18 ms·
Under iOS 11, authorities won’t be able to image your device without a passcode
- mtgx 9y ago> These changes are coming in conjunction with another privacy-minded feature that will disable Touch ID by pressing the power button five times. Wow, that's really nice. I wish Google was so forward thinking about things like this. I see no reason why a fingerprint authentication should be forced upon someone anymore than a password unlock would be. The only reason this is how it works today is because it's much "easier" for the government for force your finger onto the phone, or take blood from you, or hair, and so on - and they can't really do that with passwords. But we can fight back with technology and ingenuity and ensure that a fingerprint auth is "just as good" as as password, at least from this point of view (government forcing you to give it away).
- hprotagonist 9y ago>Unlike most Silicon Valley companies, Apple’s business model is one of "Data Liability." Unlike Google or Facebook which use advertising to extract value from users’ personal information, Apple focuses on selling things that protect a user's data from all unauthorized access — including by Apple. Basically, Apple views user data as a headache, not a monetization opportunity. https://lawfareblog.com/ios-11-may-complicate-border-searches https://lawfareblog.com/ios-11-may-complicate-border-searche...
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- adekok 9y ago> I see no reason why a fingerprint authentication should be forced upon someone anymore than a password unlock would be. In Canada, there is a difference. A fingerprint is something you have. A password is something you know. Police can compel you to use your fingerprint to unlock the phone. They can't compel you to disclose the password.
- AckSyn 9y agoYou shouldn't be compelled to give up anything that is "you" without a court order and a warrant. Not indiscriminately photographed, fingerprinted, and in some cases tested for drugs against your will.
- KGIII 9y agoCanada forces people to unlock their phones, when crossing the border, quite frequently - and have for years. They will make you unlock it, or disallow entry and/or detain you. There's a whole series that shows this. It's Canadian Border Guard, or similar. I see it when I cross the border, which I do with some frequency. I just unlock my phone for them.
- Botnet4Lunch 9y agoWhat do they do with it after you give it to them? Does the device leave your sight?
- KGIII 9y agoThey just flip through it. I'm a citizen so they don't do much with it. They usually look at texts and emails, to see if people are going to work there illegally. I'm able to work there so it's pretty silly. It has never left my sight. I can't speak for others and didn't watch the show that carefully. I live so close to the border that my neighbors get Canadian television. So, I've seen it there. I don't actually have TV hooked up, so I don't see it often.
- adekok 9y agoAs does the States. What I meant was that inside of Canada, there are situations where the police don't need a search warrant for your phone. You can unlock it with your fingerprint, so it's legally "open" and searchable. If you have a passphrase, then they need to know your mind in order to unlock it, and they can't force you to disclose something you know.
- 9y ago
- sdca 9y agoIt's not "forward thinking" to put that feature in 4 years after Touch ID debuted and people have already been forced to unlock their phones. They should be issuing warnings that fingerprint sensors are for convenience and reduce security unless they're used in multi-factor authentication.
- dkonofalski 9y agoThe alternative was passcodes and Apple's research suggested that people disabled passcodes rather than use anything secure. TouchID was determined to be far more secure than no passcode and having both TouchID and a passcode is secure enough for most users. You can't add devices without both (along with an Apple ID password) and, at that point, you have physical access to the device which negates most security features anyways.
- grzm 9y agoInteresting and pragmatic. Do you have a reference for this? I'd be interested in reading more.
- dkonofalski 9y agoThere is a reference for this as Apple published a security white-paper about it prior to the release of TouchID. Unfortunately, I'm not at a point where I can search for it. If I find the time today, I will update this post with a link.
- grzm 9y agoCheers. I'd appreciate it. Edit to add: I came across this one: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf It was linked from an article in 2014[1], though this PDF document is dated March 2017. [1]: http://www.biometricupdate.com/201402/apple-publishes-whitepaper-on-ios-security-details-touch-id-fingerprint-sensor-specs-functionality http://www.biometricupdate.com/201402/apple-publishes-whitep...
- ianferrel 9y agoIn the February 2017 case of a California artist who was questioned at San Francisco International Airport upon re-entry, after he finally agreed to unlock his iPhone, it was taken out of his sight for several minutes and could have been imaged without his knowledge. Under iOS 11, unless the artist, Aaron Gach, decided to actually give up the passcode (rather than type it in himself), he could at least have been reasonably confident that the phone could not be imaged without his knowledge. So, doesn't this just mean that border agents will force you to write down your password, key it in themselves to verify that it works, then walk away with the phone to image it?
