20 ms·
Apple Is Said to Be Working on an iPhone Even It Can’t Hack
- tptacek 11y agoThey're presumably already 99% of the way there. If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? To me, the more profound consideration is this: if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone. The AES-XTS key that protects data on the device is derived from your passcode, via PBKDF2. These devices were already fenced off from the DOJ, as long as their operators were savvy about opsec.
- w1ntermute 11y ago> if you use a strong alphanumeric password to unlock your phone, there is nothing Apple has been able to do for many years to unlock your phone Is this true even if you use Touch ID?
- themagician 11y agoTouchID disables itself after 48 hours and requires the password again.
- bobbles 11y agoAlso after 5 failed attempts - you can test with an unregistered finger
- matt_wulfeck 11y agoOr if the phone runs out of batteries and restarts.
- rdancer 11y agoIf the has been switched off or if >48h passed since the last unlock. Also remember that rubber-hose cryptanalysis is always an option.
- newjersey 11y agoCan you be convicted in the US based on evidence obtained with physical torture? Edit: Looks like the answer is it depends and not a resounding no http://www.nolo.com/legal-encyclopedia/evidence-obtained-through-torture.html http://www.nolo.com/legal-encyclopedia/evidence-obtained-thr...
- tptacek 11y agoNo, you cannot. Evidence derived from facts learned from torture is also excludable.
- CamperBob2 11y agoSure, you can. It all depends on who gets to define "torture." If they can find a judge who believes the iron maiden isn't torture while the anal pear is, then guess what... the government will use the iron maiden. Even if they can't find such a pliable jurist, they'll have no problem getting a John Yoo to write an executive memo that justifies whatever they want to do to you, and let the courts sort it out later. There's no downside from their point of view.
- rdancer 11y ago> getting a John Yoo to write an executive memo The memos didn't provide de iure indemnity. There is no constitutional basis, in fact the proposition that a memo can supersede the Constitution is idiotic on its face. The failure is the de facto doctrine of absolute executive immunity. It has two prongs: 1. "When the president does it, that means that it is not illegal." 2. When the perpetrator follows president's orders, also not illegal. Nevertheless, since there is no legal basis, there is nothing preventing the next government from prosecuting them.
- taneq 11y agoDoes TouchID have any protections against your finger unlocking your phone post-mortem?
- toomuchtodo 11y agoNo, although I'd love to see a HealthKit app that uses your Apple Watch as a dead man's switch, and disables Touch ID or powers the phone off in the event the watch is removed or your pulse is no longer detected.
- mahyarm 11y agoThat wouldn't work well with loose wrists and other similar edge cases.
- jedberg 11y agoThen those people could turn it off. But it would be a nice option.
- Crito 11y agoWithout a wristprint for the watch to read, what prevents somebody else from wearing it? The pulse and skin conductivity might change, but are either of those reliable enough metrics for such an application?
- X-Istence 11y agoIf you take the watch off, it automatically locks. I wouldn't mind it also automatically locking my phone and requiring a passcode instead of TouchID. There is a VERY limited amount of time in which you can take the watch off and switch to another wrist (like milliseconds, you have to practically be a magician to switch wrists (which I do throughout the day)). Apple has the watch, they could use it to beef up security for those that want it.
- tptacek 11y agoProbably not. If you're dead, they probably have your fingers. If you're alive, they can compel you to unlock the device with your fingerprint. The only point I'm making is that Apple already designed a cryptosystem that resists court-ordered coercion: as long as your passcode is strong (and Apple has allowed it to be strong for a long time), the phone is prohibitively difficult to unlock even if Apple cuts a special release of the phone software.
- petra 11y agoUsing a strong pin is pretty annoying, and a relatively visible signal when using the phone on the street etc, So it can be a good filter(maybe via street cams) to filter suspicious people - which isn't a bad goal for law enforcement.
- tptacek 11y agoThat sounds good until you remember the Bayesian Base Rate Fallacy: there are very few terrorists (the base rate of terrorism is very low), so filtering on "people with strong passphrases" is going to produce an overwhelming feed of false positives.
- contravariant 11y agoBe careful not to take the base rate fallacy too far, with enough difference in likelihood even a small base rate won't prevent an effect from being significant, and regardless of the base rate you'll still get some information out of it, it might just not be as much as you wanted.
- jameshart 11y agoCorporate email profiles on BYOD phones often enforce a long passcode requirement, so you've got a lot of Fortune 500 sales guys to screen out if you're stopping and searching anybody with a suspiciously long password.
- dylan604 11y ago
- r00fus 11y agoIf they have access to a live finger for the TouchID, sure they can bypass - but they could do that with the $5 guaranteed coercion method as well [1]. Copying a good fingerprint from a dead finger or a randomly placed print is not easy [2]. It's hard, doable but you get 5 tries so if you screw up, you have thrown away all the hard work of the print transfer. All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). [1] https://xkcd.com/538/ https://xkcd.com/538/ [2] https://blog.lookout.com/blog/2013/09/23/why-i-hacked-apples-touchid-and-still-think-it-is-awesome/ https://blog.lookout.com/blog/2013/09/23/why-i-hacked-apples...
- toomuchtodo 11y ago> All bets are off if the iPhone is power-cycled. Best bet if you're pulled over by authorities or at a security checkpoint is to turn off your iPhone (and have a strong alphanumeric passcode). Excellent advice. Even better, if you're about to pass through US customs and border patrol, backup the phone first, wipe, and restore on the other side. Of course, this depends on your level of paranoia. I am paranoid.
- deleted 11y ago[deleted]
- FussyZeus 11y agoWiping the phone doesn't help you. Using the strong password renders the information inaccessible, at least as inaccessible as your phone backup is. Touch ID isn't re-enabled until the phone's passcode is used. Presumably if the authorities have access to your phone's memory they also have access to your laptops, and neither will do them any damn good. And it's paranoia if there's a legitimate threat, that's just called due diligence. ;)
- guscost 11y ago> Touch ID isn't re-enabled until the phone's passcode is used. Do the docs confirm that there is no way around this? I'd guess generating the encryption key requires the passcode, which is discarded immediately, and Touch ID can only "unlock" a temporarily re-encrypted version which never leaves ephemeral storage?
