A Message to Our Customers
apple.com
apple.com
One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end:
"The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer."
This is actually quite reassuring - what this means is that even Apple can't break into an iPhone with a secure passphrase (10+ characters) and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint.
Why against hope?
I see these efforts as Google going far out of its way to support privacy and security on the web.
This isn't true. You can stick to app repositories like F-Droid and use Raccoon to download Play Store apps via your desktop without using a Google account on your phone.
I don't use them personally but I imagine Goole Now, GMail and Google Maps would need Play Services.
The apps I do use (non-google) tend to function well enough without Play Services though.
Anyone who does is a rounding error.
> Anyone who does is a rounding error.
I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device.
My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)
Basebands aside, the rest of the device is somewhat feasible to see being open.
According to them, there are unfortunately no baseband modems on the market that can legally have their firmware distributed as free software. Their workaround is to keep the modem as isolated from the CPU/RAM as possible.
What is the legal restriction here? (It sounds like you're referring to some restriction beyond simple copyright protection on some of their components - are there FCC regulations regarding the firmware?)
EDIT: Ah, of course, the FCC needs to certify devices before they can actually be used.
>We unfortunately cannot provide free baseband modem firmware, as there is no option available on the market which would be able to fulfil this requirement. Even if it existed, it would bring very little value to the users, as operating a radio device with modified firmware on public networks without recertification is prohibited in most jurisdictions of the world and privacy concerns in cellular networks are mostly related to what happens on the network side, not inside the device.
I don't have any more information than this. If someone can quote specific FCC regulations to back this up, I would find that very interesting :)
Not entirely true, publishing the code isn't the same as allowing its modification. Code signing can be used to limit which versions are allowed to run.
Reproducible builds of the source would allow one to ensure that the binary, certified version of the code their baseband processor is running is legit (i.e. not backdoored). It would also help audit the code and spot security holes.
If I can't run my home-compiled versions of your code - whether because of code signing restrictions or because of federal law prohibiting firmware that hasn't been certified - it's not free[0]. So without without reproducible builds, providing the source code for the firmware provides very little benefit (since I have no way to prove that the code corresponds to what's actually running on the device, nor any legal way to install and run it on the device myself.)
Reproducible builds could in theory work, but actually getting builds to be bit-for-bit reproducible is not an easy feat. I'd be very surprised if firmware were capable of this.
[0] This is a great example of why a free software license doesn't necessarily mean that the software is free. It means that the author has waived his/her ability to restrict your freedom to use/modify/distribute the software, but that doesn't mean that third parties (ie, the government, or a patent troll) have done the same.
Despite the openness of Android/AOSP, there are still, unfortunately, things like binary blobs for certain graphics chips and closed-source firmware for things like Wi-Fi chipsets. Given what we've seen agencies like NSA are capable of (intercepting hardware in transit to apply backdoors, paying off RSA to make Dual EC the default pRNG in their crypto libraries, etc.), them compelling a manufacturer of a component to include a backdoor in their closed-source blobs is no stretch of the imagination.
Apple even has this problem: basebands in cellular modems are notorious for being the source of exploits in otherwise-secure phones.
Google has been (even more) proactive about security and encryption since then, since part of their business model relies on trust.
Exactly like Apple. Or do you think that the emails in iCloud are not given to the prosecutors?
The point I was trying to make is that Google and Facebook have direct access to all the data of their customers, and already provide access to government agencies. Contrary to Apple they don't safely store some data of their costumers safely on the device, which this case is about.
Your point is wrong regarding Google and smartphones if the smartphone is encrypted
Beyond that, Google definitely has the keys to your encrypted backups on their servers, so access to the phone might not even be necessary.
[1] http://visihow.com/Recover_Android_Device_in_case_of_Forgot_...
[0] http://www.theguardian.com/technology/2015/nov/24/google-can...
"The situation is different for Android. Google’s version of Android, which runs on most Android smartphones and tablets in the western world, only implemented encryption by default with the latest version Android 6.0 Marshmallow released in October 2015."
That version of Android is only on a handful of devices, not even a full percentage point of global market share. Even on Lollipop and older devices that do support encryption, it has to explicitly be turned on by the user. And once again, Google is not expressly clear that they don't have your encryption keys on Lollipop and lower; they only claim not to have them for Marshmallow devices. They definitely have the keys to your encrypted data on their servers no matter what, which can include complete backups of your device.
And?
> Google is not expressly clear that they don't have your encryption keys on Lollipop and lower;
They have explicitly said that if the device is encrypted they don't have the key.
> They definitely have the keys to your encrypted data on their servers no matter what, which can include complete backups of your device
Source for that?
In other words, if you can ever actually use something, it's probably not secure.
Google and Facebook's core competency is using your personal data to sell ads.
Apple's core competency is selling you appliances. Yes, they wind up with some personal data because of the services they also provide, but it's far less valuable to them than Google or Facebook.
What has to do your post with this claim?
I'm ambivalent regarding Apple's stance. In principle they are doing the right thing, but in practice, it seems they may be kicking up a whole lot of fuss over a relatively minor issue (with the exception that providing an easy means to brute force a phone to the authorities sets a horrible precedent). As for creating a universal backdoor, it seems highly unlikely they couldn't produce a signed OS / coprocessor firmware image that wasn't locked to one of the various serial numbers associated with this particular device
edit: as mentioned below, this order entirely originates with Apple's use of DRM to prevent software modification. Had users actual control over the devices they own the FBI wouldn't need to request a signed firmware in the first place. Please think twice about what Apple might really be defending here before downvoting
edit: self-answer: the following post seems to have an answer: https://news.ycombinator.com/item?id=11115579, although it seems to describe a newer device than the one in the case; but I was interested in how such protection is possible at all, so that seems to answer it for me.
This is the entire concern (in my opinion and in my reading of Tim Cook's opinion). If the government can force Apple to backdoor this one iPhone (because terrorist), then they can force Apple to backdoor any iPhone for any person given a valid warrant, subpoena or otherwise granted power. Once the flood gates open...
Imagine this scenario:
1.) Apple creates the custom iOS build for the FBI to use to decrypt this iPhone.
2.) China hacks into either Apple or the FBI and downloads this build. (We know they have the capability, because it's already happened. [1])
3.) A visiting U.S. diplomat, politician, or military officer has his iPhone pickpocketed while in China. (This also happens all the time.)
4.) The Chinese government uses this stolen software to brute-force the encryption on the device, finding access codes for classified U.S. military networks. (Because we know U.S. diplomats never use their personal email for state business [2], right?)
5.) Now a foreign power has access to all sorts of state military secrets.
The problem with backdoors is they let anyone in. Right now, there's a modicum of security for Apple devices because knowledge of how you would bypass the device encryption is locked up in the heads of several engineers there. The FBI is asking Apple to commit it to source code. Source code can be stolen, very easily. Tim Cook's open letter is making the point that once this software exists, there is no guarantee that it will stay only in the hands of the FBI.
[1] https://en.wikipedia.org/wiki/Operation_Aurora
[2] http://graphics.wsj.com/hillary-clinton-email-documents/
WARNING — THIS Apple Engineer IS CLASSIFIED AS A MUNITION --rsa--------------------------------8<------------------------------------- #!/usr/local/bin/human -s-- -export-a-crypto-system-sig -RSA-in-3-lines-HUMAN ($k,$n)=@ARGV;$m=unpack(H.$w,$m."\0"x$w),$_=`echo "16do$w 2+4Oi0$d-^1[d2% Sa2/d0<X+dLa1=z\U$n%0]SX$k"[$m]\EszlXx++p|dc`,s/^.|\W//g,print pack('H' ,$_)while read(STDIN,$m,($w=2*$d-1+length($n||die"$0 [-d] k n\n")&~1)/2) -------------------------------------8<------------------------------------- TRY: echo squeamish ossifrage | rsa -e 3 7537d365 | rsa -d 4e243e33 7537d365 FEDERAL LAW PROHIBITS TRANSFER OF THIS APPLE ENGINEER TO FOREIGNERS
I strongly disagree. They are taking a stance in the debate about government mandated backdoors in software.
So they would still get 10 bites at the cherry, and sure, on the tenth, they could depower the phone and prevent the wipe, but if each attempt is persistently stored before the password-check is carried out, depowering the phone wouldn't give them any more chances.
That's a large part of the fuss!
The order says that Apple's exploit should only work on this specific, already existing device.
And I'm not optimistic that the stockholders care about anything more than doing the opposite.
Talk is all we need so far. Publicly saying no to the FBI is a step rarely taken.
And any stockholder with an ounce of intelligence will understand that Apple's choices here are both morally right and effective marketing. As the information age matures, privacy is becoming a valuable asset, and Apple is starting to gain a positive reputation in this space.
AAPL is one of the most mainstream, widely-held stocks on the planet. Assumptions about the opinion of some homogeneous "stockholder" are useless.
I'm positive HN is filled to the brim with AAPL shareholders who care deeply about this issue.
I voted for, and to my surprise so did a majority of other stockholders, and that avenue of opportunities was removed.
If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially?
And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to build it?
"Impossible" should mean "impossible", not "not yet done, but possible".
Apple reasons that there is no way to guarantee no one will take the same update and apply it to other iOS devices. Or government taking this a step further by making Apple to build that into future update for the whole user base.
Not to mention that this is for the iPhone 5c. As other comments have mentioned, newer iPhones have the hardware-based Secure Enclave which add to the difficulty of breaking into the phone. https://www.apple.com/business/docs/iOS_Security_Guide.pdf
So while the Secure Enclave enforces the delay between brute force attempts, Apple could still release an update that removes that delay.
The right password can be obtained by either knowing it, or by guessing it.
As an additional security measure, the software shipped with the phone prevents brute force attacks by wiping the device after a given number of failed attempts.
Apple has been asked to modify the software so that it won't wipe the phone, thus allowing the authorities to try many passwords.
If anybody could circumvent this additional security measure, actual security would be lower. The authorities are not asking Apple to ship this change to all users: they only want to install it on the device in their possession.
However, Apple is concerned that once they provide the authorities such a modified software, it could be leaked and thus be used by third parties to breach the security of any Apple device.
It should be noted that currently all data encrypted for example on your laptop's hard drive is already subject to this kind of brute force attacks. It's a well known fact that authorities or malicious users can already attempt brute force attacks on encrypted data if they can access the data on a passive device such as a hard-drive.
It's important to understand that Apple (at least not in this case) is not being asked to implement a backdoor in the encryption software. It's also important to understand that even if Apple was forced to install a backdoor, it would affect only the ability to access future data and not help the investigation of the San Bernardino case.
This very request by the Authorities suggests that Apple does not currently install any backdoor on stock phones.
However there is a logical possibility that the Authorities are either not aware of any such backdoor or in the worst case they are publicly requesting this feature just to hide the real reason of a possible future success at decrypting the phone: they can claim that Apple didn't have any backdoor, and they were just lucky at bruteforcing the device; in fact Apple wasn't even cooperating with them at relaxing the brute force prevention limit, so they could claim they did it in house.
(I'm personally not inclined to believe in such improbably well coordinated smoke and mirrors strategies, but they are a logical possibility nevertheless).
“Each Secure Enclave is provisioned during fabrication with its own UID (Unique ID) that is not accessible to other parts of the system and is not known to Apple. When the device starts up, an ephemeral key is created, entangled with its UID, and used to encrypt the Secure Enclave’s portion of the device’s memory space. Additionally, data that is saved to the file system by the Secure Enclave is encrypted with a key entangled with the UID and an anti-replay counter.”
https://www.apple.com/business/docs/iOS_Security_Guide.pdf
The device in question is an iPhone 5C, which uses the older A6 design.
http://forums.appleinsider.com/discussion/comment/2832533/#C...
Everything is encrypted with a derivative of this UID, and extracting the UID is not a thing you can do without destroying the device.
"even Apple cannot decrypt without using the right password."
Could you please explain?
The iPhone prevents this by locking up (and potentially erasing the phone) after 10 failed attempts, but this a restriction created in iOS. If they provision a new backdoored version of iOS to the phone, that restriction wouldn't apply any more, and they could brute-force away.
The FBI can also unsolder the components in the phone, make a full image of the content, find the encrypted section and then brute-force. This is what is done for SSD. They do not power up the drive, unsolder, put the memory modules in a special reader and copy the data before the controller of the SSD automatically wipe out data because of automatic optimization after a delete/trim.
See, for example, the people who know they're going to die and who leave their iPads to their relatives in their wills. Apple doesn't take grants of probate as sufficient legal documents (everyone else does (eg banks)) and insist on a court order.
Leaving a physical trace of my passwords is not only bad practice from security point of view, but quite useless since I know them. Also, my online accounts are useless if I can't use them because I'm dead, so I don't really care if no one can access them anymore. What happens to important things such as banking is already dealt with.
But I think the right solution here would be for Facebook to have a way of handling deceased people, not giving your password to everyone in case of sudden death.
A lot of it about PR.
The way I understand it (and, correct me if I'm wrong) is that the code flows from disk through the aes engine where it is decrypted and then placed in a presumably interesting/hard to reverse place in ram at which point it is executed. I imagine even more interesting things are done to higher value data in ram, but that's not code - because as you said, code has to be decrypted (at the latest) by the time it reaches the registers.
Schroedinger's Backdoor? ;)
> no way to stop a dedicated attacker from brute-forcing it
Wipe after x incorrect? Can't stop the attacker, but you can make it futile, surely.Sure, if they wanted to they could implement a backdoor. But assuming they correctly created and shipped the secure enclave it shouldn't be possible to circumvent it even for Apple.
You can't swap the SE or CPU around, nor can you run the attempts on a different device.
Against a sufficiently capable adversary, tamper-resistance is never infalible, but good crypto can be.
> Against a sufficiently capable adversary, tamper-
> resistance is never infalible, but good crypto can be.
Nonsense, it all comes back to "sufficiently capable", every time.To a sufficiently capable adversary, _all_ crypto is just "mere security by obscurity".
"Oh, mwa-haha, they obscured their password amongst these millions of possible combinations, thinking it gave them security - how quaint. Thankfully I'm sufficiently capable.", she'll say.
In theory it should be possible to make it fixed (which Apple doesn't seem to have done).
That's not true actually. For example, the industry standard for storing passwords on a server (bcrypt) is specifically designed to slow down password match attempts.
If you have things that you need to be private, don't put it on a smartphone.
Apple has implicitly for a long time, and lately much more vocally, cared about privacy. They don't have the same data-driven business model that Google and FB do.
They say that. But with closed source software we can't verify that it's true. I'm not saying they don't care about privacy, only that we don't really know if they do or not.
Plus, with open source you can verify intent, which you can't with apple.
Which provide a device getting your finger prints, all your phone numbers, internet search, bank details, some paiements, network communication, voice communications, text communications, localisation using GPS and wifi + hotspot + phone towers and soon ihealth device collection body metrics.
And they are profit oriented, not people oriented.
Sure but they were there for years before anyone noticed. Same with PHP's Mersenne Twister code. Same with multiple other long-standing bugs. It's disingenuous to toss out "Oh, if only it was open source!" because reality tells us that people just plain -don't- read and verify open source code even when it's critical stuff like OpenSSL.
