Mark Zuckerberg Backs Apple in Its Refusal to Unlock iPhone
nytimes.com
nytimes.com
The government says it just wants to unlock this one iPhone. But is it really just looking for a legal precedent in a case that the public is likely to support the unlocking?
Apple says is it afraid of creating a "master key" that could fall into the wrong hands. But doesn't it already have such a key, in the form of a signing key controlling what payloads the iPhone will agree to load? Is Apple primarily concerned with both precedent and perception of security on its phones?
I personally feel that any mechanism by which iPhones could be unlocked with a warrant -- but only with a warrant (ie. the gov't physically lacks the capability to do it themselves) -- is a good compromise. It's in Apple's interest to push back on such requests, so you have two powerful and well-funded entities adversarially fighting to define the line of what can get unlocked and what can't.
Now NSL's, those are a whole different kettle of fish.
There is no grey area for compromise here. The encryption is either secure and free of known backdoors—and thus it grants real security—or it isn't, and it doesn't.
And to your last point: this software is not secure. That's why we have this backdoor option.
> this software is not secure. That's why we have this backdoor option.
It's not perfectly secure, but still awfully secure if even the US Government can't break it themselves.
I believe they were just sloppy:
http://abcnews.go.com/US/san-bernardino-shooters-apple-id-pa...
"San Bernardino Shooter's iCloud Password Changed While iPhone was in Government Possession"
The information wasn't "awfully" secured.
(Emphasis added)
Just wondering how they can manage to produce something that will only run on this phone?
99% of the phone can be tampered with when running, after the signature is checked at install. They'd need to put that check in the secure enclave to make sure that it wasn't simply bypassed. That might not even be possible on that model.
So given that the iPhone is not secure, what do you think about whether Apple should execute this court order?
If the dead attacker had a twelve character passphrase, any amount of help from Apple would be utterly useless. Apple could write all the back-doors they liked but if the content is encrypted and the key is unknown, brute forcing is the only option.
The addition of the secure enclave makes it potentially infeasible to extract the UID so that the brute forcing could be performed on a powerful supercomputer. It depends how well the enclave has been hardened against firmware changes. Can the enclave receive a seamless firmware update while in a locked state? Can the enclave firmware be rewritten to output the UID to the main CPU? We don't know.
But common people won't. So no, Apple should absolutely not destroy the security of hundreds of millions of individuals just because some government agency wants a shot at access to some dead guy's phone.
What happens when the PRC or Saudi equivalent of the FBI demands the same for an FBI agents phone? Why should the populace and Apple have to suffer for making the world more secure?
Wait, how did you get to that point?
The FBI is currently arguing for point B - just this device. The argument is - it is so close to point A, there is no issue!
If the FBI wins point B, then they will argue for point C. - it is so close to point B, there is no issue!
If the FBI wins point C, then they will argue for point D. - it is so close to point C, there is no issue!
Repeat over and over.
At about point M or sooner an exploit or the extraction processes to the gradually less secure device would probably become available to governments through means legal or otherwise and we would probably hit point Z straight away.
Apple are trying to stop the inevitable by not starting, the FBI are arguing for point B.
[1] This is not an imaginary scenario. [2] This has actually happened.
https://www.google.com/search?q=Thailand+lese+majeste+Facebo...
With regards to international politics, if the USA can demand that Apple unlocks devices for any reason, then the US government will have a hard time defending a decision to aid Apple in resisting a foreign power when it requests the same broad privilege.
Basically, lim(consequences) = no guarantees that USA secrets are actually secret. If they can't keep the lid on one employee (Snowden) how on earth could they trust themselves with something this dangerous? 'Z' is inevitable.
The wording/example that Apple used really appeals to the common person, but you need to frame it for the government if you are talking to the government.
[1]: https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html
You are not addressing the issue at hand. You are instead arguing that if we somehow don't take your side here, then there will never be another point at which we can argue the pros and cons of possible subsequent escalations or refusals.
Which is why it's a fallacy.
I don't think that if the FBI wins the current battle then all is lost. But I do think that the FBI intends to fight all the battles until they win the long game.
That said, I don't hold any side in the argument.
The OP is using fallacious reasoning, even if it is accurate reasoning :-)
And it should be pointed out that point A never existed. Apple's device is not fully secure, or they wouldn't be capable of complying with the FBI.
Granted without the source code it would be quite difficult, but in theory, is signing the software with Apple's bootloader private key which is the same for each class of phones the only thing required?
It's weird to me that the phone will accept updates while locked...
I suppose this was left there to be able to reset the phones to the factory state after 10 wrong attempts to enter the code.
They're forcing Apple to kill its own children as a sick sort of game.
The FBI's endgame is requiring companies to build backdoors into their devices. Once they are able to successfully compel a company such as Apple to help them break into the phone, they are very close to compelling congress to pass laws to require that the option be available in the first place. "Hey, the court told them to do it before so why should they be allowed to block future need?". Here is where Apple's screw up comes into play. After all this they could shore up the security gaps to further remove themselves from the equation, but after a successful court order the FBI will move to block them from making an even more secure device.
