Apple Letter on iPhone Security Draws Muted Tech Industry Response
nytimes.com
nytimes.com
If you're cynical, you might think that this case is all about setting precedent and trying to scare one of the FBI's biggest opponents on the topic of data security (Cook). We know they have other options for cracking the phone in question (decapping, side channels, etc.). They want legal precedent for installing backdoors, and they want to scare Apple and other companies out of providing security features. No wonder those companies are hesitant to speak up.
If Facebook can't read your data, then they can't sell your eyeballs to advertisers.
If Apple couldn't do an end-run on the key derivation protection mechanisms, then they couldn't use that backdoor to aid the FBI.
"Can't do it" is a strong defense.
"Won't do it" isn't.
e.g.: http://daringfireball.net/linked/2016/02/17/panzarino-apple-...
It's not as easy as you imply. Denying themselves the ability to end run your security might well require them to not be able to upgrade or recover user devices. At all.
In general, Apple's guarantees about anonymity and security all assume that there is no risk to Apple sitting in a trust position. This case demonstrates why that's a bad idea.
This isn't some NSA mass surveillance program, or clipper chip reloaded(TM).
This is an active murder (and terrorism) investigation in which Apple's privileged position -- one they assumed by choice and to their own benefit -- already exists. It is not unusual, unethical, or establishing any new precedent for them to be compelled to use keys they already have to open this single device.
Apple does not need to, nor are they being asked to, provide a backdoor that can be used elsewhere, and any further demands of Apple will require the same judicial oversight as this one.
If Apple doesn't want to be in this position in the future, they can avoid the potential liability by not holding master signing keys that can be easily used to circumvent the security of an owner-locked device.
They are, however, being asked to _create_ a backdoor that can be used anywhere. The specific request is to remove the limits on guessing passcodes so that the FBI can brute force it.
All they're being asked to do is to use it, entirely under their own control, for this one phone.
Tim Cook is trying to pretend that commenting out a few if statements in the key derivation code path is what creates the backdoor.
But this is just speculation...
I'm definitely in the camp that believes this is a legal stunt by the FBI to set a precedent using a highly publicized terrorism case which the public will support. A previous All Writs Act claim in 2014 by the FBI for a credit card fraud case involving an encrypted iPhone didn't change Apple's position on the matter, so they are trying again with a higher stakes case.
One could twist things all day long to fit a goal.
Eileen M. Decker, United States Attorney
Patricia A Donahue, Assistant US Attorney &
Chief, National Security Division
Tracy L. Wilkinson, Assistant US Attorney
Allen W. Chiu, Assistant US AttorneyThere are dozens if not hundreds of viable methods to obtain this info, FBI is choosing to pursue the court order route instead of any of the other forensic tools available to them.
The simple fact of the matter is that the encrypted data and the key to decrypt it both live in a piece of physical hardware on the device-- no matter how well obfuscated it is, it can still be analyzed and recovered by a sufficiently advanced technical entity.
This is exactly the type of work that NSA TAO exists to accomplish, and they are widely regarded as one of the best organizations of this kind in the world.
I think I should consider moving to iOS pretty seriously. I had been dismissing it for being over-priced and not being OSS. But the true fact of the matter is, the extra cost might be worth it, because frankly, Android without Google Apps and the Google Play Services is absolutely useless.
Google seems easier to switch from, they seem less concerned with vendor lock in (don't get me wrong though, they still have some vendor lock in. Just less than apple IMO).
I think in this case it is "choose your evil" and for a lot of people, for good reason, privacy is going to win.
This is often used as an argument against Apple, but having gone back and forth over the years, I just don't think it's true anymore. It certainly was a decade ago, but now I'm finding it hard to think of any issues I've had going from Apple to any other vendor – regardless of whether it's software (migrating data, chiefly) or hardware. At least, I don't think they're significantly worse than any other vendor.
Also, I disagree with the notion that Apple "heavily pushes vendor lock in". They certainly don't go out of their way to make it easy to switch, but I can't come up with any examples off the top of my head where they're deliberately making it harder to switch without having a good reason for that decision. After all, Apple doesn't really have to do anything at all to keep people invested in its ecosystem, since platform-specific software, by its very nature, already acts as a form of lock-in, and iOS has a lot of software that other platforms don't.