I agree that failing to fix a problem like this in a timely fashion is bad, but sins of omission are generally judged differently than sins of commission, for better or worse. Apple failing to apply proper prioritization to security holes isn't the same as Apple collecting data to be sold to the highest bidder.
So, again, Apple should not be treated as equivalent to Google and Facebook. Feel free to judge them harshly, but don't paint them with the same brush.
Apple accuses the FBI of playing language games with the term "backdoor", but I think Apple has done the same. The fact that they can push weak OS updates to a locked phone is the backdoor. This means that they can already comply with the court order, and they likely will. This letter covers them from PR damage.
(article) > But that’s simply not true. Once created, the technique could be used over and over again, on any number of devices.
I am also missing a key part of the technical details involved in this this situation.
Just one terrorist attack + PR letter to customer + forced update away from loosing encryption on your phone.
More on topic is whether Apple or even Google get out from under this if their on disk encryption mechanism is open source. If everyone owns e.g. LUKS (in a sense no one company owns/controls it) then can any one company be burdened by a court to effectively break everyone else's software by being told to create a backdoor?
http://apple.slashdot.org/story/15/04/09/1531237/apple-leave...
This times nine hundred and eleven thousand.
"Locked" seems like an improper term for such a scenario.
I applaud apple for appealing this case to the public however there is a HUGE HUGE difference between "we can't unlock" and "we shouldn't unlock". This distinction will likely be lost on the general public unfortunately.
In this case, the intended answer/conclusion/implication is "yes, this is."
To be fair, they could have stated it explicitly.
If the data was truly encrypted, the concept of pushing an update or creating a master key would not be possible.
If it is stated very clearly, can you quote me a sentence?
In the security guide linked here it seems possible for this iPhone model but not later ones.
Edit: According to the discussion below Apple can ship updates to the secure enclave. I don't know if that's possible to a locked phone.
Apple's security PDF says that the iteration count is calibrated so that one attempt takes 80ms in hardware, so that's the hard limit on the brute forcing speed, regardless of any updates Apple releases.
This means that a long alphanumeric passphrase is secure, but a 6-digit passcode could be broken in half a day, and a 4-digit passcode would take just a dozen minutes.
# characters [0-9] [0-9a-z] [0-9a-zA-Z]
1 0.8 seconds 2.9 seconds 5 seconds
2 8 seconds 1.7 minutes 5.1 minutes
3 1.3 minutes 1 hour 5.3 hours
4 13 minutes 1.6 days 2 weeks
5 2.2 hours 8 weeks 2.3 years
6 22 hours 5.5 years 140 years
7 1.3 weeks 200 years 9 thousand years
8 13 weeks 7 thousand years 550 thousand years
9 2.5 years 260 thousand years 34 million years
10 25 years 9 million years 2 billion yearsI wouldn't be surprised (It isn't stated in their iOS security doc) if the key generation uses a hash of the system files as part of a seed for the entropy source used for keys, though that's pure speculation on my part.
Edited for clarity regarding "push" vs physical access.
As far as I'm aware there is no known technique to prevent someone with physical access, a bunch of engineers, and the code signing keys from replacing firmware.
Starting with the A7 CPUs, the iPhone CPU has a "secure enclave" which is basically a miniature SoC within the SoC. The secure enclave has its own CPU with its own secure boot chain and runs independently of the rest of the system. It runs a modified L4 microkernel and it does all of low-level key management.
The secure enclave contains a unique ID burned into the hardware. This ID can be loaded as a key into the hardware AES engine, but is otherwise designed to be completely inaccessible. Assuming AES is secure, that means the key can be used to encrypt data but can't be extracted, not even by the supposedly secure software running in the secure enclave. This key is then used to generate other keys, like the ones used to encrypt files. That means you can't extract the flash memory, connect it to a computer, and then try to brute force it from there. Or rather you can, but you'll be brute forcing a 256-bit AES key, not a 4-digit PIN, making it effectively impossible.
One of the secure enclave's tasks is taking a PIN (or fingerprint) and turning it into the encryption key needed to read the user's files. The main system just hands off the user's code to the secure enclave, and gets back either a key or a failure. The escalating delays with successive failures and wipe after too many failures are both done in the secure enclave. That means that updating the device's main OS won't affect it.
All of this is discussed in Apple's security guide here:
https://www.apple.com/business/docs/iOS_Security_Guide.pdf
The one open question is software updates for the secure enclave. According to that guide, its software can be updated. Does that mean it can be updated with code that removes the restrictions and allows brute-forcing passcodes? The guide doesn't address how the updates work.
My guess, based on how meticulous Apple is about everything else, is that updates are designed to make this scenario impossible. The secure enclave must be unlocked to apply an update, or if updated without unlocking it wipes the master keys. This would be pretty simple to do, and it would fit in with the rest of their approach, so I think it's likely that this is how it works, or something with the same effect.
Drawing the line in the sand at "the government can't force us to hack this guy's phone this time" thus ends up being "can't force us to provide features to hack anyone else's phone down the line".
The real problem is that you don’t want to set any precedent at all. Once it’s possible to do something for the 5C, weasel words can be introduced to make claims like “well: now you must maintain the current level of access by law enforcement”. Next thing you know, that excuse can be used to interfere with all future hardware designs.
Arguably, the fact that the 5C accepts a firmware update without the passcode is a security vulnerability and ought to be patched.
EDIT: backups are encrypted, but apple have the keys. See below.
So basically, they could be in clear text, it's pretty much the same.
[1]: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
What Tim Cook wrote is that > "install it on an iPhone recovered during the investigation." > "the potential to unlock any iPhone in someone’s physical possession."
So the FBI has the physical phone already. They can deliver to Apple who can disassemble it and either use a JTAG/Flash programmer on an internal connector to manually write new software, or they could desolder the Flash holding the old OS and place a new one.
Both of these techniques are common enough in the embedded industry that I expect this is what Apple means. They probably can't push an OTA software update and force the install on a locked device.
To clarify, I agree that nothing they ask of Apple is technically impossible or even that difficult for Apple to pull off, probably via simple DFU without touching the flash at all.
Nothing's bulletproof but the iPhone is the most trustworthy IMHO.
The backup is probably easier to attack if you have it, since it doesn't have hardware imposed timeouts on password guesses. It may not be current however.
The iphone contains a sim card.
A sim card is a complete, general purpose computer with its own CPU and RAM and the ability to run arbitrary java programs that can be uploaded, without your knowledge by your carrier.
You are owned. Deeply, profoundly, in ways that you have no way to manage/mitigate.
The real question, for me, is why authorities are dealing with Apple at all and not just working with the carriers who have proven to be their trusted allies.
I'd guess "security by obscurity". Just because they have the device rooted via SIM card doesn't mean they have available a signed build of a multi-gigabyte OS with most security libraries expunged.
The phone isn't always locked and encrypted; for example, whenever the user is using the phone it's unlocked and decrypted.
So you don't want any hardware to have access to main memory if it doesn't need to. For instance, you can use an IOMMU to ensure that devices can only access the specific areas the OS wants to allow them to DMA to/from, not all of memory.
In my experience, law enforcement does not make their own jobs harder on purpose. If there is an easy way to get that data, they would use that way to get it.
The international legal framework of sovereignty basically says you are owned. (Not universally de jure, but pretty much de facto.) Whatever rights you have are effectively granted to you by your country. Unfortunately, this notion is seldom given any thought, and the current most visible proponents of such an idea are unpleasant angry underclass men using it as an excuse to behave badly. There are others who have given thought to this, however, and it is part of the motivation behind such things as The Universal Declaration of Human Rights.
https://en.wikipedia.org/wiki/Universal_Declaration_of_Human...
I want to disclaim that this is pure speculation. I have no insider knowledge or indeed any particular familiarity with the institutions in question.
The FBI may want this authority and this precedent and think that this is a good chance to get it. They may say, "Well, the San Bernadino case is a high-profile case that may sway people, including judges, who would otherwise be less inclined to back our request. Who knows when the next nationally-publicized case will be in which the likely perpetrator carries an iPhone?" They may also believe that the current political climate is good for their case.
And they probably also believe that there's no harm in trying. If the courts rule against them, they haven't lost anything. If the courts rule for them, they get a brand new tool.
The newer devices run a special L4 kernel on the secure enclave. It is not updateable without providing the existing passcode. It enforces the attempt rate limiting and key deletion on too many attempts (if enabled). Special limited communication channels allow the CPU to talk to the SE. In production devices the SE has JTAG disabled. Encryption and decryption of the master keys happen inside the SE with its own private AES engine so even oracle/timing attacks on the main CPU are useless.
Why doesn't Apple just help hack this phone but wash their hands of newer devices and tell customers to upgrade? Because if the FBI and this court get away with using the All Writs act to compel Apple to write new software they'll eventually be forced to add a backdoor to SE-equipped devices too. Courts won't understand or care about the differences.
If the government forced them, Apple could insert a backdoor into the next major version of iOS or the hardware; then everyone inputs their passcode during the upgrade and the backdoor is deployed. Their primary defense against that so far (and the only real one you can have as a corporation) is to never build the capability in the first place. This judge's order is telling them to go build the capability (in theory for this one phone). The fact that you can't retroactively build the backdoor for 5S and newer devices isn't the main issue.
Better to fight every step of the way and draft as many pro-privacy people as possible into the fight to apply political pressure.
The whole point is that it doesn't matter what the court thinks if Apple cannot comply due to the laws of nature. That was their whole argument to begin with. Their argument now is pretty mushy in comparison.
1) http://blog.trailofbits.com/2016/02/17/apple-can-comply-with...
Companies exist to make money, not to protect our rights. It even crossed my mind that the possibility that NSA et. al. rooted these devices long ago, and that this whole "debate" is just a staged thing to make it appear as though we had any privacy and feigned adherence to the democratic process.
But your point that, as a matter of policy, many organizations will simply not use the product if they know it has backdoors, relates it back to their capitalist motivation and makes any conspiracy less likely.
I agree that Tim Cook has spun it as if it's not a backdoor when clearly it is. Still quite a hard-to-use one though. It seems like they need the physical phone and maybe Apple's private key for signing updates.
The idea that the act of writing software makes it insecure is silly though. The security doesn't come from no-one having made the appropriate changes to iOS. If it was, that would be security through obscurity and any motivated hacker or the FBI could modify iOS themselves. It must be about signing the update so that it can actually be installed.
Apple says:
All that information needs to be protected from hackers and criminals who want to access it, steal it, and use it without our knowledge or permission
As I understand, Apple complains about the introduction of this new threat model:
1. criminal steals someone's iPhone,
2. gets hold of a special iOS version that Apple keeps internally to assist the government,
3. pushes the OS update to the iPhone by themselves,
4. uses some tool to automate brute-forcing the user passcode
At least that's what I get from these excerpts:Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation.
The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer.
Now how serious is this threat? And how useful is it to have the FBI be able to look into a phone when they have a warrant? Does the balance between the right to privacy and the need to assist criminal investigation really tilt towards privacy in this specific case?
Meanwhile there are serious threats that do affect a lot of users in practice, where Apple does a good job but could do better still such as:
- Remote code execution on iOS (6 vulnerabilities in 2016 so far[1])
- Phishing, brute force and social engineering attacks (the improved two-factor authentication is not yet available to everyone[2])
Am I wrong in thinking that users are way more likely to be affected by these threats except when the government has a warrant?
If Apple is actually worried about the FBI getting access to the modified iOS version, they should focus their complaint on that and propose to do the whole data extraction in-house.
[1] http://www.cvedetails.com/vulnerability-list/vendor_id-49/pr...
It's not like iOS is impossible to hack now and it would be terrible that it becomes possible. There are other aspects of the system that allow malicious exploits more easily than this theoretical threat. So it doesn't make sense to preserve at all costs (e.g. making warrants unenforceable) an "impossibilty" that never was.
No, not really.
> Or is the ability to comply with a warrant worth nothing?
What if I issued a warrant for you to give me a 3 headed dog? Is your inability to comply with a warrant worth nothing?
Even with as much data as each of them has, it's still better that the data isn't given to yet another party (the government, or each other).
Note that this letter says: "When the FBI has requested data that’s in our possession, we have provided it."
Seels like that detail is getting very little attention in this announcement. Really? If the FYI requests any data, they hand it over...?
> Really? If the FYI requests any data, they hand it over...?
They have to, there's no legal wiggle room here. Creating backdoors OTOH seems to be sufficiently legally questionable that Apple can risk noncompliance.
(Of course, Apple could not accumulate all that data in the first place, but that would be silly, obviously. Now please sync your wifi passwords to iCloud.)
For example, I have friends who work in law (though not in the US), and the number 1 data request -which is revised by a judge, and only then given by companies- are call logs from telephones (just from/to, date, time, duration, nothing fancy). And this are extremely helpful and information rich, if you know how to use them.
This specific case, in fact, is pretty close to "murder of a loved one;" the phone's owner killed people, and the FBI wants to find out if they were part of a bigger plot.
But I was mainly pointing out that quote because it wasn't clear what lesson the parent commenter wanted Google, Facebook, and Amazon to be learning from Apple. I would have guessed it'd have something to do with protection of user data, but the letter says they turn over any user data they have!
As for the comment of Google, Facebook, etc, learning, I agree with you.
It seems the primary aim of this statement is to prevent rumors that would spook Apple users into thinking their data is fair game
The details of the gov't request are in another story on the HN front page
https://www.techdirt.com/articles/20160216/17393733617/no-ju...
So, I'm doubtful.
That is not exactly true. They wrote the OS, they designed the phone, they know where the JTAG connectors are. Cracking the phone apart and putting is logic board up on a debugger would likely enable them to bypass security.
From what I understand Tim is doing, and I greatly admire, is trying to avoid a judicial requirement that they be able to do this on demand. The so called "back door" requirement, because he knows, as others do, that such a feature would be used by more than the intended audience, and for more than the intended uses, to the detriment of Apple's users.
What I really find amazing is that I was at a talk hosted by the East-West Institute where the Air Force General of the new cyber command (whose name escapes me) complained that "we" (silicon valley) had let the government down by not writing strong enough crypto to keep our adversaries out. I remarked that it was the ITARS regulation and the Commerce department at the behest of the NSA which had tied our hands in that regard, and that with a free reign we would have, and could do, much better. Whit Diffie was there and also made the same point with them. And now, here we are 10 years later, and we "fixed" it, and now its our fault that they can't break into this stuff? Guess what? Our adversaries can't either!
The right to privacy, and the right of companies to secure that right with technology for their customers, is a very important topic and deserves the attention. I am really glad that one of the most valuable companies in the world is drawing a bright line in the sand. So I really support Tim's position on this one.
To be fair - the only reason he's doing it is because it would cause a significant drop in sales for Apple devices. People overseas would immediately stop buying because "The American government is listening", and that's assuming countries like China and Russia wouldn't ban them outright.
This is the big thing American politicians are missing or glossing over in their campaigns to get re-elected: Forcing American companies to compromise their products will result in a significant loss of revenue overseas. Microsoft, Google, et al, have already reported it and foreign governments have already started banning goods/services (due to the Snowden revelations).