Putting aside the technical issues for a minute, let's say everyone agrees Apple ought to help the US government's investigation of the San Bernideno terrorism case. Fine, and Apple might want to help, but how does their desire to help weigh against the hassle and expense of creating a new build of the OS every time something bad happens? Will it eventually get to a point where every impounded phone, of which I have to believe there are millions, can have a warrant issued and Apple has to help get the data out? They'd have to set up an entire department just to comply with the FBI's requests. At the scale of global law enforcement, it doesn't look so unreasonable that this ongoing nusiance will cost a ton of money and impair their ability to operate for their shareholders.
There's the encryption stuff, and how we have a right to privacy, but the real question is just how far a company has to go when the government asks for help with an investigation.
The more and more NSA friendly corporations back Apple the less I trust all of them.
[citation needed]
If the government hacks the iPhone themselves, they don't get the legal precedent they are so desperate to establish in this case. This paves the way for legislation that forces technology companies to install backdoors in software/hardware. This case is not about the data on the phone itself, the government is simply continuing the crypto wars.
They are really in a terrible position. No CEO wants to do interviews dedicated to a conflict with law enforcement. This is about a massive pile of unaccessable cash and the threat of a major lawsuit.
It makes sense that cook wants to invest in legislators who will listen to their lobbying cash and provide class action protection over gambling in the courts.
The question is, is this act (the whole text follows):
https://en.wikipedia.org/wiki/All_Writs_Act
"(a) The Supreme Court and all courts established by Act of Congress may issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law.
(b) An alternative writ or rule nisi may be issued by a justice or judge of a court which has jurisdiction."
a reasonable legal ground in this case to demand from a company to change their products, in this case make a special version of the operating system? Is this act good to mean "we can order anything to anybody"? Especially when there is "the Communications Assistance for Law Enforcement Act of 1992" (CALEA).
"All Writs" appears to be too dangerous to be used for precedents like this one, "change your products to help us." What is the next requested change going to be? Give us the change you've made ("obviously not an "unnecessary burden" anymore"). Make more changes, permanently. ("you've agreed already before!").
The Dangerous All Writs Act Precedent in the Apple Encryption Case
http://www.newyorker.com/news/amy-davidson/a-dangerous-all-w...
"Tim Cook, the C.E.O. of Apple, which has been ordered to help the F.B.I. get into the cell phone of the San Bernardino shooters, wrote in an angry open letter this week that “the U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create.” The second part of that formulation has rightly received a great deal of attention: Should a back door be built into devices that are used for encrypted communications? Would that keep us safe from terrorists, or merely make everyone more vulnerable to hackers, as well as to mass government surveillance? But the first part is also potentially insidious, for reasons that go well beyond privacy rights.
The simple but strange question here is exactly the one that Cook formulates. What happens when the government goes to court to demand that you give it something that you do not have? No one has it, in fact, because it doesn’t exist. What if the government then proceeds to order you to construct, design, invent, or somehow conjure up the thing it wants? Must you?"
Didn't Tim Cook force it this time?
If that's the case, then they could post the source code on Github and it wouldn't make any difference. Modifying the code to remove the device restrictions would invalidate the signature and any iPhone would refuse to run it. Isn't that the whole point of code signing?
I'm finding it hard to see how Apple's stance is anything other than meaningless grandstanding. Since the vulnerability already exists, the security of similar iPhones is currently reliant on the security of Apple's private signing key. After releasing this exploited OS, the security of similar iPhones would still rely on the security of Apple's private signing key. Nothing at all would change, it's Apple's fault for allowing this vulnerability to be there in the first place.
Where am I wrong on this? I've been hoping Apple would answer this question for me but instead I've just gotten more hyperbole.
But then someone could just build a hardware level hack, to make any other device report it's serial number as if it was this phone.
> "Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control."
The part about being able to guarantee such control seems to indicate that future requests may not require Apple's involvement.
Cook could have lied and said building a special OS was impossible. But he didn't because he knows someone will find out. When you're facing a subpoena, you don't knowingly lie.
Not that I believe Apple's CEO is lying, however…
You don't knowingly lie if you think the risk of getting caught is unacceptably high. That last part is important, I think, and indeed, you state, "because he knows someone will find out", so I know you get it. However, I don't think we should forget that a great deal of the concern we have presently in this thread about the government's capability in introspecting our technology is indirectly the result of the DNI lying under oath¹.
¹I know your post says subpoena, but it seems similar enough that its worth reminding…
Additionally, that letter is written with very carefully fuzzy language so as to remain true-ish.
As in, Apple can't make this change and guarantee that nobody else will use it. In the same way that any software change (which they do regularly) could open up a security flaw. That doesn't mean it's likely, or any more likely than any other software update.
I wouldn't put it past the NSA to have snapped up a former iOS developer for explicitly the purpose of breaking into iPhones. An ex employee could certainly call him out.
> Additionally, that letter is written with very carefully fuzzy language so as to remain true-ish.
Cook is trying to be as clear as possible to a public who doesn't understand encryption or why Apple is standing up to the FBI. That's a lot to swallow, and yes his letter is carefully worded for good reason. Given that there is a backdoor that Apple could create, it's not unthinkable that with more details, 3rd parties could figure out how to get in too.
