Justice Department Wants Apple to Unlock Nine More iPhones
nytimes.com
nytimes.com
Legal minds should weigh in, but I'm thinking the only effective remedy is going to be congressional action, to pass law that defines the limits of court discretion re: forcing firms' assistance breaching their carefully constructed security/privacy systems.
This news prompts me to write my representative and senators and strongly urge them to support enacting this form of protective legislation. If there's enough of an outcry from the electorate there's a far greater chance of putting sensible policies in place. The fact it's an election year can only make voicing our concerns all the more effective.
The more important question is "Should the government be able to access citizen's digital data with a court order? And if so, how can that be enabled without compromising the general security of the device?
I suspect we'll ultimately wind up with mainstream device manufacturers maintaining some kind of per-device master key that they turn over when ordered.
This will enable government to access data in the typical case. Including foreign governments. Sophisticated bad guys will continue to use zero knowledge software, which government will attack by other means. The per-device master keys will be compromised eventually, which will force enterprises to upgrade their fleeta but normals won't care.
No. And that's both impossible and a massive compromise.
This case helps us tackle that first question. Here the murderer's personal phone and computer hard drives were destroyed — rendering them "above/beyond the law". Just because some data is digital doesn't place it in some special legal realm more important than shreddable/burnable paper or the air secret conversations were spoken into. There are fundamental limits to recoverability. If technology companies are to be forced to maintain vulnerabilities because governments see all their customers as potential terrorists, the industry is doomed.
The real problem here is although terrorism will never touch the average citizen anywhere near the extent of other tragedies like illness, accidents or natural disasters, the media treat it like it's the single most important issue — making people fear for their lives is good business. I'd die before sacrificing freedom of speech every time, but the news business just seems too like racketeering. We need to fight the fear.
This argument ascribes zero weight to the injustice of terrorist attacks. Your logic--that a death is a death--does not admit distinguishing between someone dying in a freak accident, someone being killed by a drunk driver, and someone being murdered in cold blood. It's all the same.
You're ignoring a very fundamental aspect of human psychology: people view a death very differently based on the intent of those doing the killing. Unlike murder, terrorism isn't just an attack on one person. It's an attack on the values, religion, economy, and lifestyle of a whole society. That's why people weigh it so heavily.
I currently think a mass murderer would be a greater threat to the world collectively, but the terrorist triggers the fear that any location might be attacked. Hence, while much less destructive, has the "me" factor that pulls heart strings of society at large.
Demanding an attack vector should be seen as the same concept as demanding bad crypto, because the intent behind the request is the same. They're trying to convince us that these are different requests, but the end result is the same. A workaround to attack good security is the same as having bad security to begin with. I can't imagine why anybody would think that "bad crypto" and "attack vector" are not very nearly the same thing.
The police were already searching you and your house so we enacted rules to try to control that. Those rules didn't enable the searching - they placed restrictions on the applicability of evidence to reduce the desire to search improperly.
It will be impossible to secure that database. Any number and size of bribes would be worth spreading around to gain a dump of it. Once I have a dump, you're up shit creek because you're faced with changing every key of every device you've ever sold to resecure them. However, any key changing mechanism you create is an exploitation vector criminals can use to randomly scramble their "master key" and not report the new one to you, and again, any certs you use to secure this process will become v cost effective to bribe for. So we're left with a situation where one breach screws everyone and it hurts legitimate users way more than the criminals it is targeted at.
Back doors are back doors man. Anyone can use the door handle, once it exists.
it's not tinfoil to note that there are CAs under the control of authoritarian governments.
The government already does have access to these citizens' data. That data simply has the quality of having been encrypted.
If I have printed encrypted text and lock it in my home safe, when the government gets a court order to search my house, they'll have complete access to those documents. They can't compel me to decipher those documents though, it's on them to break the encryption.
It's the same situation here. Here, Apple may be able to perform that decription service for the government.
The question to me is, should the government be legally able to press a person or firm into service?
The problem with the locked box analogy is that it implies that the cypertext is in some way equivalent to the plain text. In practice that isn't really true. If you don't have the key you don't actually have the plain text. Nothing says you can't look for it if you want. You could even hire a company to help you look. Can you force a company to look if that search would be against their business interests?
https://en.m.wikipedia.org/wiki/Key_disclosure_law#United_St...
IANAL, but I think your original hypothetical would be roughly analogous. I think the difference in this Apple case is essentially the amount of effort required (producing a password versus actually writing [a modicum of] new OS software), but I could be wrong.
Is there any practical reason why the secure enclave could not be programmed such that any firmware update to the enclave requires the PIN, and if not it erases the key. That way Apple is still able to make updates to the enclave, but cannot be compelled to bypass security restrictions on locked devices.
IIRC, the ITAR rules even prohibited systems that lacked crypto, but that had pluggable APIs which permitted crypto to be added later (e.g., by the end-user). It's hard to see how legislation to the same effect would pass constitutional muster, but it's a gamble, and the administration has little to lose.
I don't think that's a good question at all. Regardless of the ruling, they aren't going to up and declare encryption illegal. You can't throw a legal requirement at math to stop working.
They eventually had to repeal Prohibition.
When they banned drugs, they did the same thing. It is prohibition all over again. Criminals and gangs got into dealing drugs for money and people can't give them up. The war on drugs doesn't work because the CIA makes money from drug lords, and gangs and criminals make a lot of money selling drugs on the street. I managed to grow up without getting into drug but during the 1970s and 1980s there was a lot of peer pressure into doing drugs with others when I was growing up. It has become a social thing.
Many prisoners are in prison for using drugs. So our prison system is over crowded as a result. All the war on drugs did was imprison drug users and not go after the gangs and dealers.
The government doesn't get privacy rights. So they violate privacy in order to crack encryption on an iPhone via a backdoor or master key or modified iOS that gets rid of passcode penalties and brute forces the passcode. They only see getting the data off the iPhone to use as evidence, and don't care that it causes iPhone users to lose their privacy and make iPhones less secure.