- wongarsu 11y ago>If the Secure Enclave can be updated on a locked phone, all they need to do is stop allowing that, right? That probably also means removing most debugging connections from the physical chip, and making extra sure you can't modify secure enclave memory even if you desolder the phone.
- tptacek 11y agoA lot of that stuff was already in the original threat model for the Secure Enclave ("assume the whole AP is owned up").
- twistedpair 11y agoNo one has been talking about the fact that you can rebuild transistors on an existing chip. It's very high tech stuff, the sort that Intel uses to repair early engineering samples painstakingly, but it is used. You decap the chip to expose the die with HF, and then use Focused Ion Beams and a million dollar microscope setup, you can rearrange the circuits. So, if the NSA absolutely had to have the data on the chip they could modify it to make it sing. So, if say they know an iPhone had the location of Bin Laden on it, they could get the goods without Apple.
- teacup50 11y agoThey're not anywhere near 99% of the way there; they've destroyed the heterogeneous decentralized ecosystem that broad security requires. Locking themselves out of the Secure Enclave isn't anywhere near sufficient. As long as the device software and trust mechanisms are totally opaque and centrally controlled by Apple, the whole thing is just a facade. There's almost nothing Apple can't push to the phone, and the audibility of the device is steadily trending towards "none at all". If the NSA pulls a Room 641A, we'd never know. If Apple management turns evil, again, we'll never know. If a foreign state use some crazy tempest attack to acquire Apple's signing keys ... again, we'll never know.
- 542458 11y agoI think from the context it's pretty clear that "hack" in this case is referring to "being forced to unlock". Yes, they could still deliberately break encryption for future OSes and phones, but the same could be said of any software, open or closed source. I don't think acting like an open ecosystem is the be-all and end-all of security is productive. Most organizations (let alone individuals) don't have the resources to vet every line in every piece of software they run. Software follows economies of scale, and for hard problems (IE, TLS, font rendering, etc) will only have one or two major offerings. How hard would it be to introduce another heartbleed into one of those?
- teacup50 11y agoHow does a 3rd-party researcher find the next heartbleed if they can't even decrypt the binaries for analysis?
- mbq 11y agoBinaries can be converted back to assembly and quite often even back to equivalent C; bugs are most often found by fuzzing (intentional or not) which does not require source code. The difference between open and closed source is that open is more often analysed by white hats who rather publish vulnerabilities and help fixing them, while closed by black hats who rather sell or exploit them in secret.
- zaroth 11y agoWhy would they have made the Secure Enclave allow updates on a locked device without wiping the key in the first place? Either they didn't think it through, assumed they would never be compelled to use it as a backdoor, or perhaps they were afraid some bug could end up having catastrophic consequences of locking a billion people out of their phones with no way to fix it? Do we even know for certain that the Secure Enclave on the 6s can be reflashed on a locked phone without wiping the key?
- ewzimm 11y agoFrom what's been said, it seems like it was made to be updated so that Apple could easily issue security updates. They've already increased the delay between repeated attempts at password entry. Probably they were worried about vulnerabilities or bugs that hadn't been found and wanted to maintain debugging connections to make repairs easier. A tamper-resistant self-destruct mechanism with no possibility of recovery introduces extra points of failure, and it seems that until now, they didn't think it was necessary. Look at the controversy over the phone not booting with third-party fingerprint reader repairs as an example. People were upset when they found out that having their device worked on could make it unbootable, but Apple was able to easily fix it with a software update. If it had been designed more securely, it might have wiped data when it detected unauthorized modifications, which would have meant even more upset people. Now that this has become a public debate, there will be a very different response to making it more secure.
- mtgx 11y agoHow much easier? If all they had to do to not have access to it themselves is to ask the user for his password when there's a new update, that's hardly that inconvenient...
- ewzimm 11y agoI'm not saying that it was the right thing to do in hindsight, but I get a little nervous even when updating a small web server, so I understand the tendency to leave repair options open on something as big as iPhones. Real hardware-based security is about more than just about asking for a password. It means making the device unreadable if it's been disassembled or tampered with, and that could have unintended side-effects if any mistakes are made or something is overlooked. It's definitely worth pursuing considering the political situation the world is in right now.
- Shivetya 11y agoI guess the last one percent is making sure you don't brick customer phones inadvertently with software update or fix.
- rtpg 11y agoI don't think "already fenced off if people were savvy" is really valid. That's the security equivalent of "no type errors if people were savvy", which is the same as "probably has type errors". It was near-impenetrable, but it could have been inevitable if it weren't for the fact that Apple could push OS updates without user consent. They could have made it impossible for anyone to get in even if your pin was 1234, but didn't. Kind of disappointing given their whole thing about the Secure Enclave. Bunch of big walls in the castle, but they left the servant's door unlocked.
- rsync 11y ago"These devices were already fenced off from the DOJ, as long as their operators were savvy about opsec." I hate to be that guy, but if you have an op and you have any opsec, you aren't even carrying a phone. Right ?
- ChristianBundy 11y agoLike literally every other type of security, OpSec is not binary.
- muddi900 11y agoCan the SE be updated on a locked phone? Because Apple's docs give the impression that it can't.
- jtuchsen 11y agoThe only statement I could find from Apple was from the iOS security guide that states, "it utilizes its own secure boot and personalized software update separate from the application processor." I think we can both agree that's a pretty vague statement, if you have a better source I'd like to see it.
- snowwrestler 11y agoA former Apple engineer said on Twitter: "@AriX I have no clue where they got the idea that changing SPE firmware will destroy keys. SPE FW is just a signed blob on iOS System Part" https://twitter.com/johnhedge/status/699882614212075520 https://twitter.com/johnhedge/status/699882614212075520 Then Apple seems to confirm it: "The executives — speaking on background — also explicitly stated that what the FBI is asking for — for it to create a piece of software that allows a brute force password crack to be performed — would also work on newer iPhones with its Secure Enclave chip" http://techcrunch.com/2016/02/19/apple-executives-say-new-iphones-also-vulnerable-to-back-door-requested-by-fbi/ http://techcrunch.com/2016/02/19/apple-executives-say-new-ip...
- muddi900 11y agoI understand that the boot chain is the only way Apple may modify the behaviour of the Enclave but how would the update be forced? DFU wipes the class key, making any attempt at trying to brute force the phone, useless. If debug pinout access is available, then why does FBI needs Apple to access the phone at all?
