Justice Department Calls Apple’s Refusal to Unlock iPhone a ‘Marketing Strategy’
nytimes.com
nytimes.com
<<Apple had asked the F.B.I. to issue its application for the tool under seal. But the government made it public, prompting Mr. Cook to go into bunker mode to draft a response, according to people privy to the discussions, who spoke on condition of anonymity.>>
http://www.nytimes.com/2016/02/19/technology/how-tim-cook-be...
In this case, the Justice department is clearly the one with the bigger 'marketing strategy' agenda here by trying to market the merit of their request to the American public and congress.
(As a side note, most of the non-tech folks I talk to seem to be siding with the FBI's request, so at least at some level, the government seems to be winning the marketing battle.)
They basically argue that Apple is incorrect about security implications and that marketing concerns don't cause undue burden. They also argue that Apple isn't above the law and just because Apple marketed themselves that way doesn't make a burden.
The question of whether such rights exist is separate from the question of whether breaking into one device threatens security of all others. If true that seems to call into question the assumptions on which data protection algorithms are based. In other words, assuming you can create truly unbreakable encryption and it only works if there are no backdoors, is that really a data protection strategy that meets the needs of society as a whole? You could argue it's flawed even if the mathematics work perfectly.
p.s., I'm not defending the Chinese position in any way. If it were my company I would leave the market.
p.p.s., For anyone down-voting it would be helpful to state your argument for doing so. The Apple case is not as clear cut as some of the learned commentary on HN would have it.
It seems here that nobody here is concerned about non USA citizens.
in China.
Can you imagine what a reputation for standing upto governments (in a democracy, but with most of your employees as taxpayers) will look like?
And let's be honest... this is marketing by the FBI too, picking a convenient fight on ground of their choosing to obtain this new power. The Justice Department is right, but the Federal Goverment is not in a position to throw stones from their glass house here.
"Apple wouldn't even use their technology to get the information off of the phone that the terrorists used" will make a powerful headline when the FBI and NSA are asking for the rest of the backdoors they want.
http://mobile.nytimes.com/2016/02/19/technology/how-tim-cook...
https://www.eff.org/deeplinks/2015/10/apples-eula-gives-it-l...
The government's approach is a double-edged sword. On one hand, they can pick an "easy case"--as they have here--and hope to establish a toe-hold. On the other hand, the precedent created by an "easy case" can have an anchoring effect that limits its reach. When a principle is applied to overwhelmingly favorable facts it can leave courts looking for the mirror-image scenario: if the burden is reasonable here, when is it unreasonable?
1) As Bruce Schneier poits out, if Apple can write the code to break the security, so can others (especially if they steal Apple's signing key). (He also says the vulnerability is not just in the 5c but in current iPhones too.) [1]
2) Considering #1, and that every system ever designed has many vulnerabilities, I find it hard to believe that the US government hasn't developed exploits. Perhaps they just don't want to reveal that in such a high profile case.
----
[1] https://www.washingtonpost.com/posteverything/wp/2016/02/18/...
What I don't quite understand is - how does this affect newer devices, will Apple be legally obligated to build a backdoor to circumvent the enclave from here on (if Apple complies, that is)?
(But even the idea of older generation devices being "fair game" for the government (any government - if it was done for US, it's now possible in any country Apple operates in) is creepy).
Also - what can possibly be on that phone that isn't available elsewhere? Phone records exist at phone companies, social network stuff can be obtained from the facebooks and googles, if they were using watsap - well that's not something Apple could decrypt anyhow...
I'm leaning towards the opinion that Tim Cook was right to make such a big deal out of it, even if it's a 5c.
That's why they're making their stand in this case.
In the future Apple may make it so that the iPhone must be unlocked before an update could be applied, but that isn't the case now.
Unfortunately, Apple is peeing in the pool for all of us that actually care about digital freedom. This case will set a terrible precedent, and prime government to preemptively address hypothetical devices that are secure.
Apple already "unlocked storage unit" to police where they had keys by providing police iCloud backups. Now police is asking Apple to "demolish the building".
If you think anything more than one phone's security is being "demolished", then you've been mislead by Apple into thinking their devices have security properties that they don't actually have. If their reputation takes it a hit, it will be due to their negligent design and marketing, not from the inevitably resulting correction. Security does not suffer politics.
Inside the storage unit is yet another invincible locked container, but the FBI is betting on the key being easy to guess.
It's hard, but you actually have to throw the ring into Mount Doom. You can't just put in your pocket and promise to never use it.
But you're right, it's a similar activity. Which is why the ideal move this iteration would have been to nicely go along and avoid setting a precedent until Apple was actually shipping a secure phone.
Even if Apple prevails, then the FBI subpoenas technical documentation and the signing key, and gets an independent party to write the code. The signing key would be another legal battle (and at least Apple is well funded unlike Lavabit), but that ultimately comes down to Apple having the only key to a container for which there is a warrant. Do you see this ever being decided in favor of the key holder's non-involvement, especially in such an unsympathetic case?
That's precisely why all writs is not a red herring. If all writs is not limited at this stage, it will be used for exactly what you are most afraid of.
If revealing Apple's key for the iPhone's backdoor is a national security threat, then Apple can avoid this by simply using the key to open the one specific door a court asks (that's how the argument would go).
Plus, they ultimately don't care whether proper crypto is outlawed or not. Sure they'll lobby for it not to be. But if they end up losing they'll just modify their products and still be the least-surveilling company - they're not particularly worried about Free software eating their market share.
Also, I believe you just called Tim Cook a flat out liar, since he has repeatedly, publicly talked about his and the companies beliefs about crypto.