The government isn't logical about these things, judges and politicians are for the most part not tech savvy enough to understand the technology and the need for privacy. They studied law, and other things, and not technology in the most case to understand how it works. They see getting evidence on terrorists as a priority and don't care what rights it violates. They can pass a law that pressed criminal charges at Apple employees and management for not helping out and try to force them to do what they say. We faced the same issues on the war on terror that required domestic spying and collection of metadata via the US Patriot Act.
but as it is they just shrug and say "i got nothing to hide"
smh
Well, it's not stopped them trying in the past [1] - and we now live in a world where hilariously/terrifyingly certain numbers are just flat out illegal [2]
In my mind, a large part of the problem comes from the fact that the people making these rules not only have no understanding of the underlying science, but they aren't even expected to _try_ and understand it, even at a cursory level.
Which in itself might not actually be so bad, except we've seen examples time and time again (especially in the UK) where ministers feelings or beliefs trump expert opinion and/or hard science [3]
[1] Indiana Pi Bill (an attempt to legislate math): https://en.wikipedia.org/wiki/Indiana_Pi_Bill
[2] Illegal Numbers, see also Illegal Primes: https://en.wikipedia.org/wiki/Illegal_number
[3] Medical science vs war on drugs, see David Nutt: https://en.wikipedia.org/wiki/David_Nutt
[3a] Current "Snoopers Charter" discussions where industry experts still don't understand what's actually being legislated.
Can a schoolteacher access a citizen's digital data with a court order? Can the FBI access a citizen's digital data with a court order? Can a court access a citizen's digital data with a court order?
Those questions are fundamentally different and have varying support in lawmaking.
Assuming you mean "its" then apple's capabilities are not the government's. The government could physically attack the chips holding the data instead.
They're just risk-/effort-averse and would like others do the work for them.
IMO yes and here is how I'd implement this given a secure enclave:
1) Have Apple generate a device specific key that unlocks the device without pass code.
2) The key gets encrypted with an Apple held master key and printed on the inside of the device, e.g. a sticker on the chipset. Note that at this point, the device is as secure as before if we assume that someone who gets the Apple certifier key can exchange the secure enclave software at will.
3) Apple should ensure that the unencrypted key gets deleted from all of their systems after it was printed, to ensure plausible deniability.
4) The process for accessing the data on a specific device becomes simple - law enforcement needs to be in possession of (A) the device and (B) a court order. Apple will decrypt the key if forced by court order.
I think, we can assume that up till now, Apple has its private keys protected on some disconnected machine in a HSM, perhaps multiple HSMs, that are only accessible with very restricted access. When there is a gold iOS build, some of the key personal will go through a security procedure to get the build signed.
Now suppose that such a procedure is put in place. And you get requests from US courts and Western European courts[1]. Once it's there, there will probably be hundreds, perhaps thousands of daily requests. It suddenly becomes undoable to keep the same security procedures. More people need access to the master key to handle all the requests for which there is a court order. Or even worse: there has to be an semi-automated procedure to handle such requests.
In any case, any such procedure will weaken the security of iOS devices significantly. Since Apple's master key is so extremely valuable, it will be an extremely attractive target for attacks (in the semi-automatic scenario); or it's easier to find a corrupt person to leak the keys.
Since people store anything from personal photos, access to bank accounts, to business plans on their phones, we should move into the direction of making crypto systems stronger, not intentionally weakening them.
[1] Let's avoid the slippery slope that this would trigger for not-so-nice regimes for a moment. Although, once such a backdoor is there, it will happen.
Let's be honest with ourselves, the chance to be killed by terrorists is minuscule compared to other factors that are under human control (air pollution, traffic incidents, homicides).
If you are looking at non-terrorist criminal activity, one has to wonder if you don't have more serious problems than unlocking a bunch of iPhones when your homicide rates[1] or traffic-related deaths[2] are higher than nearly any other Western country.
Terrorism and crime are just easy distractions to get more power.
[1] https://en.wikipedia.org/wiki/List_of_countries_by_intention... [2] https://en.wikipedia.org/wiki/List_of_countries_by_traffic-r...
I think there's a qualifier on there that you're missing. It's not just if the All Writs Act can compel a company to undermine their security measures. It's "if a company can undermine their security measures, can the All Writs Act compel them to do so?"
I think the answer is, arguably, "yes."
But that's a meaningful distinction because the 5C lacks trusted execution, and newer iPhones have it. I just read an article where Apple claims the precedent set in this case could force them to undermine phones with trusted execution. And that's probably true, too, IFF they can undermine it themselves.
But the All Writs Act certainly cannot bar a company from creating something that cannot be undermined.
So they'll make firmware that can't be modified without wiping the device.
If it's on-by-default, then everyone has their phone encrypted, and it's never suspicious.
I would have expected them to know better.
[1] http://www.theverge.com/2016/2/23/11100152/apple-fbi-terrori...
I wonder if that would have negative economic consequences for the US, e.g. tech companies that value privacy moving to Europe or elsewhere and customers avoiding US tech products.
If so, i imagine that would probably be the best reason for the US government to not proceed with this?
That was my immediate gut reaction, that it looks bad because Apple objections are proving true.
But now I wonder if the timing maybe works to their advantage, and the admission they want to use phone cracking everywhere is perhaps a very smart strategy. To technologists and privacy advocates, this might look like an admission of guilt. To the public at large, and the entire country, this might actually be a mountain of evidence that phone cracking is absolutely necessary, something we can't do without if otherwise phones are going to become unreadable by the "good guys".
For better or worse (and IMO it's worse) this might be a very strong argument with very good timing.
We are well, well beyond that point. This will never happen, given the authoritarian and fearful bent of the electorate and the elected.
The 3% solution is the only truly effective remedy.
I hope Google and Microsoft follow suit, and make this a requirement for future versions of Android and Windows Phone.
Do we know exactly what the secure enclave software can do and what it can't do?
There is no known cryptographic algorithm that provides inherently increasing times. The slowdown is entirely artificial, and it is believed that an update could remove it.
Of course this doesn't really matter at all if modified software could just read the key from the chip. That is the most interesting question. So, can it? Or can the software only provide data to the chip, to do the algorithm in hardware, but the software can't read the key burned (?) into the chip.
They want access so they can go fishing too? They're really not doing a good job of sticking to the 'necessary and proportionate' line.
So they are publicly stating that they are not really interested in just solving the case and prosecuting the offender. Instead, they want to see what else they can stick to the man.
I'm sure if you just dig deep enough, you will find some crime in everyone's data. Guilty until proven innocent.
-John Adams
http://rotunda.upress.virginia.edu/founders/default.xqy?keys...