- drewcrawford 11y agoThe real lynchpin here is not hardware, but iCloud. Apple can pull data out of an iCloud backup, and the only reason the San Bernadino case even got off the ground is because somebody at the county screwed up and effectively prevented the backup from occurring. iCloud backups can be secured so not even Apple can get in them, but it is fundamentally much harder to secure (can't be hareware-entangled and still restore to a new device), and it would significantly complicate iCloud password changes. I'm sure they are working on it, but it is nontrivial. That (software) problem is the real reason 99% of users are still exposed, as you say the hardware and secure enclave holes are basically closed.
- Bud 11y agoIt's not 99%; adoption of iCloud backups is not nearly that high.
- iLoch 11y agoUhh, well it's probably pretty high. Considering their adoption rate for new software is sitting somewhere around 95%. iCloud backups default to on - just like automatic updates - when the user sets up their phone. Not to mention most Geniuses would ask to turn on iCloud backup when upgrading the device for convenience.
- jonknee 11y agoWell the specific phone that started this controversy didn't have any iCloud backups, so regardless of the percentage it doesn't pertain here.
- karlshea 11y agoIt did have iCloud backups, but the latest was six weeks prior. The FBI requested the iCloud password be reset, which prevented a new iCloud backup they could have subpoenaed.
- frankacter 11y ago
- kazinator 11y agoIf the device has a manufacturer's key and the user's key, then it's basically down to simple Boolean logic: does the innermost trusted layer allow something to be installed or altered if it is authorized by the manufacturer's key OR your key? Or the manufacturer's key AND your key? Or just your key? (With a warning if it has no other key?)
- swiley 11y agoUnderrated post.
- zobzu 11y agoSecure enclave as per their docs sounds just like their implementation of trust zone.. err "Trust Zone", most likely following ARM specs. The main difference would be that everyone knows trust zone through Qualcom's implementation and software - as it's been broken many times. At the end of the day "its just software" though, which runs on a CPU-managed hypervisor with strong separation ("hardware" but really, the line is quite a blur at this level). What that means is that you need to be unable to update the secure enclave without user's code (so the enclave itself needs to check that) which is probably EXACTLY what apple is going to do. Of course, Apple can still update the OS to trick the user into inserting the code elsewhere, then FBI to use that to update the enclave and decrypt - though that means the user needs to be alive obviously. Past that, you'd need to extract the data from memory (actually opening the phone) and attempt to brute force the encryption. FBI does not know how to do this part, the NSA certainly does, arguably, Apple might since they're designing the chipset itself.
- throwaway1666 11y agoSecure Enclave is explicitly not TrustZone per Apples iOS Security Guide. It's a separate core in the SoC running on L4.
- startupljackson 11y agoAww shit.. embedded crypto hypervisors all up in this hood.
- nickik 11y agoWopw wopw
- tajen 11y agoI don't understand the whole debate about Apple security: - Apple is required to have backdoors, at least on iPhones sold in foreign countries, isn't it? - Even if the SE were completely secure, a rogue update of iOS could intercept the fingerprint or passcode whenever it is typed, and replay it to unlock the SE when spies ask for it. As far as I know, the on-screen keyboard is controlled by software which isn't in the SE. - Even if iCloud is supposed to be encrypted, they didn't open up that part to public scutinity. - Therefore a perfect security around the SE only solves the problem of accessing a phone that wasn't backdoored yet. There are all reasons for, say, Europe and CIA, to require phones to be backdoored by default for LE and economic intelligence purposes.
- lololomg 11y agoApple is not required by any country to have a backdoor and I am not aware of any agreement from Apple to install such a back door for anyone
- deleted 11y ago[deleted]
- simonh 11y agoIf the person knowing the passcode is around and you can fool them into using their passcode then yes, you could capture their passcode. Touch ID is even less of a problem because taking someone's fingerprints is a lot easier than taking a passcode out of their head. But in both those situations the weakness is in the person, not the device. Apple devices still potentially have security weaknesses which the FBI is asking Apple to exploit for them. Apple wants to fix these weaknesses, to stop Apple being forced to exploit them.
- po 11y agoApple is required to have backdoors, at least on iPhones sold in foreign countries, isn't it? I don't believe this is the case. Even if the SE were completely secure, a rogue update of iOS could intercept the fingerprint or passcode whenever it is typed, and replay it to unlock the SE when spies ask for it. As far as I know, the on-screen keyboard is controlled by software which isn't in the SE. What you say about an on-screen passcode is likely true but the architecture of the secure enclave is such that the touch ID sensor is communicating over an encrypted serial bus directly with the SE and not iOS itself. It assumes that the iOS image is not trustworthy. From the white paper [1]: It provides all cryptographic operations for Data Protection key management and maintains the integrity of Data Protection even if the kernel has been compromised. ... The Secure Enclave is responsible for processing fingerprint data from the Touch ID sensor, determining if there is a match against registered fingerprints, and then enabling access or purchases on behalf of the user. Communication between the processor and the Touch ID sensor takes place over a serial peripheral interface bus. The processor forwards the data to the Secure Enclave but cannot read it. It’s encrypted and authenticated with a session key that is negotiated using the device’s shared key that is provisioned for the Touch ID sensor and the Secure Enclave. The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption. [1]: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- wahsd 11y agoOne aspect of what all this comes down to is that governments don't want to have to do real work or even prioritize their tracking and surveillance. What encryption and security really does is create scarcity of access to information and data in order to force a market solution where government groups have to prioritize their efforts and apply them deliberately.
- studentrob 11y agoYes. The DOJ is looking for the easy way to do their job. It's not the only way.
- draw_down 11y agoThey'd have to be crazy not to. Weird that no one else who makes phones seems to give a shit, though.
- n0us 11y agoWhat is to stop the DOJ from requiring them to produce a phone that has a hardware backdoor? If they are required to produce a software backdoor then building an iphone which is immune to such vulnerabilities seemingly solves that problem but I don't see the leap towards compelling Apple to build vulnerabilities into hardware as a large one. I'm not well versed in security so excuse me for my ignorance but what if there were a way to solder chip onto the board that allows access to the secure enclave. Every time an iphone is made a companion chip is produced that contains some kind of access key which only works for that device and someone is required to foot the bill for storing them.
