Are search warrants oppressive? Can you distinguish this request from the FBI requesting a safe manufacturer modify the firmware on a single safe?
I doubt either of these can be reliably argued.
Are search warrants oppressive? Can you distinguish this request from the FBI requesting a safe manufacturer modify the firmware on a single safe?
I doubt either of these can be reliably argued.
It's not "going dark" that is an unprecedented change, it was the brief "going light" period that preceded it. Law enforcement has apparently lost the ability to do on the ground investigation work in favor of whiz bang-ery (and intelligence has lost the ability to do humint). Well, whiz bang-ery is a two way street. Now is the time to revive those old skills and deal with a _return_ to a world where you can't just outsource your job to a wire tap.
Phone call, texts, or data logs? Subpoena the cell company or the ISP.
Email? Subpoena the hosting provider.
Any communications used on that phone traveled over the Internet, and the logs are most likely preserved. They could get all of the logs of outgoing requests from the cell company and then go to each service provider and demand dumps of data from any accounts that Phone logged into right?
The primary service provider being Apple, who operates a fully encrypted messaging system where the cleartext only ever exists on the device.
It's a child abuser's wet dream.
Chances are, this happened at least once over the lifetime of the terrorists ownership of the phone - thus we can at least see who they are communicating with, right?
Wouldn't that be a good starting point?
And call records - they must have called someone - if only to talk about the weather.
Is that really acceptable to you? Maybe they accidentally screwed up once so it's OK to keep the private affairs of a dead terrorist secret for no good reason?
> Wouldn't that be a good starting point?
I would have thought the best starting point was unlocking the phone, given the owner is dead and committed horrific crimes.
But not the service provider intentionally denying access to this vital information? What a bizarre twist of logic!
Surely they have enough evidence to convict the accused. The phone likely wouldn't give them anything essential to the case. It's already a wrap.
However, the legal precedent would be invaluable for future <s>rights violations</s>legal proceedings. They have 1. Nothing to lose in this particular case. 2. A maximally effective situation for getting this ruling, complete with irrational fear-based public support ("bcuz turrists!1!").
Seriously. If your goal is to create this legal precedent, go ahead and try to imagine a better scenario under which this could rule in your favor. I'll wait.
The only iPhone the FBI have is the work phone, which he might not have used to contact terrorists with it. If he did he'd destroy it as well.
The problem is that judges and politicians are not tech savvy enough to understand why they shouldn't force Apple to make a tool to break passcodes on iPhones. How that makes any iPhone insecure in the wrong hands.
A search warrant doesn't require me to create a new capability that did not exist before.
From the FAQ:
The digital world is very different from the physical world. In
the physical world you can destroy something and it’s gone.
But in the digital world, the technique, once created, could
be used over and over again, on any number of devices...
The only way to guarantee that such a powerful tool isn’t abused
and doesn’t fall into the wrong hands is to never create it.I don't see how that's relevant. If I invent a new kind of lock you've never seen before, you'll have to come up with a way to break it.
I'm asking for why a search warrant would be oppressive, even if it involved creating new firmware for a safe.
Why?
It might, depending on the analytical outcome of the three-factor test introduced in the _New York Telephone_ case. (This case was decided before compelled pen register assistance was prescribed by Congressional legislation.)
The case itself is illustrative and enlightening: https://supreme.justia.com/cases/federal/us/434/159/case.htm...
"The power conferred by the [All Writs] Act extends, under appropriate circumstances, to persons who, though not parties to the original action or engaged in wrongdoing, are in a position to frustrate the implementation of a court order or the proper administration of justice..."
The factors are:
(1) whether the third party is "so far removed as a third party from the underlying controversy that its assistance could not permissibly be compelled by the order of the court"
(2) Whether the burden placed on the third party is "unreasonable"
(3) Whether the assistance is "essential to the fulfillment of the purpose" of the warrant
It's unfortunate that Hacker News isn't commented upon by more attorneys, and that most news articles don't link directly to the legal filings in these cases; much confusion and false assumptions about the law could be clarified.
https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
A potentially important factor is that the phone companies used pen registers themselves all the time, whereas Apple has no desire at all to write the software that the FBI wants.
It's worth noting that despite the outcome of that case, Congress still had to pass CALEA, which seems to imply there are limits to what can be compelled under All Writs.
However, you actually have to get to the courts before the All Writs Act can be applied.
CALEA was passed to create a preemptive requirement for standardized wiretap interfaces/equipment, processes, etc, prior to any actual judicial warrant or writ being written.
The fourth amendment grants us protection against "unreasonable" search and seizure, but doesn't grant the government an affirmative right to require that future "reasonable" searches be easy, or possible.
It also (unfortunately, in my view) doesn't prevent the government from requiring preemptive action to support future searches, and that's what CALEA does.
The reason I say that, is that now that it has been proven the phone does not permit access, the FBI is trying to use a warrant to force Apple to break into the phone. But if providing access was never a legal requirement in the first place, why is it Apple's problem now?
