15 ms·
Secret Memo Details U.S.’s Broader Strategy to Crack Phones
- coldcode 11y ago"My guess is you could spend a few million dollars and get a capability against Android, spend a little more and get a capability against the iPhone. For under $10 million, you might have capabilities that will work across the board". Go ahead, good luck - Apple
- skybrian 11y agoThat's not an improvement. If Apple is necessarily in the loop, at least they have a chance to fight it in court. If the FBI can do it themselves, that's one less procedural speedbump.
- Consultant32452 11y agoFurther, if Apple is necessarily in the loop Apple won't close whatever holes the government tools utilize. If Apple isn't involved there's a chance they'd close the holes even if by accident.
- deleted 11y ago[deleted]
- mtgx 11y ago> What the court is ordering Apple to do, security experts say, does not require the company to crack its own encryption, which the company says it cannot do in any case. Instead, the order requires Apple to create a piece of software that takes advantage of a capability that Apple alone possesses to modify the permanently installed “firmware” on iPhones and iPads, changing it so that investigators can try unlimited guesses at the terror suspect’s PIN code with high-powered computers. Once investigators get the PIN, they get the data. I don't think there's much difference between a backdoor and that. A backdoor can be "just a vulnerability", and that's what the FBI is asking Apple to create - a vulnerability in its security system. It's kind of like saying "we don't want Apple to break its AES-GCM encryption, we just want it to replace it with RC4." Or "we only want Apple to support export crypto protocols as well, so we can downgrade to them when we do our attacks". Whether we call it a "backdoor" or "vulnerability" or "just don't make it that secure" thing, the end result is the same. The FBI wants Apple to weaken its security, and that weaker security can and will be exploited by malicious actors, too (even if you're assuming it won't be abused by the FBI and the police itself, which of course it will be).
- MCRed 11y agoAlso, the court isn't asking, its' demanding, and its demanding Apple create a vulnerability in a system designed to thwart such vulnerabilities. I'm not sure it's even possible. What if Apple didn't fight this yet failed to create a working vulnerability? After all the phone has protections against its firmware being replaced without the passcode! IF Apple were to fail would they be held in contempt of court? This is why I have contempt for our courts-- way too many judges who are never punished for their tyranny.
- blisterpeanuts 11y agoAnother issue, tangential and not widely discussed, is the very fact that a court, at a federal agency's behest, is ordering a private company to do highly technical and difficult work, at its own expense. They have not demonstrated that Apple committed a crime, and yet they demand that Apple set up an internal project and commit employees and resources to, essentially, do the FBI's work for it. There has to be a violation of the Constitution in there somewhere. The government cannot compel private companies or individuals to surrender private property (in this case, intellectual property), it cannot restrict freedom of speech (in this case, software is an expression of speech), and perhaps there is also a tie-in to the Commerce Clause. In other words, at a certain point the U.S. government's power should be and must be limited. Unlimited power is dangerous and surely would violate the vision and foundational philosophy behind the Constitution. In this case, unlimited power means that a law enforcement agency can justify nearly any kind of forcible action with the vague reasons of "national security" or "criminal justice".
- btreecat 11y ago> at its own expense. I don't think that is true. My google-fu is failing me however. I think I remember the party being compelled to comply is entitled to charge the Gov a fee for this work.
- blisterpeanuts 11y agoI'm curious what Apple would charge for this "service". If I were CEO, I'd request ten billion dollars. A million or so for the time and manhours, and $9.999 billion for the damage to the company's reputation, stock price, etc., that this will cause -- breaking of a promise that "even Apple can't retrieve your data". Suppose Samsung, a non-American company, jumps on this and says, their phones are truly non-crackable and Samsung would not be able to do it, even if they installed a hacked OS to work around the login failure limit. Boom. Apple has just lost millions of sales. Our heavy handed government hard at work, damaging America's best companies.
- bmay 11y agoAre there any open source alternatives to the iPhone that might take off because of these happenings?
