3 ms·
The other question is if it's legal for a company to design their devices so that it is technically impossible for them to comply. Is there any practical reaso
by ascorbic 11y ago
The other question is if it's legal for a company to design their devices so that it is technically impossible for them to comply.
Is there any practical reason why the secure enclave could not be programmed such that any firmware update to the enclave requires the PIN, and if not it erases the key. That way Apple is still able to make updates to the enclave, but cannot be compelled to bypass security restrictions on locked devices.
- bryanrasmussen 11y agoIt would be difficult to design a law in a Napoleonic system that disallowed that(designing their devices so that it is technically impossible for them to comply), although in the American system I guess it would be possible.
- kabdib 11y agoWe've come close to this already (mandated Clipper chip). Which would have been a disaster, in many areas. IIRC, the ITAR rules even prohibited systems that lacked crypto, but that had pluggable APIs which permitted crypto to be added later (e.g., by the end-user). It's hard to see how legislation to the same effect would pass constitutional muster, but it's a gamble, and the administration has little to lose.
- amatix 11y agoPure speculation: I wonder if v2 of the Secure Enclave was going to do just that, but Apple wanted to make sure there weren't glaring software flaws in v1 before they lock themselves out of the chip for good.