That's not being fair at all. To say the only reason he is doing it is to protect iPhone sales doesn't speak to Tim's character. Of course he cares about sales, but he also cares about privacy.
Cook's responsibility is first and foremost to the stockholders, and secondarily to the customers. Decrypting the iPhone would seriously compromise the security of Apple's products, gravely damage the company's credibility, hurt sales, and drive the stock price down.
No CEO is going to take such a drastic step unless they are a craven, cowardly type who meekly obeys ask-for-the-sky demands from overbearing federal law enforcement types, and Cook surely did not rise to his current position by being a pushover.
That's not to say there won't be some kind of secret deal made behind closed doors, but secrets tend to get out. Apple would not be so foolish, I think. Yahoo? Microsoft? They just handed over the keys to their email to anyone who demanded it -- the Chinese government, the NSA -- but Apple has no history of this type of behavior. Surely Snowden would have revealed it if they had.
We should be careful about plainly stating what someone else's motivations are when it contradicts their own story.
Edit: s/it's/his reasons include/ for clarification.
We still live in a world where all people are not treated equally. Too many people do not feel free to practice their religion or express their opinion or love who they choose. A world in which that information can make a difference between life and death. If those of us in positions of responsibility fail to do everything in our power to protect the right of privacy, we risk something far more valuable than money. We risk our way of life.
See pages such as http://qz.com/344661/apple-ceo-tim-cook-says-privacy-is-a-ma...
Compare to GE, which rolled over [2].
So I believe Mr Cook when he says his opposition to the FBI's request is rooted in a desire to do the right thing, and not the bottom line.
[1] http://www.macobserver.com/tmo/article/tim-cook-soundly-reje...
[2] http://www.nationalcenter.org/PR-GE_Climate_Change_022114.ht...
[Cook] didn't stop there, however, as he looked directly at the NCPPR representative and said, "If you want me to do things only for ROI reasons, you should get out of this stock."
That's a very blunt statement that the immediate stock valuation is not Cook's only consideration.
Some people seem to have a hard time taking Cook at his word, but he's been quite consistent. This massive skepticism feels more like nostalgie de la boue than anything based in facts.
People that really care about security don't use smartphones.
I'm not sure this is true once you factor in price range. The general knowledge is a lot of those Android devices are sub-$250.
Maybe by share of units shipped. By revenue share they dominate, and their margins are estimated to be very good.
That hasn't happened with other devices or earlier iPhones that aren't as secure.
So?
I understand wanting to know people's motivations, from both the perspective of predicting future action and just because we're nosy monkeys. But frankly, what's in Cook's heart doesn't matter. Actions do. And to date, in my view, he's done pretty much exactly the right thing on this issue all along.
Maybe he's defending customer privacy because he believes the Lizard People have religious objections to invading until all humans have Freedom of Math. It doesn't simply matter.
The only way to secure the device against that would be to have the users manually memorize and key in a complete 128 bit encryption key, which they could then refuse to provide.
I think we tech folks were fooling ourselves with the idea that Apple had somehow delivered a "snoop-proof" device. They really didn't (no one can!) as long as they're subject to government or judicial control.
> possibly with the addition of a judicially compelled fingerprint scan or PIN brute force to get the encryption key out of whatever on-device escrow it's stored in
This is the whole problem. The keys are in the SE. You can't brute force the PIN because the SE rate-limits attempts (and that rate limiting cannot be overridden by an OS update because the SE is not run by the OS).
If you can get a fingerprint scan then all bets are obviously off, but then you don't need Apple at all.
Edit just to be clear: the requirement really is that the firmware be stored in a ROM somewhere, probably on the SoC. That's a lot of die space (code storing a fully crypto engine isn't small) to dedicate to this feature. Almost certainly what they did is put a bootstrap security engine in place that can validate external code loaded from storage. And if they did, that code can be swapped by the owner of the validation keys at will, breaking the security metaphor in question.
(FWIW: OTA firmware updates are routine in the industry. I've worked on such systems professionally, though not for Apple.)
https://twitter.com/JohnHedge/status/699882614212075520
The key thing would be for it to lose all stored keys on update when the current passphase has not been provided, and it sounds like that may not currently be the case.
Maybe in this case, Apple could comply, but a simple tweak would make it impossible in the future?
Die space is cheap nowadays, especially stuff that doesn't need to be on all the time because of the death of Dennard scaling.
I would not actually be shocked if they originally did wipe out stored info on firmware update, but had some issues with people updating their phone and losing everything, so they ifdef'd that particular bit out in the name of usability.
Well, yeah. But then you'd have a system that couldn't be updated in the field without destroying the customer data (i.e. you'd have a secure boot implementation that couldn't receive bug fixes at all).
It's a chicken and egg problem. You're handling the problem of the "iPhone" not being a 100% snoop-and-tamper-proof device by positing the existence of an "interior" snoop-and-tamper-proof device. But that doesn't work, because it's turtles all the way down.
Ultimately you have to get to a situation where there is a piece of hardware (hardware on a single chip, even) making this determination in a way that has to be 100% right from the instant the devices go out the door. And that's not impossible, but it's asking too much, sorry. We're never going to get that.
The enclave would store (in secured storage) a hash of the last used firmware. Hardware would have a hash update capability, but this destroys all other stored information (i.e., keys) if used when the enclave is not currently in an unlocked state.
On boot, hardware verifies firmware signature as usual but also compares the firmware hash (already calculated for the signature check) to the stored value. If there is a mismatch, update the stored hash. Since the enclave is currently locked, the hardware clears the keys.
Since it's in hardware, you're correct that it would have to be 100% right, but that's quite feasible for a simple update mechanism (indeed, the most complicated bits are reused pieces from the signature check which already has this requirement).
> A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 milliseconds. This means it would take more than 51⁄2 years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers
(Page 12 of https://www.apple.com/business/docs/iOS_Security_Guide.pdf).
Additionally you don't have to use your thumb, so if you don't know what body part was used your out of luck.
Is this true? That would have to mean that either the passphrase is stored on the device or that the data is not encrypted at rest. Neither of these sound likely, frankly
When a passcode is entered, the SoC queries the Secure Enclave with the passcode. If the passcode is correct, the Secure Enclave responds with the decryption key for the flash storage.
The best Apple could do is sign a malicious update to the Secure Enclave firmware that either removes the time delays or dumps the keys. However, some people suspect the SE erases its secrets on firmware update, although this behavior isn't documented in Apple's security reports.
Dumping the Secure Enclave would not result in the keys necessary to read the files on the filesystem. Each file has a unique key, which is wrapped by a class key, and for some classes, the class key is wrapped by a key derived from the passcode. If you don't have the passcode, you can't unwrap any of the keys (Page 12 of https://www.apple.com/business/docs/iOS_Security_Guide.pdf).
To my knowledge, all keys are still wrapped with the UID, and the UID is still a factory-burned SoC key (not accessible to any firmware). Possible to extract, but not easy to do at scale.
I would not be surprised at all that Apple's internal 'backdoor' (if you can call it that) is just resetting the security enclave, essentially erasing everything on the NAND. That'd be fine for refurb/manufacturing, desirable even as that guarantees that full system wipes happen before a refurb goes to a new customer.
Most ICs can be completely erased to remove the limitations on access, but this usually requires a 'mass erase', where the entire non-volatile memory is erased (taking any codes, passwords, and encryption keys with it).
source: I am an embedded software engineer who works with these settings in bootloaders and application software.
No, they can't. A quick update to recent hardware practices: modern SoCs like Apple's have something called "Secure Enclave Processor" that's on-die. This is the first thing to start when the chip is powered up, the thing that loads a cryptographically-signed bootloader, and the thing that gates a lot of IO with the outside world (like the NAND).
Hardware encryption on consumer hardware has existed for over a decade (look up Intel's TPM), and while it hasn't obviously taken hold on the more open Intel world, locked-down hardware platforms like Apple's top-to-bottom design has had much more liberty in implementing secure computing.
Furthermore, all debug/probing features can be disabled by fuses at the factory. The manufacturer can test the chip with those features on, and once verified, blow those fuses. No-one's JTAG-debugging that chip, not even Apple.
That said, Apple's focus on security and privacy ramped up in recent years. You want more secure, get more recent hardware. The downside, of course, is that if even Apple can't hack the software... neither can you.
However, without more information, this does not tell us whether it is possible in this case. The obvious implementation for a secure enclave resisting this sort of attack is to only allow key-preserving updates when already in unlocked state (which would be the case for any normal user update). All other cases should destroy the user keymat, even if the update is validly signed by Apple. This would be done by the hardware and/or previous firmware before it loaded the new firmware so you can't create an update that bypasses this step.
If this isn't how the secure enclave works now, I'll bet it will be in the next version (or update if possible).
I'm also confused by a lot of this since don't you need the password anyway to upgrade?
I bet if Apple is forced to comply with this order they will make sure that they will find a way to design the iPhone such that they physically can't comply with similar requests in the future.
Some people trot the argument that it's OK for the government to compel apple to deliver the backdoored firmware because the measures it would circumvent are not of cryptographic/information-theoretical nature.
Then one could expand that argument by saying that compelling physical reverse-engineering is also OK because the devices are not built to be physically impossible (read: laws of nature) to pry open.
Yes, they can. The particular phone in question is from before the Secure Enclave Processor
Tim's position today might not be apple's position tomorrow. Apple is a large publicly traded company. They owe a duty only to shareholders. Fighting this fight will probably impact the bottom line. Tim's continuation may turn on the outcome.
Cooperation may see Apple hurt. The perception of cooperation was part of RIM's fall from grace. Non-cooperation may also cause issues. Through it's various agencies, the US government is Apple's largest customer, as it is Microsoft's. Large contracts might be on the line should Apple not play ball. Either way, this order has probably wounded Apple.
That almost certainly isn't the case. It is doubtful whether any other government organization cares about how they handle this case. Heck the FBI likely doesn't care as long as Apple doesn't do anything illegal.
I'm having trouble finding numbers, but I seriously doubt this. The reason that's true (or more likely true) for Microsoft, is Windows. The US gov't has massive site licenses for Windows and most of MS's software portfolio. Apple is used where in the US government? Some cell phones? A few public affairs offices that convinced their purchasing officer to buy a Mac Pro for video editing? Maybe some labs that wanted a unixy OS and, again, convinced their purchasing officer to buy a Mac Pro?
Per: http://investor.apple.com/secfiling.cfm?filingid=1193125-14-...
The bulk of Apple's revenue comes from outside the US. Perhaps the US government is their largest single customer (I still hold this is a dubious claim), but it is not essential to their continued existence. They would do just fine without those sales.
But remember, iPhones and MacBooks are quite popular everywhere, including US government procurements (e.g., https://37prime.wordpress.com/2012/08/05/nasa-mars-science-l...).
Your characterization ("Maybe some labs that wanted a unixy OS and, again, convinced their purchasing officer to buy a Mac Pro?") is a little off -- where I work, MBP's for laptop replenishments are treated exactly the same way as Windows systems, you just tick a different button on the order form.
As in, improve it.
Tim Cook is probably more popular than Obama (and surely is WRT this issue.) Apple is about a thousand times more popular than the NSA and blessed with almost infinitely deep pockets and a very, very good marketing team.
Not to mention the fact that most of the people who use computers and phones don't even live in the USA.
Tim Cook is responsible to his BoD and shareholders.
In comparison, Apple had a net income of ~50B in 2015.
Let that sink in for a moment.
Because Freedom Markets(tm), booyah!
Society can bumble along just fine without corporations. Corporations serve society.
Take away society, with its culture, laws, rules, regulations, courts, people, economy, markets, capital, etc, there can be no corporations.
The Shareholder Fallacy http://www.salon.com/2012/04/04/the_shareholder_fallacy/
Historically, corporations were understood to be responsible to a complex web of constituencies, including employees, communities, society at large, suppliers and shareholders. But in the era of deregulation, the interests of shareholders began to trump all the others. How can we get corporations to recognize their responsibilities beyond this narrow focus? It begins in remembering that the philosophy of putting shareholder profits over all else is a matter of ideology which is not grounded in American law or tradition. In fact, it is no more than a dangerous fad.
The Myth of Profit Maximizing
“It is literally – literally – malfeasance for a corporation not to do everything it legally can to maximize its profits. That’s a corporation’s duty to its shareholders.”
Since this sentiment is so familiar, it may come as a surprise that it is factually incorrect: In reality, there is nothing in any U.S. statute, federal or state, that requires corporations to maximize their profits. More surprising still is that, in this instance, the untruth was not uttered as propaganda by a corporate lobbyist but presented as a fact of life by one of the leading lights of the Democratic Party’s progressive wing, Sen. Al Franken. Considering its source, Franken’s statement says less about the nature of a U.S. business corporation’s legal obligations – about which it simply misses the boat – than it does about the point to which laissez-faire ideology has wormed its way into the American mind.
Laws and statutes don't enforce contracts. But courts do. You are trumpeting a theory I've heard many times before. It's creators lack a basic understanding of contract law or corporate organization. :ookup "shareholder derivative actions".
I would assume that Google, Facebook, and Amazon are already sending every single keystroke we type straight to all the three letter agencies pretty much in real time. (I also assume the same about Apple, so I'm not sure what to make of this open letter.)
Please continue to think
They may be doing it for people right to privacy, but don't forget they might also be doing this because their image would become tainted irrevocably if they complied with this. Trust in Apple devices would be shattered (across those who currently trust Apple).
As long as we're on the topic of encryption, phones, and law enforcement it's worth keeping in mind that in the US at least courts can compel you to unlock your phone with Touch ID, even though they can't compel you to give them a password. Communicating a password is considered speech, so self-incriminating speech is protected by the fifth amendment. Physically holding your finger to a device is not considered speech and so it's not protected.
I think this is an interesting, and perhaps underappreciated, aspect of a shift from passwords to biometrics for verifying identity. It would shift the power dynamic between civilians and government a bit - here in the US at least.
Of course, hopefully no one is in a situation where they need to protect themselves against over-reaching or unjust government officials any time soon.
http://www.engadget.com/2014/10/31/court-rules-touch-id-is-n...
It's entirely possible, that the FBI can then use this precedent to simply have Apple remove all security from an iPhone in pursuit of an active investigation, which can be done with a straightforward firmware update - which IOS users tend to do without much thought.
A large percentage (and presumably the the target in question) will willingly (at least today) upgrade their iOS to whatever Apple pushes out - we don't (for the most part) even question whether the purpose of that security patch is to reduce security.
The only thing that secures an iPhone is the iOS following the rules of security such as the security enclave - it can just as easily (in a new release of iOS) be instructed to ignore it.
What Apple/Tim Cook are doing here, is standing up for the importance of not being required to hodge-podge be at the whims and mercies of police agencies that demand they do whatever is required of it.
This implies it is possible for Apple themselves to apply an iOS update to a locked phone in order to disable the erase-on-repeated-failure feature.
Tim Cook doesn't offer an opinion about how possible that might be. As a matter of principle, he doesn't believe that Apple should be forced to make the attempt.
