but a sure way to lose the bigger debate. Disclaimer: These are obviously my own personal views and nothing else. They do not necessarily reflect the opinions, policies, or practices of anyone but myself.
- cbhl 11y agoDo you still hold the same position if we replace the United States / FBI with China? Apple sells tens of billions of dollars of iPhones to China every year. If Apple provides assistance to US law enforcement but not to Chinese law enforcement, that's going to be a disaster. But if Apple provides assistance to Chinese law enforcement, that's a different kind of disaster.
- marcoperaza 11y agoSearch and seizure is a fundamental government power. I doubt any modern state would be viable (i.e. maintain its monopoly on violence) without it. In the US, we have procedures and standards of evidence that the government must meet in order to exercise that authority. That's not the case in China. So yes, the Chinese government should absolutely have this authority; they wouldn't be much of a government otherwise. They should also absolutely have protections against unreasonable searches and seizure. The lack of these protections is the problem, not that their government has search and seizure powers. A tech company operating in China has to make a choice between subjecting itself to Chinese law, or not doing business in China. The same goes for policing in general in authoritarian regimes. The Chinese police state is undoubtedly evil. But I'd bet that most of the time, they're going after your run-of-the-mill crooks that need to be policed in China just as they are in America. Your argument is a good one though. I think there is a real danger of accidentally building the infrastructure for a future totalitarian regime. It's also a good political argument when it comes to international issues, like Microsoft's argument that the US government can't force them to hand over data that's stored in Ireland. I'd like to see Microsoft win the case in court, but I suspect that the government will win. US court orders are binding even when they require you to break foreign laws. But the government exercising that authority in this case could totally undermine US cloud data providers, so I suspect that Congress could be persuaded to restrict the government's authority here.
- ekianjo 11y ago> Search and seizure is a fundamental government power. What's not fundamental is that it should not be used UNLESS you are suspecting a person of wrongdoing with serious facts in the first place. It's never supposed to be an all-encompassing absolute power. > I doubt any modern state would be viable without it. There's hardly any data on states that don't exercise such powers, so don't spread the fallacy that the opposite cannot be true. It's not because right now A is linked to B that you actually need A to have B in absolute terms - you just don't know that. We are living in an era of nation-states themselves coming from a long history of monarchical power (an inheriting the same rights and powers, more or less as governments instead of a single person), so it's not like we have ever tried to design societies in a very different way at all so far.
- WatchDog 11y agoNot sure if this has been discussed, but it seems that the only reason this is an issue is because Apple has the ability to install new software on a locked device. Couldn’t Apple simply remove the ability for a software update to take place without the device being unlocked or wiped? Obviously this wouldn’t apply retroactively to old IOS versions, but it would be consistent with their change in policy from IOS 7 to 8.
- dustingetz 11y ago> Apple has the ability to install new software on a locked device. People keep saying this but it probably isn't true. When law enforcement has physical access to the hardware, they can take apart the phone and flash it with new software and put it back together.
- TazeTSchnitzel 11y agoI don't think that's what's meant either. You can plug any iPhone into iTunes and flash new firmware to it, as long as it's signed by Apple. That's what the FBI want to do, I believe.
- Normal_gaussian 11y agoThis is correct. To prevent this kind of attack surface the mechanism for applying new firmware needs to wipe access keys for the encrypted data, and for these keys to not be accessible without changing the firmware.
- dustingetz 11y agobut i already have to enter my password to apply the update and again when my device boots? Can you link to technical details please, I have been following these developments and have seen no technical explanation of the vector.
- typicalbender 11y agoI don't know if they do, and if they do they going out of their way to keep it hidden. They released an update to fix bricked phones where the touchID was repaired by a 3rd party [1]. The update was only released through iTunes because they cannot push an OTA update to a locked device. [1]: http://techcrunch.com/2016/02/18/apple-apologizes-and-updates-ios-to-restore-iphones-disabled-by-error-53/ http://techcrunch.com/2016/02/18/apple-apologizes-and-update...
- sandworm101 11y ago>>> Apple also argues that since its reputation is based on security and privacy, complying with the court’s demands based on an expanded application of a 200-year-old law could put it at risk of tarnishing that reputation. One one hand, a corporate reputation. On the other, people from the FBI saying they need access to prevent terrorist attacks. There are many arguments to be made. This is not the winner.
- heartbreak 11y agoFortunately that argument is being made in the NY case which is not the terrorism related case in CA.
- MBCook 11y agoThe interesting thing in the CA case that's not getting a ton of play is the FBI has the support of the phones legal owner (a government agency) but the owner doesn't know the passcode in this situation. If the suspected terrorists owned the phone themselves, we'd also have the 5th amendment wrapped up in that case too.
- rosser 11y agoIf the suspected terrorists owned the phone themselves, we'd also have the 5th amendment wrapped up in that case too. No we wouldn't. The "suspected terrorists" are dead.
- lern_too_spel 11y agoNot all of them. Their neighbor is a suspected accomplice and is currently being investigated.
- rosser 11y agoIrrelevant. He has no 5th Amendment standing vis à vis the deceased shooter's work phone.
- dclowd9901 11y agoI get so sick of this. Whenever some sort of dictatorial measure is taken or proposed, the go-to cleanup is "this is the norm, this is status quo, nothing to see here." We saw it all over the fucking Bush campaign when special rendition reports and waterboarding shit was coming out. We even saw Bush (probably Cheney) writing his stupid little memos which he tried to mold into executive orders, absolving the CIA of torture. Does anyone actually buy this fucking defense?
- satyajeet23 11y agoIf it's about Apple, some key detail will always get jacked up by a journalist like Shane Harris of 'the daily beast', trying to translate it for the public. Report is extremely misleading and an example of bad journalism.
- hauget 11y agoExcuse my ignorance, but is Apple's encryption in iOS 9 devices significantly stronger than any of the newest Android devices? Also, are there any precedents of any government demanding the unlocking of any Android phones?
- CaptSpify 11y ago>Excuse my ignorance, but is Apple's encryption in iOS 9 devices significantly stronger than any of the newest Android devices? AFAIK, I don't think we know, or can compare. It's my understanding that Apple's setup is closed-source, so we can't inspect, whereas Android's is open. Someone please correct me if I am wrong. >Also, are there any precedents of any government demanding the unlocking of any Android phones? This isn't an issue, as, by default, android phones send everything to the cloud (exceptions for custom roms, etc). So govt can just ask Google for a copy from their server instead.
- weinzierl 11y agoThis is interesting and new to me: > For iOS devices running iOS versions earlier than > iOS 8.0 [..] > Please note the only categories of user generated > active files that can be provided to law enforcement [..] are: > SMS, iMessage, MMS, photos, videos, contact, audio recording, and > call history. > Apple cannot provide: email, calendar entries, or any third-party > app data. What is the difference between the two categories? Are email and calendar entries encrypted on iOS7 and below?