If innocence isn't held in the highest regard, then society itself collapses as people no longer deem it necessary to act in an ethically- and morally-superior manner.
I see many signs in modern society that this maxim was ignored.
I bet any living noun knows someone who knows someone who knows someone who knows someone who is a paid assassin.
So heck yes we definitely should search noun's phone.
"The judge has indicated skepticism over the government’s demands. Initially, Apple agreed to a formal order to help the Justice Department gain access to Mr. Feng’s phone, but Judge Orenstein balked, questioning whether the All Writs Act could be used that way. He invited Apple’s lawyers to raise objections."
The judge's initial order was issued ex parte -- meaning the judge issued it to the justice department without Apple lawyers being present to argue against the order. Instead, as it was issued ex parte, the judge invited Apple lawyers to respond to the order after the fact by offering reasons it was an undue burden.
Essentially, Apple wasn't there to agree or disagree to it. The Judge encouraged Apple to object to it in recognition of the fact she was issuing it ex parte, not to nudge them out of inaction.
> In interviews with BuzzFeed News Wednesday, the former officers with the FBI and NSA acknowledged that U.S. intelligence agencies have technology that has been used in past intelligence-gathering operations to break into locked phones. The question, they added, was whether it was worthwhile for the FBI to deploy that technology, rather than setting a precedent through the courts.
This article seems to confirm that Law Enforcement is going to do its best to set a legal precedent.
The fact that they can resist the order and in a such a public way feels a little bit theatrical, given what we know about how these things work.
I wonder how much of what's happening between apple and the fbi / rest of the government is the tip of the iceberg.
I wondered that too. I read that Apple wanted to keep the debate quiet, and that it was the FBI who wanted to have a public debate.
Anyway, here we are having the "public debate about security vs. privacy on computers"
FBI sympathizers complain that some people are talking in extremes, and that the issue needs a balanced, nuanced approach like Bill Gates has offered.
Tech experts tell them that encryption can't be outlawed and the FBI is deaf to it
Regardless of whether we're talking about zero knowledge devices or not, now is the time to have the debate, because compelling Apple to act here is one step away from telling them they can't legally create a completely secure device. If we do this, so will China and other oppressive regimes, and it will hurt the global cause of free speech irrevocably.
What I think we're having is a debate about access vs. security.
The government wants access to be more important than information security.
Apple, and I guess people educated on the topic who aren't the government, want information security to be more important than access.
If one actor has a magic key to a system, n actors have that key because logic and the faliability of human systems. The government has proven too often that information security is not its chief concern, and we should expect they'll not perfectly protect the capability they're asking for as well.
Do we care to keep information safe, or "safe"? I think that's what the legislature is going to have to decide.
That's commonly assumed, but it's not quite accurate. It's not about "data originating from foreigner". Instead, the criteria[1] is "foreign data" or "data that traveled over a foreign connection". It's not the person that must be foreign, but the data or specific wire on which it travels.
Several sources have explained how the NSA captures domestic data when it travels internationally, such email (gmail) that is stored or processed at a foreign data center. This probably allows almost any data to be captured with some clever packet re-routing.
[1] this may be from one of the infamous "new interpretations" of FISA/etc
What do you think the odds are that the gov. wins?
The main difference, of course, is that adding an ability to allow someone to intrude on privacy for a service is different than adding functionality to a product that allows someone to intrude on privacy. The service provider can act as a gatekeeper to ensure that a warrant is provided. If you make a special build that anyone can load onto a device, then, of course, there is no gatekeeper for the warrant.
The key is that I am aware of no law that requires a gatekeeper. Services ask for warrants out of respect for their customers. Often they don't respect their customers and provide access without a warrant. It's not like the software we added to the telephone switches requires some kind of special key or anything. There is no oversight and there has never been any oversight.
The thing is that (as an American in US) you are under no obligation to hand over your cell phone, unless the police have a warrant. Once they have a warrant, then I don't think you have any recourse. As we have seen, you can be found in contempt of court if you do not reveal your password anyway.
So from the perspective of the law, I think it is relatively straight forward. It's going to have to go all the way up to the supreme court. I imagine that the supreme court would choose to hear this case. Essentially you will have to argue that compelling a company to create an exploit to satisfy a warrant constitutes an unreasonable search if that exploit can also be used to perform illegal searches. I think the case would be heard, but I doubt very much that the argument will succeed. If the exploit is constructed on the condition that it is only used to satisfy the warrant in question, I'm pretty sure that it will be acceptable. We all know that such a condition need not be followed since the FBI et al don't care if the evidence they gather is admissible in court. However, I doubt it will matter legally.
Wiretaps ordered into the U.S. phone and internet networks via CALEA and FCC rulings, which basically meant that all network and phone switches internationally would have the back door. (See what happened to Greek politicians thanks to that). But the phone portion of those rules came from a very deliberate act of Congress. (Don't get me started on CALEA and the Internet...)
The All Writs act is vague as hell.
And there are definitely laws that require legal process; your telephone records, for one. That's why the Congress passed a law retroactively immunizing AT&T, Verizon, et. al. for helping the NSA collect communications data on American citizens in plain violation of communication privacy laws.
In this case, NOTHING is straightforward. Apple could win on First Amendment grounds; the assistance asked for could be determined to be too burdensome. The Fourth Amendment may not even be an issue.
I'm not even sure this will go to the Supreme Court. If the feds lose, they may well choose NOT to appeal on purpose so they can continue browbeating companies with All Writs act in other jurisdictions and under seal.
That said, if your threat model involves anyone technically sophisticated or any government actor, I would suggest not relying solely on a fingerprint ID to control access to a device.
And when framed like that -- government ordering a private company, without negotiation or contract or even agreed-upon -in-advance compensation, to develop a product -- I don't think there's a chance in hell of it standing up. The question is whether the court that ends up hearing the final appeal will frame it like that.
What you describe is not what's being asked for. What the FBI wants is a tool to get into this phone. They will definitely want to get into more phones in the future, but that's not the same as a single tool that gets into any phone. It can be a new one every time. If it wasn't possible to make such a tool, I'd be a lot more outraged. But it is. Tell me why that can't be done.
Personal computers in general are not covered by any such regulation. It is legal to create and use encryption on your own device without building in a government backdoor. For now.
CALEA was extended to ISPs once the industry coalesced into a much smaller number of central players.