- EGreg 9y agoRubber Hose Cryptanalysis? Can't wait for iOS to have the deniability factor of having different passwords unlock different things :) For the sensitive stuff, have periods of time that require several computers to solve cryptographic challenges in order to unlock the phone. Some of which may be your friends' devices. If they don't hear from you and your intended hosts in a certain amount of time, phone stays locked. Or one of the devices can be an NFC or Wifi hotspot in a certain area, and one at home. If you don't reach it, phone stays locked.
- DanBC 9y agoThat's the worst case for rubber hose. Even if you give up all your passwords they can still keep beating you to get the "real" pass.
- deleted 9y ago[deleted]
- DigitalJack 9y agoThey should have an "erase everything" password.
- dogma1138 9y agoIf you are under the threat of violence that won't save you.
- matt_wulfeck 9y agoI have never seen a company both so technically capable and supportive of user privacy as Apple. It stands completely apart from all of the tech giants of today.
- Prefinem 9y agoThis is the only reason why I moved from Android to iOS even though I enjoy the Android phones and Google Fi more. I wish Google Fi would support iOS devices.
- komali2 9y agoThis change alone is tempting me, and I have been diehard anti-apple for about a decade now for walled-garden reasons. I know, I know, walled garden prevents users from opening their phone to vulnerabilities or guaranteeing a secure experience. I guess I wish I could have my cake and eat it too.
- lern_too_spel 9y agoAndroid has required the user to enter the unlock code to back up the device for years now. This is Apple playing catch-up.
- eridius 9y agoiOS devices have always required the device to "trust" the computer before allowing the backup. Looking at the article, the only real difference now appears to be that you can't just use TouchID, you're forced to use the passcode.
- lern_too_spel 9y agoYou are correct. Android does not require you to enter a passcode to trust a computer if you have a fingerprint registered. The change is that Apple now requires you to enter a passcode if you have set up a passcode on the device in the past. If you haven't, the attack vector still exists, and if you are traveling with a trusted laptop with fingerprint unlock, the attack vector still exists with one level of indirection.
- bobsil1 9y agoFace ID is going to screw this all up. Cops won't even need your cooperation to unlock.
- valine 9y agoApple is adding a kill switch to iOS 11 that lets you discreetly disable Touch ID (and presumably Face ID) by hitting the power button 5 times. And of course if you're concerned you can opt out of Touch or Face ID entirely and simply use a pass-code. https://www.theverge.com/2017/8/17/16161758/ios-11-touch-id-disable-emergency-services-lock https://www.theverge.com/2017/8/17/16161758/ios-11-touch-id-...
- X86BSD 9y agoI think I would prefer the passcode which can be set to a length much larger than 4 digits when travelling or getting anywhere near fed-gov.
- extrapickles 9y agoiOS lets you set a complex password instead of a 4 digit pin (turn off the "simple passcode" setting).
- bobsil1 9y agoDefault PIN has been 6 digits since iOS 10, and you can make it a long passphrase instead.
- X86BSD 9y agoI am aware. I don't know why I phrased it the way I did. I meant I would rather use that feature of the longer passcode instead of facial recognition. Bad grammar for the win.
- rorosaurus 9y agoThanks for sharing that info, but I think the problem is that Apple is marketing these methods of identification as methods of authentication. Sacrificing security for convenience. Even if they have a kill switch in place, the users least likely to know about it are the users who are most likely to use insecure methods to "secure" their phone, I would think.
- mLuby 9y agoHere's hoping for multiple password options that unlock secret partitions. Best way through authority is plausible deniability.
- throw2016 9y agoWhen you need Apple or any technology to fight for your privacy against your own government you know you are in serious trouble. The government has no right to interfere with your personal effects, this is fundamental to freedom and democracy, and the idea of the private individual. Yet it seems this too is 'normalized' and citizens are more interested in technology workarounds to deal with this abuse from the state.
- deleted 9y ago[deleted]
- dataangel 9y agoWith it being such a closed platform, what are the odds this is actually true? There's no way to verify that they don't have a skeleton key.
- tajen 9y agoAt least I'm confident the French, Turkish and NK governments don't have the keys. The FBI wouldn't share the secret with simple policemen, unless for extremely rare reasons, in which case iPhone security isn't your main problem.
- pvg 9y agoYou think they lie to the US government every time it asks them to decrypt phones and they can't?
- willstrafach 9y agoI regularly reverse engineer components of iOS and have done so since the first iPhone was released. Never seen anything like a "skeleton key" and there is certainly nothing like that in place now. Starting at iOS 10, firmware components have not been encrypted (obfuscated), so you or anyone else can also reverse engineer it.
