But isn't the procedure already pretty straightforward and well known?
1) Make a build of iOS which has the pin timeout feature disabled.
2) Sign that with Apple's private key.
3) Flash onto the iPhone.
That's more or less it, right?
What's keeping the general public safe isn't some sort of secret or obscure procedure. The general public's safety is in Apple keeping that private key private. And the FBI isn't asking for their private key, they're just asking that Apple use it in private, just like they normally do when they push out normal updates.
Am I missing something?
This would require a new OS to be installed in a way that bypasses what I imagine are merely software blocks to installing OSes (it sounds like if they have possession of the device, they can install the OS to it).
This is a technique and a technique can certainly be replicated. Only problem is next time, Apple can't say, "this is an unprecedented step, and very burden-some," which actually turns out to be a legal basis.
This isn't them taking a stand in some sort of NSA spying case, as much as Apple fanboys seem to think that's what's happening here. They're refusing to lift a finger in an investigation of mass murder.
This is a common (and completely understandable) misunderstanding of the relevant paragraph:
"Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. ...
The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. ...
The government suggests this tool could only be used once, on one phone. But that’s simply not true. Once created, the technique could be used over and over again, on any number of devices. ..." [0]
Notice how the first sentence of the last paragraph talks about "this tool". "The tool" is the specific version of iOS that the FBI wants Apple to make that would only run on the phone that it wants to unlock.
Notice how the third sentence talks about "the technique". The change in terminology isn't accidental. "The technique" is "the act of demonstrating that Apple can create (and can be ordered to create) a backdoored version of iOS that bypasses tamper protection features of iOS".
The particular software that Apple would create can surely trivially be restricted to run on only a single iPhone. Unless there's a way to make iPhones run unsigned OS code without wiping the device, the only way that the image that Apple provides the FBI could be modified to run on a different iPhone is if someone got a hold of Apple's code signing keys. [1]
The problem to which Cook refers to is -therefore- not that there's a risk that someone might steal the image Apple provides to the FBI and use it to pwn more phones... it's that the government will do as it always does and keep coming back over and over and over again, demanding that Apple produce yet another image that unlocks yet another single phone of interest, regardless of whether or not they expect that the data on that phone will be particularly crucial to their case.
I expect that this would be disastrous for Apple's reputation. It certainly would not be good for society as a whole.
On the one hand, I can see how denying the government's request would be good for the industry and society. On the other hand, if the courts ultimately asserted that the FBI's request is legal and proper, it might spur Apple (and other similar companies) to ensure that the parts of their devices that handle device encryption and unlocking were not upgradable by any means... making generation of software to bypass features of those parts next to impossible.
OTOH, such an assertion would leave software-only privacy software (like Signal, GPG, WhatsApp, et. al.) in a really bad spot.
[0] http://www.apple.com/customer-letter/
[1] If someone gets Apple's code signing keys, many people are going to have many bad days.
> A law enforcement source in the San Francisco Bay Area has confirmed to CNET that Apple has for at least three years helped police to bypass the lock code, typically four digits long, on iPhones seized during criminal investigations.
http://www.cnet.com/news/how-apple-and-google-help-police-by...
It's one thing if you use it as a starting point for discourse, it's another when you use it to beat down the opposition with what amounts to childish antics dressed up in a suit and tie.
This must be weasel-word day. The FBI is asking for patch, hypothetically just for this phone. But only in this post have I seen anyone imagine "a way that can not be reused" since the point raised stated by the parent article is that such a patch could inherently be reused.