Yes, only Apple can do what the FBI wants to do. In my mind, that should not be sufficient, in the absense of a legislative requirement, to force Apple to break a software system against their will--even their own software system.
I mean, let's say the FBI wants to run a sting operation against a gangster. Can a court use All Writs to force some random person to participate in the sting? I would think not.
Let's say law enforcement needs to pull a hard drive from a 30th floor apartment, without alerting the doorman. Can a court use All Writs to force a rock climber to climb up the building and go in the window to get it? Again, I would think not. Even if there was only one rock climber in the entire U.S. who could do what the FBI needed, it doesn't seem likely to me that an All Writs warrant would succeed against that person.
So why should it succeed against Apple? I mean, Apple is the only company that can do what the FBI wants--true. And they did build the phone to prevent access. But there was no requirement to build it any other way, so why would that be relevant?
If they didn't have it, they couldn't be required to use it.
Apple has many capabilities--they're a $500 billion dollar technology company. Which capabilities are not available to the FBI via an All Writs warrant?
I'll quote the DoJ's legal brief on how Apple is not "far removed" from this phone owned by a 3rd party:
"... the government is seeking to use capabilities that Apple has purposefully retained in a situation where the former user of the phone is dead ..."
"... iPhones will only run software cryptographically signed by Apple ... Just because Apple has sold the phone to a customer and that customer has created a passcode does not mean that the close software connection ceases to exist; Apple has designed the phone and software updates so that Apple's continued involvement and connection is required."
"More generally, the burden associated with compliance with legal process is measured based on the direct costs of compliance, not on other more general considerations about reputations or the ramifications of compliance".
That does not in any way explain why Apple should be compelled to write new software, that they would not otherwise choose to write, before pushing it as an update.
Apple retained the ability to push updates to improve the performance and security of products, not to make it easier to hack them. There is a difference!
Nobody else can.
That's a big difference.
ISTM the right outcome is for Congress to weigh in with specific legislation that can supersede AWA in cases like this.
And calling it "creating new technology" (not your words, but others'), is silly too. Doing almost anything with software is creating new software, but calling it new technology makes it sound like they have to go out and do a bunch of R&D and make some significant breakthroughs or something. In reality, it's a trivial thing.
To address the quote you posted, it sounds like Apple is probably lying there too. Especially given the vast exaggerations in other parts. I highly doubt they would have a hard time making a modified OS that was device locked.
But if it's really true that they can't make a device locked firmware, well, then of course I hope they win this fight.
Possible? Maybe, but if it was that simple the FBI could simply change the signing key. It's not, and they can't.
The question is can you change one devices ID to exactly match another. This might require hacking the BPP or finding a SHA1 hash collision, both of which are absolutely possible but not necessarily trivial.
It is foolish to assume that the FBI would stop at this special version of iOS, especially given how they have been arguing and fighting to break encryption for over two decades.
edit, on icebraining's interpretation:
That's exactly right - once the difficult part about targeting an individual phone is finished, it's easy to take the iOS signing key and target any device you want.
Clearly it is not, otherwise they would have done this. They did not.
This is what I understood, at least, from the parent's post.
An earlier comment with more technical detail: https://news.ycombinator.com/item?id=11141499
UDID lock is good enough for tying development builds to specific devices but is not an unbreakable guarantee the software cannot be run on another device.
Yes, if you can do that, then you can flash anything to the phone. When someone shows me that happening, then I'll believe in this technology.
Even then you cannot "flash anything" to the phone. But you can flash a build signed by Apple which hard-codes a UDID check.
For example changing the WiFi or Bluetooth MAC is not locked down and effects the UDID. Because the UDID was never intended to be a way to bypass the device encryption it was not designed with anywhere near the same level of care and sophistication as handling the encryption key itself.
I never suggested the UDID. Please don't ascribe a claim to me that was never made. SHA512 the serial and macs independently. Job done.
This is not mysterious. Can the FBI require a software company to subvert their own security guarantees? Should they? Do bank vaults have back doors for the FBI?
That's a bit of a specious argument though – of course, if they produce different software in the future, it could be used again!
If the FBI want their own ability to sign Apple updates, then that's obviously a different situation. But the point you were making – that it's not possible to write software that will run on only one device – is not true in this case.
This is not mysterious. Can the FBI require a software company to subvert their own security guarantees? Should they? Do bank vaults have back doors for the FBI?
I don't really know the right answer.
What prevents the iOS image from being loaded onto another device?
Apple isn't magic; the code they write to verify device identity isn't going to be the first perfect, unbuggy, unexploitable code written in human history. if(device_udid == terrorist_id) {...} might seem infallible, to you, but the reality is that the device_udid is just SHA1(Wifi MAC + Bluetooth MAC + ECID + Serial). All of those are writable, some via the Baseband and some via physical access. Generating SHA1 collisions is completely feasible for ~$1,000,000 of computing time, which is chump change to nation states.
There is no infallible way for Apple to make an iOS version for one single device.
Edit: And stories like http://abcnews.go.com/Technology/york-da-access-175-iphones-... make it absolutely clear that this is not stoping at a single device.