- chinathrow 11y agoWhat if another agency already has an NSL in place requiring exactly the same (backdoor, weak crypto params, weak by design secure enclave) and they simply are under a gag order to talk about?
- Pharaoh2 11y agoYea NO. NSL's can't do that. At worst they will tell you to release and data that you have and your private keys. At best they will tell you to make sure you archive everything and don't permanently destroy records in case they are required in the future. They cannot force you to add backdoors or create a weak crypto , although they can indirectly suggest you to do that and its then on the company if they do so.
- aioprisan 11y agoNSLs can only ask for information, not force a company to build a product. That kind of request would have to come through legislation and apply to all US companies in a similar situation.
- teacup50 11y agoThat's not really true; as evidence, I give you Room 641A: https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A "Room 641A is a telecommunication interception facility operated by AT&T for the U.S. National Security Agency" As long as you have a backdoor, and Apple does, shady government agencies can and do come knocking. We've got plenty of shady government agencies, and can never guarantee that we won't have more in the future.
- condour75 11y agothat's the endgame of government surveillance requests: it's increasingly in a company's best interest to have the best security possible so they can't be compelled to hack their own devices.
- robhu 11y agoSurely it is a company's best interests to have 'good enough' looking security to serve their PR purposes while also secretly providing government access to maximise government kudos and all the benefits that would entail?
- trowawee 11y agoThe counter-argument would be that that opens you up to catastrophic exposure when Snowden 2.0 releases the data.
- petra 11y agoSo the backdoor is built in such a way that Apple could have strong deniability. The NSA already did this with EC-DRBG.
- TillE 11y agoYou really have to pick one side or the other, unless you're extremely good at keeping a secret and deceiving outside researchers. That's a much higher level of difficulty than simply creating a secure system.
- buro9 11y agoNot really. For many customers of hardware and software trust is what is being sold. As trust is eroded 'good enough' is no longer good enough. The only way to continue to be trusted is to be more secure, and as the grandparent points out the endgame there is that the encryption puts the software and hardware beyond the reach of the company that produced it.
- 11y ago
- jarcoal 11y agoDon't they just need to tell people to switch away from 4 or 6 digit pins and use longer passwords?
- trowawee 11y agoI wish Apple would start pushing passphrases. Easy enough to remember, plenty strong, already usable with the current system on iphones.
- rm_-rf_slash 11y agoNobody would adopt them. It's annoying enough to deal with 4 digits when it's cold and I'm wearing gloves and I just want to change the song I'm listening to. Passphrases suck enough whenever you have to log back in. Are people really gonna put up with that every time they want to use their phone? On the other hand, if there were a convenient way to toggle between passphrases and 4-digit unlock, (especially if you had to use the passphrases to toggle back to 4-digit) then I would be all for it.
- plorkyeran 11y agoI'd love to have a long passphrase that has to be entered after booting and every 48 hours, and then a 4-digit pin that's usable when TouchID is for when I'm unlocking my phone with my nose.
- trustfundbaby 11y agoclearly you're not the average user.
- shawn-furyan 11y agoExactly. Short passwords/longish pins suffice for short durations if they are random (i.e. not guessable), particularly if the device requires external hardware to brute force due to attempt duration scaling. I currently use a generated long password on my Android phone and have adapted to the extra work, but having the option to enter a password once a day and a pin or shorter password throughout that day would be a welcome convenience option, and it's not really significantly more onerous than just a pin.
- awqrre 11y agoThe problem with software is that none have been 100% secure yet... I doubt that Apple will be able to achieve that in the near future. Someone should send a phone to John Mcafee at the very least [1][2] ... 1. http://www.pcgamer.com/john-mcafee-on-his-fbi-iphone-hack-offer-our-government-is-illiterate-in-cybersecurity/ http://www.pcgamer.com/john-mcafee-on-his-fbi-iphone-hack-of... 2. http://arstechnica.com/staff/2016/02/mcafee-will-break-iphone-crypto-for-fbi-in-3-weeks-or-eat-shoe-on-live-tv/ http://arstechnica.com/staff/2016/02/mcafee-will-break-iphon... edit: added source #2; see Google for additional sources...
- jjnoakes 11y agoWhat an awful article. And it isn't even the real article.
- mtgx 11y agoThis is why the FBI's argument and that of those who say "they just want balance" is such nonsense. "Balanced" compared to what? To the 80% insecurity we have now? And "balance" for what protocol? For all existing protocols? For all future protocols? What if hackers learn how to exploit that "balance" in a massive way? Will companies be allowed to fix it by improving the security or will they be "impeding law enforcement"? It's unbelievable to me how hard the government is fighting against basic security.
- morninj 11y agoThis is excellent, but unfortunately it will not protect any data on the millions of iPhones that already exist.
- dylan604 11y agoIt would be a huge middle finger for Apple to design this new iPhone as a free upgrade for all current iPhone users. With their cash reserve, it would be a huge PR spin. There are however those pesky share holders to keep happy.
- cromwellian 11y agoAny device that relies on hiding secrets inside the silicon itself is subject to hacking. Several secure-enclave like chips have been hacked in the past by using electron microscopes and direct probes on the silicon. If BlackHat conference independent security researchers have the resources to pull this off, Apple and the NSA certainly can. Exfiltrating the Enclave UID could be done by various mechanisms at the chip level, especially if you have access to the actual HW design and can fab devices to help. I mean, we're talking about threat models where chip-level doping has been shown as an attack. This just seems to be a variation on the same claims of copy protection tamper resistant dongles we've had forever. That someone builds a secure system that is premised on a secret being held in a tiny tamper-resistant piece, only the tamper resistance is eventually cracked. It might even be the case that you don't even need to exfiltrate the UID from the Enclave, what the FBI needs to do is test a large number of PIN codes without triggering the backoff timer or wipe. But the wipe mechanism and backoff timer runs in the application processor, not on the enclave, and so it is succeptable to cracking attacks the same way much copy protection techniques are. You may not need to crack the OS, or even upload a new firmware. You just need to disable the mechanism that wipes the device and delays how many wrong tries you get. So for example, if you can manage to corrupt, or patch the part of the system that does that, then you can try thousands of PINs without worrying about triggering the timer or wipe, and without needing to upload a whole new firmware. I used to crack disk protection on the Commodore 64 and no matter how sophisticated the mechanism all I really needed to do was figure out one memory location to insert a NOP into, or change a BNE/BEQ branch destination, and I was done. Cracking often came down to mutating 1 or 2 bytes in the whole system. (BTW, why the downvote? If you think I'm wrong, post a rebuttal)
- quantumpotato_ 11y agoI upvoted because I think you are absolutely correct. Better security could be had with a two-factor system -- plug the phone into a cryptobox to decrypt. Having everything in one place is vulnerable.
