6 ms·
Apple’s dangerous game, part 2
- dang 12y agoPart 1: https://news.ycombinator.com/item?id=8349006 https://news.ycombinator.com/item?id=8349006
- junto 12y agoWhen I first read part 1, I was slightly annoyed that such a prominent lawyer would take such an approach. I have to say I must now applaud Orin Kerr, for taking the time to take the opposing arguments into account, and for publishing those reflections in somewhat of an apology. It is rare that a lawyer is prepared to reconsider their position, especially so objectively and publicly.
- prawn 12y agoHis initial article also noted that he was prepared to take on board any criticism. As you said, good on him for having that attitude and following through.
- akmiller 12y agoHe deserves no such applause. The fact that he recanted his position so quickly shows that he literally put no research/effort into his initial article that was published not just on a small personal blog, but on the Washington Post's website. It is completely irresponsible of a man of his intelligence/qualifications to post something like that to a major news organizations website. edit: If down-voting I'd like to know why as I'm not saying anything inflammatory. Please don't down-vote for disagreeing as that's not what down-voting is for!
- PeterWhittaker 12y agoThe author is (apparently) an expert in his field (the law). He is not an expert in our field (technology, broadly speaking), and certainly not an expert in my field (security, broadly speaking). He wrote a post based on legal considerations and upon his domain knowledge. One of the interesting things about domain knowledge, or, more to the point, lack thereof, is that without any, one cannot know the exact extent of one's ignorance of other domains. I am not going to go so far as to assert the author was heretofore unfamiliar with the concept of a zero-day exploit, though it seems likely, but I would suggest that the author is now at least notionally familiar with the concept - and has written quite a good, clear follow-up article devoid of our jargon (which is easily among the worst of the several domains I've been exposed to over the years) indicating exactly and precisely why he reconsidered his position. THIS IS HOW KNOWLEDGE WORKS. Forgive the caps, but they are appropriate in this case. If we waited for everyone to know everything we think relevant before they wrote anything at all, all we would have written would be recipes. And pornography. A domain expert wrote a reasoned piece based on their domain knowledge. Others helpfully directed that expert to domains relevant to the piece. The domain expert then (quite speedily, I think) absorbed just enough of that domain's knowledge to draw and state reasonable conclusions. This is also how the law works, which is why it is so maddeningly slow sometimes. Editorial or "meta" notes: I upvoted because I don't believe in downvoting (I often upvote downvoted comments for this reason) - but I believe you were downvoted because you were lazy and chose to post ad hominem comments without due consideration.
- phaus 12y ago>The author is (apparently) an expert in his field (the law). He is not an expert in our field (technology, broadly speaking), and certainly not an expert in my field (security, broadly speaking). He markets himself as an expert on computer law. He also brags about working on a government panel that studied privacy and other security related topics. You cannot be an expert on computer law if you lack the context that is provided by a basic understanding of privacy / network security issues. The man is an incompetent fraud at best. Shortsighted and technologically ignorant people acquiring authority is a large part of the reason the United States' computer laws are terrible. We aren't talking about a complex issue that requires domain specific knowledge, this guy was genuinely surprised that a backdoor designed for admin access could be used by those with malicious intent. If he really cared about justice, he would hand over his license to practice and refrain from talking while there are adults in the room.
- akmiller 12y agoThere was nothing ad hominem about my post at all. Oh well...so goes HN these days.
- netcan 12y agoThe world is getting very squirrely. I feel like when we are talking about privacy, security, rights and such we are awkwardly working with metaphors that are struggling to maintain a logical relationship with the world as it is now and as it will be going forward. Realistically, a great part of my conversations and hence and great part of my thoughts are digital, therefore aggregated, analyzed, stored, distributed, vulnerable and everything else that comes with digital information. The spies, the cops, the criminals, the banks, the entrepreneurs are all treating it as a resources they can tap into.
- disjointrevelry 12y agoWelcome to the watering hole.
- jeswin 12y agoThe naïveté in the articles was a surprise to me. If Orin Kerr, professor of law and scholar in internet crime and surveillance, is enlightened* by the suggestion "If Apple can decrypt, so can others", how much would the average lawmaker or judge know? Keep things like encryption out of regulation; because it can't be. * edit: was "amused", which was incorrect.
- fulafel 12y agoBy my reading he took it seriously, what do you mean by amused?
- jeswin 12y agoSorry my bad, language issues. I meant "fascinated, by the idea". What would be a good word here?
- patio11 12y agoI think "enlightened" might be the word you're looking for. It means both that the hypothetical conveys new information to him and that, as a result of the new information, he comes to a new (and improved) understanding of the larger picture. The sentence doesn't strike me as 100% native phrasing with that substitution, by the way, but it would be clearly comprehensible.
- jeswin 12y agoEnlightened is indeed what I was looking for. Thank you.
- fulafel 12y agoHe still sounds like a government key escrow apologist, just with a newfound appreciation of third party misuse of the mechanisms. But I guess it's a good start that he acknowledges there can be "net public benefits" that outweigh the wiretapping benefits, maybe at some point he will start appreciating protection against the security state as well.