Apple believes that proper crypto can be used to provide the best security for their users, and Tim Cook may personally believe that crypto provides the best rights to individuals. But corporations operate in terms of what is legal. If proper crypto were made illegal, that just shifts the playing field for everyone. Apple would still exist and try to provide the best security they legally could - they don't have a mortal stake in this fight.
This attack isn't some discovered flaw, but an explicit property of their system design. There are widely-used systems that hold up to the attack in question. For example, Linux's LUKS/dmcrypt does not have this vulnerability.
Apple wishes to use lower entropy passcodes, necessitating the use of trusted hardware. Few have gone down this road, so I've detailed properties of a hypothetical design that could be free of manufacturer backdoors.
Apple needs to either stop marketing their devices as secure against nation state attackers that can compel Apple, or actually build trusted hardware that's secure from manufacturer as I'm describing. Cryptography is not a "best effort" endeavor.
The fundamental flaw remains that Apple utilizes closed-design trusted hardware based on a manufacturer backdoor. This type of system is insecure against the manufacturer (and by extension USG), and marketing it as secure against such is willfully negligent.
If you want to persist in that assertion, you should easily be able to point to the marketing you are refering to.
1. Apple does not market their devices as secure against nation state attackers.
2. You have not detailed any alternative that is.
Then what exactly is this court case for?
> You have not detailed any alternative that is
As I had just said, Linux's LUKS/dmcrypt. The authors simply do not have the power to unlock other peoples' volumes.
Some other properties are traded off, but since you are unwilling to discuss system models ("completely hypothetical"), then I don't see the point of detailing the landscape. A system can have a vulnerability without needing a nearly-identical system without the vulnerability for comparison.
You don't it to be nearly identical, but if it can't do the job, then it is an invalid comparison.
This case right here! We've got, by most anybody's standards, a legitimate search warrant. There's no judicial overreach with regards to scope; process is the only thing they're arguing in the legal realm. The FBI could adjust their request for technical documentation on the KDF, create their own hardware, and the forced creation aspect would disappear.
The only reason Apple didn't quietly unlock the phone was because the FBI publicized the request (against Apple's wishes), and Apple wanted to avoid the inevitable press field day undermining their reality distortion field of "privacy".
> LUKS/dmcrypt is a small component that cannot provide anywhere near the necessary features to substitute for the iOS security system.
LOL. And yet a default Debian install would be locked for eternity (barring implementation flaws, which are not under discussion here for either system).
You can't have it both ways - arguing the properties provided by each system differ, while simultaneously refusing to discuss security models. You're attempting to narrow the domain to a single point, so that no objective comparisons can be made.
The sheer ridiculousness of this statement leads me to believe I'm talking to an Apple partisan rather than someone who earnestly analyzes security, so I don't see the point of continuing this discussion.
A default Debian install is nowhere near to being able to replace iOS as a practical smartphone OS for 1 billion users.
This is an indisputable fact. What is ridiculous is that you seem to be claiming otherwise.
We are talking about the real world where objective comparisons can very much be made. I'm trying to discus real software - not fantasy extrapolations.
For the record, if an open, secure, and practical alternative existed I'd much prefer it to what Apple has produced, and I have been hoping for such a solution since the iphone was introduced.
It seems a lot more like you're the one with an agenda to push.
It sounds like they could have made a device that even a firmware update couldn't break, but they didn't. I really don't see how they can refuse. Your analogy is good.
This is nearly impossible because the development lifecycle and end-user usability almost necessitates there be software or firmware updates that would be authenticated (to either fix dev bugs or help users).
To avoid bricks, a full device reset puts the security chip into an unlocked state after erasing the encryption keys.
Let's hope more "greedy corporations" seek out my business by supporting human rights. I'll buy that.
It's not just about this case, where any data on the phone will be of at best little value. It's about future cases, and the possibility of widespread abuse of the back door not just for "terrorism", but far less important things like minor drug cases - or worse, wholesale data mining, like the NSA has already done with phone data.
Thus, any decision that a company makes is in effect "marketing" if the goal is to grow/preserve market share.
It's unfortunate if the underlying mental model of employees of the Justice Department is that we should all sacrifice our privacy (and that of our customers) for some notion of the greater good.
It's scary when anyone thinks that his/her own job interests represent the greater good for everyone else... even worse when that job is a position of governmental authority.
Sorry, blind allegiance to the government is not a religion I want any part of. It's also odd to use the anti-capitalist smear technique of labeling something "marketing" to undermine it.
If the government want something done, surely it will have to be eventually? What do apple have to win by going up against them? Gov could make their life pretty difficult?
How did the government get such power? Immediately via overthrow, or incrementally?
At what point do you draw the line? Has there ever been a government that got some power and then stopped trying to get more? Look at the history of the USA for the past 200 years.
Apple is trying to draw a line in the sand. We can debate about where the line should be, but there has to be a line.
No-ones going to ever know really, bar apple and the gov
Either they are tone-deaf or being deliberately ingenious about things. Neither is a good thing.
I think both sides of the case are engaging in a lot of PR. The original FBI request for unlock looks pretty tame, unlock ONLY that device, disable ONLY a software protection that would delete files on failed attempts. I think the best way to compare it to is physical objects so we can get the software pieces out of the way and reason with it a bit better. Would it be within the FBI's power to ask a Safe-maker to disable a mechanical security measure on a safe that destroyed the contents of the safe when the combination was entered incorrectly after a specific number of attempts, and the FBI had no other way to obtain entry to it?
I'm not sure how far that analogy gets you or what the laws actually are, but the only way to actually get them changed is to challenge them.