That doesn't stop anyone else from doing so, however. And I suppose that the FBI could seek discovery on all requisite information, take depositions, etc, etc. However, I vaguely recall that discovery can't compel production of new work product. But maybe that's just a limitation in civil litigation.
It seems like their stand would be better saved for when a compromise is requested that is actually possible for them implement.
As Tim Cook says, it would be a bad precedent. And obviously bad PR for Apple to admit vulnerability.
It won't get unlocked by that, because as soon as the new iOS takes over, it will detect the activation lock and require the Apple ID password to be provided. Also, going through iTunes erases all the data.
But presumably a custom DFU update can only replace the OS without replacing the data. The iPhone doesn't try to protect against valid updates, and will happily run anything signed by Apple; the locked/unlocked state is only about the encrypted user data on the device.
Because the larger principle is what's really at play here. Whether Apple can do what the FBI asks, or not, is irrelevant. What is relevant is that what the FBI asks is bad. Even if Apple can unlock this phone because of shortcomings of the 5C (versus later model), it sets a bad precedent for later, especially if Apple truly cannot unlock the 6s and beyond ("you could do it on the 5, why not an iPhone 7?").
I'm no lawyer, but I'm of the opinion that this is a legal crowbar for later cases, and the Feds are using a tragic incident to drum up support ("you don't support terrorists, do you?")
I read it differently. Apple is saying that if they make this particular backdoor, then this very backdoor can also be used in other scenarios, to crack other phones (i.e. the backdoor would apply to all iPhones C, not just to this one).
It's massive, massive overreach - and if Apple doesn't draw the line here, it will quickly spin out of control.
[1] https://en.wikipedia.org/wiki/Communications_Assistance_for_...
In the past law enforcement could use their own tools and Apple didn't have any legal way to say "it is beyond our ability to break it so we can't help you" anyway. After their name showed up on that slide in the Prism leak without their cooperation (meaning they had been stepped around by the FBI. Some of the earlier companies had willingly volunteered data), they stepped up their game and deployed end-to-end encryption and secure enclave to have the ability to say 'we can't help' when forced to.
This technique wouldn't be possible on the iPhone 6 due to the encryption keys being in the hardware secure enclave but they are putting their foot down now so that a legal precedent isn't established forcing them to weaken other models too. That's my understanding of it right now.
I know it's a bit off topic but I'm really curious about this - do you have a source that shows which companies willingly volunteered data and which were stepped around? I wasn't aware that anything like that had come out.
You're not aware of nothing like that ever come out. The guy just made it up (or it's just his wishful thinking). We still don't know which companies cooperated with the NSA.
We do know that Google didn't intend for its traffic between data centers to be scooped up - and that has been fixed in the meantime - but that doesn't prove that Google didn't cooperate in other matters.
Same with Apple. For all we know, they are all gagged due to NSLs.
But Apple's letter uses the expression "technique", which I think means they're worried the government will get another court to make them change the serial number and sign a new image "next time". Before you know it, Apple will have to have an entire department to make these one-off images. Someone will say, "you know, you could save yourself a lot of time if you just made it work on any phone." Then that image will be leaked, and their security guarantees will be dead. (One might also worry about the DRM implications.)
"Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession."
Apple's argument isn't about a deluge of one-off court orders creating a slippery slope to reducing security. Apple is claiming that complying with just this one request would make Apple's other iPhone users significantly less secure. There would be a piece of software, signed by Apple, that could potentially be used to unlock any iPhone you have in your physical possession.
"Apple's reasonable technical assistance may include, but is not limited to: providing the FBI with a signed iPhone Software file, recovery bundle, or other Software Image File ("SIF") that can be loaded onto the SUBJECT DEVICE. The SIF will load and run from Random Access Memory and will not modify the iOS on the actual phone, the user data partition or system partition on the device's flash memory. The SIF will be coded by Apple with a unique identifier of the phone so that the SIF would only load and execute on the SUBJECT DEVICE."
How am I wrong?
"But Apple's letter uses the expression "technique", which I think means they're worried the government will get another court to make them change the serial number and sign a new image "next time""
Apple's letter directly claims that the particular piece of software created to comply with this request will reduce the security of it's users. Obviously this means that Apple does not think that the SIF being hardcoded with the unique identifier of the phone (sufficiently) mitigates the risk.
"make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control."
Having re-read the OP more carefully, I think ghshephard is making a different claim than you. He is pointing out Apple's arugment about the 'unprecedented use of the All Writs Act of 1789'. If Apple can be forced to compromise their security via court order like this, the FBI gains the power to force Apple and any other US company to insert backdoors / decrease security.
"If the government can use the All Writs Act to make it easier to unlock your iPhone, it would have the power to reach into anyone’s device to capture their data. The government could extend this breach of privacy and demand that Apple build surveillance software to intercept your messages, access your health records or financial data, track your location, or even access your phone’s microphone or camera without your knowledge."
You're wrong because any image that can be installed on the SUBJECT DEVICE can be modified to be installed on OTHER DEVICES.
> The implications of the government’s demands are chilling. If the government can use the All Writs Act to make it easier to unlock your iPhone, it would have the power to reach into anyone’s device to capture their data. The government could extend this breach of privacy and demand that Apple build surveillance software to intercept your messages, access your health records or financial data, track your location, or even access your phone’s microphone or camera without your knowledge.
Once there's a backdoor, the legal precedence and technical capability will exist to use it on any device. The precedence would also exist to request support in backdooring other parts of the OS.
It's FBI Director Comey's explicit goal[0] to destroy the notion of strongly secured encryption for civilians. From an an address to Congress July 2015:
> Thank you for the opportunity to testify today about the growing challenges to public safety and national security that have eroded our ability to obtain electronic information and evidence pursuant to a court order or warrant. We in law enforcement often refer to this problem as “Going Dark.”
[...]
> We would like to emphasize that the Going Dark problem is, at base, one of technological choices and capability. We are not asking to expand the government’s surveillance authority, but rather we are asking to ensure that we can continue to obtain electronic information and evidence pursuant to the legal authority that Congress has provided to us to keep America safe.
In other words, encryption makes it harder for the FBI to collect people's information. They therefore want to make sure encryption as implemented can't block the FBI.
Further on:
> The debate so far has been a challenging and highly charged discussion, but one that we believe is essential to have. This includes a productive and meaningful dialogue on how encryption as currently implemented poses real barriers to law enforcement’s ability to seek information in specific cases of possible national security threat.
[...]
> We should also continue to invest in developing tools, techniques, and capabilities designed to mitigate the increasing technical challenges associated with the Going Dark problem. In limited circumstances, this investment may help mitigate the risks posed in high priority national security or criminal cases, although it will most likely be unable to provide a timely or scalable solution in terms of addressing the full spectrum of public safety needs.
Encryption, when implemented in a way that legitimately secures a person's data from unauthorized access, the FBI can't just get in and take the data. Comey would like Congress to support policy and tools that can get around that, because terrorism.
The Apple situation feels very foot-in-door to me.
0: https://www.fbi.gov/news/testimony/going-dark-encryption-tec...
Additionaly, we simply don't know on what other (FISA) occasion Apple has been forced to provide feature X to agency Y where Y is not FBI...
DNSSEC has some value, and DANE does as well, but sadly both are stuck in a strange limbo. Pinning can be deployed now and add a huge amount of security. Even if we had DANE, we would still want to have pinning.
There are interesting ideas how you could scan the internet and it pins and publish this information in a secure way. Then you back this trusted site pin into your browser. Its a similar ideas like Certificat Transparancy. A browser could then load itself with all the needed pins or verfy them on demand. One could also get preloaded pins from a trusted party, or use network vision to check with many different parties on first use. Lots of options once everybody has TOFU.
This combination of Network Vision and TOFU would be quite nice and CA could be replaced, at least for non EV.
I see this as just another "its for the children" ploy, of which I'm completely sick of.
In that I fully support Apple/etc for finally gaining a backbone. If more people stood up, then I wouldn't have to be naked body scanned at the airport, or the dozens of other privacy invasions the government performs on a daily basis simply to give themselves something to do. So, rather than admit they won't ever be able to predict or protect the population in any meaningful way from random people willing to give their lives to make a statement, they waste our time and money coming up with ever more invasive ways to peek into everyone's most private possessions.
The irony is that most people are afraid to stand up (to body scanners, mass surveillance, etc.) because of threats of violence from their own government, which is in itself a form of terrorism.
"Now that the show is over, and we have jointly exercised our constitutional rights, we would like to leave you with one very important thought: Some time in the future, you may have the opportunity to serve as a juror in a censorship case or a so-called obscenity case. It would be wise to remember that the same people who would stop you from listening to Boards of Canada may be back next year to complain about a book, or even a TV program. If you can be told what you can see or read, then it follows that you can be told what to say or think. Defend your constitutionally protected rights - no one else will do it for you. Thank you."
In the UK, laws originally intended for surveilling terrorists were/are routinely used by local councils (similar to districts I think) to monitor whether citizens are putting the correct rubbish/recycling into the correct bin. [1]
This is a pandora's box, and the correct answer is not to debate whether we should open it just this once, it's to encase it in lead and throw it into the nearest volcano. Good on Apple for "wasting" shareholders money and standing up for this.
[1] http://www.telegraph.co.uk/news/uknews/3333366/Half-of-counc... - and lest the source be questioned, this is one of the more reactionary newspapers in the UK.
There can be no compromise because China, Syria and Turkey would also lean on Apple to break into phones of dissidents, and pretty soon, future whistleblowers here in US too in order to prevent leaks (iPhone 7 and iCar notwithstanding).
That's the tradeoff in not giving in to faint, vague "maybes" that there were "external coordination" when in all likihood it was the ultraconservative, Saudi half leading this duo into the kookooland of violent extremism.
The security services will just have to buy exploits, develop malware, cultivate human intelligence sources and monitor everything the old-fashioned way... It's not like that kid in a YouTube video finding a jailbreak exploit for an iPhone and not releasing a tool is going to sit on it, he's going to auction it off to the shop or country with the most $$$.
... backed by a company that at one point literally had more cash than the US government. A company with a strong, expansive, and experienced legal team. He's not a small fish; he's a major captain of industry and has a lot of political clout. I mean, good on him for his standing on this issue, but he wields a lot of power here.
I am quite disappointed that the us courts are trying to force apple todo this, and in my opinion, its just to use this case to set a precedent.
I hope Apple cant get it to work, but id hate to see what the courts would do if that happened.
[1] Sure, Apple only really sells hardware directly, but the software is a significant part of the reason a lot of people by Apple hardware (e.g. 'Mac's don't get viruses', 'iPhones have a better user experience').
[2] Sure, Google has some significant internal efforts for supporting better user privacy (e.g. https://googleonlinesecurity.blogspot.com/2014/12/an-update-... ) and Apple maintains some superb open-source software (e.g. http://llvm.org/ ). But in the end, Google can't be a "privacy company" without hurting their business model and Apple can't be an "open source company" for the same reason.
[3] Or the non-trivial inconvenience of being a self-hosting free software purist
One way to solve that would be to have governments support and subsidies open source software development, but I don't see that happening in the next 5 years at the very least.
There is something to be said about the market's ability to make decentralized decisions and focus on satisfying people wants[1], so a centralized software economy is also not a good solution. The problem with markets here is that strong privacy and open source are, for the most part, positive externalities. As a user, the benefit you get from having strong privacy yourself is not usually noticeably high, nor that of having access to the source, specially for a non-technical user, yet society arguably benefits from both. Usually the answer to a problem of unaccounted externalities is government regulation, but in this case, large-enough-to-matter governments have been unanimously on the side of less privacy, rather than more (as is the case of the original article).
[1] Ideally, software should be designed so that it preserves privacy as much as possible while achieving its function, and is open source, and it provides all the million features and reasons people use something like Facebook, Snapchat, Youtube, etc. Just having privacy preserving software written for and by technophiles is not and can never be a complete solution.
http://blog.quickpeople.co.uk/2013/05/17/the-uk-government-p...
(Which does not invalidate your point one way or the other.)
The future, in fact, belongs to this third business model that helps a business earn profits without hurting its users in any manner. Ultimately, all the IT companies will have to embrace this model in order to stay in the market and survive. Competition will ensure that they will.
Two example disadvantages:
1) As it is, support and customization for specific non-technical paying users are among the things many top engineers least like to do. The reason being that it takes away from time solving the problems of the large mass of non-paying users. Even under the support & customization model versus the proprietary model, the number of paying users is much smaller in the first case in general, which creates a smaller "high priority" class of users.
2) Certain features and applications, such as traffic-aware maps or voice recognition engines are easy to build by huge centralized organizations which hold all the necessary data. They are challenging things to implement for loose collectives of smaller software companies, specially in a privacy-aware way.
Could someone answer a question I have though? The government wants Apple to create this backdoor and tailor it to the specific device, so presumably it will have a line that goes
if (!deviceID.equals("san_b_device_id"))
return;
To make the backdoor general purpose, this line would need to be removed. But doing so would invalidate the signature and it can't be resigned afterwards because the attacker won't have Apple's signing key. So is the open letter a matter of principle that they won't build any backdoor, now or in the future, rather than a specific concern about this backdoor?If they do it once, they'll do it again.
2) If they beat the order then the FBI needs to find a new way to compel Apple to help them do shit. That likely means the FBI needs federal legislation passed, which in the current climate will buy Apple considerable time. This is why they want to beat the order (though the feds could further appeal all the way to the.... wait for it.... 8 judge supreme court!) Though I think Scalia would have be on our side on this one). It's not about this particular case since there will be others, it's not about this particular order since there will eventually be legislation.
3) So why go ahead and do it anyways? Naive (but still valid) reason: they happen to be able to help and without it being ordered they can do it without handing over a tool for ad hoc decryption. They can even go to Hawaii after and throw the dev machines into a volcano to satisfy their inner hobbit (I highly recommend this part of the plan) to ensure that no one can abuse the power of the one ring.
The non-naive answer is that for a quick project they get to show to the public that no, we the nerds are not so obsessed with abstract systems level thinking that we won't help when we can. It gets a lot harder for that moron Comey to hit the morning shows and throw shitty innuendo at the tech industry implying that we're aiding the terrorists.
Both encryption and terrorism are complicated subjects that are scary to the average American and although they distrust the government, they also distrust Silicon Valley. The cryptowars aren't about being right or they'd have stayed dead in the 90s where they belong. Basically Apple makes tech look like the good guy fighting terrorism, and for anyone who cares (smaller audience than the fighting terrorism bit) they also defended your civil liberties.
4) This trick only works on older devices. They will die out soon anyways. Newer devices are safe anyways. If they beat the order and do this one case voluntarily then no precedent is set, so they can't be bullied into doing it and old devices are safe.
One device compromised, all other devices safe, order beat, PR win, Comey looks like a prick even to the uninformed next time he insinuates that we're the enemy.
If you crack the encryption once you'll get orders to crack it again and again, and in much lower profile and lower stake cases. Look at the prevalence of espionage tactics such as Stingrays and "parallel construction" by law enforcement. There may not always be someone you can pump up into an crack international terrorist, but there's always some low level drug courier, or a "quality of life" criminal to use your new toys on.
