DoJ to Apple: we can force you to decrypt
boingboing.net
boingboing.net
It is a delicious twist, though.
I think the main argument in the linked document is that Apple has the ability to unlock pre iOS 8 phones, and has done it before. Again, that "Apple is not 'so far removed from the underlying controversy that its assistance could not be permissibly compelled.”
The OP seems wrong but IANAL.
> it doesn't have the technical capability to do so;
Is factually incorrect in this case... Right?
[0] https://ia801501.us.archive.org/27/items/gov.uscourts.nyed.3...
In other words, Apple design their security measures under the assumption that they themselves are not the enemy. That's not good enough anymore. If you get compromised, you become the enemy. The designer should lock even themselves out, the end user should be the one in control.
Even so-called zero-knowledge centralized software like iMessage is only a centrally mandated update away from turning their backs on their privacy policy.
iMessage theoretically also does this. The difference is how key exchange is handled, with iMessage preferring a more usable but potentially less secure approach.
Signal have none of those particular problems.
I'd like to see more viable options in this space for communications that truly need to be confidential, both in terms of content and metadata. Centralized services can only provide the former for as long as the centralized provider has not been compromised, and simply cannot provide the latter at all.
If you're the only one to decide what software runs on it, this crap can't be enforced against you.
It's not fully specified, but since the PDF mentions "iteration count" then Apple is using some sort of KDF after you enter your PIN to make brute force attacks harder to perform. It also mentions the following delays:
Delays between passcode attempts
Attempts Delay Enforced
1-4 none
5 1 minute
6 5 minutes
7-8 15 minutes
9 1 hour
There's also an optional setting you can enable so that after 10 failed consecutive attempts the device's data is wiped.Also note how they mention "six-digit" before "four-digit". Six digits is the default on new installations now (http://arstechnica.com/apple/2015/06/apple-to-require-6-digi...)
Which restrictions? The table of delays is on the same page as "six-digit, four-digit, and arbitrary-length alphanumeric passcodes", about 3 paragraphs away. If this is what you're referring to, I see no reason to believe PINs vs. passwords are treated differently.
If this goes badly and loses on all appeals it is over.
http://qz.com/356233/apples-capitulation-to-china-undermines... http://www.wsj.com/articles/us-presses-china-on-bank-technol...
RIM at the time fought Saudi Arabia on the same thing, but has also eventually given up.
http://www.dailyfinance.com/2010/08/07/rim-deal-saudi-arabia...
Companies will always do what it's profitable for them, for RIM Saudi Arabia at the time was a big enough market, today it's China. While there might be some backlash, most people don't care and while you might need to invest money in spinning this if a country doesn't allow you to sell the products in the first place you lose by default.
ATM there seems to be sufficient public pressure to fight against these decisions in the US and Europe, but not so much in other regions, and if China gets to access your phone YBA the US won't be in a position to give up on it either, not that they seem to want to at least at this point in time regardless of that reality.