This sounds like a misunderstanding. No clever third parties are going to find a way to break code signing. To exploit the security hole Apple already created would require having Apple's signing certificate so that a phone could install the code. If it wasn't for the certificate, it would be quite a bit more trivial to hack a firmware to do a malicious thing and install it on any phone.
Except that invention != turning over information.
The Justice Department would like to change this, so that complying with the Writs act literally means doing anything they tell you to do.
Which is a massive, blatant power grab.
If the government wants to go past that, pass a law, and hope it doesn't run afoul of the Constitution.
For instance, there's also a law that compels telecom providers to give the government cooperation in installing monitoring equipment in their pipes. But that's an exceptional situation, which is why they had to pass an additional law: it does not just follow from All Writs.
It'd be the same if Apple was building a sewer system:
---
FBI: "Hey, company building a sewer system!"
Apple: Hi.
FBI: "We have an ongoing investigation, and need your cooperation."
Apple: Rock on. I'll comply with the law! I have access to the system at all of these points. If you need access to that, just ask.
FBI: "No, we need access to a specific toilet bowl in a specific house."
Apple: ... I don't have access to that. They haven't flushed it; it's still in their house.
FBI: "Yeah, but you designed the system. So to comply with our request for information, we need you to come up with an easy way for us to break the system."
Apple: Break it how? Gee, FBI, this sounds a lot more involved than just giving you access to some information.
FBI: "No, this is just like turning over some papers. Now, we need your engineers to drop everything and immediately come up with a foolproof way of suddenly, and violently, reversing the flow and pressure of any arbitrary customer's toilet so that we can use it to propel an FBI Fecal Trawler drone into their house."
Apple: Whoa. You're asking us to develop, for you, a massive new operational capability. But there's not a law that compels us to suddenly spend our time being FBI contractors! Also, if we develop this the way you are asking us, that means many of our engineers will be working on, and learn how to, turn our toilet connections literally into deadly weapons! That's just ... gross, and immoral! And probably a breach of our duty to our customers!
FBI: No. It's law. Turn over our writs.
Apple: This is insane. You got laws passed to make telecom companies do this kind of thing -- I'm sorry, but until you get a similar law passed, and have to take it before the public in the way that will entail, I really think this is government overreach! ... Why are you even talking to me about this? Go in through the front door or something.
FBI: We threw the key away.
---
And yet the reporting on this story continues to be "Oh, Apple, why you can't be like those good nerds on </scorpion> who know how to help their country?"
You ever been responsible for writing secure software? It isn't easy. Locking it down to a single device is in principle possible. No one wants to be responsible for really doing it though if they can avoid it. Especially not when it is obvious this is not a one time thing. Not at all. You think every device manufacturer can do it without error too? There will be a lot of secret cracking tools if this gets started.
So the real question is: Can the FBI compel apple to create a "department of helping the FBI hack into iPhones?"
All I can say is that they genuinely do their best to protect you. For me it's that they have to spent a lot of resource (fiscal and other) to protect you from what is in my opinion: really sketchy shameful shit on the US and many other government's part.
If people want to really know why tech companies are at the point of enough is enough, it's because many governments continually try to twist laws/regulations/random stuff/whatever they want/made up shit in an attempt to get what they want. Eventually becomes boring, annoying and very expensive telling them they're wrong.
Since you're quite obviously having to dance around how to communicate the fact that you've received NSLs and invocations of CALEA that made you feel queasy (I feel your pain for similar, vague, hypothetical reasons), perjury isn't the legal concept that you're after there. You want 18 USC 2709, and for those keeping score at home, to my knowledge nobody has been prosecuted for violating (C)(1) which would test that law on appeal. The Internet Archive famously challenged the nondisclosure itself and won, which is a bit different.
I honestly don't know with what they'd charge you. Obstruction, maybe, but there's enough national security buzzwords in the (again, I've heard) letters and law to give me pause on considering civil disobedience there. The law does say in 18 USC 3511 that they can invoke a district court to force compliance, and then contempt can follow. But unclear on the nondisclosure part in the absence of a court order, and that's scary.
(BTW, IANAL, just an ex-hoster with a penchant for policy, and I'd love to hear someone like rayiner's view on this.)
To others: Don't go into hosting, particularly the abuse side, if you value your sanity and a positive outlook on humanity in general.
The essence of "All Writs" is (actual quote) "all courts established by Act of Congress may issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law."
which if I understand means in simpler English "we can officially request anything from everybody when we do our job, unless it appears as too illegal."
I've had minor problems with Dreamhost, but nothing major yet.
On top of that, our server in Portland STILL isn't ready, and we don't have an eta on when it will be. There's been a couple of other little things too - basically it feels like a major problem with the server every other day, clients are mad, and we feel out of our depth.
Anyway, I leave work at 5pm but my boss doesn't and I don't want him to die of a heart attack. So. Digital Ocean is being investigated.
I currently use OVH for dedicated servers. Low prices (starting at $70/mo), unlimited bandwidth use (most other hosts charge for bandwidth above a certain amount), DDoS protection as a standard feature (most hosts just threaten to kick you out when you get DDoSed or make you pay $15,000/mo for DDoS protection), and they've only been down once in the past few years I've used them:
https://news.ycombinator.com/item?id=10494475
(And they automatically refunded me for that incident; didn't even make me open a support ticket or anything!)