- blisterpeanuts 11y agoI was wondering that as well, but on the other hand, by its nature an open source device would be much easier to hack, would it not?
- abrichr 11y agoNo. This is called security through obscurity, and is not effective. See: https://en.wikipedia.org/wiki/Security_through_obscurity?wprov=sfla1 https://en.wikipedia.org/wiki/Security_through_obscurity?wpr...
- xaduha 11y agoDon't keep stuff on your smartphone, that's my solution. At most it should be a thin client.
- MCRed 11y agoYou don't see them going after servers, because the servers are far more vulnerable.
- xaduha 11y ago> You don't see them going after servers, because the servers are far more vulnerable. Really? Every kind of server? I'm sorry, but that's some ridiculous statement. A device running proprietary software that governments have physical access to (after it was confiscated) is less vulnerable than (possibly) your own device running open source software that nobody except you has physical access?
- onion2k 11y agoThe statement "servers are more vulnerable [than phones]" doesn't mean "every server is more vulnerable than every phone". It's a more general point; trusting any given server is a greater risk than trusting any given phone. The fact that you can harden a server against attacks doesn't mean that your data being stored in the cloud is safer because, on the whole, people don't do much more than the minimum. Phone manufacturers do do more than the minimum.
- sarciszewski 11y agoWarning: Autoplay video.
- blisterpeanuts 11y agoSigh, I guess it's time to enable Click-to-play again[1]. I wish there were a way to just automatically pause on load, without needing to completely disable flash. 1. https://news.ycombinator.com/item?id=8802986 https://news.ycombinator.com/item?id=8802986
- coldpie 11y agoFirefox supports loading plugins like flash on demand on the Addons settings page. Additionally, Firefox has a setting "media.autoplay.enabled" to prevent HTML5 media from playing automatically. However, some websites assume autoplay succeeded and behave wrongly. For example, YouTube's paused/play button state is backwards.
- MCRed 11y agoMy Facebook feed is full of people ragging on Trump for being on the wrong side of this issue, but they are silent about Obama: "In a secret meeting convened by the White House around Thanksgiving, senior national security officials ordered agencies across the U.S. government to find ways to counter encryption software and gain access to the most heavily protected user data on the most secure consumer devices, including Apple Inc.’s iPhone, the marquee product of one of America’s most valuable companies, according to two people familiar with the decision."
- blisterpeanuts 11y agoIn 2007-8, Obama the candidate railed against warrantless surveillance as allowed under the Patriot Act.[1] Yet, when he came into power, he changed his position and supported all of the NSA's programs. It was only after the Snowden revelations that he said "we need to have a national dialog" and then pushed through a law that slightly narrowed the scope of surveillance but apparently left the core of the programs intact. To our knowledge, the NSA still has a tap on AT&T's Atlantic hub that can scan billions of packets an hour. The NSA still is as capable as before, only perhaps a bit more circumspect about it. Little has changed. 1. https://www.youtube.com/watch?v=ZVUwUCe1e-A https://www.youtube.com/watch?v=ZVUwUCe1e-A
- randcraw 11y agoObama is not running for President.
- liquidise 11y agoYou're right. Unlike Trump, Obama's misguided opinions actually matter.