- GuiA 12y agoThe guy doesn't really understand how encryption and cryptography and infosec work, making the whole article very laborious to read and quite misguided. Weep for the future of our world governments, which will be shaped by people like this.
- idlewords 12y agoThe guy made a reasoned argument and changed his mind on an important point after reading counterarguments. Seems like the kind of person we need more of. Not going to weep!
- Tloewald 12y agoHe hasn't figured out that iCloud backups are also encrypted, so wait for part 3.
- daxelrod 12y agoAre full-device iCloud backups additionally encryped? Apple possesses the key for most data synced with iCloud, or a huge number of iCloud features would not work. According to [1] Apple can still turn over iCloud data. [1]: http://www.washingtonpost.com/business/technology/2014/09/17/2612af58-3ed2-11e4-b03f-de718edeb92f_story.html http://www.washingtonpost.com/business/technology/2014/09/17...
- madeofpalk 12y agoYou aren't suggested that Apple has access to files in full-device backups, are you? iOS backups are/could essentially be encrypted zip archives (poor example, but you get the idea) - this doesn't require apple to have the key for it. Is it possible to (en/de)crypt something using a password, if that password changes?
- Tloewald 12y agoMaybe I'm misreading or thinking wishfully: "This means that your data is protected from unauthorized access both while it is being transmitted to your devices and when it is stored in the cloud." And "iCloud Keychain encryption keys are created on your devices, and Apple can't access those keys. Only encrypted keychain data passes through Apple's servers, and Apple can't access any of the key material that could be used to decrypt that data." And finally: "You can choose to disable keychain recovery, which means that iCloud Keychain is kept up to date across your approved devices, but the encrypted data is not stored with Apple and cannot be recovered if all of your devices are lost." (The last is opt-in, but seems quite explicit.) http://support.apple.com/kb/ht4865 http://support.apple.com/kb/ht4865
- Htsthbjig 12y agoI think is it very naive to believe that the States(any State) side with your interest. In fact, the biggest crimes against humanity had been come from the state: Stalin, Hitler, Pol Pot. They are responsible for tens of millions of dead people, torture, kidnappings or rape and they were the heads of the State. Hitler or Mussolini came from democracies. If Apple could access ANY of their devices, they have to tell the NSA how they do it, thanks to "Patriot Act". This means the gobertment could AUTOMATICALLY access any device, they don't need to ask anybody, only as a pantomime for justifying what they already know. This is too dangerous, democracy means that power could change if it does not serve the public interest, but people in power want to remain in power by any means.
- vacri 12y agoThe biggest benefactors to humanity also come from the state: outlawing slavery, implementing universal healthcare, providing law and order, underwriting transportation networks. Knee-jerk fearmongering about the government doesn't help anyone.
- BugBrother 12y agoI am from Sweden. We do trust the state and each others. The society comes really high on the sociological metric of "trust". That said, it is just ... naive... to argue that "Some instances of X have done good, so let's trust (all?) X". Especially since these X evolve surprisingly over time, sometimes quickly. (The whole of Europe demilitarised totally after the cold war and are now surprised we have something like a Hitler as a neighbour.) Edit: Hmm... that comment was about internal US politics? OK... Living in a country with trusting idiots which believe what they are told to believe, I do know that politics for internal consumption can seem weird from the outside! Both the US extreme left/right seems crazy (say, Chomsky and Fox).
- chernevik 12y agoWariness of the potential abuse of power is no more paranoid than following proper technique handling a sharp kitchen knife.
- phaus 12y agoHow is it that three of the best schools in the country churned out a computer crime lawyer that knows so little about computers? If you go around calling yourself an expert in computer law when you are clearly a layman in the subject of general computing, you should lose your fucking license to practice law.
- vfclists 12y agoSounds like an apologist and a shill for the entitlement mentality which seems to afflict the entertainment, security, and law enforcement industrial complexes. Their sense of ENTITLEMENT is ENORMOUS. "We are ENTITLED to YOUR PRIVATE DATA."
- antimagic 12y agoGood grief. I would have thought that it was blindingly obvious that if "Apple" can access information on a phone, that means that some employees of Apple can also do so, and I doubt very much that control of that access is as tight as I for one would wish it to be. Closing the backdoor is a win purely on that basis. Add into that the large question marks over FISA's legitimacy as a court ( https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act#Criticism https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla... ), and the potential for illegitimate use of the backdoor becomes decidedly alarming. My way of thinking is to compare a potential backdoor to what would happen if the backdoor doesn't exist. You get a warrant, and now you use the warrant to try and compel the accused to reveal the passcode to their phone. The accused refuses. Now what? Two possibilities: 1) the defendant is protected by the 5th Amendment, and can refuse to answer on the grounds that it may incriminate. If this is how the law goes, then any attempt to backdoor the phone is essentially an attempted end run around the 5th amendment. 2) The courts decide that this does not infringe on the 5th, and is instead covered better by the provisions for warrant-based search as provided for in the 4th amendment. In this case, the courts already have well-established remedies for refusal to acquiesce to a search, which should be used. Again, the backdoor is unnecessary.