I don't want to sound like a shill but I (and others I know) tried a few hosts before settling on OVH and OVH has just been so much better in every way than any other host I've tried...
On the other hand, if you're looking for a really cheap dedicated server, Oplink has a $35/mo dedicated server: https://www.oplink.net/dedicated.html
I used to use Oplink and still like them, but they were one of those hosts that kicked me off for getting DDoSed (related: if you run a popular game, expect to get DDoSed).
Did you get any information about what the deal is with Dreamhost? I want to give them the benefit of doubt because they have been great for a couple years - their live chat is especially useful for me, and their backend is easy to work with. But this move to Portland that they have going on seems to be an absolute shitshow, and I wish we could get a proper explanation for what is going on over there.
There are parts I like and parts I dislike about the Dreamhost backend. The email stuff is really clunky. The other stuff isn't great, either, tbh. I like how easy it is to upgrade to PHP 7, though...
Incidentally, I think I was using around 20 TB of bandwidth a month when Dreamhost "subtly" started hinting that I should move on from their $8/mo shared hosting.
We then want Apple to improve their security so that no such request by governments would be possible in future. Tighten the security so that not even a special custom version of iOS would make a difference to the self destruct measures in place. Then we wouldn't need to waste any time arguing about it.
Just to be clear, I'm against mandated backdoors in products. I should be allowed to make my product as secure as I want to, even against myself. Yes, that might hinder government search and seizure, but that's the government's problem, not mine. I agree with Apple and most other tech companies on this.
But Apple isn't being asked to create a backdoor. The door already exists, and was voluntarily created by Apple. Apple has all of the tools and knowledge in its possession to walk through it. Whether that's the PIN itself (it's not), or the code-signing key and source code needed to disable attack mitigations (without which a 4-digit PIN is worthless), doesn't make a difference. As you observe, they could design the phone such that this attack is not possible. They did not, even though they've been claiming otherwise for years now.
All of the arguments in favor of Apple boil down to a general opposition to government search and seizure, worries about damage to Apple's reputation, a claim that code-signing occupies a privileged legal position (akin to attorney-client privilege), or a slippery-slope argument that the government will ask for mandated backdoors on all iPhones next. None of these has a chance in court. I'm more and more convinced that Apple is well aware of how legally wrong it is, and is just doing this to save face over erroneously advertising that their phones were secure even against Apple itself (and therefore any government coercion of Apple).
If someone is going to challenge me on this, please answer this two-part question: If Apple had the phone's PIN stored in their database, do you think the government should be able to compel them to hand it over? And why is that any different?
It's not completely unprecedented to require active assistance from a third-party. There's a Supreme Court case about this very issue, United States vs New York Telephone Co. The FBI wanted New York Telephone to install monitoring hardware on their premises and assist the government in its operation. The district court issued an order to that effect. The company offered to instead give the FBI only information, which the FBI could then use to install and maintain the system themselves. The Supreme Court ultimately ruled in favor of the FBI.
The main criteria that people have read out of that case is "unreasonable burden". I don't think that the FBI's request to Apple is an "unreasonable burden", especially since the government will pay for any costs. The biggest burden will be on Apple's reputation, but that is self-inflicted from making claims (honestly or not) that ultimately weren't true. I can't imagine the court allowing Apple to keep its technical assistance from the government.
> If Apple had the phone's PIN stored in their database, do you think the government should be able to compel them to hand it over? And why is that any different?
Well, I think, they should not, but I don't claim its different.
Apple wants to have it both ways, build it so that they have full control and they can be compelled by nobody to give up that control. I would rather they build a system, where nobody is in control at all.
This is also the idea behind TPM chips which are in almost every phone/laptop these days, so consumers couldn't tamper with DRM and other similar crypto systems.
I find it ironic that this argument in support of TPM, etc. is being made for phones (not necessarily by you), but this same site has vigorously opposed it for PCs, especially Linux.
You can also seal against some other value. So you'd have seal(plaintext, pin) and unseal(secret, pin). Unseal only returns the plaintext if the PIN is the same that was used to seal.
This is where it gets really fancy. The TPM has a bunch of built-in registers called PCRs (Platform Configuration Registers). You set a PCR by calling extend(newmeasurement). At boot, the firmware hashes the bootloader and sticks the hash in the first PCR by calling extend(hash). Then the bootloader measures the next boot component (probably a second stage bootloader, or perhaps the BIOS settings), and stores that hash in a PCR, and so forth. The resulting value of each PCR is based on both the measurement passed to extend() and the previous measurements, so the whole chain is verified. The cool thing is that seal() and unseal() can use these PCRs the the same way as, and in addition to, a PIN. Now your disk will only be decrypted if you boot the OS that you used to encrypt it. If you're willing to trust the firmware and OS makers, you don't even need a PIN anymore. The OS's built-in authentication could be enough.
Windows PCs tend to have TPMs, but iOS devices have their own hardware encryption solution.
I've glossed over and simplified away important details, but that's the gist of it.
Apple can either create a special update key for the TrustedZone and distribute it to User (SmartCard in the package you buy the phone in) or they could just put in a non-upgradable system.
Both would work.
Just two different beliefs in what serving the people means.
The FBI et al did.
