What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.
What Apple needs to do then instead of writing this letter, is release an update that closes this backdoor.
"The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer."
Quite likely.
As I posted on the other discussion here: https://news.ycombinator.com/item?id=11116343
> If it's possible to make such a "backdoored" build of iOS, then there are state actors who will be throwing $Millions at doing it already, with or without any willing help from Apple.
I guess what the FBI wants is a backdoored iOS version and to have Apple sign it with their signing key (which means that the FBI can use it over and over again).
For instance, signing keys can and have been stolen, on the principle of "if you can't brute-force it, hack in and take it".
http://arstechnica.com/security/2013/02/cooks-steal-security...
http://blogs.adobe.com/security/2012/09/inappropriate-use-of...
http://www.androidauthority.com/ssl-added-removed-google-moc...
http://arstechnica.co.uk/tech-policy/2016/02/its-legal-for-g...
I assume that Apple has a hardware security module for key generation and storage, perhaps even custom-designed and built, to prevent key extraction/copying.
Of course, in the end you have to trust Apple that only a limited number of employees have access to such hardware, that they have proper auditing procedures, etc.
But the probability of a compromise can never be 0, unless you design and produce your hardware yourself, write all code that this hardware runs yourself, and never leave your computing device unattended. Since that is not practical for most people, you have to put trust in some third party.