> They certainly don't go out of their way to make it easy to switch, but I can't
> come up with any examples off the top of my head where they're deliberately
> making it harder to switch without having a good reason for that decision.
Just an example for those that are not familiar with Apple devices.You can sync your calendar, reminders and contacts with iCloud. But you don't have to.
iCloud calendar sync is basically a CalDAV server. You can setup your own CalDAV and sync with that if you like. On the iDevice you have to set the parameters for your server which makes it slightly harder to setup than iCloud, but that's just the way it is and not Apple's fault. There are no other stumbling blocks to make it more complicated than it needs to be.
Once set up it works like a charm. I can say "Hey Siri, remind me to buy pasta" and a split second later I have a new VTODO on my CalDAV server.
I think that statement's based on an old stat that, at that time, Google's revenue from licensing (Apple was paying for Maps) and advertising (including web and search advertising, and at the time Google was the default search provider on iOS and this was also before Siri was around to displace some web search) to iOS users was greater than its revenue from Android.
The facts on which all that was based (market share, basis of iOS revenue streams, etc.) have changed substantially since then.
Ah, the other figure from a report from Goldman Sachs that nobody has seen but it is now dogma.
When you find the report, please, put it.
And, by the way, using Appleinsider as source is very funny
This is not, strictly, the fault of Apple, but of app developers and myself. Either for not making multi-platform a thing (Omnifocus), or for others not stepping up to compete, or for my inability or unwillingness to continue my search for suitable alternatives.
All this said, most of my coworkers use Android devices, and several want to switch to iPhones, but have run into the same issue I did, but in reverse.
http://www.minyanville.com/sectors/technology/articles/Apple...
Source?
Then it will be easy to find any source that it is not the same old "Google makes 4 times more from iOS than from Android" that was debunked years ago for using assumptions about a royalty figure in the Oracle vs. Google trial and nothing real
What is completely ridiculous is claiming things without any proof
> it's still generally accepted that Google makes a significant amount of its mobile revenue off of iOS
This is not your claim
> Doubly-so since it doesn't even matter what the numbers are,
Oh, no, it matter when you have made a very specific claim that can't be supporte
I'm not quite ready to jump ship yet, but it's looking more and more tempting every day.
I'd love a good FOSS alternative to their software/services. I try to run my own software/services, but there are some things I still just can't replicate.
Cook very publicly tangled with shareholders that argued against Apple's environmental & accessibility initiatives:
"'When we work on making our devices accessible by the blind, I don’t consider the bloody ROI,' Cook said, adding that the same sentiment applied to environmental and health and safety issues.
He told Danhof that if he did not believe in climate change, he should sell his Apple shares. 'If you want me to do things only for ROI reasons, you should get out of this stock,' he said.
Cook’s comments and visible passion over the issue are one of the strongest signals yet of his commitment to reducing Apple’s environmental footprint. He told shareholders that he wanted to 'leave the world better than we found it'."
http://www.theguardian.com/environment/2014/mar/03/tim-cook-...
Apple chooses a business model that is aligned with what it thinks is right, not the other way around.
There's nothing evil about wanting to provide contextual information and to do that they need the context. Its just the nature of the service they provide.
The argument you've presented is ends justifying the means. I don't mean to imply that there is no convincing arguments to be made involving the points you present, but this is not it.
The face value reading of purely "providing contextual information" is benign af. But that does mean evil can not lurk in implementation constraints, and/or the design decisions made in service of making that presentation monetizable.
I don't mind the extra cost that much if I can be assured that the phone is the actual product the company is making money from—not by selling ads targeting me.
The problem is that Android phones are so much better now (IMO of course). :/
Yet....I love my S6 too damn much
Do they really pitch anything under the F/OSS banner? I don't understand why Google has this reputation. Android is OSS, but that's a fairly recent addition, and it's not really played up very much.