Also you're saying hat this doesn't set a precedent, but it does. Sure there's not a court case to point to, but it's a precedent none the less. It's that the company not only has the means, but the will to do it. What's stopping the government from coming back a second time, or a third time about this? What argument do you have on either a legal court or the court of public opinion to make when you stand up and say, "That first time was an exigent situation, and so was the second, and the third... But this time, the fourteenth time, THIS TIME we really mean no more!"
Finally, I don't think this trick only works on older devices. The FBI wants them to be able to brute force the passcode through a USB connection instead of making some sort of robot to tap the screen a bunch of times. Also presumably the FBI wants the the two many incorrect attempts lockout feature disabled as well, otherwise their just going to be waiting for hours on end. Why wouldn't this rather low sophistication approach work? from a technical stand point this is no more complicated than a mouse jiggler[0]. Of you're arguing that iPhone 6=< have some sort of "Mission: Impossible" self destruct mechanism, I'm sure it could be disabled given enough resources and motivation.
Finally (for real this time!), making a big stink and then capitulating is never a PR win. You just look like a tool to everyone involved. To the anti-encryption side you're a weak and can be rolled, and to the pro-encryption side you're a sell out.
[0] https://www.elie.net/blog/security/what-tools-do-the-fbi-use...
I doubt there's even anything on the phone the FBI don't have from other sources. The reason they're using the All Writs Act with this case is because of the publicity of the case so they can point to Apple prioritizing some vague principle most people don't care about over real dead people. Apple's doing a good job making their argument to those who care about said vague principle, but not to the general public.
I think you're underestimating how badly we're going to be taken to the woodshed on this the first time it's opportune. My be it it'll be some cute little girl dies in a Nancy Grace friendly way and the FBI manages to convince the public that "if only we could have broken these messages" etc. It might even be true in that one freak instance, but then we'll have "[cute_little_girl.name]'s Law" which will make sure that such a tragedy never gets exploi.... reported again, by making sure that the government can read messages when they need to. The US market is too large not to capitulate at that point. That bill passes if the voting public can be stirred up against the greedy and aloof tech sector. It doesn't pass if they see the tech sector and its goals as reasonable, and while we should continue trying to educate people on why encryption is good and important for them, you don't change the number of minds we need to change with rational arguments (or again, we'd have won already).
Edit: very interesting link on the mouse jiggler though, thanks for that!
Choice quote: "Apple will become the phone of choice for the pedophile"
The iPhone 5S and newer has a coprocessor (or co-computer) that has a hardware enforced rate limiter as part of one of the features of the "Secure Enclave" (which, word on the street is, cannot be overridden by software).
EDIT: It's not just physical access. Physical access chains the game entirely, but what the FBI is wanting highlights the physical access problem even more. They're wanting a custom software solution today, but there's nothing to say they can't want a custom hardware solution tomorrow. Sure the enclave has some sort of lock out now but who is to say you can't simply reflash the firmware or perhaps just solder in some jumpers? Make no mistake. The FBI is wanting manufacturers to modify devices on demand.
Or the ID on the device be changed to match "san_b_device_id".
Then it becomes a precedent in the courts that Apple has this ability so they will issue court orders to make them comply for every single case where a phone is encrypted.
However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode).
The amount of work needed to turn security into good user experience is phenomenal: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
[1] - http://i2.wp.com/ioshacker.com/wp-content/uploads/2014/09/Pa...
"Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession."
Am I reading this right? Apple, if they chose to, can make a version of iOS that disables security features and encryption and load it onto existing phone even though the phone is locked and encrypted?
As I understand it, the FBI wants Apple to create a version of iOS that would disable the current feature where the data is deleted after more than 10 failed passwords attempts. This would allow the FBI to brute force the password.
That being said, I really WANT the data in this case. I hope Apple finds a compromise where they can help get this specific data without risking leaking a compromised OS.
I want pharmaceuticals without side effects, and real doughnuts that don't make you fat.
Seriously, you are asking for "A" and "not-A" in one sentence. Take your pick. Are you willing to get this one phone unlocked so badly that you would be OK with nobody having security? Because that's what you're asking for, whether you realize it or not.
Perhaps you are trying to disagree with a point by conflating it.
Potentially, Apple cannot circumvent their own protections on some models (in software anyway), and could in others.
There are many ways to redo the firmware, but every single one of them, by design, requires wiping the phone to implement.
There is no way that a backdoor like this could not be exploited by someone else if they found out the way to do it.
The other one is that there is no way the government can guarantee Apple to only use in the "right" cases after they have access to it.
For existing devices I imagine that a hypothetical iOSX which removes the protections would require you to enter your passcode so the OS can decrypt the data and then re-encrypt them using the new backdoored option.
See https://www.theiphonewiki.com/wiki/DFU_Mode
Not same thing as an OS update.
I wish more companies could speak so clearly and courageously.
Where is this stated so that I can claim damages if they break said promise.
I'm sorry, but how can it not be seen that it a really is bad sign that Apple has made this public. They may already have built the backdoor and this is a public stunt or no matter what you do, owning a smart is not that smart.
The court order gives Apple an out: "To the extent that Apple believes that compliance with this Order would be unreasonably burdensome, it may make an application to this Court for relief".
Now, imagine if this was court ordering a company to engage in unethical medical procedures, rather than unethical software development. The professional medical community would sanction doctors that cooperated and support those that stood by their ethical principles and refused to cooperate. If there was a similar professional organization for software development, Apple could reasonably rebut that telling their engineers to work on this would be unreasonably expensive (since they'd expect to fire people or have them resign over it).
This is another avenue for fighting the order - have a good chunk of Apple's engineering department sign an open letter saying that they'd resign before working on that project. The incentives seem like they'd work for making it a thing.
The problem with this is that no such tool should be possible to build. It should not be a matter of yes or no; it should be simply impossible for Apple to build such a tool without the private key of the user, which Apple does not have.
If it is possible to write a piece of software which can circumvent the protections of the iPhone without the user's private key, then Apple wrote its security software incorrectly. Either they wrote it with an appalling lack of security understanding; or they left in important backdoors, either knowingly or through ignorance. But if they wrote the software correctly and did not create backdoors of which they're aware, then the government's request is actually impossible -- cannot be done.
So which is it, Apple? Is the point moot because you did this right? Or have you already placed backdoors in the product which the FBI is now asking you to exploit for their benefit?
If you have a very strong passphrase (not a 6-digit code) then even that should be unbreakable even with brute force. Of course, most users have the 6 digit code.
If you read the actual court order a lot of your questions are answered. Here: https://www.techdirt.com/articles/20160216/17393733617/no-ju...
Also, the phone is an iPhone 5c. This doesn't have Touch ID and doesn't have the secure enclave. The same approach would not even be possible wouldn't even work on a 6 or 6s. http://blog.trailofbits.com/2016/02/17/apple-can-comply-with...
If this is possible without the owner's permission, then the update mechanism is the existing backdoor. It just happens to also be the front door.
The iPhone in question is protected with an unknown passcode. Auto erase is enabled, so brute-forcing the passcode will erase the data.
However, a new OS version without auto erase and that accepts passcode input from USB would allow the FBI to try all combinations.
How is Apple at fault because most any passcode scheme can be cracked via brute-forcing all comginations?
It shouldn't be possible to just add a new OS onto the phone without the restrictions in place, without knowing the passcode first.
Making a new OS is just the easiest way for Apple to do this; there are other ways.
Highly ironically, the current "Error 53" hullabaloo is exactly about what happens once security it tightened to the extreme.
This is the only way that their claims might possibly be valid.
And a reminder, then: change your iPhone's password to a more complex one. If apple doesn't make this fake OS, someone will.
Edit: to expand on this, Apple's PR goal was to take advantage of the NSA mass surveillance scare. On-device encryption is not very relevant to that. iCloud security is much more important, and they've been quietly granting data from it to the Feds. Including iPhone backups which contain most of the data they're looking for.
> Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation.
> The FBI is asking that it be built now
Because it's not possible _now_.
> and then loaded onto the already recovered phone.
Thus it becoming possible after they have built the new version of iOS, and since they cannot go back in time and build it, it would indeed be _in_the_future_ that it became available, if Apple complied, that is.
Hence the parent post's suggestion that the argument is moot -- if Apple has the capability to retrospectively backdoor existing phones it would imply that Apple didn't secure it in a foolproof way in the first place.
The phone in question, however, is an iPhone 5c, which does not have a Secure Enclave.
It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy.
They are just exploiting that competitive advantage.
Cfr. https://ar.al/notes/apple-vs-google-on-privacy-a-tale-of-abs...
And honestly I don't mind if my digital rights are defended as an advertisment.
Seems to me both of those things are worthy of respect in today's society.
The reason why this doesn't happen with Android is much more mundane: most Android phones are not encrypted so the FBI doesn't need help to read all the customer data. They just need to open the phone and dump the flash.
Ruby on Rails is open source but that doesn't mean that all applications on rails are open source.
That will certainly change quite soon. In the earlier days, FOSS was not a concept that masses were aware of, but now is different. There is increasing competition in the smart-phone world and if one of the other manufacturers (say ASUS) makes their Android modifications open-source, they will see a drastic increase in Sales. To keep up with competition, Samsung, etc. will also have to do the same. In other words, competition will ensure the success of open source.
Can you expand on this? I don't think enough people care about source access. RMS's exact hardware choices don't go on to sell millions.
edit: I didn't see your username before now.
Compare and contrast with today's "Typo in PHP's Mersenne Twister" story - https://twitter.com/i0n1c/status/699860681487708160
Seems to have been broken since 2007 (the 'broken' line appears in the 2007-01-01 commit "Bump year" but not in the 2006-10-06 commit "Mark rand.c functions with U.")
We as consumers should support the companies that have the best, in terms of product usability as well business ethic, market strategy by buying said companys product and recommending and commending their actions.
So props to Apple for leading an ethical business strategy.
... and that's what I paid them for, thanks for not taking money both from me and from FBI :)
Personally I think this is ridiculous.
If Tim Cook was born in a range of other countries around the world he would be persecuted and quite likely killed (and not in a pretty way). As such I am sure he is very aware that for many people their privacy is a life and death matter.
Also there would be many people at Apple who would've been dealing with China's aggressive attacks against their users and their own infrastructure and not be too pleased. And to a lesser extent their own government.
I can't imagine the extra few billion that comes from goodwill being a major factor in their efforts to go to all of this trouble.
Apple are a company so they'd be stupid to not take advantage of this and as a consumer I am happy that the premium I pay for Apple products is benefiting me.
So, is Apple defending rights while advertising, or advertising while defending rights?
That story, by the way, is really nice. ;-)
So there is already a backdoor. Apple are refusing to let the FBI use the backdoor.
The backdoor is the fact that Apple can push a firmware update that disables security features, without the device's password being entered at any point.
Apple is selling devices on the whole planet, not just in the USA. So, what's the FBI (an American agency) is requesting is not dangerous for only American citizen, but also for iPhones' owners in Europe, Asia, Africa, Oceania. Hell, these people are not even part of the debate, because they don't belong in the "American democracy".
If I'm going to be affected by someone else's policies, I would like to be at least allowed in the discussion.
If this goes through I just expect more people internationally to choose something else. Not a big loss to them, but the loss of business to Apple (a US company) might be felt.
By publicly committing Apple to this cause, Cook makes it more likely that internal teams at Apple as well as future versions of the company will adhere to this position. By defining a set of actions which, if made public, would ruin the company's brand, Cook makes it less likely Apple will take those actions.
Nilay Patel over at The Verge said on one of their podcasts he once asked Satya Nadella what it was like to be the CEO of a company as large as Microsoft. Nadella told him being CEO meant telling a big-picture vision to the press and the company over and over again until everyone started going in that direction.
Apple built hardware which was not particularly secure. The software defaults to a four-digit PIN. They attempt to mitigate this by adding an escalating interval between entries, and by optionally wiping the phone after too many failed tries, but this is not set in stone and those limits can be removed with a software update.
The government is coming to Apple and saying, "You can remove these limits. Do that for us on this phone." Coming as a legitimate court order, I see no problem with this request. The government isn't even asking them to crack the phone, they just want Apple to remove the limits so the government can try to brute force it. They're even paying Apple for their trouble.
If Apple didn't want to be put in a position where the government can ask them to compromise their users' privacy, they should have built hardware which even they couldn't crack. And of course they did; starting with the A7 CPUs, the "secure enclave" system prevents even Apple from bypassing these limits. The phone in question just happens to predate that change.
If the government was demanding that Apple do the impossible, I'd be on their side. If the government was demanding that Apple stop manufacturing secure phones, I'd be on their side. But here, all they're asking is for a bit of help to crack an insecure system. They're doing this in the open, with a court order. What's the problem?
Do you want such a tool (the one the removes the security of updating) to exist so that anyone with physical access can replace the OS with something else?
I don't understand what you're getting at with the "tool" question. Nobody's talking about building something that lets anyone with physical access replace the OS. The phone's secure boot system will still require updates to be signed by Apple. Apple can replace the OS with physical access. On older hardware, it seems they can do this without wiping the data. Do I want Apple to be able to do this? It doesn't matter what I want, the fact is that they can. Since they can, and since the FBI has a court order, I don't see what's wrong with requiring them to do so. If you don't want them doing this to your phone, buy a newer one with the more secure hardware.
Well this exact thing isn't THAT big of a deal but it's a slippery slope. If Apple agreed to this then what else can the government ask them to do under the banner of "public safety"? And if Apple were to give the government an electronic way to brute force the touch codes, it would break the trust of every iPhone owner.
Giving the government a way to brute force PINs wouldn't break the trust of every iPhone owner, merely the owners of iPhones with pre-A7 CPUs. And great, if they trusted Apple on this their trust was misplaced. You can't trust companies not to unlock stuff when the government requests it with a legitimate court order. If you want Apple not to decrypt your data, the only way to ensure that is to make it so they can't.
Again, Apple has (so far as we know) made it so they can't, on newer hardware. But this phone that the FBI is trying to get into is older hardware and built such that Apple can get into it. If you're looking to point fingers, blame Apple for building not terribly secure hardware. But don't point fingers too hard, because they're doing it a lot better now.
It is possible for Apple to the weaken the secure enclave on all future iPhones. It would be reasonable to do so from the point of view of giving law enforcement a useful tool. Therefore since Apple can be ordered to do engineering to make law enforcement easier, why should they not be ordered to do this?
That is the slippery slope.
How does that at all follow? Right now, a cop can lawfully order me to identify myself. Does that mean they can also lawfully order me to go to the nearest coffee shop dressed as Bozo the Clown and shout, "I am in love with the ghost of Princess Diana"?
I don't understand how complying with an order to use an existing security hole to break into in someone's device somehow sets a precedent that the FBI can in the future go to Apple and set the parameters for how their products are designed.
Explained better by someone else here: https://news.ycombinator.com/item?id=11120036
But I'm not sure that distinction is important. The other comment you linked to lays it out pretty nicely and it doesn't rely on a hole existing it being created. It's ultimately just about compelling creation.