From the majority opinion in another All Writs case that made it to the Supreme Court[1]:
"[The lower court] was apparently concerned that sustaining the District Court's order would authorize courts to compel third parties to render assistance without limitation regardless of the burden involved and pose a severe threat to the autonomy of third parties who for whatever reason prefer not to render such assistance. Consequently the Court of Appeals concluded that courts should not embark upon such a course without specific legislative authorization. We agree that the power of federal courts to impose duties upon third parties is not without limits; unreasonable burdens may not be imposed."
The order also said:
"The order provided that the Company be fully reimbursed at prevailing rates, and compliance with it required minimal effort on the part of the Company and no disruption to its operations"
So the FBI could be expected to reimburse Apple for weakening its product and future earnings.
More details on that specific case as it relates to Apple vs. FBI are available from a post by a computer crime law professor [1]
[1] https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
Instead, the question is whether the All Writs Act grants sufficient power to compel a company, third-party to the action, to build a tool for breaking into its product. This is different to your telephone interception example, because that interception is authorised by a specific statute, not using a general writ issued under the All Writs Act.
The argument here is executive overreach - that they should be asking the legislature to pass a law specifically to require this kind of assistance, rather than using the All Writs Act.
It would be neat if the supreme Court would say this is unconstitutional on some ground, because that would seem to apply to other forms of wiretapping. They aren't fundamentally different. I'm sure the first time the gov asked a company to help them install wire taps, it seemed like a big deal.
I think some people are being intellectually dishonest when they say a backdoor can't be created without sacrificing security for everyone else. It can be done such that your privacy on an iPhone is just as good after a backdoor is created as it was before. Which is to say, not perfect because Apple had the key either way. If you want real security use a good passcode and keep it in your head.
One thing he hasn't talked about yet is how the FBI would reimburse Apple.
The most recent relevant court case that used the AWA was US vs. New York Telephone. Part of the court decision states:
"The order provided that the Company be fully reimbursed at prevailing rates, and compliance with it required minimal effort on the part of the Company and no disruption to its operations."
In his analysis, Orin simplifies and assumes that the FBI could pay for Apple's services. I wonder if they could. Apple is being asked to weaken its product, and despite the government claiming otherwise, I think Apple knows best about whether their product is being weakened or not.
[1] https://www.washingtonpost.com/news/volokh-conspiracy/wp/201... [2] https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
I still don't understand why Apple needs to save the FBI from it's own incompetence in asking the government office that managed the iPhone to reset the password.
It seems to me that unless tech companies come together to defend Apple, we may see (unregulated and unaccountable) government become very very part of all facets of computing.
If they're able to help, and can be compelled legally, why would the FBI having previously had the ability to get the data but losing it to a mistake change their obligation?
Their mistake shouldn't confer access through arguably illegal means (the legality of the court order compelling Apple not yet being settled).
Superman represents an unchecked power, and Batman finds this unchecked power to be unacceptable as a risk, in case the power is ever used against humanity.
Is this a subtle marketing ploy from DC Comics‽
Superman caused a lot of damage in The Man of Steel movie and many people died as a result of his fight with Zod that ended up with him breaking Zod's neck and killing him. The movie could have gone a different way if he asked his Father's hologram about Zod, and any weaknesses he might have during the 24 hours he had to think over. Then use the craft he came to Earth with to destroy Zod's ship engines, defeating him without any property damage or killing innocent people.
But anyway Batman always has a plan in taking down any super powered being in case they go rouge or mind controlled. He stores them on his computer and makes technology or finds items that can weaken them or take away their powers.
For Superman he has a battlesuit and kryptonite. The battlesuit gives him strength and power to fight Superman and the kryptonite weakens Superman so Batman can fight him.
Yet in The Dark Knight, Batman used a program to use everyone's cell phone to create a spying device that gave hi the location of the criminals Joker employed and where the victims are. Sort of abusing his own powers for domestic spying and making cell phones insecure by infecting them with an exploit that installs his own backdoor to get access to the cameras etc to scan for things.
ps. Not big on DC/Marvel comics/movies, they're all the same to me but keep some f*cking consistency plz.
"But anyway Batman always has a plan in taking down any super powered being in case they go rouge or mind controlled. He stores them on his computer and makes technology or finds items that can weaken them or take away their powers."
Frank Millar's The Dark Knight tells a different story.
That's why DC invented Kryptonite, so Superman would have a weakness. And Batman is familiar with Kryptonite, and possesses some to use in a fight against Superman.
> consistency
That ship sailed long ago.
I am a Nexus user.
Having said that, high-end devices [1] from Marshmallow onward (6.0+) are supposed to have encryption enabled by default, according to the Android Compatibility Definition Document [2] so we'll probably see Android playing a bigger role in the encryption debate in the future. Budget phones are exempt from the requirement.
[1] - For device implementations supporting full-disk encryption and with Advanced Encryption Standard (AES) crypto performance above 50MiB/sec
[2] - http://static.googleusercontent.com/media/source.android.com... Full Disk Encryption (section 9.9)
Has the FBI/DoJ never encountered an encrypted desktop or server before? or has it not been a problem when they have?
"In a sweeping November report on encryption, Manhattan District Attorney Cy Vance wrote that Google can “reset the passcodes” on some Android phones without full encryption, when served with a search warrant. “This process can be done by Google remotely and allows forensic examiners to view the contents of a device,” according to the report."
> "Google has no ability to facilitate unlocking any device that has been protected with a PIN, Password, or fingerprint," [Android’s security chief, Adrian Ludwig] wrote. "This is the case whether or not the device is encrypted, and for all versions of Android."
Also note it talks about being able to unlock phones without full encryption. Which yes, understandable. But I'm interested in specifics at the level that we've been talking about with iPhones - eg, on phones with appropriate TPMs (like the new Nexus devices), is it possible to bypass?
EDIT: Reading the source post [1] more, it notes that
- Google has no ability to facilitate unlocking any device that has been protected with a PIN, Password, or fingerprint. This is the case whether or not the device is encrypted, and for all versions of Android.
- Google also does not have any mechanism to facilitate access to devices that have been encrypted (whether encrypted by the user, as has been available since Android 3.0 for all Android devices, or encrypted by default, as has been available since Android 5.0 on select devices).
- There are some devices that have been configured to use a "pattern" to unlock. Until Android L, "pattern" unlock did provide a recovery option with the Google account. This recovery feature was discontinued with Android L.