In addition to AOSP, Chromium (and Chromium OS) are open source; while App Engine isn't, the App Engine SDK is, and Google has supported an open-source reimplementation of App Engine. Dart is open source, as is Go. And a lot of other stuff.
They definitely did advertise themselves with the motto "Do No Evil," which they dropped some time ago, but open source hasn't really been a part of Google's DNA. Google's extensive use of open source software without publishing their modifications is exactly the reason that AGPL was invented.
Google has not dropped that motto
As for data stored on user's devices, Google also ships their phones with full disk encryption which Google cannot bypass - the implementation isn't as good as Apple's, but the concept is the same. Facebook doesn't sell any end-user devices so I'm not sure why they are even in your comparison.
FWIW, Mozilla does the same thing for Firefox Accounts sync data - it's an opaque blob that we couldn't decrypt even if we wanted to.
(Disclosure: Mozilla employee)
brew cask install chromium
last night. AFAICT, it's exactly the same as chrome minus the proprietary code. I literally haven't noticed a single difference other than the nicer icon.Google is the advertiser. I'm surprised how often people make this mistake. They don't sell user data to other advertisers. This not only goes against their terms of service, but also makes no business sense. Why would they give up their best signal for targeted ads?
1) never sell that data at any time in the future (perhaps if they should suffer a bad year financially), and
2) that they will be able to retain control of that data (no leaks, no employees that abuse access, no attacks from other people interested in the data).
Without these criteria, saying anything about what Google "re4ally does" with their data is a best describing the past and maybe the present. Why does everybody act as if current business plans are some sort of Truth that we can rely on? Plans change, management changes - unless it's in writing on an actual contract, it's just wishful thinking.
Of course, this doesn't matter when talking about Google and their data. We already know they give data to the government because they are part of PRISM[1].
As for advertisers, the scenerios "Google gave customer data to an advertiser" and "Google did the targeting work for the advertiser as a (paid) service" differ only in minor details. The end result is the same. There numerous creative ways the data can be moved by proxy or as a service.
[1] https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl...
The same can be said about other for profit organization. If the times changes and the board changes they can change their behaviour. So, it is only ifs.
> Of course, this doesn't matter when talking about Google and their data. We already know they give data to the government because they are part of PRISM[1].
So is Apple
> As for advertisers, the scenerios "Google gave customer data to an advertiser" and "Google did the targeting work for the advertiser as a (paid) service" differ only in minor details. The end result is the same
Minor details? Yes, NOT giving access to the data to advertisers is just a minor detail /s
Only those for-profit organizations that are keeping personal data for long periods of time. This is not at all universal, and nobody[1] is collecting data on anywhere near the scale that Google is, across such a wide range of data sources. How many other corporations have entire browsing histories (google-analytics), email histories, and phone call and location logs?
Do you deny that the aggregation of this data is a risk, should someone abuse it? Do you think this data is going to ever be deleted? You call this "only ifs", but this is a constant risk as long as the data exists. The numerous leaks of personal information we've heard about in the last ~year prove this risk exists. I suspect that Google will do a better job at securing their valuable data than most organizations, but nobody is perfect.
> So is Apple
Entirely off topic. The fact that there are risks when giving data to other businesses doesn't make the risk of giving data over to Google go away. While it is a common meme recently, appeal-to-popularity is still a fallacy.
> Yes, NOT giving access to the data to advertisers is just a minor detail /s
Advertisers... like Google.
[1] save for a couple other corporations that are in the data-collection business
That's not selling user information in the same way that Ford doesn't sell automobile factories.
> They aren't directly selling the data itself
Nor are they indirectly selling the data. No one else gets the data.
> they are selling a service that is an extension of that data.
They are using the data to produce a service that they are selling, in the same way that Ford uses a factory to make a car. No one else gets the data, in the same way that no one else gets the factory from Ford.
> I think the semantics are negligible.
I think there is a substantive difference between transferring data to third parties and over whom neither the person the data describes nor Google exercises control and retaining the data internally and using it to provide a service to third parties. And I think that is a critical difference when it comes to privacy.
I mean, you erase the distinction between a armed security guard (who sells a service which involves a firearm) and an arms dealer (who sells firearms).