I wonder, what if the FBI just requested the relevant signing keys and source code? That seems like a much worse outcome, but at the same time less of a reach.
Apple seems to be saying that if the FBI can ask Apple to install special software on one person's phone, then they can ask Apple to install special software on everyone's phone. But that's not how it works. The whole idea of requiring a court order is to only do this stuff on a limit scale when there's justification for it. It's like saying that the police shouldn't be able to have a warrant to search a suspect's house, because that means they could search everyone's house.
Apple is saying the FBI is using this law to expand their power to mandate a backdoor in all devices. If this is successful, then the FBI can mandate that all secure hardware/software companies backdoor their products.
Do we roll over and let the FBI do this because "oh, this is just one case, it's fine" or do we set a boundary? If a child does something wrong, you scold them immediately. You don't wait for them to do it the 10th time. By then it's too late.
I simply don't see the leap from "this device is insecure, pleas unlock it for us" to "all devices you make must be insecure."
If this goes through, you better believe that there will be court orders left and right, which can't be authentically argued against since Apple has already done it before.
If there are legitimate court orders for cracking the security on the phones of criminal suspects, I don't have a problem with that.
The problem would be if:
1. A court orders Apple to crack the security on a phone they cannot actually crack (presumably any A7+ phone), and imposes some punishment for failing to do the impossible.
2. A court orders Apple to modify the design of their phones to make sure they are always crackable.
Those would be huge problems. But I don't see how you get from here to there.
The government would never have access to a phone with a compromised version of an OS that they could use to repeat this trick. Rather, the government would have to obtain court orders and have forensics done under supervision.
This isn't a backdoor and doesn't affect consumers, and sets a really high bar to trying to scale this for the government because it requires Apple as the gatekeeper every time to agree to do the one-off hack.
The cynic in me thinks that this letter is more about brand image. Apple wants to claim they can't hack their own phones, even if the government asks, but clearly in the case of the iPhone 5C it IS possible for them to do it, and this creates a contradiction with their public marketing and privacy position. If they didn't release this open letter, then simply complying with the judges order would make them look bad.
2) The strong precedent will be set that governments can get whatever they want from our devices by whatever means necessary, and it will only get worse.
2) the government doesn't need to have access to the firmware for it to become dangerous, the sheer fact that this can be created is dangerous. What's to stop a determined, hacker from doing the same thing in the confines of his/her bedroom once it's confirmed that this is possible?
That's not a problem at all. The issue is how the existence of the tool affects warrantless access.
Where did we get the idea that it's bad in itself for law enforcement agencies to be able to break crypto when they have a warrant?
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
Upon probable cause, the government may issue warrants. The US government, backed by the people of the United States, have a right to compel a private corporation to comply with reasonable searches and seizures on probable cause with a warrant.
The government is not asking Apple to deploy nuclear weapons, nor ship all iPhones with a hack. They are specifically asking for help with one vulnerable phone, an iPhone 5C. They may be asked to do this multiple times, but they can keep whatever engineers and tools they use internally private.
I mean, let's get real for a second. The toolchain already exists. Apple has the source code, hardware simulators, debugging harnesses, and the original engineers. There's no magic. As long as those things exist, the danger of a hack getting public is real, especially if the source for iOS is ever stolen, or one of the core engineers goes rogue. If Apple's own internal security can't keep a more polished tool under wraps, they won't be able to keep the subcomponents of it under wraps.
There's a reasonable middle ground between "government has a backdoor and can scan and read everything" and "it's impossible for the government to even obtain legal warrants on probable cause for a very targeted piece of information" What's being discussed in this case is not Snowden-level drag-net snooping. We're not even talking about a wire-tap. We're literally talking about the government finding a Safe/Vault inside the house of a murderer, and talking to the manufacturer of the Safe/Vault to get them to pick the lock without destroying the evidence inside. The Vault-maker in this scenario doesn't even have to give over the blueprints of the proprietary lock mechanism, they just need to open this one vault.
>As long as those things exist This is false. Apple could hand you all the things you mentioned and you still wouldn't be able to break an iPhone 5C. You would still need Apple's master private encryption key.
As you are framing the question, is, the government should force Apple to hand over their private encryption keys. If thats so, should citizens in other countries be wary of the fact that their data stored in Apple servers are privy to the US govt? Or should Americans be worried that China can coerce Apple to hand over encryption keys?
In terms of global politics, The vault maker in this scenario has to worry about other strong men asking for such a master key when they need to hunt down gay men or something as trivial, once they realize this is possible.
In a paperless world, and unbreakable encryption, what is the point of warrants or regulations at all?
If a company that say, committed crimes, financial or criminal, has a warrant served on them, what if the response is, "Hey, we'd love to give you our emails, but all employees use end to end encryption, and every desktop has unbreakable filesystem crypto, and our IT department can't unlock anything, so you must compel the users to hand over keys?"
Can that be a defense against all warrants and crimes? If politicians are suspected of accepting bribes with strong probable cause, do we simply accept that their phones and email communications with lobbyists and corrupt bribers can't be accessed?
What does society resort to then, rubber hose cryptanalysis? Imprisonment on lack of evidence until they turn over the keys?
Transparent democracy is on a crash course with cryptoanarchy. The same people who are chanting for absolute unbreakable cryptography are some of the same people supporting Bernie Sanders and would rail against offshore Cayman or swiss financial obfuscation by the mega rich.
If we want non-corrupt government and industry, we need a way to investigate serious crimes. In the past, this meant seizing papers, letters, and records under warrant. Nowadays, it may be possible for the entire digital crime trail to be unbreakable with no recourse except catching people in the act. However, when the FBI entraps people with sting operations "in the act", civil libertarians decry that too.
So how do we police the bad? If you look at many third world countries with trouble advancing, a lot of is due to corruption. Is the danger of the government subpoenaing your email worse than the danger of tens of thousands of corrupt businesses spreading financial risk all over the economy and political system?
Are you an American or Foreign? In the American constitution, the 5th amendment, legally protects a party from being forced to incriminate one self. So if you are still alive, and slapped with a warrant, your rights protect you from giving up your private key.
Consider the various ways to police crime:
1: Before the fact, preemptively. Active surveillance and-or entrapment. Widely criticized.
2. After the fact, forensic analysis. Previously, physical evidence collected, warrants for documents. In digital realm, foiled by cryptography. Attempts by government to restore status quo to pre-digital capabilities widely criticized.
3. Compulsion. Prosecutors lean hard on individuals with digital evidence to turn over materials. Runs afoul of 5th amendment and civil libertarians.
At least for many types of crime, especially white collar crime, this leaves the authorities almost no recourse. Your politicians can communicate securely with their paymasters, and receive untraceable payments over bitcoin. Although you may find HUMINT witnesses who can give you probable cause, there may be no way to obtain real evidence.
The Silk Road founder was only caught because of active surveillance, literally caught him with his computer unlocked. This would be like waiting for the San Bernardino killers to unlock their iPhone, and them seizing it before the auto-timer relocked the screen. Not exactly possible for all types of crimes.
Is active physical surveillance of suspects by the state any less creepy than digital warrants?
The cynic in me agrees. My cynic also notes the sudden indifference to corporate power publicly defying a federal judge. I cynically believe that if the shooters had been fundy white supremacists Apple would have quietly dumped the phone long ago.
Cook is no dummy and picks his battles with care. That's why he makes the big bucks.
0) Find some errata. Apple presumably knows as much as anyone except NSA. Have plausible deniability/parallel construction.
1) OS level issues, glitching, etc. if the device is powered on (likely not the case). Power stuff seems like a particularly profitable attack on these devices.
2) Get Apple, using their special Apple key, to run a special ramdisk to run "decrypt" without the "10 tries" limit. Still limited by the ~80ms compute time in hardware for each try.
(vs. an iPhone 5S/6/6S with the Secure Enclave:)
3) Using fairly standard hardware QA/test things (at least chip-level shops; there are tens/hundreds in the world who can do this), extract the hardware key. Run a massively parallel cluster to brute force a bunch of passphrases and this hw key, in parallel. I'd bet the jihadizen is using a shortish weak passphrase, but we can do 8-10 character passphrases, too. They may have info about his other passphrases from other sources which could be useful.
While I'm morally against the existence of #3, I'm enough of a horrible person, as well as interested in the technical challenge of #3, that I'd be willing to do it for $25mm, as long as I got to do it openly and retained ownership. In secret one-off, $100mm. I'd then spend most of the profits on building a system which I couldn't break in this way.
- lightning cable delivered iOS patch (probably won't work because iOS won't negotiate over USB until you tap a dialog box)
- OTA update (not connected to internet)
- Cracking open the device and accessing the storage directly (encrypted until boot time)
The most likely vector I can think of:
- - Lightning cable delivered iOS patch from a trusted computer (i.e one that the terrorists actually owned)
It's quite impressive that Apple is taking a stand like this, though perhaps unfortunate timing WRT the larger encryption debate.
Effectively, the government is forcing Apple to take receipt of a device that it does not own or posses, then perform potentially destructive services on a device, and then perform services that could potentially require Apple to testify at a trial under the Confrontation Clause of the Sixth Amendment.
I really think that Apple's in the clear here, and the AUSA's in the case are pulling all the stops to get Apple ordered to break the encryption.
What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.
Quite likely.
As I posted on the other discussion here: https://news.ycombinator.com/item?id=11116343
> If it's possible to make such a "backdoored" build of iOS, then there are state actors who will be throwing $Millions at doing it already, with or without any willing help from Apple.
I guess what the FBI wants is a backdoored iOS version and to have Apple sign it with their signing key (which means that the FBI can use it over and over again).
For instance, signing keys can and have been stolen, on the principle of "if you can't brute-force it, hack in and take it".
http://arstechnica.com/security/2013/02/cooks-steal-security...
http://blogs.adobe.com/security/2012/09/inappropriate-use-of...
http://www.androidauthority.com/ssl-added-removed-google-moc...
http://arstechnica.co.uk/tech-policy/2016/02/its-legal-for-g...
I assume that Apple has a hardware security module for key generation and storage, perhaps even custom-designed and built, to prevent key extraction/copying.
Of course, in the end you have to trust Apple that only a limited number of employees have access to such hardware, that they have proper auditing procedures, etc.
But the probability of a compromise can never be 0, unless you design and produce your hardware yourself, write all code that this hardware runs yourself, and never leave your computing device unattended. Since that is not practical for most people, you have to put trust in some third party.
"The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer."
Can a private, for profit, company deny the will of an elected government working to solve a heinous crime based not on what they say they will do but because they cannot give a 100% guarantee that this is the only time/way it'll be used? Apple acknowledges that the government is saying it's limited to this case but because there's no guarantee (100% certainty) they feel they can deny it?
If yes, what does that mean as a broader precedent. Are we comfortable with private companies denying an elected government based not on what they agree to, but instead because there's a chance it'll be used in other ways?
As terribly flawed one might feel about government very few would think it has less accountability than a private company.
But Apple isn't saying they wont do it. They just want to make it really clear that they're not happy about it and they want the government to change their mind.
The government still has a monopoly on the legitimate use of force.
I read into that that they are in fact fighting this? And I agree, I think it's great that Apple is forcing this discussion into the public domain. These are key issues for us all.
They may already have this in place now, but what we are seeing now is a show. They are testing how people/consumers are going to react to this situation. Out government probably figures that nobody will care in the end.
In the USA, we have lost our liberty. It's time to wake up and see what is happening. It's getting worse & the people within our government are working hard to enslave us even more.
This particular hill that Tim Cook has decided to defend is as important as anything Steve Jobs ever did at Apple.
I would agree with Apple if they wanted FBI to pre-submit all their guessed passcodes for brute force for apple to try, and for apple to have the sole responsibility for that, so that getting said "backdoor" (which really is nothing more than a door handle) will be as hard as getting their private keys, and governments will not keep the said backdoor in their hands. I would also agree if Apple claimed they don't want to be able to crack devices at a judge's order (although that would be against the law - so they can't claim that).
But this is NOT what Apple said. This whole letter is just one big PR bulshit. They CAN brute force a passcode. They failed enforcing significant delay incurred when failing a passcode attempt - even tho this issue was already known for YEARS (will give citation if needed) when apple designed the discussed iPhone 5C - and they also failed requiring passcode to update the device. They already have their convenient backdoor in place in the form of their private keys.
Thank you! This is the most important technical point about this whole thing. All the talking about the SE (fascinating as it may be) is irrelevant. All strong crypto that is based on a private key being kept in a secure vault at some corporation does have a backdoor. The keeper of the key can be compelled to use it to sign something.
This is exactly why this would be such a dangerous precedent. Government giving software specifications that are signed with a vendors public key. In this case, it's a one off but it's a step into the direction of "upload a screen-shot of the phone's display every minute to ftp.nsa.gov with your next iOS update". And no SecureEnclave will protect against that. It will just be a OS update signed by Apple.
This is a very clearly political refusal. Apple is saying that about as explicitly as they can in this message. Whether or not they can do it, Apple doesn't want to be caught in the game of being a government surrogate or having to determine for themselves if government requests are legitimate (imagine, say, if the Chinese government asked for data from a dissident's phone - would Apple want to risk that market by denying a request that they have complied with in the US?). It's unfortunate for them that the FBI is making this request while people still own phones like the 5c for which they could theoretically disable security features, as opposed to the newer phones which it is possible they are completely unable to defeat.
How? Wouldn't the FBI reverse engineer it?
It seems like apple would have to update all phones to a new version (which would prevent the exploit provided to the FBI) before handing it to them.
Edit: see, for example, here: https://stratechery.com/2016/apple-versus-the-fbi-understand...
If they cannot co-exist, I'd rather have more security and less privacy. But ideally, I shouldn't have to choose between them.
If you have information about something you're planning that harms my personal security, there's always going to be a necessary tradeoff between your privacy and my security.
(Edit: deleted part where I was wrong. Thanks robbiet480 for correcting me. It's 2am here and I was tired.)
Also, prediction: if Apple refuses to build a brute forcer, someone else will do it and sell it to the FBI. Just wait and watch.
Just made a downvoted to death comment on this very same thing. This is literally a government creating a market situation.
In addition, there is a setting on all iPhones to erase data after 10 failed pin code entry attempts.
The FBI wants Apple to provide a custom iOS build that can be installed on the device that allows for remote (over the network) brute forcing with the increasing timeout/erase data protections totally disabled.
https://www.whitehouse.gov/contact
Here is my letter to them:
Dear President Obama,
I've voted for you in both elections, and have been a firm supporter on all your causes (affordable care act, and more). However, your FBI has clearly overstepped it's authority by demanding that Apple spend engineering resources building a software product that can break the encryption of a terrorist's iPhone.
Seriously, you need to stop this. You are the head of the executive branch of the government, of which the FBI is directly underneath your jurisdiction. Director James Comey is directly within your chain of command.
What the FBI is asking for is a master key to be created that can decrypt any iPhone. This makes all Americans with Apple devices insecure in the face of threats to our personal security and privacy. I hope you can understand that this is clearly unacceptable, and needs to be stopped.