- arkadiyt 9y agoFor anyone concerned that authorities force you to give up your password to them (thus allowing them to image your device), you can pair your iPhone to a computer with a MDM (managed device profile), which will prevent any other device from connecting to it. iOS security researcher (now Apple employee) Jonathan Zdziarski has 2 blog posts on this: Counter-Forensics: Pair-Lock Your Device with Apple’s Configurator: https://www.zdziarski.com/blog/?p=2589 https://www.zdziarski.com/blog/?p=2589 Protecting Your Data at a Border Crossing: https://www.zdziarski.com/blog/?p=6918 https://www.zdziarski.com/blog/?p=6918
- amckenna 9y agoThat's a great idea! Does anyone know if this technique works with iOS 10? The linked blogpost is for iOS 7 and 8
- dannyw 9y agoYes, the underlying technique has not changed and works for iOS 11 (beta). By the way, the writer of this post now works for Apple on their Security Architecture team. I would not be surprised if this change came from him.
- arkadiyt 9y agoIt still works great, however the linked post uses Configurator and Apple has since replaced it with Configurator 2, so some of the options and workflow are different now.
- chrisper 9y agoWhat happens if your computer breaks? Is the iPhone paper weight then?
- dovdovdov 9y agoHave you ever considered reading the article? "you have to start fresh, with a brand new install of iOS."
- q3k 9y agoUntil forensic companies get hold of new exploits. Which is how high-value targets have been getting dumped for a while now.
- cgb223 9y agoWith facial unlock couldn't they just hold my phone up to my face to image it?
- sim0n 9y agoThe article says they will no longer allow Touch ID to trust a computer, I imagine they also won't allow Face ID.
- knodi 9y agoThis is why I love Apple.
- csomar 9y agoAnyone could shed a light on how difficult would be the implementation of the following: - All data encrypted by default - The "dump" of the phone memory or macbook hard-drive makes it looks like the whole drive is full. It means that the free space is populated with random data that is, itself, encrypted. - User can switch from his user profile to a fake user-profile and import some data (like contacts/messages/photos)
- cstrat 9y agoThis would be awesome.
- csomar 9y agoNo it is not. It signifies a divide between the tech sector which strives for privacy and government (which is/was supposed to protect the people)
- cstrat 9y agoOh? I might have misunderstood your post. I thought you were suggesting a way that meant phone backups all appear the same size as the disk 100% of the time. (meaning the true volume of content is hidden) Then the second point is the user could potentially have two (or more) profiles on the device, and it is possible to unlock it into one or the other. Meaning a user under duress can unlock a device and not reveal the true content while the person trying to get into the device has no way of knowing if that is the true profile or not. I figured that would be a pretty sweet feature. It would also tie neatly into allowing users to have multiple profiles on their device which is currently impossible on iOS...
- csomar 9y agoIt is a good feature, but my comment was on "awesome". It is not an awesome situation, far from it.
- 9y ago
- punnerud 9y agoWhat if Apple also added a feature for showing an innocent/clean phone if a specific password is pressed? How would the law enforcement know the difference? You only need to show the cellular call log, because they already have it and could use it to prove that you used the "mode".
- HugoDaniel 9y agoHere is a slide from the PRISM leaks: http://www.washingtonpost.com/wp-srv/special/politics/prism-collection-documents/images/prism-slide-4.jpg http://www.washingtonpost.com/wp-srv/special/politics/prism-... #neverforget
- archvile 9y agoThe mention that is varies by provider is notable. Apple encrypts End-to-end all iMessage chats, as well as FaceTime (VoIP) calls. None of the other providers on that list do that, so at least there's that. Also, people here act like Apple jumped willingly onboard the PRISM program. You can bet your ass their arm was twisted by the government or they were taken into the program unknowingly (datacenter ISP taps, etc).
- HugoDaniel 9y ago"Apple encrypts End-to-end all iMessage chats, as well as FaceTime (VoIP) calls." End-to-end encryption does not guarantee that Apple keeps your data encrypted, or that they don't process it for 3rd parties (NSA would fit as a 3rd party, where Apple would be for them a content provider, as the slide shows). "You can bet your ass their arm was twisted by the government or they were taken into the program unknowingly (datacenter ISP taps, etc)." Can you back that up ? How can you be so sure ?
- zimpenfish 9y ago> End-to-end encryption does not guarantee that Apple keeps your data encrypted I'm probably misunderstanding something here but doesn't "end-to-end encryption" mean that A encrypts it with B's key and [whoever is in the middle passing it along] can't decrypt it because they don't have B's key?
- willstrafach 9y agoYou are not misunderstanding, you are correct.
- 9y ago
- Havoc 9y agoTechnological solutions to a non-tech problem. The US have demonstrated they'll quite happily just lock people up forever if they can't get to the encrypted data. Good on Apple, but not a solution.
- sqeaky 9y agoDo it to one man and its an oddity, do it to a thousand and lots of people will be demanding change. This makes it more likely it will happen to lots of people.