Freedom, the US Government, and why Apple are still bad
mjg59.dreamwidth.org
mjg59.dreamwidth.org
http://www.bloomberg.com/news/articles/2016-02-24/apple-fbi-...
Apple has indicated that they're going to continue to keep increasing the security of their products in the future, which may make it impossible to update firmware to the Secure Enclave (or at least require the user's permission first), but that's actually a weak measure.
I'm not sure why tech people think that technical means to accomplish zero knowledge is the holy grail, that will never trump having the law on your side. Congress could pass legislation (like CALEA for tech companies) that would require everyone to design their products to make them accessible to law enforcement any time they want.
Can't download? Take a photo of printed material, OCR it and then install. That's hard to outlaw in the US.
It seems like it would be quite easy to outlaw this, the only question is what collateral damage would result from the process.
In the 1990s, PGP was published as a printed-and-bound book in a layout that was readily OCR-able, with code-friendly fonts, checksum and other features to make digital reassembly easy. The theory was that the US government would be unlikely to successfully ban an actual, physical book.
Thought experiment: Apple provides a pamphlet, free for the taking in every Apple store, that when scanned will armor your phone. Extend the thought experiment to a web page that the phone just downloads, compiles and installs (yeah, you probably want that code signed).
This would be hard to forbid in the US. The government would probably go after the plugin system on the phone (which would be an interesting battle). Places like the UK would lose no time banning such media, but it would still be readily available.
After all, even if a law is passed to protect something, it can be changed later. Not like the Constitution hasn't been... stretched by now.
[1] https://www.netmarketshare.com/operating-system-market-share...
Your average everyday person doesn't care about back doors and that's where market share is.
Governments accept some level of foreign penetration. The whole spy thing is just a complex game - trust me I know I played it.
Updates to the OS and applications are encrypted, completely opaque, signed by Apple instead of the original developer, can be granted additional entitlements for arbitrary permissions, and cannot be audited by anyone but Apple without a jailbreak.
When coupled with push updates, Apple already has a targeted backdoor into every iPhone anywhere connected the network.
This is a much more difficult problem to solve, as securing against that threat model requires an diverse ecosystem of 3rd-party audit/review, software, and tools.
I don't see any way of solving that issue while also maintaining their stranglehold on the platform via DRM.
What's the highest permission an app can have? Wouldn't that be the limit of the vulnerability here? Also, many permissions require manual granting, e.g. contacts, camera.
Edit: also, that could be mitigated partly by requiring user approval of any updates adding permissions.
Why do people (smart people, even!) continue to insist that this problem can be solved by technical measures? This problem cannot be solved technically. Stop it. Please. This misinformation is hurting all of us.
If you want snoop-proof encryption then the user needs to manage the keys herself, which I believe was MJG's point in that blog post. (And even then you're trusting the hardware itself not to have a backdoor to pull off the pass phrase, etc...).
At this point the techindusty should have drawn a line and fight for it.
Maybe this is Apples strategy. The want to raise the conversation but know they are gone lose this perticular case, so that they have a better position in the next, more important case.
I wonder if that was intended by the author.
If you'll forgive the abuse of an old parable...