https://www.reddit.com/r/technology/comments/46exkr/john_mca...
https://www.reddit.com/r/news/comments/46np5t/san_bernardino...
Any truth to this?
https://www.reddit.com/r/technology/comments/46exkr/john_mca...
https://www.reddit.com/r/news/comments/46np5t/san_bernardino...
Any truth to this?
Secret Memo Details U.S.’s Broader Strategy to Crack Phones
http://www.bloomberg.com/news/articles/2016-02-19/secret-mem...
"Silicon Valley celebrated last fall when the White House revealed it would not seek legislation forcing technology makers to install “backdoors” in their software -- secret listening posts where investigators could pierce the veil of secrecy on users’ encrypted data, from text messages to video chats. But while the companies may have thought that was the final word, in fact the government was working on a Plan B. In a secret meeting convened by the White House around Thanksgiving, senior national security officials ordered agencies across the U.S. government to find ways to counter encryption software and gain access to the most heavily protected user data on the most secure consumer devices, including Apple Inc.’s iPhone, the marquee product of one of America’s most valuable companies, according to two people familiar with the decision."
But... the fact that Apple can do anything is a result of the OS update backdoor in the first place in this case! If this were a 5S this entire court case wouldn't be possible. This court ruling is not "Apple needs to install a backdoor". It's "Apple needs to exploit the backdoor they have a key to".
Someone in this community could quite reasonably root against apple, on the basis that a DOJ loss would give the DOJ a lot of fuel to push for legislation mandating backdoors.
It's a very different situation when Apple can reasonably do something to undermine encryption and when there's nothing they can do, and the precedent going forward from this case is negligible considering that the 5C is the last holdout of an enclave-less iPhone. What we should fear is legislation that bars the creation of truly secure phones. A ruling for Apple might aid in the creation and passing of such legislation.
This is just one more step towards winning the Crypto Wars-
The Crypto Wars is an unofficial name for the U.S. government's attempts to limit the public's and foreign nations' access to cryptography strong enough to resist decryption by national intelligence agencies (especially USA's NSA)
Or else, even if this case doesn’t give them sufficient precedent to force that kind of access, it’s certainly a legal stepping stone along that route, which is precisely why the FBI is taking the case all the way even though it’s clearly not necessary in this specific case - the NSA is perfectly capable of gaining access to the phone in question if they want to & according to Snowden they even have the legal right to do so since it was a work-issued phone where the issuee had signed over the right to scrutinise it at any time.
Sure... if there's a warrant for a specific phone, and that Apple even has a way to update the Secure Enclave (my understanding is that updating the Secure Enclave wipes the contents).
One overreach I could see happening from this precedent is getting Apple to participate in a targeted wiretap: Target brings phone to iStore, Apple "accidentally" wipes Secure Enclave (installing backdoor), and target could now have phone hacked later. Contrived, but I think this would be precedent.
But in no way is this ruling a precedent to push out a backdoor to every iPhone ever made. And the precedent that Apple must help unlock an iPhone has existed for over 100 years I think. Based off of the whole "digital key" == "Physical key" logic of the courts, if Apple didn't want to help exploit the backdoor, a judge could probably rule to force Apple to hand over its actual signing keys for updates. Awful, but the precedent is totally there
At the moment, for phones with a secure enclave, this isn’t possible: Apple intention was to create a system that they themselves can’t crack precisely in order to prevent anyone else from being able to crack their phones. It’s possible that the NSA has physical attacks that can work around the secure encalve now, but these are always vulnerable to future improvements in the devices - the government would vastly prefer to have some kind of mandated access.
Winning this case is a step along the path of building up the legal precedent for them to be able to do this. Sure, by itself it won’t be sufficient, but they don’t expect it to be - it’s a stepping stone along the route.
For the second link, where they suggest turning off the phone after a passcode attempt, I believe that hole was patched with an iOS update at some point.