- twoodfin 12y agothe defendant is protected by the 5th Amendment, and can refuse to answer on the grounds that it may incriminate. If this is how the law goes, then any attempt to backdoor the phone is essentially an attempted end run around the 5th amendment. I'm pretty sure that's not how the 5th Amendment works: Just because your protection against self-incrimination allows you to withhold potential evidence doesn't imply that the government can't attempt to acquire that evidence themselves through other means. You can refuse to answer questions like "What's written in your diary entry for the night of the murder?" or "Where did you hide your diary?". The police can still get a warrant to search your house for your diary and read it.
- Someone1234 12y agoThere's another scenario which isn't relevant to the 5th or 4th: If the victim of crime was dead/incapacitated OR the perpetrator of a crime was dead (and the big G want evidence against their cohorts, or details on a crime which may harm others (like addresses where letter bombs were mailed)). Dead people aren't protected by the US constitution.
- chvid 12y agoI don't get why this is turned into some big political/philosophical discussion. If the government wants a backdoor and it wants Apple to open up iPhones based on court orders then the government needs to make a law explictly ordering Apple and similar to provide this service. There is a parallel in my opinion in the legaslation for telecommunication companies in many western countries requiring them to log their users activity and when a court and in some cases just the police requires it, give them the data. For a national telco this is major cost; just in Denmark it was estimated by the former telemonopoly TDC to be in tune of 20 mio usd per year. No company bears that sort of expense out of morals/patriotics. Secondly other countries than the US may be interested in requiring this feature of the phones sold in their jurisdiction.
- eevilspock 12y ago> "If the government wants a backdoor and it wants Apple to open up iPhones based on court orders then the government needs to make a law explictly ordering Apple and similar to provide this service." If such legislation passes Congress and fails to be ruled unconstitutional, 1984 was just 30 years late. Big Brother is Watching You WAR (on terror) IS PEACE FREEDOM (privacy) IS SLAVERY IGNORANCE (gag orders) IS STRENGTH (and Apple's 1984 superbowl ad takes on a suddenly literal meaning)
- hahainternet 12y ago> If such legislation passes Congress and fails to be ruled unconstitutional, 1984 was just 30 years late. What rot.
- jburwell 12y agoThe government does not have a right to wiretap, and citizens are not obligated to make their property searchable by the government. The ease with which the government has been able to wiretap and search computers was a side effect of technological immaturity not a design intention. Heck, one can think of wiretapping as one of the first hacks of the phone system. As the numerous recent data breaches have demonstrated, we need to build systems as securely as possible. Allowing anyone besides the key owner access to the data requires that the system be made fundamentally less secure. We have presumption of innonocence in the USA which means I am assumed to be a Good Guy (tm) until the government proves otherwise by due process of law. Furthermore, a citizen's desire not to disclose information to the government is not ns indication of guilt (5th amendment). The author of this these editorials either forgets or misunderstands these rights -- accepting the argument that everyone should surrender their privacy rights if they nothing hide. Living in a free society requires citizens take some degree of personal risk.
- cyphunk 12y agoThe argument about criminals going dark with crypto is just fear bating and FUD. The criminals you "really" want to worry about are already dark. The only people iOS8 protects are your standard domestic criminals, which if they hadn't already learned how to use crypto trust me --- they likely leak like a sieve through many other vectors (web mail, pc's, ISP, etc). What we should be debating is job security for domestic police. Because if we do not put user-centric-crypto in everything one day police will loose their jobs to robots and algorithms. Well, at least this argument is only as absurd as the authors FUD.
- gkoz 12y agoDoes the threat of unauthorized remote access affect the public interest balance much? It shouldn't be impacted by encryption.
- ctdonath 12y agoAmong other interpretations, I'm seeing this as a continuation/expansion of one of Apple's axioms: "No comment." Whatever steps they can take to facilitate not saying any more than they have to about anything is a self-imposed imperative. By expanding implementation of encryption they can avoid compulsion (legal or social) to get embroiled in users' activities and have no reason, even no way, to comment on dubious legal or moral activities of others. The data services involved exist, from Apple's perspective, solely to entrench users in the ecosystem and thus sell ever more hardware. Implementing robust encryption prevents entanglement in anything beyond that objective goal.
- gress 12y agoJeff Bezos's newspaper publishes a legalistic piece impugning Apple. Who is surprised?
- the8472 12y agoThe whole premise of the argument strikes me as odd. Users always had the option of running a phone OS that does not send the keys to the kingdom to the mothership. Desktop operating systems similarly provide such tools either out of the box (e.g. bitlocker, filevault, dm-crypt) or through 3rd party applications (e.g. truecrypt). Apple's old security model may have been convenient for law enforcment agencies, but that does not mean that they are entitled to this convenience, i.e. that it is reasonable to demand that this security model is the only one offered to users. So Apple merely switched to a different model that other systems were already providing out-of-the-box.
- wvenable 12y agoWhile reading this article, one real world metaphor kept coming to mind for me: a safe. That's really what the iPhone is; it is personal information stored behind a combination lock. Are safe manufacturers required to provide back doors to safes for government searches? Is there any analogy to this in the real world?