3 ms·
I find myself divided on this article, as a person who values security very strongly. 1. If the vulnerability the FBI used worked because the device was an iPh
by eggbrain 11y ago
I find myself divided on this article, as a person who values security very strongly.
1. If the vulnerability the FBI used worked because the device was an iPhone without a secure enclave, Apple probably knows how they did it, but they can't really fix devices that have already shipped without the security features. While this obviously hurts users of those phones, every phone going forward won't have this issue, and this won't be replicable on a mass scale.
2. Because this was a vulnerability that was found, not intentionally created, there is a high likelihood that the bug will be found again by security researchers, or at the very least paid for handsomely by Apple. This isn't necessarily true (Heartbleed existed for 2 years without being noticed), but it means that the vulnerability has a timetable that rapidly closes. This is far different from an _introduced_ backdoor/vulnerability, where Apple knows exactly what can be used to get into a device, but has their hands tied by the government, which would _unilaterally_ make our phones less secure. I don't like buying a door lock if I know there's a master key that can open any of the doors of that brand.
3. The author I feel is misleading when he says things like "A vulnerability in Windows 10, for example, affects all of us who use Windows 10". Even if a piece of software has a vulnerability, that vulnerability could perhaps only be exploitable under certain conditions, like software running on certain hardware (eg: without a secure enclave), or under certain conditions (passcodes of less than 4 digits). It also can be highly theoretical or impractical to do on any sort of scale -- if the vulnerability involves reading data off a hard drive using an electron microscope to check for magnetic signatures, I'm not going to be too worried that it will be abused, as the man hours to have it work for a single case would be astronomical and only feasible in the most extreme circumstances.
It's probably very frustrating on Apple's part that the FBI found a vulnerability that they (likely) don't know about, and in an ideal world, governments would disclose those vulnerabilities to make us more secure. But as long as the software and hardware continue to get more secure and not intentionally crippled, any benefit they derived feels short lived at best.
- coldcode 11y agoI am sure Apple knows exactly what they did, it's their system and their own hacking team likely finds stuff like this. The key is if anyone else in the US is able to purchase this hack to unlock a phone: if they do and try to reference evidence based on that a judge will require the process be disclosed.