Apple Has Not Unlocked 70 iPhones for Law Enforcement
techcrunch.com
techcrunch.com
Couldn’t Apple simply remove the ability for a software update to take place without the device being unlocked or wiped?
Obviously this wouldn’t apply retroactively to old IOS versions, but it would be consistent with their change in policy from IOS 7 to 8.
Edit: No, apparently this is wrong. I got it from https://www.washingtonpost.com/news/volokh-conspiracy/wp/201... , but that article has since been updated.
The California case, in contrast, involves a device running iOS 9. The data that was previously accessible while a phone was locked ceased to be so as of the release of iOS 8, when Apple started securing it with encryption tied to the passcode, rather than the hardware ID of the device. FaceTime, for instance, has been encrypted since 2010, and iMessages since 2011.
So Apple is unable to extract any data including iMessages from the device because all of that data is encrypted. This is the only reason that the FBI now wants Apple to weaken its security so that it can brute-force the passcode. Because the data cannot be read unless the passcode is entered properly.
the phone at the center of the current controversy had not been updated to the new version of iOS
If the phone was on iOS 9, as the article claims, then... that's the latest version of iOS.
People keep saying this but it probably isn't true. When law enforcement has physical access to the hardware, they can take apart the phone and flash it with new software and put it back together.
You can plug any iPhone into iTunes and flash new firmware to it, as long as it's signed by Apple. That's what the FBI want to do, I believe.
To prevent this kind of attack surface the mechanism for applying new firmware needs to wipe access keys for the encrypted data, and for these keys to not be accessible without changing the firmware.
[1]: http://techcrunch.com/2016/02/18/apple-apologizes-and-update...
One one hand, a corporate reputation. On the other, people from the FBI saying they need access to prevent terrorist attacks. There are many arguments to be made. This is not the winner.
If the suspected terrorists owned the phone themselves, we'd also have the 5th amendment wrapped up in that case too.
No we wouldn't. The "suspected terrorists" are dead.
The San Bernardino shooters demonstrated rather competent op-sec, and the 5c the FBI wants Apple to backdoor was a work phone, not even a personal one. I'm spectacularly skeptical they used that phone in any way whatsoever relevant to the attack. More to the point, the attackers are already dead. There is nothing to prosecute here.
They picked this case as the one to push because they thought it had the best PR value for their purposes, not because of any exigence or concern over further impending attacks.
That is to say, the FBI is cynically leveraging the outrage at a mass-shooting, inflicted by "brown people", to further their anti-crypto, "We must have access to ALL OF THE THINGS!" agenda. It's pretty disgusting, frankly.
EDIT: snark.
The courts, the congress and the people will ultimately determine who prevails.
The FBI's stated position, "These people did a terrible thing and we have to investigate it" is pure PR; the phone the case is proximally about is not at all what it's ultimately about.
How is this not a fact?
Referring again to my point up-thread about the shooters' op-sec, there wouldn't be any useful intel on their (once again!) work phone, anyway. "Investigation" is a red-herring to disguise their actual motive.
Red. Herring.
EDIT: Aside, I just went down a diverting and entertaining little web-hole on the etymology of the expression "red herring". It is, indeed, a deliberate diversion: in the 19th century, fugitives would cover their tracks with smoked (red) herring, because it would put the bloodhounds off their scent.
I see nothing "disgusting" about the FBI's behavior here.
I don't.
As for what the "majority of people" find reasonable, all I have to do is look at the polling numbers in the current presidential race to find myself in abject disgust at what the "majority of people" appear to think. They seem not to give half a shit what happens to anyone else, as long as they can watch the next episode of American Idol without fear of "getting blowed up by terr'ists" — despite the fact that more people have won the lottery than have died from terrorism in the US since September 11th.
EDIT: Anyway, there's nothing new or informative to be found in this discussion. We disagree. Let's leave it at that.
If you want the law to change, I would hope that the court sides with the FBI, as that will provide far more ammunition to anyone wanting to change the law than ruling in favor of Apple.
We saw it all over the fucking Bush campaign when special rendition reports and waterboarding shit was coming out. We even saw Bush (probably Cheney) writing his stupid little memos which he tried to mold into executive orders, absolving the CIA of torture.
Does anyone actually buy this fucking defense?
AFAIK, I don't think we know, or can compare. It's my understanding that Apple's setup is closed-source, so we can't inspect, whereas Android's is open.
Someone please correct me if I am wrong.
>Also, are there any precedents of any government demanding the unlocking of any Android phones?
This isn't an issue, as, by default, android phones send everything to the cloud (exceptions for custom roms, etc). So govt can just ask Google for a copy from their server instead.
> For iOS devices running iOS versions earlier than
> iOS 8.0 [..]
> Please note the only categories of user generated
> active files that can be provided to law enforcement [..] are:
> SMS, iMessage, MMS, photos, videos, contact, audio recording, and
> call history.
> Apple cannot provide: email, calendar entries, or any third-party
> app data.
What is the difference between the two categories? Are email and calendar entries encrypted on iOS7 and below?Report is extremely misleading and an example of bad journalism.
My views on the general encryption controversy are:
1. Everyone must be free to make their technology as secure as they possibly can. There can be no mandated weakening of security, back-doors, or other requirements to make the information more easily accessible by law enforcement. On newer iPhones, Apple has patched up the flaw that the FBI wants their help with exploiting. They must continue to be allowed to do that.
2. The government must be able to demand, with a court order predicated on probable cause, that companies provide any and all information that they have that could be useful in circumventing their security features. This can be everything from technical specifications and threat-model analyses, to lists of unpatched vulnerabilities and code-signing keys.