- CaptSpify 11y agoObama already gave up this fight right away. He came on board promising to fight it, and doing the exact opposite. I guess I'm saying: We already know where he stands, therefore, he's not interesting anymore
- blisterpeanuts 11y agoThe Clipper chip initiative[1] from the Clinton era completely failed, for two reasons: one, the technology was proven to be flawed, and two, privacy advocates shot it down. It seems as though all the debates and analysis on this topic have already occurred. Yet, here we are again: a law enforcement agency demanding special privileged access to privately owned consumer electronics because it might contain useful crime fighting information. It seems to me that the U.S. needs to have a broader discussion about what levels of government surveillance and intrusiveness into private lives we are comfortable with. The outside threat of terrorism is now the club being wielded to force the issue, but is there really any evidence that this type of increased access helps? We had the Boston Marathon attack, in which two brothers immigrated from Chechnya, a known breeding ground for some of the most brutal terrorists in the world, the Russians actually phoned to warn us about them, and nothing was done. Similarly, there was chatter in 2000-2001 about an attack involving passenger jets, reported by Israeli and German intelligence agencies. Yet, nothing was done. One would have thought it common sense to scrutinize foreign nationals, especially from Muslim countries with a lot of hostility toward the U.S. among the populace, who were involved in aviation. Reportedly, the Israelis even were monitoring a couple of the 9/11 hijackers in the U.S. at one point. Should we not be streamlining our intelligence bureaucracies to avoid another Marathon fiasco, before sacrificing what little remains of our privacy on the altar of national security? 1. https://www.eff.org/deeplinks/2015/04/clipper-chips-birthday-looking-back-22-years-key-escrow-failures https://www.eff.org/deeplinks/2015/04/clipper-chips-birthday...
- MCRed 11y agoWe don't need to have a discussion. As you point out we already had it. It doesn't matter. We want privacy, we believe we have human rights. They don't care. They want power. That's what this all boils down to. They want power. And they are going to keep trying until they get it, just as they have taken over so much already.
- venomsnake 11y agoWe don't want privacy - we want the illusion of privacy that entrusting couple of corporations to not assist the LEOs gives us. What they want from apple is to use ability(and keys) they already have - so apple has not provided you with privacy in the first place.
- kbenson 11y ago> Knake said that the Justice Department’s narrowly crafted request shows both that FBI technical experts possess a deep understanding of the way Apple’s security systems work and that they have identified potential vulnerabilities that can provide access to data the company has previously said it can’t get. I assume the actual request is more technical then, because the overview they gave here explains the things you would want to do if you knew nothing about the encryption and wanted to brute-force. Reduce password attempt timeouts, allow automating the password attempts, and don't melt-down after too many failures.
- AngrySkillzz 11y agoThat's why a lot of people (myself included) are so cynical about the request. We all know the intelligence community has experience with side channel attacks, decapping processors, etc. But they've apparently decided not to use them in this case, "in the interest of time." If they really wanted that data, they could get it with their current capabilities. They don't really want that data; they want the legal precedent to compel companies to subvert their own security mechanisms, and they want to intimidate one of their harshest critics (Cook). That's part of their broader strategy; if we can compel you to break security you built, you build security you can't break. The next logical question is whether they can compel you to not build security mechanisms you cannot break in the first place. That's the legal question the FBI really wants to ask.
- t4cos 11y agoIn the latest Ctrl-Walt-Delete, Nilay (an ex-lawyer) makes a great, and chilling point, that it's entirely possible that the FBI can easily get into the phone with the help of the NSA, but that they're choosing to make a public request in this case to set precedent since so many facts are on their side. Terrorism, simple request, giving Apple full control, etc.
- lostlogin 11y agoFacts are on their side? Please could you explain that?
- guelo 11y agoI wonder if these "national security" people sit around longing for the next non-white person terrorist attack in order to spring their plans into action. EDIT for the downvoters, my point about non-white people is that terrorist attacks by white people, such as all the mass shootings, don't seem to trigger the grand plans that these national security types like to execute.
- marcosdumay 11y agoThey don't. They spend the entire time pushing their plans into execution (that's in plain sight). And when a terrorist attack happens, they probably just commemorate, adjust tactics, and follow on.
- morganvachon 11y agoThat's a hair's breadth away from the lunatic fringe. It's a simple logical leap to the conspiracy theory that the shootings are false-flag operations put in place by the powers that be to initiate legislation on encryption. That's probably why you are being downvoted.