I am weary of this idea that no man is wrong except the man who says he is right. The FBI is an institution that was built by a seriously flawed megalomaniac.
I think in terms of building a just and reasonable federal law enforcement agency, you'd 1) need to pass a federal amendment and 2) not build it upon an overreaching and power hungry organization built by J. Edgar Hoover.
We can do better.
No. Not unless you are omniscient and all-powerful. And even then, still no, because different people are different and want different things.
No one is claiming that the FBI is without fault or even that its actual goal is serving the people. But there are plenty of people out there who have a sincerely held -- and in a few cases even informed -- belief that the FBI is on the right side of this debate.
So respecting natural rights and popular sovereignty are not the right way to serve people? Your perspective on this was the point of Professor Bloom's book, The Closing of the American Mind.
I don't personally care what ill-informed people who are victims of the American Historical Association think about classical liberalism and human freedom.
The FBI will not exist in the future, solely because it is a threat to human freedom and in a better world, such a powerful authoritarian organization won't be needed.
It's really not. GP (or whatever) was saying that perhaps there's a reasonable difference of opinion. You responded by stating the author was wrong becuase "there [is] one best way to serve the people" and accusing GP of relativism (which is clearly a Bad Thing).
> So respecting natural rights and popular sovereignty are not the right way to serve people?
Natural Rights: There are reasonable conceptions of natural rights which allow for the FBI's interpretation of the All Writs Act. The exact scope and meaning of natural rights has never been and never will be resolved. Anyone proclaiming otherwise is just wrong. Hell, the philosophers who originated this concept had heated disagreements about their meaning. Things have only become more convoluted as we've tried to apply this idea in scaled-up settings.
Popular sovereignty: It's not at all clear to me how what the FBI is doing violates popular soverignty. In fact, it seems to me that they are fully engaged in a PR campaign designed, precisely, to leverage the legitimacy of popular sovereignty...
More generally, "natural rigths + popular sovereignty" is not a deterministic algorithm. It's entirely possible for people to adhere to both of thse philosophies and still vehemently disagree on the best way to govern. I might excuse a philosopher for not being able to foresee this fact 2000 or even 300 years ago. But clinging to the notion that "natural rigths + popular sovereignty" is a panacea to political disfunction after the past 200 years is rather astounding.
I happen to strongly agree with Apple and loathe what the FBI is trying to do. But I also think the argument you're making here is dead wrong. The case against the FBI here is not based upon natural rights. It is either based upon constitutional rights, or it is based upon pure pragmatics. And the final answer will almost certainly the latter.
> Your perspective on this was the point of Professor Bloom's book, The Closing of the American Mind.
1. No, it really isn't...
2. I was educated in exactly the style Bloom suggests. Suffice it to say that actually reading the classics has a way of undermining the authority that staunchy old conservative men try to get out of their particular interpretations and applications of ideas expressed in those books.
2a. Damned marxists bastardized Nietzsche and also rock music is for flooseys. lol
3. If Bloom's opinions were at all sincerely held, he would likely have agreed with the observations about natural rights and popular sovereignty given above.
> I don't personally care what ill-informed people who are victims of the American Historical Association think about classical liberalism and human freedom.
Don't worry, I use tin foil bookmarks.
> The FBI will not exist in the future
Okay.
There may be a few hardcore privacy advocates that buy an iPhone because of this, but it's not going to make any significant change in sales.
And as for criminals, well most of them don't know or care about encryption and aren't thinking far enough ahead about what would happen if the cops seized their phones. The organized "professional" criminals aren't going to rely on device encryption to protect their secrets.
And of course, the cynic in me thinks that Apple (et al) has already given the FBI what they want and this whole case is just public posturing to make the world think that iPhones are immune to government snooping.
No, they don't have any credibility in the matter. They're working an emotionally poignant tragedy to curry favor for the expansion of their authority.
[1] - http://www.npr.org/2014/07/28/335288388/when-did-companies-b...
Corporations aren't fundamentally different from the government. Both are just groups of people, at an abstract level.
It's actually not uncommon for local governments to literally exist as incorporated entities. Or for corporations to serve as the de facto government for a region.
It's a relatively recent phenomenon that we view these as completely different concepts, but they're not as distinct as we often think. It's more accurate to think of government as a special case of corporations rather than a completely different concept.
It's more accurate to think of governments as a special case of corporations.
Governments don't always "include everyone", and as we've seen, they definitely don't necessarily act on their constituents' behalf.
In certain contexts, corporations have also been responsible for creating and enforcing law, even though that's not the context we are used to today in the US.
I don't remember who said it, but there is a quote along the lines of: "People should look to the private sector for growth, and to the government for justice. Increasingly, they look to the government for growth and to the private sector for justice."
Edit: Found proper quote and source thanks to mbrock's pointing out where I likely heard it last.
The quote is:
"We have come to rely upon capitalism for justice and the government for economic stimulation, precisely the opposite of what reason would suggest." - Donald Kaul
And it comes from here: http://articles.philly.com/1990-10-17/news/25891604_1_budget... (Timothy Taylor did quote Kaul in the podcast mentioned in the comment below)
Yes, and that is the problem. Both are enormous institutions with tremendous wealth, resources, and power over individuals. A democracy is supposed to check this kind of power, but instead we're relying on it, only from a different source. The corporations' interests are currently aligned with the people's only by good fortune. When they're not, who will check them? Who will check the government?