- The lost pattern recovery feature never applied to PIN or Password so if you are on an earlier model device and don't want to use the pattern recovery feature, you can switch to a PIN or Password and it will be disabled.
I am usually wary of oversimplifying these sorts of controversies, but this one does seem exceedingly simple to me. It goes like this:
Is it possible, even with Apple's help, to break the encryption of <insert device model here> without knowing the encryption key, given that the passphrase provides reasonable entropy?
If the answer is other than a flat, unambiguous "no," enjoying the consensus of the scientific and security communities, then that device is simply not secure, right?
...and, to extrapolate just a bit: when device that are secure by this definition are in the mainstream (and my understanding is that even current iPhones, unlike the one at issue in this case, are) then this is entirely moot, right?
...and, more to the point: when phones come out that don't have this vulnerability, none of this will matter, right?
Even if both of these particular vulnerabilities are closed, it's almost a guarantee that additional vulnerabilities exist which Apple could be forced to exploit.
The next best example is perhaps police forcing Apple to wiretap iMessages in real-time. They have tried countless times and Apple has said they do not have the capability and refused to create it. But it is clearly technically possible from the design. Closing that vulnerability would require significant changes to the iMessage UX. Some people argue we can't trust Apple and they should make those changes in any case, but obviously Apple is willing to impose some level of trust in their own infra in order to gain UX advantages.
I am only spitballing here, but does anyone else think the heat has risen for federal law enforcement to set some precedents on this stuff now that Antonin Scalia has died? My hunch is that with another liberal judge on the Supreme Court there may be a push to have some of this type of case heard at the highest court.
Scalia often ruled against law enforcement's attempts to abuse their search powers.
Examples:
https://www.oyez.org/cases/2000/99-8508
https://www.oyez.org/cases/2012/11-564
https://www.oyez.org/cases/2014/13-9972
https://www.oyez.org/cases/2008/07-542
It's not clear to me how he would have ruled in this case, but I don't think it would have been open and shut.
I don't recall ever hearing a big standoff with MS refusing to decrypt a Windows desktop or server.
Is encryption just that much more common on Apple devices? or is Apple just the first ones to make this all public?
The requirements for Android 5.0 had to be relaxed and Android 6.0 is barely available.
http://arstechnica.com/gadgets/2015/10/android-6-0-re-implem...
https://github.com/carmaa/inception
Note that this is the open source, made by one guy in his spare time version, so it has some caveats. But I'll bet you dollars to donuts that the three-letter agencies have their own, more capable version.
The page even explains this:
But with Bitlocker, it only requires a password at Windows login, and by then all the Firewire etc. drivers are up and running. So you have no protection for computers that are stolen/seized by law enforcement.
Maybe this whole thing will turn out to be a giant Streisand Effect that gets even more people using encryption and call out the companies who aren't doing a good job.
Have something to say, Bill?
*Director
https://www.fbi.gov/news/pressrel/press-releases/fbi-directo...
Wait, how many have they been able to unlock and how? Sheer luck?
https://www.youtube.com/watch?v=meEyYFlSahk
I naively thought it was a machine with a robotic finger, derp
And the full (!) text of All Writs Act is just:
https://en.wikipedia.org/wiki/All_Writs_Act
--
"(a) The Supreme Court and all courts established by Act of Congress may issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law.
(b) An alternative writ or rule nisi may be issued by a justice or judge of a court which has jurisdiction."
--
Note it's not any law that regulates any form of encryption or communication security or what some company has to do to help some law enforcement procedures, a lot of laws with such topics were fought about, proposed, discussed and introduced through the years, like CALEA. This is just "we can demand anything we want."
The issue is, should this Act be allowed to be used in such contexts. A precedent can even make unnecessary the current process by which the laws are being made. Note there's nothing specific in that sentence from 1789. Who needs laws if anything goes?
Do you own a car?
The executive branch can obtain warrants from the judicial branch to "exploit vulnerabilities" and gain access to these "devices".
1. A person's "papers," memories and life details typically lives as data on their personal smartphones and other devices. Currently, a phone/laptop seems to be treated as pocket lint and other personal property, so a warrant is typically not needed to access contents, i.e., airport enhanced security screening, traffic stop, etc.
2. Important papers may reside in a home in a safe or filing cabinet. A warrant or probable cause is needed to search a home.
3. A search warrant is not needed to search a vehicle, only probable cause. All kinds of road vehicles including van conversions and RVs are considered vehicles, not homes, even for the folks whom dwell in them, and so there is currently little protection.
The fourth amendment needs an amendment to explicitly include one's personal electronic devices, hosted servers and cloud data in order to be congruent with the spirit of the law, because LEAs clearly do not respect sensible boundaries.
Furthermore, the Apple refusal is mostly a protest stance but moot considering the offensive LE tools industry jumps with glee at every opportunity to provide solutions... if the 10x-wipe retries counter is unencrypted, it will be broken by third-parties. (I hope this is not the case, and that it is an encrypted token of some sort)
It can't be encrypted with the same key as the rest of the harddisk, or it wouldn't be possible to increase it on a failed decryption attempt. But even if it is, you can always restore a previous state from backup.
To be honest, I still don't understand who the FBI can't brute force it (other than the time it would take), and how Apple's assistance could possibly help, if the encryption was done well.
To block all encryption apps, you'd need to censor the internet and check every digital device at the border. The government needs to understand that this is the implication of the direction in which it wishes to take us.
Bruce Schneier goes into more detail: https://www.schneier.com/blog/archives/2015/07/back_doors_wo...
I fail to relate the scenario we have now to software project (though no doubt the FBI will try to).
With hardware you typically have a clear manufacturer. However things might get interesting if more people make their own hardware using open-source designs.
This is curious, because I was under the impression (due to the lawyers on HN) that this is basically an open and shut case in the eyes of the law: the government has the ability to compel Apple to act. Why would the judge think differently?
(I'm genuinely curious as to the legal aspects of this and not taking a side either way.)
What Apple is being asked to do here isn't simply to unlock a phone. They're being asked to use their engineers, money, and expertise to build a tool to defeat the very encryption they developed.
It's not clear the All Writs Act enables the government to simply order a search warrant recipient to create new technology for them.
For the lazy, here's what I found,
Compelled speech: http://law2.umkc.edu/faculty/projects/ftrials/conlaw/compell...