If you're implying that advertisers can target an specific user, this is false
Apple doesn't do that. Their iAds are nothing in comparison to Google/FB's data mining. The only thing you get to go off of is the Advertising Identifier and the user can change/reset that at any moment effectively not tying them to any specific targeting.
I'm not sure what could be said of iCloud, but Apple itself isn't a big player in the ad-selling market unlike Google and Facebook. So unless Apple is straight selling off iCloud user data, it's a different ballgame.
edit: you also have to take into account Google and FB's ability to track you across the (near)-ENTIRE internet. Every FB/G-Plus share button, every video, image, asset loaded from FB/Google can track you via cookies. You could be reading a blog about pregnancies and how to prepare for a newborn on a cute little blog and Facebook may then target you for pregnancy/newborn products and services, etc. Unlike Apple, Google and Facebook aren't limited to their own properties in terms of info harvesting and ad-targeting.
People say this a lot, but Apple disagree: https://support.apple.com/en-us/HT205223
Highlights: name, address, age, iTunes/app etc. purchases, offers in Wallet, news read.
There is an opt out of those ("Limit ad tracking") but by default Apple will target on those things.
Probably semi-irrelevant because of Apple stepping away from iAd but Apple clearly use the Apple ID to target advertising.
Not from what I've been able to determine doing some research today. Or at leaast they're very poor at advertising it if they do.
Samsung KNOX uses the ARM TrustedZone to provide remte-attestation of running software, but I can't see anything similar to Apple's Secure Enclave for filesystem encryption keys.
If anyone does know an Android phone that does this properly, please let me know and I'll buy two this week. I am very impressed at the engineering Apple have built in this regard.
Pretty sure anything made in the last few years has had a secure element because you needed it for Google Wallet. That might have changed for Android Pay though.
In an smartphone with encryption. If the data is on iCloud they can read it
Ups, the same case than Google
And here I believed that the difference was that one sells hardware and the others software.
https://www.wordfence.com/blog/2016/02/wordfence-supports-st...
I'd encourage every other tech company who has the ability to talk about this (in other words you don't sell to the intelligence community), to also inform your customers and take a viewpoint on this issue.
This is obviously nothing new, but we're finally at the point of inflection we've all been anticipating. If Apple caves, it will set a precedent that the government can use a law from the 1700's (and anything else they can dredge up) to force surveillance and backdoors on tech companies in the name of security. For startups alone, even if you ignore the chilling effects and impact on privacy, to simply comply could be onerous enough to hurt innovation.
I also urge other founders and exec teams to join in. The best chance we have of stopping this is a strong show of agreement across the community.
For those who oppose this kind of behaviour by the US Government, it's a relief that they picked on Apple: a company with strong opinions about this topic, and the financial wherewithal and gumption to oppose it as robustly as anyone.
Not people—companies.
Not just targets of bad publicity, but probably lawsuits as well. The Feds don't want the dismantling of the 4th Amendment to be challenged in court and the companies complicit in said dismantling don't want it to hurt the bottom line.
Not only that, but so many other tech companies rely on user-data. They can't sell it, then turn around and say no when the govt asks for it.
I don't think it was luck, I think they picked on apple specifically because they clearly state that they don't rely on that data.
That's not clear at all. It's hard to find neutral ground in political problems like this. Staying quiet to avoid implication isn't a neutral position. Evil triumphs when good men choose to step aside instead of helping their neighbor.
Tim Cook is the only one doing the right thing here.
Because it was Tim Cook who was dragged into this mess. What if the shooter had an Android phone, rather than an iPhone? I'm sure Lary Page would be penning a similar letter, in that situation.
Only Apple takes security seriously.
Only the fact that this is a terror case makes them willing to roll the dice at all on the craps table of public opinion. It gives them an advantage, but not an overwhelming one.
I absolutely believe that the FBI thinks this is the only way to get this data.
Yes, they might like to get a strong precedent in favor of this, but what if the precedent goes against them? You never know what you're going to get in court. This would be appealed to the 9th Circuit, which has a history of being skeptical of government arguments in favor of collecting digital data. And if the Supreme Court deadlocks 4-4 (as it could now), the appellate ruling would stand.