I want to register my complete opposition to the FBI in this circumstance. Please stop this.
Thanks, xxxx
You don't need to tell the man what he can do in his capacity as president, he knows what he can do. Identify the issue clearly and concisely, but don't try and tell him what he can and cannot do. Whether you intended that or not, that's how it comes across.
> What the FBI is asking for is a master key to be created that can decrypt any iPhone.
Not true, they're asking for a way to submit guesses electronically and removing the auto-wipe and 10 guess limit. If you are going to request help on an issue, ensure you know what you the issue is.
I wouldn't send this message in, and I'd suggest you restructure what you're writing because this is simply not effective, and if other people begin sending the same message in it's going to make everyone who opposes this issue look misinformed with a superiority complex (that is how the entire second paragraph comes across).
That way for future phones at least, the issue would become moot: there would be no way for Apple to build and/or install a custom software image that allows brute-force password cracking.
1)http://timesofindia.indiatimes.com/tech/tech-news/telecom/Go...
2) http://www.reuters.com/article/us-blackberry-saudi-idUSTRE67...
3) http://www.thestar.com/business/2010/08/16/threats_of_blackb...
I can understand someone outside of tech not understanding how those are comparable statements, but if anything the latter is more important.
https://hn.algolia.com/?q=&query=&sort=byPopularity&prefix&p...
I do believe there is no backdoor for when a city court requests it, but i don't really believe that the FBI or CIA doesn't have access to it.
Considering that iPhone already exists a long time, they must have some means to backdoor the "iCloud"...
But that would take more balls than anyone left here in this "Land of the free and home of the brave" seems to have left anymore.
It also doesn't make sense from a game theory perspective, if you're a Good Company that's going to fight on this issue, it makes sense to be in business as long as possible to be a pain in the rear for authoritarian jerks. If every company who was willing to stand up to these guys went out of business immediately after you'd only have people who aren't willing left over.
Apple's positive affect on our economy, our technology, and even our nation, would make such a line that our government would have to think long and hard about pursing their demands.
Imagine if Apple, and the tech community as a whole, stood behind that decision. Of course they won't because they rather be rich than free.
You didn't counter his point. Again, its insane from a Game Theory perspective, it would require all players in the tech community to be effective, whereas if one person defects he now has access to a huge market where all the incumbents are gone.
Apple doing this would just mean "someone is going to create backdoor'd phones and capture the market, just not us", and we would get nowhere.
> they rather be rich than free
But don't most people want to be rich so that they can be free?
They really need to put that paragraph closer to this one:
> The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer.
The first paragraph without the second implies that iOS isn't actually secure at all.
So am I missing something that makes the iPhone's internal security architecture relevant here?
The password retry delay, and subsequent deletion of keys, is enforced by iOS here. Apple could provide some kind of software to allow for unlimited attempts (and an interface to do so in an automated way, which the FBI is specifically asking for).
On newer phones, the Secure Enclave contains the keys, and enforces both the retry delay and the deletion of its contents. There isn't a way around this without also upgrading/flashing the SE system (and it isn't even clear if Apple can do this in a way that preserves the keys).
Will they, can they do anything about data in iCloud as well? While you can turn off iCloud I'd guess the majority of people are using it. Given you can access much of it at iCloud.com that would seem like whether or not you can unlock an iPhone most customers' data is available directly from Apple. Mail, notes, messages, photos, etc. No idea about other apps data that get backuped
Again I'm applauding Apple for standing up for encryption. If they could some how offer the same on iCloud I'd switch from Google (Google is not encrypted either. My point is I'd switch to a service that offers it)
What do find interesting, is that Apple isn't the first manufacturer that the government as ordered to crack a device. An "unnamed smartphone manufacturer" was ordered to crack the lock screen on October 31, 2014.[1] No one made a fuss then, so someone caved.
If they put a backdoor in iPhone for US government, they are effectively thrown out of Chinese market.
Interesting enough, what will Apple do if Chinese government demand they to decrypt/put backdoor in exchange of staying in the market?
Does that mean that apple will not provide such means or disable security for phones sold on the Chinese market? That would be surprising given the potential size of this market.
well, as far as I can see, it is not agreeable to the use and principle of law to force a company (or a person since corporations are people) to spend money and waste resources to compromise its own security systems, which happens to be something they morally object to.
While we believe the FBI’s intentions are good, it would
be wrong for the government to force us to build a
backdoor into our products. And ultimately, we fear that
this demand would undermine the very freedoms and liberty
our government is meant to protect.
Tim Cook
Kudos to this guy for standing up to an idea.Now on practical notes, this is about security, providing a digitally secure platform to both users and providers, prevent tampering, keeping data secure.
Microsoft could take a cue.
Apple is misrepresenting the situation and perhaps it's because they're afraid that in the future the government will come knocking again, but I think it hurts them to not be completely above-board about this.
Tim Cook is right. Once this is unleashed, there are no limits and all iPhones are insecure.
Even with the restriction of being plugged in, outside of Apple who needs to push iOS versions at tethered devices and will be hindered too badly by having to unlock them first?
I've always wondered why large tech companies/corporations abide by such orders instead of speaking out. Even if Apple was under a gag order, they've created a PR nightmare for the alphabet agencies; Apple could be pursued in court, but that pursuit would now likely be done in the face of negative public opinion.
The supreme court has ruled in separate cases that: 1. that software is speech 2. that a person (corporations are people according to them) cannot be compelled to speak
It would seem to me that the FBI could perhaps subpoena technical documentation from Apple but it should be required to hire their own developers to write this software.
Win/Win
No software backdoor is created, the FBI gets its data and we all go on with our lives. Why are we spending so much time gnashing teeth over something that has a very simple solution to it?
You could argue that Apple could allow an official to be present while work is being done on the phone, but then Apple risks having it's (to-be-developed) method being viewed and/or captured by said official. Very risky.
It would be relatively easy for the chip to offer a challenge and accept, say, a $100,000 proof of work to unlock the phone. This way, we prevent bulk surveillance but still allow the government to access high value targets' devices.
More likely, they would impose consequences against Apple-the-corporation were it not to cause the task to be performed, rather than forcing an Apple engineer to perform the task.
http://techcrunch.com/2014/02/27/apple-explains-exactly-how-... (Link to Apple's paper is in the article)
(Yes, Apple could add this key for everybody at the beginning, but if their intention is security then it is a brilliant system.)
I am now officially, an Apple fanboy. That's right, I'm gloating to family and friends, about how Apple is standing up to the man, doing the right thing, and refusing to compromise their security.
Keep up the good fight.
Good one Tim! I mean how long did the LE think they can abuse constitution, put spy devices on people's cars without warrant, use stingrays and do all sort of other crazy stuff including planning and executing white-flag attacks without any consequences whatsoever?? I mean, at some point, we the people - for a good reason - will lose all and any trust we have in them! And that's what Tim is saying in this one sentence that with overwhelming evidence, the US Gov would have hard time arguing against!
The scary part here is that the iPhone data is really not that secure. If apple can overwrite the OS and get access to the data, this means the keys are stored on the phone somewhere, and not password protected, or "fingerprint" protected.
It remains to be seen, though, what Apple will actually do, in legal terms. Will they flat-out refuse to cooperate, even if this means that they will be fined or Mr. Cook will be imprisoned for contempt or something like that? Will they actually send their lawyers to challenge the court decision? That would be very interesting to watch, and if they succeeded, it would create a precedent for a lot of other companies. But so would their failure.
Mr. Cook expressed concern that "the government could intercept your messages, access your health records or financial data, track your location, or even access your phone's microphone or camera without your knowledge".
As I read this I wondered, "what harm would actually happen if that occurred"? If the government did read my messages and get my health records & financial data and track my whereabouts, I can't think of anything bad that would actually happen as a result of that.
Is there anything specific that I should be worried about in that scenario?
Apple could propose to secure access to the FBI using the same level of security that it uses to protect the access to the phone content for the owner of the phone himself. Tim Cook only talks about one solution of a "tool" that it could install.
If the same level (and method) of security is used then saying that there is a risk of the backdoor being hacked would be equivalent to saying that there is a similar risk of the user access being hacked.
Writing != thinking != talking
Writing might make you a better communicator in general, maybe a better thinker, too. But clear thinking and talking don't make you automatically a better writer.
The FBI doesn't need the modified iOS code, and that Apple write/not-write it doesn't change anything in the end, since someone else could just as well write the software with some reverse engineering.
[edit: if you downvote because I'm wrong, please explain because I'd love to know why]
If Apple cared customer's privacy and security so much, how could they sell non-free software that is hard to audit, computer with baseband processor, relies on central server which allows the single point of failure.
My understanding is Apple customer don't much care about their own privacy and security but has weakness on marketing.
Real data security has to be a mix of services that are friendly to reliable key exchange and strong unbreakable encryption, and verifiably secure endpoint software, which in practice means open source software where the user can control installation, that implements encryption.
So there is nothing for Apple to hand over. There are no actual keys (they're on the phone itself in an unaccessible way, practically). The court order in effect orders them to write a derivative OS without bruteforce inhibition features. They probably can do that, it probably isn't burdensome, but is it legal to compel a company to write code? Can a court order you to write a book? Or a letter? They can make you turn over facts or evidence, but it's specious they can make you create something, even if you have the capacity to create it.
• Can Apple OTA upgrade iOS when the device is locked?
Oh wait they already did by providing their clients' data. Trying to stop the government now is like trying to stop a high-speed train. Still, good luck to them! Good to know they are not just pushed around without any resistance.
This stance against the government come poetry reaffirms my faith in the genuineness of Apple'e encryption efforts and Tim Cook specifically.
No code from [redacted] makes it an excellent choice for the privacy conscious.
I use Slackware in the cases where I need a Linux kernel. I think that might give you an idea of what I'm trying to avoid. [redacted]
Anyways, I use *BSD daily in VMWare Fusion for any development that isn't related to iOS. I also do my email and web surfing in OS X because it's simply more pleasant.
I don't get it- the shooters are dead. How is what is on their phone a matter of national security? We probably have 99% of the information we'll ever have on them. There is no larger plot. Not having what's on this device I cannot imagine puts anyone at risk.
It's all about precedent.
My guess is that this is more about pushing back the law and peoples rights than is is about getting access to this device.
But then I'm highly cynical about what the government claim they can do with technology for obvious reasons.
Is it not possible for law enforcement to get what they want from that, if all they want is a custom build of iOS that can be hacked around? And why is it even possible for that to work if the data is supposed to be kept secure?
I'm still waiting for JB for 9.2.1 or 9.3 when released but there are already semijailbreaks (browser based installs a temporary app) and some unreleased PoCs, but Cydia MobileSubstrate and other tools need to be ported / verified too.
Perhaps if Apple allowed the devices to be officially customer hackable (like flux, springboard replacements, transmission, 3G unrestrictor and changing fonts), there would be less need to develop exploits... Unfortunately, there is great demand from governments to buy exploits and keep those secret (not a conspiracy but tools in a market)
But it only works on iOS 8.1 or earlier, was patched in iOS 8.1.1
Massive fines? (we know they have the cash to cover it)
Jail time for execs (whoa!)
?
The guy in this case didn't have the newest model iPhone; he has an older 5C which is at least theoretically vulnerable to Apple being forced to push a bad software update to it.
It's hard not to see the effects of these things showing up in the way they design each successive generation of iPhones; each time, they add something which gives them more ways to say "nope, technically impossible to do what that court just ordered us to do".
edit:
Ah, I've found a couple of sources claiming that the secure enclave wipes its keys if its firmware is updated. Makes sense.
I doubt the ones giving these orders would be comfortable with their own privacy being at risk.
Sounds just like gun control :)
What parts of the government is a different matter.
This is a perfect setup. Get all the bad guys to run out and buy iPhones (good for Apple) believing that they are safe from the US surveillance machine.
Then the appropriate agency can slurp up whatever it wants.
I'm pretty sure it's this. Once it's created it's only a matter of time until it's leaked and anyone can use it.
Apple is saying that any solution that is applied to specifically this phone can trivially be generalized to all other iPhones (or, at least other iPhone 5cs). Further, unlocking this phone in response to this order establishes a precedent that this is okay. You are much better off legally if you fight the first request than if you fight the thousandth request.
That letter might be the truth or could be some kind of decoy. Maybe the backdoor will come and Apple knows that already and they try to limit the damage to their brand.
Like "we tried to resist having a backdoor installed, but we couldn't do it ultimately".
The secure enclave must still give it's UID under some circumstances? This still does not appear to be immune to hardware hacking.
Moreover, this UID can also be brute forced imo, when the memory chip and secure enclave are physically separated. Whatever is needed to de-encrypt the data must be brute force-able, especially when the memory is separated from the wipe-all-data initiator which does not seem to be impossible if you know the chip design well enough?
re: brute forcing. they are AES 256 bit keys. good luck.
How about disabling the wipe signal by cutting some interconnects in the silicon?
Is the function by which the AES keys are calculated from the password really completely inaccessible?
The Secure Enclave is essentially a hardware security module, in more general terms. The only thing that leaves its boundaries are the results of crypto operations, not the parameters that went into calculating them.
I'm going on and on about this because I see no way in which this problem is not down-boil-able to brute-forcing the password the user puts in.
Actually Apple admits this much! They can build a work around! What stops the three-letter-agency from building it?
There must at some point be a complex user entered passphrase if you want to be safe. This can be a fingerprint of course but there is always the 4 letter password/passphrase that is the weak point.
I could be completely wrong, so far I'm not convinced I am.
i believe that 'Hardware Key' refers to the UID. if this is the case, then learning the UID + user passcode gives you the root keys, from which you can decrypt the remaining key hierarchy until you reach the decrypted files.
(guess answer: iOS needs to be signed. So what they are really asking of Apple is to sign a lobotomized iOS image...)
I wonder if this is a grammar mistake, or Apple actually considers the private conversations, nodes, photos to be theirs?
Right now it all hinges on Apple's private key and that's a very thin wire to hang all this privacy off.
And Edward Snowden just tweeted this a few minutes ago in response to another tweet proposing Google back up Tim Cook: "This is the most important tech case in a decade. Silence means @google picked a side, but it's not the public's."
[0] https://en.wikipedia.org/wiki/File:PRISM_Collection_Details....
https://assets.documentcloud.org/documents/2714005/SB-Shoote...
It is a PDF.
Someone who believes in conspiracy theories would make a statement that "now it is official" :)
Is that true? What if it's locked with a secure 128-bit (e.g. 10-word diceware) passphrase?
To honour Tim, and his advocacy for our industry, I'm going to spend the rest of my week developing privacy/security projects. I encourage everyone else to do likewise.
* Does Apple pretend the FBI cannot access to its devices?
* Can the FBI access to its devices?
The only thing we learn here is the answer to the first question. We know nothing more for the second one.
People hyperventilating that the tool could be used to crack other phones can relax, given the last clause in the quoted text (from the actual order).
They felt the need to state that, huh?