Code is free speech: http://archive.arstechnica.com/wankerdesk/2q99/freespeech-1....
Reminds me of this xkcd: http://imgs.xkcd.com/comics/legal_hacks.png
"In the case U.S. v. New York Telephone Co. 434 U.S. 159 (1977), the Supreme Court established a three-factor test for the admissible application of the All Writs Act: the party ordered to perform an action cannot be too far removed from the case, the government's request cannot impose an undue burden on that party, and the party's assistance is necessary."
My guess would be that "undue burden" is probably what the judge is pondering. Possibly "the party's assistance is necessary" (it doesn't say "convenient"!) seems interesting in this case as well, if there are other means to break into the phone (NSA, John McAfee[2]).
[1]: https://en.wikipedia.org/wiki/All_Writs_Act
[2]: https://www.rt.com/news/333326-mcafee-interview-fbi-apple/
However, here's something I haven't thought of, though I sort of hate to boil the thing down to a business proposition. The fact is that iPhone is a massive business. What all is a company allowed to claim as "burden" in the discussion of undue burden?
Let's say the FBI wins, and Apple is forced into this. Then the narrative in the mind of the public is that Apple has back-doored their phones and made them insecure.
Apple loses literally billions of dollars per quarter for some amount of time until they can repair the PR damage.
Is the loss of, say, 50 billion dollars in revenue over the next calendar year something a reasonable person would call "undue burden?"
What about other ancillary effects that cost either direct money or productivity? There are rumors of something like an iPhone 6c that is scheduled to be released perhaps soon. (Supposedly a revamped 4" phone like the 5s but with the latest hardware) After all this hubbub about a potentially insecure 5c, who is going to go buy a 6c without wondering if it has the same problems?
Casual tech watchers don't understand the nuts and bolts of this situation. They hear some things, read some things and go along with the popular media consensus.
If the alleged 6c were actually going to be launched in a couple of months, the branding, production, packaging, marketing would all have been bought and paid for already.
Does having to recalibrate the launch of a new product and all the costs that might incur count as "undue burden?"
Etc., etc. Maybe they need a significant portion of the iOS team to do this, and the work causes delays in the next version of iOS, iPhone 7 has to get pushed back for release and misses the holiday quarter, again, lost sales accounting for billions.
I think the potential impact on Apple's bottom line could honestly be taken into consideration of burden. Curious about what other people think. Is money just not talked about in these considerations?
I wonder the same. In another comment in this thread I mention that it's not just undue burden here that is expected under AWA according to USA vs. New York Telephone, it is also expected that the FBI pay for any work they ask Apple to do.
Yahoo was forced to deal with many requests from the NSA in 2008, only those dealings were unknown to the public until recently. [1] The last 8 years have not treated Yahoo too well..
It seems when you fight the government on privacy, you lose. It's better if you roll over and wag your tail like Microsoft
[1] http://www.theguardian.com/world/2014/sep/11/yahoo-nsa-lawsu...
Everyone else can choose a 4 digit code, and still enjoy very good security up until the point they are wanted by the FBI.
People are confusing the fight for unbreakable encryption with this new fight to keep manufacturer-specific passcode retry attempts nice and secure.
The very fact we have this dependency between the encryption and the retry system, is a weakness probably deserving of attention.
Apple's argument is that this will set a precedent, and the FBI will ask to unlock many phones in the future, possibly even to the point of preventing Apple from creating a phone that is not unlockable. Further, that the creation of the proposed hack will by its very nature put the whole iPhone ecosystem at risk if and when it gets out into the wild. The more requests that the FBI makes, the more people Apple will need to train to service such requests, and the more risk that there is a leak.
The analogy here, although dramatic, would be the atom bomb. Hillary even alluded to the need for a Manhattan-like project to circumvent encryption, although I don't think she thought that would be received as a bad thing.
The FBI's argument is that they're only asking Apple to unlock a single iPhone. The DOJ is unwilling to comment on how many iPhones law enforcement across the country would like to use this on, and defers to local officials to answer that question. They are pretending to focus on this one phone while knowing full well the value of what they're after. They wouldn't call up the AWA for a single phone.
Obama is unwilling to draw up legislation with congress about this issue given the nature of the public's attitude about mass surveillance, particularly during an election year. They're probably terrified this issue would fracture the public vote and then there's no telling who we will elect as the next President. So, they directed the FBI to use the AWA.
I'll take a guess that your position is identical to Apple's recent letter on the matter.
I think Apple should help unlock these phones, with the condition that such help may be impossible in future versions of the OS. Who wouldn't want future versions of iOS to prevent these requests from being possible even with Apple's intervention? How that can be achieved I don't know. Perhaps some fancy new hardware chip that kills the phone at any sign of tampering. I'd vote for that, most people would, but the FBI would hate it.
The crucial point is getting as much of the public on side as possible. Most people would support increased security and privacy measures for their phones. They would feel threatened by legislation denying Apple or others the right to improve security for customers, meaning such legislation would unlikely pass.
By fighting this current situation, Apple are putting themselves in an awkward situation of "not helping criminal investigation" which is not easy to get everyone on side if you're not being helpful.
It's a bit like chess, and Apple might have done better to make their move at a later time, first helping with these iPhones, then shutting the door on that option in later OS releases. "Sorry, it's encrypted inside and out, no way in, that's how good the security is, because that's what our customers wanted" would be impressive, and hard to defeat with new legislation.
So Apple should comply now, and make a better chess move later. I could be wrong, but that's what I think for now :)
Was your original question rhetorical? In case it wasn't clear by my summary, no, we should not be satisfied with a longer passphrase. We should be concerned about the precedent-setting nature of this case.
> your summary wasn't needed
This is an open discussion. Nobody's forcing you to read my summary.
> "I think" is not a bad thing to say once in a while.
I think that is implied by the fact that I wrote all that. Anything that I haven't cited is my personal take on the issues.
> I think Apple should help unlock these phones, with the condition that such help may be impossible in future versions of the OS
Nobody believes the FBI will adhere to this condition. They can always change their minds down the road.
> It's a bit like chess
It is like chess, you're right. The move has been made and the hand removed from the piece. Time to act, carpe diem. The best thing to do now is educate people about encryption and potentially make this an election issue at some point in the future. Right now the public has nothing to do with this case. It's going to be decided in a court among experts, lawyers and judges.