- ionised 11y agoFalse flag operations aren't exactly an alien concept to US law enforcement and intelligence services, as well as other countries; https://en.wikipedia.org/wiki/Operation_Northwoods https://en.wikipedia.org/wiki/Operation_Northwoods http://www.washingtonsblog.com/2015/02/41-admitted-false-flag-attacks.html http://www.washingtonsblog.com/2015/02/41-admitted-false-fla...
- ionised 11y agoI believe they do. The Patriot Act/Homeland Security were planned and ready to go long before the September 11th attacks. http://www.washingtonsblog.com/2011/12/ron-paul-%E2%80%9Cthe-patriot-act-was-written-many-many-years-before-911-and-the-attacks-simply-provided-opportunity-for-some-people-to-do-what-they-wanted-to-do%E2%80%9D.html http://www.washingtonsblog.com/2011/12/ron-paul-%E2%80%9Cthe... The security/intelligence establishment were just waiting for an opportunity to put them into action and that act of terrorism provided all the justification. They are gross opportunists of the most obscene order.
- ipsin 11y agoJust in case I'm missing it, the story is that there's a National Security Counsel "Decision Memo" defining a strategy, but that memo has not been leaked?
- Zpalmtree 11y agoThis may be a stupid question and obviously Apple would never do it, but if Apple decided they wanted to ignore these requests, and stopped selling Apple devices in the US until the government backed down, do you think public opinion would force the government to comply? Just wondering how much power such a huge company has.
- AnimalMuppet 11y agoGiven that they're a US corporation, ignoring the requests could result in Tim Cook (and others) in handcuffs. Ignoring the government is not a safe option. That's where it would start. Then we'd see if public opinion was enough to rescue them. And I doubt that public opinion would be strongly enough in favor of Apple to save them. There's a lot of people who love Apple, true; but there are a lot of people who love national security, too. (And yes, I am aware that there is not an inherent contradiction between Apple's stance and national security, but I'm not sure that enough people understand that to make public opinion come down hard on Apple's side.)
- newman314 11y agoOr cue what happened to Naachio. https://www.washingtonpost.com/news/the-switch/wp/2013/09/30/a-ceo-who-resisted-nsa-spying-is-out-of-prison-and-he-feels-vindicated-by-snowden-leaks/ https://www.washingtonpost.com/news/the-switch/wp/2013/09/30...
- joering2 11y agoCouldn't have more respect to this man. And his case feels like carbon copy of Lavabit, where he couldn't defend himself (literally!!!) But Nacchio was prevented from bringing up any of this defense during his jury trial — the evidence needed to support it was deemed classified and the judge in his case refused his requests to use it.
- newmemory 11y agoNope. The CEO will just be tried, convicted and jailed. And while that's happening, the backdoor will be quietly installed. Remember Quest[1]? [1]: http://www.denverpost.com/business/ci_25434854/former-qwest-ceo-nacchio-claims-tv-his-jail http://www.denverpost.com/business/ci_25434854/former-qwest-...
- pc2g4d 11y agoI think this issue is important and I hope Apple prevails over the FBI. However, I'm also left feeling that they're subject to this request only because of what amounts to a security flaw in their own devices. How/when can I run a phone OS that simply isn't subject to such known flaws and corporate manipulation? What are my options?
- treebeard901 11y agoTwo interesting possibilities to consider: 1) The government has already gotten past the iPhone security and read the data. 2) Apple already has the software they were asked to create.
- rbanffy 11y agoSimple question: what prevents the FBI from removing the components from the phone and using software they themselves wrote to drive the hardware crypto and decode the data they want? It can't be that difficult, if you have FBI-class resources and some help from the NSA, to lift the components and make them work on a copy of the encrypted data.
- rbanffy 11y agoNever mind. Just read the Q&A on the secure enclave. I wonder if decapping the chip would allow to extract the UID from the chip wiring.
- noblethrasher 11y agoThe iPhone in question is a 5c, which does not have the Secure Enclave.
- rbanffy 11y agoIf I understood it correctly, the UID is still not directly readable even though the actual computation happens in the same CPU, not inside a secondary secure environment.