Corporate interests are not a sustainable, effective, or remotely wise defense of liberty. The fact that Cook and Zuckerberg are doing our fighting for us is evidence that the correct methods are not functioning properly.
It's not so surprising when you consider that corporations can span many countries. Apple doesn't need the U.S. nearly as much as the U.S. needs Apple.
Of course corporations will be pragmatic about when they step in to "protect the people" as you put it. But let's not kid ourselves about governments ever being fully (mostly, even) on the side of the people.
Exactly. What kind of democracy is this?
"Democracy is the most vile form of government" (James Madison)
"A simple democracy is the devil's own government." (Benjamin Rush, signed Declaration of Independence)
"Democracy will soon degenerate into an anarchy..." (John Adams)
"The democracy will cease to exist when you take away from those who are willing to work and give to those who would not." (Thomas Jefferson)
Many, many more at http://www.godtheoriginalintent.com/democracy_republic_quote... (sorry about the choice of web site, but the selection of quotations is impressive.)
Today democracy is simply a catch-all term.
What was really revealing was Tim Cook's answer on 60 minutes when pinned down about Apple's international tax strategies - why don't you being this money back to the US thereby making it taxable. His answer essentially: because I don't want to.
Privacy, tax avoidance, H1Bs - more showdowns to come.
Well, he also doesn't HAVE to. If you don't HAVE to do something, especially if it's beneficial to not do that thing, why would you?
That said, 13th century England was not supposed to be a government of the people and for the people, so being in a similar situation now is arguably less than ideal.
Governments explicitly "on behalf of the people" are more or less an historical rarity, even if all governments have needed to keep people below the successful armed revolt threshold as a practical matter.
You're ignoring the desires of the people simply because they didn't have the political leverage to gain them.
I am saying that powerful interest groups can, occasionally, half-by-accident, represent the best interests of the powerless. We probably shouldn't rely on them to do so, and it is not the ideal state of affairs, but it can happen.
Thus, furthering lazaroclapp's point that sometimes there are special interests (the church, companies, nobles/rich people) that are aligned with average people. That is beneficial for society, but it in no way is a solution to the problem. We need to actually restructure our government so it is not an oligopoly.
[1] http://journals.cambridge.org/action/displayAbstract?fromPag... http://www.telegraph.co.uk/news/worldnews/northamerica/usa/1...
I really wonder what Apple would do if Chinese government asks similar backdoor. May be they have already complied.
http://www.npr.org/2016/02/22/467602161/the-seeds-of-apples-...
This is an entirely new stance from Apple. Historically, they've been on the other side.
No, there really aren't. From the article:
"The cases are different, but the underlying legal question is very similar," says Alex Abdo, a lawyer with the American Civil Liberties Union. "The question in the New York case is whether the government can rely on this very old statute to conscript Apple into government service."
Moreover, the "ask" in this case is nearly identical. Apple is being asked only to bypass the 10-failed-attempt device wipe, so that investigators can enumerate all 10,000 codes:
http://arstechnica.com/apple/2016/02/encryption-isnt-at-stak...
...which means that it's effectively exactly the same thing that Apple has done in previous cases. The only technological difference is one that has been manufactured by Apple.
This whole thing boils down to a question of whether or not Apple should facilitate a brute-force attack on a single phone, under a search warrant, for a known criminal. And they've done same thing 70-some times in the past.
Everything that you've read about a "backdoor" or a "key" is totally uninformed commentary on the matter. The intarwebz are outraged (outraged!), but they don't even understand the debate.
The other times weren't though.
> they don't even understand the debate
Look in a mirror lately?
Just as easy? Maybe if you ignore the effort to create it and secure it. I really can't believe writing secure software is being trivialized in the comments here.
The only difference is that this time the software they install would also have to turn off the delete-after-ten-attempts thing.
(You're probably having a hard time with this because the debate sounds absoultely ridiculous when the facts are laid out plainly. Totally understandable. The technical debate is absolutely ridiculous. The legal debate is the only one that matters, but it's not technical at all.)
Also, before had zero risk of going wrong. This is difficult and already fucked up by the FBI.
So Apple is all we've got left. The top-rank leftists in our politics today—Hillary, Sanders, and Obama—are all failing us.
Here in Delhi, and even more so in rural parts of India, connectivity to services like internet,banking,healthcare etc. is still a luxury for the majority. Most people here wouldn't even understand this hot issue of iPhone unlocking request by FBI.
When I see folks on HN, indulge passionately in discussing the most minute detail of this Apple issue, I really wonder how long would it take for my country (or for that matter, the majority of the world population that still lives in poverty and distress) to come to a stage where we can start thinking about the next basic right that comes once you have achieved the food, water, shelter part of life, that being privacy.
That being said, I believe part of the issue is the balance of power has changed into corporate hands with marketing taking a front role into leading us (the mass of consumers). The morale values that were one of the corner stones of previous institutions like the Church or the State to motivate nations are now just another commodity traded openly by economical actors that have but one goal: the bottom line.