- johntb86 11y agoIf you need to plug the phone into the cryptobox to decrypt it, they're going to be in one place anyway.
- joezydeco 11y agoCould DOJ slap Apple with an injunction forbidding deployments of new iOS releases until the San Bernadino case is concluded? If Apple can't launch new iOS versions, can they still launch new iPhones?
- studentrob 11y agoBy saying what exactly? That an unhackable iOS is illegal? That's not currently true and it is the precedent that everyone believes the DOJ would like to set, but that the DOJ keeps denying.
- joezydeco 11y agoI'm just thinking out loud, but who knows? DOJ has been pretty creative about making this issue more critical than the other times they've tried to unlock iOS devices (because, of course, terrorism) What if the feds decide that an O/S update closes a zeroday that the NSA was using (note they've been really quiet here) and interferes with an FBI investigation in process? And yeah, DOJ keeps saying it's just the one device, just this one time. What happens if they suddenly change course just to prevent iOS from getting more secure?
- studentrob 11y agoThere is currently no law on the books that compels Apple to act here. That is why Comey asked Obama to ask congress for a law. Obama said no and advised using the AWA. They won't try to pass this law until after this election year. It's too sensitive an issue and will fracture the voter base along unexpected lines, thus giving Trump a chance at winning.
- abalone 11y agoIt's important to emphasize something: iCloud will always be "backdoored", by design, and backing up to iCloud is what most users should and will be doing. The reason iCloud data will always be accessible by Apple, and thus governments, is not because Apple wants to make it accessible to governments. It's so that Apple can offer customers the very important feature of accessing their own data if they forget or otherwise don't have the password. That is an essential feature, and why this aspect will never change. When someone passes away, for example, it would be a terrible compounding tragedy if all their photos from their whole life passed away along with them, because they didn't tell anyone their password or where they kept the backup key. So Apple wants and needs to provide an alternative way to recover the account. (For example, they will provide access to a deceased person's account if their spouse can obtain a court order proving the death and relationship.) Harvard recent published a paper (called "Don't Panic") that essentially states the same.[1] Governments shouldn't "panic" because in most cases, consumers will not be exclusively using unbreakable encryption, because it has tradeoffs that aren't always desirable. And the reason why most consumer should be backing up to iCloud is similar: that's how you prevent the tragedy of losing your data if you lose your phone. Just something to keep in mind when discussing the "going dark" and "unhackable" news items. It is worth noting however that people who do "have something to hide" from governments probably won't be using iCloud, if they know what they're doing. Then again if they know what they're doing, they wouldn't use anything that is backdoored anyway. So the naive criminals will still probably be hackable, and that's about all we can hope for. [1] https://cyber.law.harvard.edu/pubrelease/dont-panic/Dont_Panic_Making_Progress_on_Going_Dark_Debate.pdf https://cyber.law.harvard.edu/pubrelease/dont-panic/Dont_Pan...
- surye 11y ago> When someone passes away, for example, it would be a terrible compounding tragedy if all their photos from their whole life passed away along with them, because they didn't tell anyone their password or where they kept the backup key. Would you really expect Apple to recover the data in this scenario for the next of kin? I certainly wouldn't, and I wouldn't want them to.
- IBM 11y ago
- deleted 11y ago[deleted]
- studentrob 11y agoGood. Congress shall pass no law abridging freedom of speech, and code has been ruled free speech. The only reason previous wiretapping laws were passed is because they weren't in the limelight and the public never had a chance to weigh in. Let's make this an election issue
- dragonwriter 11y ago> The only reason previous wiretapping laws were passed is because they weren't in the limelight USA FREEDOM was passed fairly specifically because the issue was in the limelight.
- kzrdude 11y agoTake a step back and fight campaign finance and gerrymandering, so that people are once again represented well in lawmaking. Campaign finance needs to be reformed so that it becomes affordable for representatives to represent their country instead of their sponsors, and gerrymandering so that democracy has the competition it needs to select better politicians.
- studentrob 11y agoI'm fine with that. But this issue is being debated now, and if you choose to not take a side, keep in mind that that is still taking a side. You've simply let someone else decide for you.
- TazeTSchnitzel 11y ago> Good. Congress shall pass no law abridging freedom of speech, and code has been ruled free speech. Unless it breaks DRM!
- teacup50 11y agoWhich, ironically, is exactly what Apple is protecting here. DRM.
- 11y ago
- nickpsecurity 11y agoMy last write-up on smartphone risks applies to this discussion. https://news.ycombinator.com/item?id=10906999 https://news.ycombinator.com/item?id=10906999 Apple is far from having a secure phone right now. NSA certainly has ways to bypass this based on my attack framework and their prior work. They just don't want them to be known. They pulled the same stuff in the past where FBI talked about how they couldn't beat iPhones but NSA had them in the leaks & was parallel constructing to FBI. So, the current crop are probably compromised but reserved for targets worth the risk. That said, modifying CPU to enable memory + I/O safety, restricting baseband, an isolation flow for hardware, and some software changes could make a system where 0-days were rare enough to be worth much more. Oh yeah, they'll have to remove the debugging crap out of their chips and add TEMPEST shielding. Good luck getting either of those two done. ;)
- kevinnk 11y ago> They pulled the same stuff in the past where FBI talked about how they couldn't beat iPhones but NSA had them in the leaks & was parallel constructing to FBI. Do you have a link to a leak that shows this? I couldn't find anything with a simple google search.
- nickpsecurity 11y agoIt was in the leak on mobile OS's. They not only found iPhone vulnerable but mocked their users.
- kevinnk 11y agoCould you be more specific? I've followed the NSA leaks with some interest, but not particularly closely, so I'd be really interested in seeing the actual presentation/document/whatever. For reference I've googled every combination of "nsa apple mobile OS leak" I could think of and couldn't find a primary source.