Apple put in a feature, which they may circumvent, that will effectively brick the device if it is tampered in certain ways. The lowest risk option for retrieving the data is to get the people who designed the device to implement their circumvention method. That is exactly what the FBI asked for and what the judge agreed to.
Why should the FBI have to waste resources reverse engineering Apple's product (and risk destruction of evidence) when Apple is wholly capable of helping out?
If a warrant can force Apple to do this work now, then what is the criteria that would determine when Apple wouldn't have to help out? That is the key legal question.
If a warrant can force Apple to do whatever the warrant says would be helpful to the FBI, then that's a pretty huge scope of potential work.
so now apple has to pay for engineers to design and implement this change to their product because the government said so? why is apple required to "help out"?
I do think there are some interesting questions about "forced work" here, but that can be said of any subpoena, and I don't think many would contest the entire concept.
From my standpoint: Apple can prove critical in obtaining whatever evidence/information may be on the device. It may certainly be the case that there is nothing valuable there, but such events should be thoroughly investigated. This was a personal computing device of a person who killed many, we need to know what is on it, and we can. It wouldn't surprise me if Apple were already working on the software.
> Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession.
> The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor.
So it's not a matter of technical impossibility.
The best part - even if google can make custom version of the OS it won't help the least.
It is a tough nut to crack.
But if you buy Apple you won't have to.
Apple tried to do it by providing also their own key, but that helps little when a dedicated agency has physical access to the device. And legal hammer to compel Apple to spill the beans.
http://blog.trailofbits.com/2016/02/17/apple-can-comply-with...
The short answer is, Apple compensates for the low entropy of 4 digit PINs by rate-limiting the number of guesses you can make.
So apple didn't provided their users security. They provided security with potential backdoor in the design.
So I say - it is good if FBI can force apple to exploit their own backdoors - to learn their lesson.
I'm not certain what you're asking for here. A device that is completely impregnable?
Or just some honest marketing. Like - your device is not secure if we cooperate with LEO and let consumer make their choice.
But yeah all that be damned - let us see how quickly we can paint the other teams in gray. Let's also ignore that Google's CEO basically agreed with Apple's and if someone brings it up let's dilute it - not strong enough words and it's on Twitter!!
Oh and while we are at it let's jump to the "you're the product" bandwagon as well especially when it isn't relevant to $subject at all. Clearly since Google and MS sell your data (whatever that means) they don't care about your privacy right? I guess Google forgot about violating your privacy if you are using ChromeOS - https://www.chromium.org/chromium-os/chromiumos-design-docs/... ?
Microsoft also forgot to violate the privacy expectations of their Irish customers I guess - https://en.wikipedia.org/wiki/Microsoft_Corporation_v._Unite... ?
And yes let's also imply that since Google and MS can read your email - getting that to the government is no big deal for them! It's the same thing right - government's just gotta sign up for Bing Ads and Google Ads?
When the other titans don't have that feature, they have less of a stake in the argument at hand.
Their business model is to sell ads to 3rd parties based on the information they have about you. Selling your info itself would be detrimental to their business.
Google's targeting would be less effective if they gave everyone PGP keys and locked themselves out of the conversations they host.
Making money from targeted ads doesn't mean they think the FBI should be able to bypass device security via hardware and software vendors.
Basically: making money from data != believing that a right to encryption doesn't exist.
Of the total number of requests, which Apple references here: http://www.apple.com/privacy/government-information-requests...
> 94% were Device Requests--law enforcement seeking a stolen device
> 6% were Account Requests--law enforcement seeking personal information
> 27% of U.S. account requests received between 7/1/14 and 6/30/15 resulted in disclosed content.
> Less than 0.00673% of customers have been affected by government information requests
Interesting stats...
It's also very important to note that preview law enforcement requests are not in the same scope as the FBI's request published yesterday. All of the information disclosed above is data held by Apple. The new request is for Apple to commit development resources to produce brand new software, not just turn over data.
