6 ms·
This seems to be a common question and I've seen it answered incorrectly a number of times. The simple answer is that Apple has the key to sign software that w
by Judson 11y ago
This seems to be a common question and I've seen it answered incorrectly a number of times.
The simple answer is that Apple has the key to sign software that will run on iPhone boot, AND Secure Enclave boot. Neither technically require the phone to be unlocked, and SE updates do not (currently) wipe secrets.
Lots of talk about 5c vs 5S onward phones, but Apple can remove bruteforce protections from all iPhones currently on the market.
The answer is B (though they can only update the software to remove bruteforce protections in this case).
(That said, I firmly believe that won't be the case for long)
- bcg1 11y agoSo to clarify my understanding... i-whatevers have some sort of "trusted computing" bootloader or something... so can only boot a digitally signed version of the OS. So even if the FBI dumped the firmware from the phone and found just the right branch instructions to flip to disable the time delay and data erasure... they couldn't deploy the firmware because it wouldn't boot. Is that generally what the issue is? And if it is... wouldn't that mean that Apple is 100% correct in saying that creating such a firmware would allow "law enforcement" to do this to any phone in their possession (since they could install the same firmware on other Apple devices?)
- pfg 11y agoThe FBI is saying Apple should create a version of their firmware that only works on this specific device. I'm not sure if that's possible, though - if whatever ID they're checking can be spoofed on another device, they'd have a backdoor for all devices. This is really more about the legal precedent.
- abalone 11y agoYes except the FBI wants to send the phone to Apple to do the hack and remotely access it so the firmware never leaves the building. Apple's claim is that this 1) may be abused by authorities through subsequent requests and 2) is too dangerous to create because "cyber criminals" will try to hack them and steal it. Abuse is definitely a concern, although one would hope that could be resolved through democratic oversight, rather than shutting down the ability of law enforcement to obtain digital records under most circumstances. But as for the concern about getting hacked, I wonder if Apple is being a bit coy. They already possess the private signing key. That's already a super valuable secret that would allow criminals to install their own malcode. That danger already exists. It would be harder if the hacker also had to hack the firmware, but probably not harder than hacking Apple to get the private key in the first place.
- ryukafalz 11y agoThe private signing key can and should be stored only offline. It's presumably only used when new OS updates need to be signed, and as a result it's fine to require manual intervention during that process. By contrast, putting a device with the modified firmware on the network and allowing it to be accessed remotely makes it a much easier target than the private signing key. A compromise still isn't likely, mind you, but that's a pretty damn attractive target.
- abalone 11y agoThat's a good point about the private key never even touching a network. Here's a thought: if the crack firmware does leak, and Apple becomes aware of it, could they just push out an OS update that rotates the signing key? That should effectively disable it, once updated. What I'm getting at is this seems more about resisting government abuse / repressive regimes than technical infeasibility of limiting it to authorized users.
- Judson 11y ago> i-whatevers have some sort of "trusted computing" bootloader or something... so can only boot a digitally signed version of the OS. Yes. > So even if the FBI dumped the firmware from the phone and found just the right branch instructions to flip to disable the time delay and data erasure... they couldn't deploy the firmware because it wouldn't boot. Correct. > Wouldn't that mean that Apple is 100% correct in saying that creating such a firmware would allow "law enforcement" to do this to any phone in their possession. Only Apple knows the answer to this with 100% certainty.
- natch 11y agoDepending on how it was done, they might still have to go through Apple. But China/Iran/Russia/whereever could say: "You did it for the FBI, so you need to do it for us, too." And the FBI could say: "You did it in that last case, so you need to do it in these other cases too." And every local podunk sheriff in any jurisdiction could do the same thing, and there would be no end to Apple having to fight these things or do this work. Not to mention that its customers would start getting harmed in countries where leaks of your private information can lead to your death.
- teacup50 11y agoThat's not an argument against legal search and seizure. If Apple doesn't want to be in that position, they shouldn't have put themselves in that position by retaining and requiring full control over devices via platform-level DRM.