- nickpsecurity 11y ago
- alfiedotwtf 11y agoIf you want to keep a secret, you must also hide it from yourself" - George Orwell, 1984 - Apple, 2016
- ymse 11y agoThat brings to mind this classic.. Today, we celebrate the first glorious anniversary of the Information Purification Directives. We have created, for the first time in all history, a garden of pure ideology—where each worker may bloom, secure from the pests purveying contradictory truths. Our Unification of Thoughts is more powerful a weapon than any fleet or army on earth. We are one people, with one will, one resolve, one cause. Our enemies shall talk themselves to death, and we will bury them with their own confusion. We shall prevail! https://www.youtube.com/watch?v=R706isyDrqI https://www.youtube.com/watch?v=R706isyDrqI They should re-run this commercial for iPhone 7. "On September 24th, Apple Computer will introduce iPhone 7. And you'll see why 2017 won't be like 1984."
- aback 11y ago"You'll see why 1984 won't be like Nineteen Eighty-Four." - Apple, 1984.
- kbart 11y agoJust a nitpick, but 1984 by G. Orwell was first published in 1949 what makes it even more impressive.
- alfiedotwtf 11y agoThat was intentional
- zekevermillion 11y agoThe article doesn't cite a source. It doesn't even say that it is anonymously sourced from someone close to Apple (who presumably is leaking). That makes me wonder if the real source of this info is Apple-approved, and sort of an indirect way of engaging policymakers. I get the sense that Apple is picking a fight b/c the DOJ has violating an unwritten agreement, basically that Apple will provide all the help requested, informally, as long as the DOJ doesn't push for court orders or new laws that tie Apple's hands in constructing its devices and the software that runs on them.
- TillE 11y agoThat's normal style in mainstream journalism, weird as it is. If you read a lot of sports journalism for example, you'll see a ton of articles which are literally just a summarized transcript of a phone call a reporter got from an agent, written as if it's just pure factual information that appeared from thin air. At least in those cases it's trivial to guess who the source actually is. Again, it is objectively very strange to not even hint at what the source of your information is. But it's also standard practice.
- zekevermillion 11y agoYeah, standard practice maybe. I guess I'm more interested to know if this story is sourced from Apple (unofficially) or is it based on a more indirect rumor that's going around...
- godgod 11y agoThank you Apple. The FBI forced the end of the encryption debate. This is good news.
- drdrey 11y agoThe original story has changed its title to "Apple Is Said to Be Trying to Make It Harder to Hack iPhones". I was a bit surprised by the clickbait-y nature of the HN title, but we can see in the nytimes URL that this "Apple Is Said to Be Working on an iPhone Even It Can’t Hack" was the original title, eh.
- riquito 11y agoThey can have perfect hardware crypto, but they can always send a new OS update to every phone with "if your account id is in top 100 wanted, send a copy of everything to x.y.z". Nobody would ever know (until it's too late, at least) (of course if the phone is not in use anymore it doesn't apply)
- JustSomeNobody 11y agoA lot of the comments on that article burn me up. People in the U.S. really think there's a terrorism problem here. The only problem is that government spending so much money on a non-issue! Politicians love to "debate" it because they know it is one of those things that looks good to the naive citizens but they really don't have to do anything because there's nothing to be done.
- weaksauce 11y agoit's an appeal to emotion and it's actually a bit disgusting to me. I wish my government would stop creating the terrorists that it wants to then fight.
- ewzimm 11y agoWhat really burns me is that this strategy is so well known. 1984 was written almost 70 years ago, and yet we have millions of people begging for persistent, unavoidable surveillance by authorities as part of a never-ending war with an ambiguous enemy that our own policies are strengthening.
- VladKovac 11y agoReferencing 1984 is childish in this context, we're talking about obtaining a warrant for known suspects or already convicted persons. The enemy isn't ambiguous, you're purposely muddying their image.
- jzelinskie 11y agoI believe the GP was making a generality and not talking about just this specific scenario. "Terrorism" is an ambiguous enemy and while the number of deaths to terrorism is disheartening, it pales in comparison to many other problems (e.g. car accidents or heart disease).
- goldenkey 11y agoLet's not forget that because terrorism is ambiguous, our own government can create mock attacks and blame them on 3rd parties. Furthering their own agendas. Invoking fear and loathing in the citizens.
- nxzero 11y agoUnless the implementation is public and verifiable, which is unlikely, the idea that there is a "secure" iPhone is just that, an idea.
- blinkingled 11y agoCould Apple not push an OS update that can compromise everything they are doing to make the iPhone unhackable? As long as user has to trust Apple there's always going to be the possibility that FBI/NSA/Whoever force Apple to update a target's iPhone to enable tracking/recording of whatever information. It's not an attainable goal in practice. Today they generate a per device customized update that can be installed without user intervention. Even if they tomorrow enforce user intervention they still retain the capability to push a targeted update for a specific device on law enforcement/court order. The user has no way of telling what the update did.
- pauloday 11y agoI think they could do all the stuff that makes it unhackable in hardware, and/or they could make it so updates aren't installed while the phone is locked.
- tekklloneer 11y agoIt's very difficult, especially since they aren't open source. However, they could attain a state where to compromise a device requires the user accepting a malicious update, which would make the FBI's current request moot. (although there's a whole separate set of legal attacks unexplored)
- ianamartin 11y agoWhat I want is a service that deletes all my online presence after I die. A deadswitch. All texts, messages, emails, facebook posts, pictures anywhere, everything. I want it all to go when I do. Hell, I want some of it to go now. After I'm gone, I want to leave no part of my existence on the internet. I realize that's not possible. But I want to minimize my footprint. It is totally possible for a local device. I have a deadswitch on all my computers. If I don't log in and set an alive flag via the command line in any of my computers for more than a week, that computer securely wipes itself. Let it be known, I have nothing to hide. I just think this is the best way to do things. Edit: My reason for this is the frequency with which I encounter people who are no longer alive. It's a harsh thing to look at a link to someone who said something, and you used to know and then suddenly realize, "Oh shit. He's dead. And I used to be his best friend." I know facebook has memorial pages, but those are difficult to get.