3. It seems to me that American companies have a moral obligation that goes beyond the legal obligations in point #2. They should be actively assisting the government in recovering information, especially when concerning issues of national security. In extreme circumstances, like total war, this should definitely be legally mandated. I'm undecided as to what the policy should be generally. On a practical level, it's probably not feasible for the government to, e.g. start hacking around the iOS codebase themselves, so just information might not be enough.
I'm not too troubled by this court order, especially given the particular circumstances. The right to make products as secure as you can, even from yourself and the government, is what's really important to defend.
Trying to argue that the tech industry shouldn't help, even in this case, is not only the wrong position in my book, but a sure way to lose the bigger debate.
Disclaimer: These are obviously my own personal views and nothing else. They do not necessarily reflect the opinions, policies, or practices of anyone but myself.
Apple sells tens of billions of dollars of iPhones to China every year. If Apple provides assistance to US law enforcement but not to Chinese law enforcement, that's going to be a disaster. But if Apple provides assistance to Chinese law enforcement, that's a different kind of disaster.
So yes, the Chinese government should absolutely have this authority; they wouldn't be much of a government otherwise. They should also absolutely have protections against unreasonable searches and seizure. The lack of these protections is the problem, not that their government has search and seizure powers. A tech company operating in China has to make a choice between subjecting itself to Chinese law, or not doing business in China.
The same goes for policing in general in authoritarian regimes. The Chinese police state is undoubtedly evil. But I'd bet that most of the time, they're going after your run-of-the-mill crooks that need to be policed in China just as they are in America.
Your argument is a good one though. I think there is a real danger of accidentally building the infrastructure for a future totalitarian regime. It's also a good political argument when it comes to international issues, like Microsoft's argument that the US government can't force them to hand over data that's stored in Ireland. I'd like to see Microsoft win the case in court, but I suspect that the government will win. US court orders are binding even when they require you to break foreign laws. But the government exercising that authority in this case could totally undermine US cloud data providers, so I suspect that Congress could be persuaded to restrict the government's authority here.
What's not fundamental is that it should not be used UNLESS you are suspecting a person of wrongdoing with serious facts in the first place. It's never supposed to be an all-encompassing absolute power.
> I doubt any modern state would be viable without it.
There's hardly any data on states that don't exercise such powers, so don't spread the fallacy that the opposite cannot be true. It's not because right now A is linked to B that you actually need A to have B in absolute terms - you just don't know that. We are living in an era of nation-states themselves coming from a long history of monarchical power (an inheriting the same rights and powers, more or less as governments instead of a single person), so it's not like we have ever tried to design societies in a very different way at all so far.
I agree 100%. In this case, the government has a court order for a specific phone used by a specific person who committed a particular crime. What exactly are you arguing against?
> There's hardly any data on states that don't exercise such powers, so don't spread the fallacy that the opposite cannot be true.
I'm sure there's an interesting discussion to be had about alternatives to the nation-state and how they might control the exercise of violence, which is by definition the fundamental characteristic of any system of government. But we live in a world where this authority is centralized (or sometimes, in federal systems, split between different levels of central authority).
I was arguing about your statement that seemed like a blanket one. I have no problem with the use of search in this particular case.
> But we live in a world where this authority is centralized
Yes, but that does not mean there is no alternative. Large scale societies are still very recent in Human History - and authoritarian systems have largely led to wars up until now, so assuming this is the only working system is just survivor bias at work.
This request is not so much a red line, it's more of a yellowy orange line. A yellowy orange line that takes us one step closer to crossing the red line without even realising we are doing so. See: http://imgur.com/xWpvw
There is a real danger in accidentally building the infrastructure for a future totalitarian regime.
Full credit to Apple for actually seeing this and being willing to make a stand.
I think it's more they listen to the NSA rather than the FBI, as opposed to giving the tech industry any sort of benefit of the doubt.
https://theintercept.com/2016/01/21/nsa-chief-stakes-out-pro...
> In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession.
Please see this comment for discussion about that line of reasoning: https://news.ycombinator.com/item?id=11131777
I'm not saying that your intuition here is wrong, but rather that Cook's statement has some subtle nuances to it that some seem to miss.
There's valid questions whether a data set should or needs to be encrypted. But giving up private keys means some entity can masquerade as that key's owner, and alter what that owner has written. Not OK. Authentication, veracity, provenance, of a data set is vital to the trust model. Why would you advocate breaking this?
Second, assisting which government? Any? All? Some? What's the metric?
A digital signature does not inherently mean much. It just (pseudo-)guarantees that a holder of a copy of the private key signed the data. Taking that to mean anything else, such as that a signed update was freely designed by Apple with only pure intentions, or even that Apple is the only holder of the private key, is nothing but our own wishful thinking. This court order has hopefully shattered our naivete. The real-world now says that you can't trust that a third-party's private keys are not controlled by governments. It was extremely unrealistic for Apple to include the government as an adversary in their threat-model, claim to protect against it, but then leave this opening.
>Second, assisting which government? Any? All? Some? What's the metric?
When it comes to questions of legality, the simple answer is that the company has to abide by the laws of all of the countries that it operates in. If they don't want to, or if they can't because two countries have conflicting legal demands, they have no choice but to leave that country. This cannot be any other way. See my other responses in this thread for a more detailed discussion of this "but what if China did this" issue, if that's the argument that you're alluding to here.
When it comes to questions of only morality, it's up to the individual people in a company to advocate for the right course of action. Only their own conscience, and the free judgments of their peers, can guide them.
You're basically making a might makes right argument, far extended from a Hamiltonian position of implied powers.
If public key cryptography can't be trusted, and governments are as a matter of fact not fully trusted and in at least the U.S. we're taught explicitly that it can't blindly be trusted which is why we have a written constitution, then the entire trust model fails and we can just stop with all of this nonsense and go back to pen and paper.