It would be absolutely trivial to disable security features before selling to the customer. Afterward is more difficult.
They question the lawfulness of this particular request.
But, one thing has been bugging me about this case and your comment that Apple questions the "lawfulness of this particular request" leads me to ask:
Does 4th Amendment protection end at death...?...the terrorist is obviously dead...
I've been looking and don't find answers that satisfy me...?
Anyone?
So this request is really a request for Apple to develop a way to break their own encryption, which brings up a lot of slippery slope concerns. If Apple can be forced by the government to develop a way to break into this version of their OS, what would stop them from being forced to develop cracks for other versions of their OS?
Few years back Cornell University adopted Gmail for their staff and faculty under the condition that the company wouldn't data-mine the emails. Google did anyway. Now we use Outlook.
is this site[1] old then? Sounds like they have a very explicit privacy agreement[2], which isn't surprising...Cornell isn't a small school.
(according to the wayback machine, the privacy section in [2] has been in place unchanged since February 2012)
[1] http://www.it.cornell.edu/services/cmail/index.cfm
[2] http://www.it.cornell.edu/services/cmail/faq.cfm#privacy
Still with that out of context quote?
And then you could explain why Cornell uses Google Apps for the students.
An encryption bill that is being worked on by the Senate that would try and make it a crime to not help the government decrypt messages from smart phone or other device.
Suddenly these courts find they can't get evidence to convict people if their phone is encrypted and so are the messages. So they want tools to decrypt the messages to get the evidence.
As usual for him, it's hyperbolic and over the top.
It starts with this...
> This is a black day and the beginning of the end of the US as a world power.
And snowballs into this:
> And why do the best hackers on the planet not work for the FBI? Because the FBI will not hire anyone with a 24-inch purple mohawk, 10-gauge ear piercings, and a tattooed face who demands to smoke weed while working and won't work for less than a half-million dollars a year. But you bet your ass that the Chinese and Russians are hiring similar people with similar demands and have been for many years. It's why we are decades behind in the cyber race.
Yes, McAfee just said that the Chinese and the Russians are hiring people who insist on smoking weed at work.
I've considered federal work before but every time I think hard about it, I keep coming back to the scene in Snow Crash where the fed works at a place where every little action - the time you arrive, the time you leave, whether you take the stairs or use electricity by taking the elevator - is scrutinized and judged. Yuck.
I work for a defense contractor, and while we do have some annoying DCAA-mandated timekeeping policies, it's really not half as bad as the Snow Crash FBI. We just have to write down time in, time out, and the amount of time worked on each contract each day (in tenths of an hour). The first two are only because the DCAA mandated it, and the third is for accounting purposes (IIRC, the company gets paid based on how many hours are billed to each contract).
It's because of this, by the way, that overtime is virtually nonexistent here; we can't bill the government more hours than have already been agreed to, and it would be illegal to lie. Thus, if we end up staying late or working on a weekend to meet a deadline, we take time off later in the month so our billed hours for the month match up with how many the company is allowed to bill.
Oh, and I'm an openly transgender person with a pink stripe in my hair, and I've never had any trouble with either. There's also no dress code, everyone knows that I'm a heavy drinker outside of work (and doesn't care as long as I don't drink at work or come to work drunk), and the environment is relaxed enough that we can talk about any subject during breaks.
Wasn't that the corporate guy that did that to his employees? Intruding into their homes, even?
I can't speak for all federal jobs, but I doubt any involve anything like that level of busybody-ness unless a very high level of security clearance and access is involved.
Well, the Fed was the one that monitored everything at work and bugged its employees' home phones too. L. Bob Rife was the corporate guy who didn't think that that was good enough, and wanted to be able to partition work data in his employees' minds so that they didn't have access to it outside of work. I think Rife is mentioned in passing as doing the former kind of monitoring whereas the Feds' practices are described in excruciating (and entertaining) detail, so you can certainly be forgiven for conflating the two.
>Do you live in China (or Russia) and work for the Chinese (or Russian) government?
No.
I'm sure you understand his point.
The largest company by revenue would rank 28th in largest country in world by GDP.