- ubernostrum 11y agoI wrote about this a while back: http://www.b-list.org/weblog/2013/jan/29/persistence/ http://www.b-list.org/weblog/2013/jan/29/persistence/ Since then I've started noticing services rolling out the ability to specify someone to take over your account after you die, and I suspect the legal framework around wills and estates is robust enough that you could leave instructions (and have them enforced) to delete things.
- dclowd9901 11y agoWhen something you create is public, you no longer have a right to dictate it. You do not have a right to be forgotten. That would be an attempt at some sort of thought control, and you don't get to tell us that this comment you just wrote can and should be forgotten. If I choose to remember it, outside of your wishes, there's nothing you can do about it. Private information is another matter, but when people presume they have rights to choose how others think, it really makes my blood boil.
- ianamartin 11y agoUmm excuse me, but go yourself. You do not in any way own anything I create just because you may or may not have seen it on the Internet. I am not a public figure simply because I walk around in public. My words do not belong to you simply because I put them in a place where you can see them. Everything about your post is wrong in the worst possible ways. You are the opposite of the idea of freedom of information. You are literally arguing in favor of information tyranny. Please go home and do something besides posting on the Internet.
- pmarreck 11y agoGood.
- jarjoura 11y agoHmmm... this absolutest attitude by Apple begs the question for me, are we SURE we want to have phones that absolutely cannot be unlocked when the owner is no where to be found/dead? It's such a grey area and I will probably get down voted for commenting this way. I 100% agree that the power, in the wrong hands, is horrible, but can't we talk about this in a way where there's some kind of middle ground? All I've been reading are either extremes.
- TheCondor 11y agoWrite your pass code on a piece of paper, put it in an envelope, and staple the envelope to your will and deposit it with your lawyer. Nothing prevents you from telling loved ones your pass code. They give you the choice.
- blamarvt 11y agoIsn't this problem already solved in the non-tech world through a last will and testament or a bank lockbox which contains passwords you want people to have in the event of your death? I'm not sure it's a perfect solution but might be better than counting on someone to reverse engineer or hack into your phone. If you're serious about encryption you should always have a backup key somewhere... unless you want a single point of failure (you). Both should be an option.
- kbart 11y agoOf course we want! Then only I am in the power to chose who can access my personal data. What forbids you from leaving your private keys and passcodes to the next of a kin? Furthermore, if information in your phone is important to more people than you only (family photos etc.), it should be backed up somewhere else anyway, you don't keep all eggs in a single basket. The real problem is that cryptography is very powerful tool and we need to educate people how to use it properly. Of course, it's naive to hope that it can be done overnight, but small, incremental changes might be done imho. For example, before asking user to create it's master passcode, emphasize in big, bold letters, that it's your reponsibility to keep this password safe and accessible, because if you lost it, there's nothing can be done to bypass it. Keeping user key/password backup (aka MS style) is a sloppy security tactics.
- joering2 11y agoThis is one of those moments I wish Jobs was still here. Had he lost to the DOJ, here is what would (might) have happened: - he would gladly unlocked this phone and bill DOJ for the time spent on redesigning IOS - going forward, he would label each phone's box in red letters: CONTAINS GOVERNMENT-REQUIRED BACKDOOR (I doubt Gov can forbid him from doing that) - he would then stop selling devices in Apple stores directly and only allow to order them in stores with direct home delivery from Apple website hosted and operated outside USA. - all the shipping would be done directly from China by-passing US-tax system all together. - shortly after he would remove the backdoor IOs for devices that are not directly sold on US soil That would be a big fat middle finger to the DOJ.
- venomsnake 11y agoAnd then Jobs would find himself for a long long prison term after the DOJ decides to go full power with him for something otherwise unrelated or small. You commit a lot of federal offenses by just existing in the USA. Or every other country. There is always something that they can nail you for.
- codeisawesome 11y agoThis is quite horrible but, if his diagnosis had come after such a middle finger... I wonder if he would care.
- drcode 11y agoDarn... this, along with the fact that the MacBook Pro my work gave me is so much better than I expected, is making it harder for me not to become full-on Apple convert.
- ADRIANFR 11y agoThis title reminds me of a quote from The Simpsons: "Can God create a rock so heavy that even he cannot lift it?"
- bunkydoo 11y agoThis marks a very interesting time in my opinion. We have corporations with more money with governments making (or at least attempting to make) certain social decisions once reserved for only public sector government officials. If Apple is successful here, it will usher in a new era of what a private company can do.
- zobzu 11y ago"Impossible for security agency to hack" Nothing is 100% proof, crypto certainly isn't. It's going from child's play to "you actually need to knowledge" to "this is actually hard now" (but.. not impossible).
- Piskvorrr 11y agoPerhaps "infeasible" is a better word: "possible, but it would take about 300 years."
- deleted 11y ago[deleted]
- Gratsby 11y agoHow about you simply encrypt your data store? There's no reason you can't encrypt things in such a way that your operating system does not have direct access to it.
- Aoyagi 11y agoSo what are the odds that this is just an act, whether Apple knows about it or not?
- malandrew 11y agoIf Congress does pass such laws, I would love it if Apple considered security so important to it's product vision that they'd be willing to use their cash reserves to restructure the company and engineering and moving it's security engineering to a country that pledges never to force it to compromise on security. Apple is no stranger to keeping internal secrets and keeping concerns isolated. I have no doubt that they could find a way to guarantee security. IMHO governments are security bugs to be patched.
- wantreprenr007 11y agoAs much as I <3 Apple, they're still a SPoF just like Lavabit or anyone else with centralized servers that aren't "SWAT-resistant." If iDevices could work without iCloud and usefully communicate with each other directly (sans cell network too), that would be impressive... storage, processing and wireless tech are all getting cheaper... p2p "iCloud" might be within the realm of not-quite-insane. (Somehow, I feel iMessage and related apps are MITMable because there is no mandatory, mutual, out-of-band validation of a recipient's identity.)
- geertj 11y agoI've been very impressed with what I've learned in the last few weeks regarding Apple's efforts to provide privacy for its customer using what it seems some very robust engineering and design. I'm currently an Android user (Samsung S6 edge) but am considering seriously going back to the iPhone because of this. The cynical side of me says that Apple's marketing tactics have worked. But I've got a feeling, heck, I want to believe, that this is actually driven by company values and not a short-term marketing benefit.
