5 ms·
While I find security fascinating I would not consider myself expert in the low level implementation details or hard limitations of these specific systems. Per
by jkyle 11y ago
While I find security fascinating I would not consider myself expert in the low level implementation details or hard limitations of these specific systems.
Perhaps someone more knowledgable could clarify, but....
Isn't the entire point of good security that I don't have to "trust" Apple to do the right thing? Shouldn't it be impossible for them to do the wrong thing?
For example, if I encrypt my phone with my key and set it to secure delete after so many failures how could Apple circumvent this in a truly secure system? Shouldn't they not be able to push an update without my permission? Permission that can't be given because the phone can't be unencrypted?
So the fact that Apple can circumvent the encryption of they want is an indication of a vulnerable system?
- gresrun 11y agoUltimately, all security is founded on a basis of trust. Be it trust that their word is good, their signature is difficult to forge, their code they open-source is actually what is running, etc. We trust these companies to do right by us as their customers.
- criddell 11y agoThere's an entire tower of technology and thousands of people that you have to trust. Unless you are going to build a computer by starting with a pile of sand, you build on things made by others that you have to trust to some degree.
- interpol_p 11y agoThey can't circumvent the encryption. They can only bypass the failsafe mechanisms to allow for a brute force attack rate limited by the hardware (80ms per retry). Those two mechanisms are: exponentially longer password retry attempt delays, and deleting all data after 10 failed attempts. I imagine they are working hard on preventing themselves from being able to bypass the failsafes.
- predakanga 11y agoYou're right in that the system is vulnerable, but this doesn't mean that it's not "secure" in practical terms. One could argue that the phone is secure because even Apple has no way of recovering your passcode, nor do they have a master key that might give access to your data. That's fairly secure. On the other hand, the system is insecure because it can have updates applied (which is what the FBI wants Apple to do) without requiring user consent, only physical access. Imagine that updates required a user to put in their passcode, or otherwise wiped all the encrypted data; it would be more secure, but is that enough? Theoretically, there are still ways of getting at the data - someone might find a bug in the software, or they might physically crack open the CPU to get at a piece of needed data. Security is always a balance - we want to trust Apple as little as possible, but I know of no way to create an invulnerable system.
- greggman 11y agoI'm probably just not remembering it correctly but I know of no way to apply updates to a locked iPhone. Even when unlocked if you plug it into a new computer the phone will ask if you trust the new computer. Is there some method of updating the phone when it's locked I'm unaware of?
- nicky0 11y agoI think it's some kind of device recovery mode designed to recover from "bricked device" situations. It's not the same method that you use when updating via iTunes.
- predakanga 11y agoAye, it's called Device Firmware Upgrade (or DFU) mode, and it's specifically mentioned in the FBI's request: > "The SIF will be loaded via Device Firmware Upgrade (“DFU”) mode, recovery mode, or other applicable mode available to the FBI."
- sago 11y agoThere's a lot of messy use of words in this case. Apple can't circumvent its own encryption (not that we know, anyway, and that hasn't been claimed). The FBI knows that the govt have tools capable of breaking the encryption, with time. They essentially scan for the correct key. Apple has security in addition to the encryption though: in this case they have two: one is a timing system that limits the guessing rate, and the other is a 'self-destruct' system that destroys the data if too many guesses fail. These are the systems that the FBI want compromised. They would then set their normal password cracking toolchain to work. It's disturbing, because the govt are definitely not the only ones with such a toolchain. And when you increase the number of devices that can be scanned (by producing and signing a version of iOS without these protections), you increase the ability to crack at least one. In general 'the bad guys' have it easier, because they are rarely interested in cracking a specific phone, they are interested in cracking some of a larger set of them. The aim is to have these kind of security features on the silicon, so we don't even trust them to keep the extra security in place. But that's not the case here.
- alanwatts 11y agoYes, in an ideally secure system even the manufacturer should not be able to get it. I am not aware of any such system, however. No system is completely secure.