Should we find a way to coerce those ruling private entities that are corporation into performing actions that would benefit the rest of the society, we might actually be able to spread the wealth a bit better. Until then, you and me are bound to fight over the left overs of those new overlords.
Sorry for the long rant, which is partly ironic.
[1]: http://www.theguardian.com/money/2015/oct/13/half-world-weal...
Shortened the article for ya.
And not only that, but "backdoor" isn't accurate. It's not what has been requested. "Backdoor" sounds more provocative though, and helps build numbers for the Apple side of the debate.
If Apple can crack the phone open, let's see it happen. And then after that, they should improve iOS security so not even Apple can crack it.
I'm not impressed that Apple can if they wanted to, build in a system to weaken my phone's security. They should patch that opportunity in the next release.
If a loudly media backed ruling to force Apple to comply with the FBI is then followed by Apple making a phone which makes it impossible to comply with such requests in the future, it will much easier to get legislation or rulings requiring the all phones have an inbuilt backdoor.
This is why the FBI is forcing Apple specifically to do what they or another organization (eg McAfee) might do. Especially since the phone in question, while spectacular from a media perspective, probably has very little interesting on it.
I think honesty is the best option. Apple should say "yes, we can help this time, but we believe in privacy and security, so in future our phones will not be able to be cracked by this or any method". Apple gets to be the good guys for customers, AND help the FBI in this instance. Win win.
In future, the FBI couldn't ask Apple anything because we all know their phones are unbreakable.
But Apple have dug themselves a hole this time by refusing to go the full distance even though it's technically possible. Probably not the best move IMHO.
I'm of course only presuming it's possible to make such an unbreakable phone in future.
When news of the FBI's demands to Apple first appeared, I hoped to hear from Google, Twitter, Facebook, and Amazon, as online service providers. Mozilla and Wikimedia as related infrastructure. Also Samsung, LG, Lenovo, and Dell, as hardware providers, and T-Mobile as a mobile services provider (AT&T and Verizon are assumed to be in the tank with the FBI/NSA/CIA).
This puts the list of supporters at Twitter, Google, and Facebook. Good work.
Waiting on Microsoft and Amazon.
https://plus.google.com/104092656004159577193/posts/PyMCaHdE...
http://www.npr.org/2016/02/19/467318811/mozilla-foundation-b...
Sure, unlocking this one phone sounds pretty reasonable. Apple will maintain control of the unlock mechanism, the FBI gets it warrant obliged, end of story. This is what the government side is spinning (see the nytimes op-ed today from William Bratton, NYC police commissioner).
The reality is that is not the end of the story. New York City has already said they have 200 phones waiting to be unlocked. Given an FBI win in the case, and Apple building the unlock mechanism, there's no reasonable defense against these unlocks. And this is just one city.
I wonder how many full time Apple employees would be required to service the steady flow of requests from law enforcement across the world to unlock phones. Hundreds? Thousands? I'm sure they already have law enforcement liaisons, but we're talking a whole other level of commitment in order to essentially create a worldwide law enforcement IT help desk.
Somewhere during the process of industrializing the unlocking of phones, a lot of people are going to start saying it would make sense if Apple would just provide the ability to unlock directly to law enforcement agencies. That would solve the problem of law enforcement heavily burdening Apple with all these requests.
Assuming Apple capitulated to that (presumably forced to capitulate because I doubt Tim Cook would do it willingly), we finally reach the nightmare scenario where access to the unlocker is no longer strictly enforceable and it's only a matter of time to where criminals have it. This is a true Pandora's Box, because there's no patch that will plug this hole.
This is a true slippery slope, in that its progression is all but assured. The only thing capable of stopping it is to have hardware that is incapable of having an unlocker created for it. Hopefully that's where we're at with newer phones, although that seems to not be fully confirmed. It's one thing for law enforcement to make Apple open a lock it has the capability to open. It's another to require that Apple make their product less secure than they otherwise would make it. I don't see that happening through the courts. At the very least, it would require an act of congress, probably followed with a lengthy court battle over the constitionality of such a requirement.
I have a feeling the government will eventually figure out a way to get its way without our realizing.
We have to make it very easy for the general public to understand what's going on at an incredibly simple, "oh I get it" gut level.
Simple words communicated simply will go a long ways to showing the importance of keeping good security practices in place in our tech.
Where can I sign up for that Congress? Is that opt-in? Because that sounds great.
[1] http://www.gallup.com/poll/182816/little-change-percentage-a...
Not saying it's easy, but when it comes to election day, that politician truly does hinge on the majority of people filling in the bubble by one name. If you can make that not happen a real threat in the candidate's mind, they'll listen to your desires.
Not everyone will agree with you, even if you use itty bitty words they can understand. I understand the issue, even when explained in grown up words. And I don't agree.
In this case, Apple already was not "keeping good security practices in place" because they made a weak system. If they had actually made a phone that kept good security practices in place, it wouldn't be possible for them to help the FBI.
They should comply with this and then fix their crap. Then you can worry about explaining the importance of fighting any law that would undermine strong security.
Think about something like climate change or vaccinations. You probably have no actual idea how it all works. But with some explanations you can understand the gist of the technical sides of those issues.
The main disconnect between the tech crowd and the general public isn't technical knowledge but values. A lot of people in the tech community put a lot value on absolute privacy or secrecy. The general public doesn't. Especially in a case where the privacy or secret information is to a 100% certainty related to an actual mass murdering terrorist.