- Udik 11y agoDo you really need such strong security? Or after the FBI forced Apple to apply their best engineering minds to crack your phone, they'd just find a grocery shopping list and pictures of your cats? Because this sounds a bit like Tesla's "operating room air quality" - something that might be useful 0.001% of the customers, and it's just marketing for the remaining 99.999%
- erkkie 11y agoHow can you ask a question like this? Define "so strong" in this context? It's similar to asking "do you need so free speech". We're not talking about anything special here beyond a standard expectation of reasonable security. The fact that apple is trying to make it "so secure even they can't hack it" is just a means for them to protect themselves that happens to align with the interests of the user.
- Udik 11y agoGeneral, unbreakable crypto security applied to all contents is a feature that very few people ever needed or even tried to achieve. Until a few years ago you were perfectly content with keeping an agenda in your pocket and pictures in your living room's drawer. A minimum of privacy is of course needed and welcome; however, unless you're planning a major terror attack, or strategic war plans, or you have incredibly valuable industrial secrets (all cases in which you'll probably be using specialized SW to keep your information) you don't really need incredibly advanced security simply because nobody is going to spend vast amounts of time and resources to uncover your little secrets. The GP is talking about switching phone (spending money) to obtain a level of security that he won't need in a million years.
- frb 11y agoSorry for the cynicism, but am I the only one feeling that this is a huge marketing stunt for the new iPhone 7 with super encryption?
- jokoon 11y agoI thought they already couldn't hack the iPhone.
- tempodox 11y agoTim Cook has gained my respect over this.
- beshrkayali 11y agoIf this means that there's going to be some hardware measures in the iPhone itself that would prevent multiple passcode entry attempts then that'd be good. Otherwise, as long there's that "troubleshooting" system that can update/reinstall the firmware without the passcode and all measures taken to prevent brute forcing the passcode out are built in the software, it's all talk. There's nothing enlightening in this article.
- emodendroket 11y agoCan Apple make an iPhone so heavy even they cannot lift it?
- alexnewman 11y agoHope they learn how to Build baseband proc
- kazinator 11y agoThis is all just theatre. The real motivation is to control the platform: to ship a piece of hardware that dictates who can install stuff on it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access. Since 197X, people had home computers (and institutional computers for two decades before that) on which the FBI could install anything they want, if that equipment fell into their hands. This fact never made news headlines; it was taken for granted that the computer is basically the digital equivalent of a piece of stationery, written in pencil. There is nothing wrong with that situation, and on such equipment, you can secure your data just fine. No machine can be trusted if it fell under someone's physical access. Here is a proof: if I get my hands on your device, I can replace it with a physically identical device which looks exactly like yours, but is actually a man-in-the-middle (MITM). (I can put the fake device's board into your original plastic and glass, so it will have the same scratches, wear, grime pattern and whatever other markings that distinguish the device as yours.) My fake device will collect the credentials which you enter. Those are immediately sent to me and I play them against the real device to get in. Apple are trying to portray themselves as a champion of security, making clueless users believe that the security of a device rests in the manufacturer's hands. This could all be in collaboration with the FBI, for all we know. Two versions of Big Brother are playing the "good guy/bad guy" routine, so you would trust the good guy, who is basically just one of the faces of the same thing.
- pfg 11y ago> This is all just theatre. The real motivation is to control the platform: to ship a piece of hardware that dictates who can install stuff on it, instead of the traditional hardware that lets you completely overwrite everything in it if you have physical access. This is already the case. Right now, only firmware signed by Apple can be installed. The next logical step is to build a system where the unit that deals with PINs cannot be updated at all, or at least not without wiping all keys. This would prevent any non-invasive attempts of bypassing the rate-limiting of PIN attempts or auto-wipe. > There is nothing wrong with that situation, and on such equipment, you can secure your data just fine. Again, this is also true for an iPhone with a sufficiently complex passphrase, Because Crypto™. Secure Enclave is just an additional layer that protects against everyone not in a position to get custom firmware signed by Apple. > No machine can be trusted if it fell under someone's physical access. Here is a proof: if I get my hands on your device, I can replace it with a physically identical device which looks exactly like yours, but is actually a man-in-the-middle (MITM). (I can put the fake device's board into your original plastic and glass, so it will have the same scratches, wear, grime pattern and whatever other markings that distinguish the device as yours.) My fake device will collect the credentials which you enter. Those are immediately sent to me and I play them against the real device to get in. The scenario here isn't an Evil Maid Attack. It's about protecting locked devices while someone else has physical access to them. Right now, you're fairly safe from most attackers in this scenario. In the future, with a read-only Secure Enclave, you're also safe from Apple and anyone who could force Apple to sign firmware. The fact that Evil Maid Attacks are harder to pull off because of this is just a nice extra. > Apple are trying to portray themselves as a champion of security, making clueless users believe that the security of a device rests in the manufacturer's hands. This could all be in collaboration with the FBI, for all we know. Two versions of Big Brother are playing the "good guy/bad guy" routine, so you would trust the good guy, who is basically just one of the faces of the same thing. This doesn't make sense. There's no crypto backdoor. The worst case scenario for their current security architecture is that it falls back to how FDE works on a desktop system - i.e., it's completely dependent on your passphrase complexity.
- parkej60 11y agoWhen will personal technology legally be considered an extension of our minds? Full disclosure I understand this was a persons work phone. This is a statement which is solely being posted to stimulate theoretical discussion.
- Evolved 11y ago@everyone: All this hubbub and no guarantee the phone wasn't already wiped and/or doesn't contain any sensitive information because they didn't use that phone for those purposes. @Udik: I could just keep my tax documents in printed plaintext on top of my dresser but I opt to keep them locked up. Privacy and security are important. If people who utilize privacy/security tools are up to no good then why does the U.S. Gov't have a clause for not revealing information due to State Secrets? Why do we set our Facebook profiles to private? Why have passwords at all on anything? Are you beginning to see the point?
- gaia 11y agoMy Nexus 6 running Android 6.0.1 is encrypted and uses hardware backed credential storage. If the software (Android) had the same type of protection (if the wrong PIN is entered 10 times it destroys the key), would this device be at par with the iOS approach?
- deleted 11y ago[deleted]