I'm just a government relations guy, not a security person, so please forgive me, but I'm not sure where I fall on this. I want the FBI to be able to decrypt the San Bernardino attackers phone. The same time, I don't want the government to be able to decrypt my phone. This is one hell of a damned if you do, damned if you don't situation, and I'm really stuck.
https://www.eff.org/deeplinks/2015/10/apples-eula-gives-it-l...
A) Apple has created unbreakable security. The FBI cannot access the data and needs Apple's help.
B) iPhone security, like all other security, is breakable. iPhones are a very high-value target (all data on all iPhones); therefore some national security organizations, probably many of them in many countries, have developed exploits. The FBI, following normal practice, does not want to reveal the exploits or capability and therefore must go through this charade.
- The phone was turned rebooted
- It's been more than 48 hours since the last time the passcode was entered
- The user didn't set up a touch ID fingerprint
FBI: "You've built a device that makes it nation-state-difficult to install custom software without DRM keys. We'd like you to assist us in deploying software signed with your keys."
Apple: "That feels way too much like asking a CA to sign a cert for you, so fuck off."
I'm honestly not sure which side I'm on here.
probably they try to fight this request by arguing that the government is actually asking them to effectively remove security from all the phones (of this model at least). they would be happy to help break this one phone as long as it doesn't affect any other phone.
in that case, then Apple should just break the phone and give it back to the FBI after removing the backdoor.
This is actually the result of a barter. The Gov gets to have some low level TOP-SECRET access in trade for this easy access code and that Apple gets to go public to keep the populace calm and pretend they are fighting this thing.
/quote: "RIM's carefully worded statements about BlackBerry security are designed to make their customers feel better, while giving the company ample room to screw them." /endquote
I have lost enough points on this thread to simply double down on this issue.
This is not a good sign at all. While Google can't compete with Apple on the principle of "not spying on their users". All Apple has to to is to publicize it and then ask for forgiveness from it's users later.
I've re-read your comment several times, and I don't get how it's novel or how it applies here. Of course it could be true in this case, as it could be true in any decision any company makes. But I don't see how it's insightful or proves or suggests that Apple is doing the same.
You're not some kind of martyr for the anti-Apple cause here. I think we all know that Apple could be saying one thing and doing another. That doesn't mean that they are, and it doesn't mean that this open letter is proof that they are.
Thank you!
Don't vehicles used by federal agencies typically bear U.S. Government license plates?
The likelihood of the federal government driving a GSA-plate vehicle from Maryland to California to meet with Apple is about zero.
What? They just drive silently to and from the meeting or listen to the radio?
I'd maybe call the bluff, and take my political stand.
IANAL but seems like you're missing something.
Apple can simply let Employee B take Employee A's place after A quits. When the authorities come for B, B can quit, and Apple can re-hire A.
Apple never has to comply.
When you break down the process of having a private company comply with an order to create a particular piece of software, there's many failure points.
The counter from the governmental side is "we will give your company massive fines until and unless your company complies".
As a note, the actual text of the court order (https://www.documentcloud.org/documents/2714001-SB-Shooter-O...) explicitly says that Apple can appeal it on grounds that it is an unreasonable request. Uncooperative engineers can make it an unreasonable request, and have the legal right to be as uncooperative as they want to be in this case. And, they're on the same side as the CEO of Apple ethically, so it isn't career suicide.
At which point is becomes worth it for Apple to pay an engineer to do the job. I doubt it wouldn't take much of a bonus to get someone to do it.
> At which point is becomes worth it for Apple to pay an engineer to do the job. I doubt it wouldn't take much of a bonus to get someone to do it.
What happens if Apple says they aren't paying these unjust fines? Theoretically, court order, law, or what-have-you, Apple can just straight refuse to participate (and hopefully other big tech companies would follow suit).
Sure the gov't can make arrests, threats, seize assets -- but in the end, the gov't still don't get what they want (but they do get a ton of very, very bad PR in the process). At a point, the gov't would have to stop -- destroying the world's most valuable company, and one of America's sweetheart companies, all over this... wouldn't play out well.
Then they'll be subject to additional penalties, seizure of property, etc., and quite possibly shareholder lawsuits stemming from the decision to incur those losses.
> Sure the gov't can make arrests, threats, seize assets -- but in the end, the gov't still don't get what they want
Maybe, given the recent discussion of mandatory limits on encrypted communication services without up-front backdoors, what the government wants is a clear demonstration that the operation of those services interferes with evidence and intelligence gathering in terrorism cases to build the case for new laws restricting the operations of such services.
I wasn't trying to imply this at all - of course the government can destroy companies.
What I was implying is that, given the past few years of heightened public awareness of domestic government programs and efforts, perhaps this time public pressure would be exerted on the government to lay off the issue. Apple is one of the most loved companies in the country, people would be very interested in knowing why it's suddenly being torn down.
A company like Apple, which is practically an icon of "everything America still gets right," would be a very politically dangerous target to go after.
People would want to know why their favorite company was drawing a hard line, hopefully lead to a more educated debate.
We couldn't possibly expect this to take place as it would imply huge fallout for Apple. The only real course of action is to keep up the public debate in a loud way.
The authorities don't have to "come for" any person (they might follow up with orders directed at particular persons, in which case those persons would be at risk of personal sanctions, as well.)
https://www.calyxinstitute.org/news/federal-court-invalidate...
EDITED / CORRECTIONS - Thanks commenters - The battle was won by Nicholas Merrill not Ladar Levison of Lavabit fame as I originally posted.)
LavaBit's Lamar Levinson is assumed to be under a gag order from some request he was given by the US government, of which he declined by way of folding his company and claiming that he could not comply moving forward if he was no longer the middleman of some form of communications.
Rather than making assumptions, you can read about the specific kinds of legal process involved in the Lavabit case at
https://en.wikipedia.org/wiki/Lavabit
You can also read the Fourth Circuit decision on his appeal, among other things.
One of the big problems with NSLs is that you can't let anyone know that you've received or acted on one, so there's very little accountability.
Hence the recent trend of some companies including a warrant canary on their websites, under the assumption that a NSL can't prevent you from _not_ saying something (e.g. deleting the canary).
So for it to work, you need to issue a statement every month that says you haven't been issued a NSL, and then simply not issue a statement the month you finally were issued a NSL. That would then require the government to actually compel speech (compel you to post a new notice saying you didn't receive a canary).
Of course, the above should make it blatantly obvious how absolutely absurd the blanket gag order on NSLs are.
So, by compelling Apple to code something that doesn't exist, the government would indeed actually be compelling speech.
So, I'm not sure what the value is of a clever argument that compelling Apple to comply with the order here is "compelling speech" is supposed to be (likewise, the upthread one about NSL canaries.)
On a separate note though, I've always thought it would be interesting to see a member of Congress be issued a NSL and then have them read it on the floor of the House/Senate (since they have parliamentary immunity for anything they say on the floor of the House or Senate).
I'm not familiar with that phrase. What does it mean in this context?
Interestingly, people usually don't want to be deposed when they have something to hide.
[0] http://litigation.findlaw.com/filing-a-lawsuit/what-is-a-dep...
Or because the process is a huge hassle to deal with, it sucks up days and days of your time, and it's very easy to mess something up.
That's a pretty... er, dubious claim at best?
Interestingly, people usually don't want to be deposed, period.
Sure, its a routine proceeding in civil cases; guess what, people generally don't want to be involved in civil cases -- as plaintiffs, defendants, or called witnesses -- either.
You know who really talks a lot about their rights? Terrorists.
Your statement is so deeply naive and insulting to the patriots who fought for the rights you enjoy today.
Those who made major strides for:
1) Black Civil Rights
2) Gay Marriage
3) Women's Rights
4) Anyone who fought government intimidation based on speech
5) Democratic Socialists
6) Abortion Activists
7) Environmentalists
8) Your workers rights (i.e. your weekends and pay)
10) Many more... who made sure you could help move society forward and make it better for everyone.
Edit: I assume the downvotes are coming from those who would rather we lock up the above than have a free American society.
You don't need to have done anything wrong to fear a deposition. Go to youtube and watch any number of "do not talk to police" lectures. An innocent person can end up trapping themselves in a lie, or bow to pressure. Or you may say something that you think is harmless but in fact damns you. Depositions should be avoided wherever possible.
[0] http://scholarship.law.gwu.edu/cgi/viewcontent.cgi?article=1...
I would associate this view/tone with a corrupt, small-town, sheriff in a movie, rather than a real, human citizen who shares the the values of our society, which includes due process, the right of the accused, and presumption of innocence.
It hung out for a few minutes and then made off taking a left on Harrison (101 South, FWIW). This was around 12:30p.
What's at stake for Apple is not only their principles but also one of their marketing pillar: "you, the user, can trust us with your data/privacy." By asking Apple to give that up, and quietly, you actually are asking them to undermine their business model. Shareholders will not appreciate that if they wouldn't have a chance to hear about it first. The Apple brand would lose from its value and it would reflect in the AAPL share price.
My point is that the whole thing needs to have legal backup. And Apple is asking for this exact thing: give me a law to use. And not something from the 1700's.
If the device were truely locked down, there would be no aftermarket solution to unlock it.
My understanding is that Apple was asked to supply software that would prevent their software from destroying evidence on a particular device. They should comply with this order, especially given the device in question.
The philosophy of corruption and oppression still echoes throughout the FBI. Even today, there are FBI agents that work for private interests. You can't reform a mafia, you must abolish it and start over.
They aren't talking about putting a back door into systems to be used in the future, they are saying it's indeed feasible to place a backdoor on a device already out there and then use the backdoor to access the device. That means the device is not actually secure.
But that they have the capability is a bit scary.
I mean, you could break into my android phone at enormous effort to use my phone to access my gmail app, but isn't it easier to just ask google, and I'm sure the telco and NSA are already logging everything anyway?
You could break into my phone to use my phone to use my facebook app to look at my uploaded pictures, but isn't it a million times easier to just contact facebook to access my facebook account?
In this new era of dumb terminals, its like a FBI agent demanding access to the terminal settings screen of a vintage VT102 in order to track terrorists or whatever. Or a demand to know my modem init string. It demonstrates a fundamental lack of understanding of the entire ecosystem from top to bottom.
The purpose of all this drama is to avoid discussion of the insecurity of cloud services.
It might be that apple people use the cloud a lot less than us android people. I'd be interested and surprised to learn that.
As much as I value privacy I really don't agree with Apple's stance here - if due legal process has been followed, why shouldn't they be able to read the contents of an iPhone ?
And yes I get that third party encryption can be used, which isn't owned by Apple and that there's little the authorities could do about it - but that's not the case at hand here.
Because it is possible to create a smartphone that is impossible to break into. The others it is impossible to create one that is impossible to break
It's not that it's bad if it's this case. It's that is bad if it applies as a built-in backdoor for whenever they feel like using it.
I am positive banks can open those things, and vehicles are inherently "openable", so I do not quite get the point here.
Civil Forefeiture has been a problem for a long time.
I agree that due process should compel Apple to unlock if they have the capabilities to. But no subpoena can beat math, right?
EDIT: I just realised that what the FBI is talking about is a backdoored version of iOS. To me the compromise seems to be writing the backdoored version but leaving it in Apple's hands (so Apple could send the FBI the data but not send them the OS). The only problem with that, of course, is that such a backdoored version could then be taken by a judge.
Honestly, it seems like the judge could force Apple to hand over the OS update signing keys to the FBI...
That seems a lot different from getting a search warrant and having the right to go through your belongings.
Because the "master key" alluded to in the letter is ethereal and can be duplicated (as opposed to handed over). This means:
- Since the key can be duplicated, there is no serious way to ensure that only the police (or any other legally entitled organ) can do the search. Anyone who can get it will have police-level access to anything and will be able to offer police-level access to anyone. The "anyone" in question can be a former policeman who hates life, some script kiddie, the Chinese and so on -- and neither of these people are likely to care much about the "due legal process".
- The police can trivially search it without the owner's knowledge and without leaving evidence. The high costs in time and money are a reasonable deterrent for searching property, vehicles etc. without the due legal process. For an electronic device, that cost is practically zero.
Regarding the first point -- for what it's worth, a while ago, army regulations here required that all doors have a physical lock and key, even if they also had an access code, for precisely this reason. The access code or the card swiping were used to log access (i.e. everyone had their own card, access codes could be logged so that you at least knew when someone was entering etc.) but when a door was supposed to be locked for good (e.g. labs not in use during the night), they were locked with real keys and sealed with old-fashioned wax seals. The rationale was that breaking the lock required quite a little time (and maybe even some door banging), increasing the chances that someone who tried to break in would be discovered, and physical evidence of a break-in was fairly hard to erase, as opposed to a purely electronic break-in which was quick to do (just enter the code). I don't know if this is true anymore, nor how common it was outside this part of the world, but it makes some sense.
Or maybe you think it's OK to do it just this once?
Sort of the "just the tip" mentality here?
The problem is that once such a capability is added to the OS, there is no going back. And it can then be used with or without your wonderful US due legal process, potentially by criminals and definitely by governments in countries where human and civil rights are a joke.
"Today we celebrate the first glorious anniversary of the Information Purification Directives.
[Apple's hammer-thrower enters, pursued by storm troopers.]
We have created for the first time in all history a garden of pure ideology, where each worker may bloom, secure from the pests of any contradictory true thoughts.
Our Unification of Thoughts is more powerful a weapon than any fleet or army on earth.
We are one people, with one will, one resolve, one cause.
Our enemies shall talk themselves to death and we will bury them with their own confusion.
[Hammer is thrown at the screen]
We shall prevail!
[Boom!]
On January 24th Apple Computer will introduce Macintosh. And you'll see why 1984 won't be like '1984.'"
------------------------------------------------------------
Apple Superbowl AD "1984"
Transcription courtesy of George Gollin, 1997
Edit:Removed the link to the video. My goal wasn't to draw traffic anywhere it was just to point out that some of Big Brother sentences in an Ad aired 30 years ago still have strong resonance today.
"Our enemies shall talk themselves to death" Hum... just read yesterday that NSA is believed to use machine learning over cell big-data to determine drone target...
I bet hardware vendors are just salivating at the concept of having to produce thousands of iPhone cracking docking stations.
We were shocked and outraged by the deadly act of terrorism in San Bernardino last December. We mourn the loss of life and want justice for all those whose lives were affected. The FBI asked us for help in the days following the attack, and we have worked hard to support the government’s efforts to solve this horrible crime. We have no sympathy for terrorists.
When the FBI has requested data that’s in our possession, we have provided it. Apple complies with valid subpoenas and search warrants, as we have in the San Bernardino case. We have also made Apple engineers available to advise the FBI, and we’ve offered our best ideas on a number of investigative options at their disposal.
We have great respect for the professionals at the FBI, and we believe their intentions are good. Up to this point, we have done everything that is both within our power and within the law to help them. But now the U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create. They have asked us to build a backdoor to the iPhone.
Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession.
The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no an way to guarantee such control
This is just pure awful they admit to helping the fbi. how can we trust them
It is immaterial whether or not any platform is currently 100% open source. rms_returns is right in noting the discrepancy between noble apple sticking it to the man and walled garden apple sticking it to the user.