I'd bet if anything, the general public would overestimate the privacy risk the apple crack would cause. They don't know about signed updates, for example.
The FBI has been running their own propaganda campaign, but when James Comey talks about the supposed "need" for backdoors, the common response by the people that understand crypto is to talk about how stupid Comey's suggestion was, sometimes with suggestions that he must not understand how crypto works. Meanwhile, the intended audience doesn't hear how backdoors aren't possible, and now have to unlearn the lesson that is "bad".
edit:
A suggestion on how to educate people about encryption: remember why[1] Philip Zimmermann wrote pgp - to provide an envelope for network communication.
[1] https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html
If they asked the question "Should Apple make it easier for terrorists and foreign hackers to access information on American phones", I suspect less than 50% would say yes.
If Apple really can tie the firmware to a specific piece of hardware with no possibility of it being modified I would be impressed but even still a little cautious.
Making the build not-modifiable is easy. That's what's stopping the FBI from modifying the existing build to remove the wipe rule.
You're disagreeing with every cyber security researcher I know, as well as the EFF, with no sources at all. At least google the subject.
Perhaps it's a bit premature to treat people's responses to a quickie poll as evidence that people are "taking an opposite stance" as opposed to giving their immediate impression.
It seems likely that Apple, Google and Facebook could make a case that would persuade people, especially with the support of the EFF, ACLU, and Amnesty International.
It is very easy to make people bend over and grease up by threatening them that some bad people are planning to kill them.
Defending liberty does not need 50%. You need few extremely vocal people willing to fight the good battle and help the discourse.
http://arstechnica.com/tech-policy/2016/01/att-ceo-wont-join...
Plus their CEO studied accounting. When you see a tech company led by someone without an engineering degree or somewhat similar experience, its days are numbered.
All he said, according to this article, was:
"I don’t think building back doors is the way to go, so we’re pretty sympathetic to Tim and Apple.”
“It’s disappointing to the mission that we’re trying to do.”
We're talking about a company that gives away your information to FBI, CIA, and publicly via an API. Of course they are going about it the wrong way - you just simply give them the data to begin with, as a business model.
- If the NSA approached Apple to ask for the same, would it be legal for Apple to talk about it? To refuse it?
- Hasn't the NSA already done that?
- Would the Chinese government allow a non-backdoored iPhone on their market?
I am sorry but I really do not see any reason to believe that Apple's devices are not already rooted to the core. This one FBI issue seems to be a perfect PR occasion.
Apple gets to be shown as a customer-knight in shining armor defending their customers to the bone.
Government gets to convince public that they don't already have the data.
Governments have ordered people to do bad things before. How do you view those who justified their evil actions with excuses like "I was just following orders" or "just doing my job"? Is it right for our government to put people into that situation -- not just government employees or their targets/adversaries, but neutral 3rd parties?
If a policeman ordered you to do something repulsively bad that would harm your family, friends, and neighbors, would you not want to be able to say no?
That view doesn't require any great technical knowledge of cryptography or hardware/software/etc. Pretty much anyone could understand it. Yet no one seems to be mentioning it.
The situation is like owner of a device forgetting his code and ask a phone maker to help unlock the device the user owns to get info. FBI does not ask for some backdoor or unique access key. FBI does not ask to get access to unauthorized private information.
FBI ask for Apple to not brick the phone and not erase all information while FBI tries different device locking codes—FBI does not want to crack the encryption. It is not about cracking encryption at all.
In this particular case Apple is doing wrong and it looks like a PR show. It is not about encryption, it is not about backdoor, it is not about universal key to access private information, it is not about surveillance, it is not about privacy, and it is not about unauthorized access. It's about getting to potentially life saving information that FBI has official permission to get from the device owner.
So given this seems to be the case, isn't Zuck a huge hypocrite and this is just a PR stunt?
More security for everybody. No backdoors. The FBI can as for speciak version all they want.
To be sure, they could still ask apple for a prober backdoor, but at least they can anker it to a individuel case.
This article is overlooking that it's not only governments that people would have to worry about if intentional backdoors are implemented.
<tinfoil> What if the FBI's request is just a ruse to obscure the fact that the NSA has already unlocked & decrypted the phone and found evidence needed in the criminal charges? </tinfoil>
The FBI initially wanted to get in by having Apple build a backdoor that could be used to defeat the security on ANY iPhone-- that's the bad thing, and it's still a bad thing.
And re: "thanks for the downvote"-- stop digging when you're in a hole.
Good security will keep out anyone that does not know the secret. That includes "owners." The concept of ownership is irrelevant to the design of a secure system.
I made this post last day [1]. It received 3 votes.
If you or I asked Apple to recover data from our phones, they'd just act sympathetic until we went away. Perhaps walk you through some of the backup options.
Virtually all the relevant phone data and metadata are available from other sources, including call, message, and email data, and backups until six weeks prior to the attacks.
Apple could have provided a data extraction on request, as it has done previously. This wasn't what the FBI had demanded.
Due to the FBI's own actions and direction, the data on the phone has quite probably already been destroyed.
Legally, my read is that the request has few or no merits.