5 ms·
>"It is no different than [the question of] should anybody ever have been able to tell the phone company to get information, should anybody be able to get at ba
by zer01 11y ago
>"It is no different than [the question of] should anybody ever have been able to tell the phone company to get information, should anybody be able to get at bank records,” he said. “Let’s say the bank had tied a ribbon round the disk drive and said ‘don’t make me cut this ribbon because you’ll make me cut it many times’."
Seriously? It's absolutely different (not to mention his ribbon analogy makes no sense at all). I see all of this more a question of "can Americans actually have anything remain private on a commercial device?". I don't want anyone but me to have unfettered access to my data, regardless of if it's phone records, bank info, or my phone's contents.
Here's hoping that the iPhone 7 has a secure enclave that either 1.) deletes keys on firmware flash, or 2.) doesn't allow it to be upgraded ever.
- noxin 11y ago> I see all of this more a question of "can Americans actually have anything remain private on a commercial device?". It's Americans now, but if Apple gives in, investigators from other big markets might pressure Apple to do the same for them. I think that's what's meant with cutting the ribbon many times.
- camillomiller 11y agoThis debate is global. Why is it so hard to understand for most politicians? It's a matter of national security because the matter is not strictly national, and could have reverberation all over the world, especially in very sensitive markets like China.
- saurik 11y agoThe reality is that Apple already has unfettered access to this device: they left themselves a backdoor to which only they have the key, in the form of a "secure" update mechanism that is so "secure" that even the user can't control it, only Apple can. To me the actual question here is whether the FBI should be allowed to ask and then force Apple to use the backdoor Apple built into their product; Apple painting this as if they are being asked to build a backdoor instead of use an existing one is them being nothing more than dishonest in an attempt to twist the story and shift the blame. So yes: I think it is fair to describe the security of this device, from the perspective of Apple, as nothing more than a ribbon, as Apple already has "unfettered access to [your] data". Apple trusts users so little that they don't give users control of the hardware they own... this is frankly a good lesson on them that this is responsibility they should never have hoarded. "Here's hoping that the iPhone 7 no longer has a backdoor that is controlled by Apple."
- acqq 11y ago> from the perspective of Apple, as nothing more than a ribbon, as Apple already has "unfettered access to [your] data" No! Since iOS8 Apple intentionally encrypts the user's data on the phone in a way that even they don't have access to them. They have access to the hardware, to be able to reconfigure it, but not the encrypted data on the phone. Because the data is encrypted, intentionally so. And they have access to the iCloud backup data and they gave that data to the FBI. Then FBI actually locked their access to the phone by changing the iCloud password.
- saurik 11y agoThis is an iPhone 5C, which does not have the "secure enclave" feature, and it isn't even clear helps as Apple has stated to reporters that it is possible to do what the FBI wants, so we know the software on that component must be mutable. If it was actually impossible to do the thing the FBI wanted them to do then we would not even be having this discussion today: Apple would just say "can't, sorry" and the FBI would be forced to move on with their lives as nothing Apple could do would help them get access to the device.
- acqq 11y agoSecure Enclave is irrelevant here. Even without Secure Enclave the data on iPhone 5C is encrypted with the user's password and Apple doesn't have access to the data as it doesn't have user's password, contrary to your claim that "Apple has the access to the data." No, FBI has access, but only to the encrypted data. And FBI can't decrypt it. They locked themselves out of the phone, actually. And the phone is not the private phone of the killer, he destroyed that one, and his computer too. And note that he didn't care about this phone. FBI demands from Apple to change their product (iOS) to make the encryption cracking attempts by FBI easier.
- saurik 11y agoIt takes mere minutes for us to crack the 4- digit passcode on the iPhone 4 (which I only specify as that's where we were last able to easily do this in the jailbreak community; it might be faster now), and most people likely don't use terribly strong passwords; the FBI might also have "leads" on what the password is, but not good enough ones that they feel confident dealing with ten attempts. This is a backdoor to the lock: you can quibble with me over the definition of "unfettered" (I do not consider "it will take some time, but I absolutely have a 100% chance of getting access without fail" terribly "fettered", but it definitely is more than the people who are frustrated with this situation seem to want the FBI to have). > FBI demands from Apple to change their product (iOS) to make the encryption cracking attempts by FBI easier. ... and we should be thankful the FBI didn't simply demand the 4096-bit key Apple uses to sign firmwares, because that's all they actually need--nothing more than 512 bytes of data--in order to accomplish the thing everyone is upset about here.
- acqq 11y ago> Here's hoping that the iPhone 7 has a secure enclave that either 1.) deletes keys on firmware flash, or 2.) doesn't allow it to be upgraded ever. If you hope for that, consider the legal base on which FBI made the current request: All Writs Act, which is, in full: https://en.wikipedia.org/wiki/All_Writs_Act https://en.wikipedia.org/wiki/All_Writs_Act "(a) The Supreme Court and all courts established by Act of Congress may issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law. (b) An alternative writ or rule nisi may be issued by a justice or judge of a court which has jurisdiction." Note it's not any kind of law that regulates any form of encryption or communication security, a lot of laws with such topics were fought through the years! It's just "we can demand anything we want." Then consider how long such Secure Enclave will last if this precedent on such use of this Act is now to be made.
- zer01 11y agoI agree that it would be upsetting if precedent was made, but I believe it is technically feasible to build a device whose keys are only known by an end user. The FBI is basically asking to go down legitimate update channels to brute force their pass-code, and while that's still a feasible option, of course the FBI is going to ask to use it. Updating the security model of the secure enclave to either destroy keys on flash or disable the flashing mechanism all-together would render the ability outside of even apple's reach, then it goes back down to a question of if you can be compelled to give up your encryption pass-phrase, which I believe precedent has already been set on (please correct me if I'm wrong). As an aside it bugs me to a fairly large degree that we still attempt to apply very old laws to something they were never designed to address the things we put in front of it. It feels very akin to trying to jam a square peg in a round hole. Ever play with a wifi pineapple? Ever build one yourself? Congrats! You broke a federal wiretapping statute! https://www.law.cornell.edu/uscode/text/18/2511 https://www.law.cornell.edu/uscode/text/18/2511 https://www.law.cornell.edu/uscode/text/18/2512 https://www.law.cornell.edu/uscode/text/18/2512
- acqq 11y ago> I believe precedent has already been set on (please correct me if I'm wrong). No, as far as I understand, this now would be a new and dangerous precedent: Nobody was ever asked to alter their product using All Writs. That's what's here all about.