> Apple should comply now, and make a better chess move later
That's fine, it's your opinion. I disagree, and would add that now is the right time to take a stand while this is in the public spotlight. It will take time to educate the public about encryption and we might as well start now. Compelling Apple to circumvent its own security will make us less safe. There is a black market where exploits are bought by intelligence communities, and if Apple creates this exploit, there's a chance it will fall into the wrong hands.
Suppose Apple loses and tells its engineers to produce this update. What happens if those engineers all refuse? Can they be found individually in contempt of court?
If every engineer refused to do it at any price, Apple would cease to exist.
Around 2007-2008, Yahoo faced a $250,000 per day fine for non-compliance with the NSA's Prism program [1], according to documents released in 2014 [2]
Note also that the CEO and co-founder Jerry Yang left his position at the end of 2008, after which time, it seems, they became compliant and the orders stopped.
[1] https://en.wikipedia.org/wiki/PRISM_%28surveillance_program%... [2] http://www.theguardian.com/world/2014/sep/11/yahoo-nsa-lawsu...
Apple will have however to show that they are doing their best effort, and so will be forced to fire/transfer them to other positions and hire engineers willing to do the job.
So an icloud backup negates the need to force apple to unlock?
Any way to backup an ios device online on a 3rd party, encrypted using a public key?
Not as seamless as the iCloud backup. Essentially you need to back up each service itself and restore it all manually when you need to.
Not that Android is any better in this regard; it works pretty much the same.
It's unfortunate as there has been a huge focus on device security, mostly for the payment capability but the actual data on the thing? Easily backed up and extracted via government request.
There may not be a foreign equivalent for US companies working on complex or enterprise problems.
Europe is often times the second highest revenue generating region outside of the US for US tech companies. Do European businesses care about this? Would this cause them to adopt a lesser alternative? Does this comply with EU Model Clauses that govern regulated verticals like defense, finance, academia, healthcare, etc?
I am not a lawyer, but I can't imagine the EU Model Clauses would allow for something like this.
Did that actually lead to companies choose EU providers over USA ones? Not sure, but it certainly was a factor that many considered.
Especially in areas where client data is very sensitive (like healthcare), EU companies are extremely paranoid about it.
"It is no different than [the question of] should anybody ever have been able to tell the phone company to get information, should anybody be able to get at bank records. Let’s say the bank had tied a ribbon round the disk drive and said ‘don’t make me cut this ribbon because you’ll make me cut it many times’.“
(https://www.yahoo.com/tech/bill-gates-says-apple-unlock-0451...)
The difference is that ribbon isn't hard to cut and so the bank wouldn't have to develop a whole new type of scissors to cut it and doing so doesn't weaken the security of a bunch of other bank records secured with similar ribbon.
this discussion is not about complexity!
It's not just about time. Part of Apple's product is security. The DOJ is asking them to weaken their product. This could cost Apple their business in the long run as foreign companies enter the fray and offer a secure product that Apple is no longer allowed to produce.
Keep in mind that there's a black market where hacks and exploits for various systems are sold by hackers and bought by intelligence agencies. If this software is created by Apple, there's a chance it could get out there and end up in the wrong hands.
I'm not a lawyer. Is the FBI asking something from Apple which is not legal? Than go to court.
Exactly. So why are we asking Apple to do something which Obama rebuked China for doing last year? [1]
> If more than 50% of the population wants the phone to be cracked it should be done
This isn't up to the public, it's up to the courts, who've been asked by the DOJ to consider the issue.
The public only comes into play around election time when there's a chance to vote in a new President. And, it's likely this decision will be made before Obama leaves office.
> Law is formed by the wishes of majority
No.. Law is created by elected officials who are tasked with studying the law more closely than the general public
[1] http://www.reuters.com/article/us-usa-obama-china-idUSKBN0LY...
The only time the exception was ever made was to prevent monopoly about a hundred or so years ago.
Otherwise its perfectly ok to be an American corporate citizen and challenge the law.
The fact that Apple has the ability to update a phone while it is locked is a backdoor.
Guess law enforcement thinks telling the truth is not something "good guys" are required to do.
President Obama told President Xi that China would not be able to do that if they wanted to do business with the US [1]
As far as I know, the iPhone still sells in China, so that law never made it through. If the US allows this to happen, you can bet China will demand the same.
[1] http://www.reuters.com/article/us-usa-obama-china-idUSKBN0LY...
Still another issue is, if they were compelled to create it they could be compelled to surrender it too. With that its a matter of weeks or months before it gets leaked to a criminal organization or country.
My long term concern is, would we ever know if they got compelled to change iOS to insert a backdoor that gets pushed to our phones. Even if we do how long before carriers are required to lock users out for not updating?
"Every child porn videographer in America is trading in his camera for an iPhone"
We're talking about cracking a 4 digit access code of a phone, which is extremely easy. Apple knows this, that's why they set a digital booby trap which fires after 10 tries.
So the real discussion should be, "Can the government force a company who placed a booby trap, to remove that same trap if needed?"
Whether this is a digital trap, of a bomb placed on a doorknob is not important.
Technically, it's obviously not just a 4-digit access code that prevents FBI to unlock the phone, otherwise they wouldn't demand Apple to produce the whole new version of their iOS and setup them special access only to enable that.
And even more important, the legal basis they claim to have is the "we can do anything" sentence from 1789:
https://news.ycombinator.com/item?id=11165699
There's nothing about the obligation of companies to do something specific there, certainly not about changing their own products or making the new ones.
NB: if it were so easy, we wouldn't be having this discussion. So, apparently there are some mitigation techniques which help in case of weak passphrases, and make it not-so-easy, no?
My whole point is, this is not a technical issue. It is easy. It is a legal issue. Can the government force a company to do such a thing? Especially when the impact on society is zero. The firmware upgrade is not released outside of Apple, no other phones get it.
It feels almost like a publicity stunt to me. Apple being the underdog in the fight against the big evil government.
If they don't want to cooperate and there is no legal basis for doing so, than don't cooperate.
Alternatively, introduce a restriction that this form of forced labor can only be compelled in terrorism cases where lives are in imminent danger. How many phones will be left to hack?
That would simply spur a lot more manufactured "high profile terrorism cases" hitting the news.
