4 ms·
I agree - this is the type of vulnerability that, assuming Apple is extremely careful about protecting their signing key, is only exploitable by court order or
by geographomics 11y ago
I agree - this is the type of vulnerability that, assuming Apple is extremely careful about protecting their signing key, is only exploitable by court order or similar state request. This crypto implementation on iPhones and the like isn't really designed to protect against that, it's really more to prevent the common criminal from accessing your personal data. Apple already comply with law enforcement requests to access iCloud backups and other such data, so assisting with this passcode crack isn't really much of a stretch.
- outworlder 11y ago> I agree - this is the type of vulnerability that, assuming Apple is extremely careful about protecting their signing key, is only exploitable by court order or similar state request. Apple has been trying to prevent jailbreaking for years - they've always failed, so I'm skeptical about this "only exploitable by court order" bit. Determined people will find ways around the protections. Heck, it is even possible that someone (think nation-states) has already found a way to circumvent the passcode lock. This will only lower the barrier of entry.
- geographomics 11y agoJailbreaks address a different type of vulnerability - that of incorrectly written code or poorly designed systems, that can lead to a privilege escalation. The vulnerability that the FBI are using is the ability of Apple to update the iPhone with arbitrary code, provided it has been signed with their secret key. It's an important feature, of course, but still a security vulnerability - albeit an irrelevant one for the vast majority of iPhone users.