The FBI is hoping to have Apple develop a new iOS that does not automatically wipe the device after <x> invalid password attempts, then use their signing keys to push a deployment of that operating system onto this specific phone.
Nobody else has access to Apple's signing keys, ergo nobody has the ability to do this on Apple's behalf.
I haven't heard of the FBI asking to get apple's keys before, but that is crazy.
Aside from that, a fourth amendment search or seizure cannot generally compel someone to open a door. The usual logic is that it allows agents entry; the trade-off of letting them in is that you don't have to replace your door after.
This isn't a matter of standing aside while the agents effect the search, it's a whole different thing. Put into (what will assuredly be a bad) analogy, whereas a physical property search involves opening a door, or standing aside while the cops break down the door, this scenario is more akin to demanding that Apple build an entirely new house, one without doors, then removing the old building and installing the new building in its place so that the cops can enter.
Being the cynical fuck I am, a former action arm of the darkside, I have been telling friends and family for years that they should assume anything with a cellular modem in it is potentially comprimised by a nation state or above actor (yes, "above" nation state exists... Its called the deep state you fool).
I automatically assume that such publicity is actually closer to a honeypot to entice foolish mid level criminals into thinking iBrain devices are "secure", when I think they probably have miltiple backdoor avenues in place.
Of course, I'm just the hn resident conspiracy theorist, so it's probably just me being paranoid...
You... that's where you lost me.
http://www.amazon.com/American-Deep-State-Democracy-Library/...
That one is new to me. What does it mean?
To use the word "unlock" seriously blurs the lines of what's going on here. They're merely asked to flash it with software that removes a delay in submitting passcodes and removes the wiping function after ten failures.
That's not unlocking it.
If Apple complies with the order, the FBI will still be getting an encrypted iPhone back, and they'll still have to sit around and try to decrypt it.
What if this guy used a long passcode? They're still going to try to get in, and the only difference is that they'll move the heavy lifting off of the iPhone and try to crack it with beefy computer. And to do that, they'll have to lift the chip off the SoC anyway.
My point is that when people say Apple will "unlock" the phone, it insinuates that the only thing standing between FBI and the data is Apple. And that isn't true. Even if Apple complies, they're they're not guaranteed to get in. Furthermore, Apple could comply and they still might find themselves pursuing an angle that they're already capable of. FBI are going through all these court hearings and process all for the sake of trying 0000-9999.
In other words, this is obviously bullshit on the side of the FBI. The question is why they're doing that. I suggest that it's not about legal precedent, because newer iPhones can't be undermined like this and the All Writs Act can't compell Apple to stop producing such devices, it can only (arguably) compell them to undermine devices if it's within their reach. (IANAL so please call me out if I'm wrong about that.)
I suspect it's about PR, because when they lose they can throw their hands up and the news pundits will scream about terrorists winning in our courts. Washington will then push their backdoor legislation that they've been asking for over the past few months.
Legal precedent isn't what they're after, IMHO. The legal precedent that would be set wouldn't be applicable to where things are headed. They're looking for public appeal.
They're not ordered to decrypt it. And I think when a layman hears "unlock", they're led to believe that means decrypt.
If it were rephrased as "Hello Mr. Landlord, we're ordering you to open a machine shop and pay several employees to develop a new lockpicking device that could be copied infinitely for free and which would allow us, or anyone really... a North Korean agency, an organized crime syndicate, or a jealous and abusive ex-lover perhaps, to more easily break into any of the homes of billions of people around the world with or without reason or warrant?" then the layman might perceive it a little differently.
That seems to be like the message that Apple's trying to communicate, but I don't know if they're getting it across clearly enough for most people.
That's where your analogy breaks down. This hardly makes it easier. If North Korea or FBI or NSA or a criminal organization wanted to break into your iPhone, and this backdoor existed and was distributed, they would have to externally flash it with firmware and then hook up a controller that tricks the digitizer so that they can brute force the passcode, trying each one synchronously on a shitty mobile processor SoC.
Is that really less complicated than externally reading the memory itself and using John the Ripper and a supercomputer? Is it meaningfully less complicated?
I don't fully trust the government, but I trust it far more than I trust Apple.
Sometimes I feel like the whole Snowden thing is just an excuse for big corporations to keep all their data and analytics practices to themselves outside of the scrutiny of the government. Since when did the government become the enemy? There is something really twisted happening behind the scenes here.
Big corporations are manipulating us into thinking that the government is not to be trusted. But think about it; the government doesn't care about making a profit.
Without the government, the masses have no voice. I would gladly help society and let the government look through my phone if it will help prosecute a criminal.
Not much wrong with the FBI ruining guilty peoples' lives; it's all the innocent people they'll inevitably fuck over.
edit: Not to mention there's no such thing as a "back door for law enforcement only".
Is this a serious question? There are volumes upon volumes providing viable, defensible answers. The problem is that you have to empathize with the under-privileged and unrepresented.
Why risk opening that Pandora's box? If the tool doesn't exist, it can't be exploited by bad actors
Everyone else is still safe. Safer, I might add. So long as there is a clear process for the government to get access to specific keys for specific phones.
If Apple is CAPABLE of building such a tool (and use it for themselves), then I think the government should have access to it too.
What the FBI is asking Apple to do is write software that will turn off the "wipe after 10 wrong passcodes" feature of iOS, so that the passcode can be brute-forced.
Setting aside the government's interest in such a tool, imagine the interest from hackers.
Consider that in 2011, someone hacked into RSA to steal info about their tokens, just so that they could then hack in Lockheed to steal top-secet info.
Now imagine someone hacks into Apple (very possible to happen) and steals the security-defeating software code to install on other iPhones.
Though I find it hard to believe that Apple doesn't already keep some sort key(s) to unlock individual phones or to turn off this "wipe after 10 wrong passcodes" feature.
Facebook (and pretty much every other internet company on earth) keeps password hashes and salts in their databases - So in theory, the government could already brute force the vast majority of our personal data from these websites.
At least with a phone, the government has to physically get a hold of it in order to brute force the phone and read the data.
Passwords control access to features of the web application, but employees of the company can just go around that and get the data off the server directly.
iPhones running iOS 8 or higher are different--they do encrypt data at rest, and create the key by combining device-specific info with the passcode that the user creates. So without that passcode, no chance to decrypt without brute forcing.
If the US government gets access, so does Russia and China and whoever else wants it.
Since they began to treat the people as the enemy.