FBI’s Comey Concedes Mistake Was Made Over iPhone in San Bernardino Case
wsj.com
wsj.com
And that belief is based on what exactly?
Apple has being saying the opposite. Apple doesn't know it's own code? FBI knows it better.
Let's say that some attacker wants to create a compromised OS and install it on a certain device.
If apple never creates the compromised OS, they would need to hack into apple, get all of the source code necessary to build iOS, figure out how to build it, figure out how to modify it in the desired ways, how to get it installed on a phone, steal the crypto keys necessary to do the signing, and sign the bad build.
If apple has created the compromised OS, they would just need to hack into apple and get the compromised OS build, steal the crypto keys, and sign it.
The first scenario is a large-scale software engineering project. Anyone that's been given a large source dump will tell you that it's horrible and takes forever to do anything, and iOS is going to be absolutely huge and tricky. You'd need a large, highly trained team of security/OS devs, which is hard to come by and would be extremely expensive.
The second scenario could conceivably be done by a single hacker, if they can find vulnerabilities in apple's security.
Now, let's say that they have written it for some reason, but it is restricted to a single device id. Well, it's now a lot easier for the government to compel Apple to hack another phone, because they can creditably argue that all Apple has to do is change some string constant and re-sign the package. The burden of work is now much, much less than if the tool itself doesn't already exist.
Apple doesn't want to ever create the tool. If they have to create it for any reason, even if it starts out being locked to a single device id, they've lost the war.
Crackers broke copy protections for decades without having access to source code of protected games.
The only thing you would need is to have access to private key needed to sign the new code so that phone will accept it, but even that could be broken by hardware engineer.
Anyway the whole thing does not make much sense. Those shooters are already dead, they destroyed their private phones, this was a work phone, they already can access metadata (outgoing/incoming calls etc) from cell provider. FBI went public with this even though in their best interest would be to do it secretly. What does FBI expect in doing this publicly? Did they expect is to cheer for them and complain about evil Apple not helping to break evil terrorists' phone?
It doesn't make much sense... unless the real goal was to make people trust Apple more after Snowden's disclosures. Isn't interesting that Google, Facebook, Microsoft... every company which was previously involved in PRISM supporting Apple? Trusting them benefits both, the agencies and those corporations.
I think that is exactly what they expected. Terrorists and pedophiles are the best way for federal TLAs to expand their powers.
And if you can get around the digital signage, you don't need the compromised OS.
Conway's technical interpretation of the Apple deliverables is right. There's a legal precedent which could cause reuse (and is rightly matter for debate/utter refusal of the FBI position), but if you just debate the technical merits Apple has been very misleading about the consequences.
China (or Russia or Germany or whoever) could force Apple to backdoor phones used by CIA informants in that country.
It's a ticking bomb, man.
This carries with it the assumption that the digital signing and verification mechanisms are infallible and impervious to attack. That is an unwise assumption. Even if a software system appears to be perfectly secure at a given time, it is reasonable to assume that at some point a vulnerability will be discovered.
Not necessarily. Someone could get their hands on the signing keys or find a vulnerability in the signature verification without having the knowledge or resources to create something worth signing. Or figure out a way to bypass the check by changing something that isn't covered by the signature, or use something like rowhammer or hardware hacking to flip the bit from saying the check failed to saying the check passed, etc.
signing <> encrypting
Wait three weeks or three months for the FBI to request n copies of the evil thing, tailored to each of the n phones it wants to open. Better still, wait for a few others to make similar requests. Now penetrate or impersonate a law enforcement agency of your choice and send Apple a routine request for the n+1th copy, tailored to the phone of your choice.
Once you have done that, the other steps are easy.
Thus, having the signing key (or the power to compel signing at will) is an incredible ability privy only to Apple.
[0] Some Mach-O information is lost. Decryption of the imgX formatted kernel is preferable.
Comment out the function call. Change the number of allowed guesses to MAX_INT. Change the time increment to zero. Click build.
This is not a hard task!
This is the best writeup I found: http://blog.trailofbits.com/2016/02/17/apple-can-comply-with...
So, you'd need an update to iOS/the phone firmware, and for newer devices you'd also need an update to the secure enclave firmware. You can't do anything about the 80ms delay, because that's baked into the hashing function (and changing the hashing function would generate invalid results). The FBI is also asking for the ability to enter passcodes electronically rather than via the touchscreen, which would be new code.
If iOS and the SE firmware are really nicely factored to disable security, and it's not hard to add the new functionality, then this might not be too much work. However I doubt that that is going to be the case. The whole point of the security system is to make it difficult to crack, so there might be other countermeasures involved, tricky dependencies, and low-level hardware hackery. If it were simple to do, why wouldn't it have already been done by others reverse-engineering the compiled code? There is certainly financial motivation to do so.
I'm willing to bet iOS has a huge build infrastructure, many different components, and about a snowball's chance in hell of having a single nice clean Makefile for you to type one command to get a build without access to that infrastructure.
People are making it out like the FBI is asking Apple to rewrite a big part of iOS. That's not the part of the request that's the problem.
Come to think of it, why aren't free market standard bearers rallying against this as government intrusion into market features?
Example from organization supporting free markets. http://fee.org/articles/apple-defies-fbi/
And then there is no shortage of examples from the presidential candidates who claim to support free markets, yet none are standing behind Apple.
For instance, do you really think Microsoft will be able to sell Office software to the Netherlands Government if the DOJ/NSA/whoever can use the All-Writs Act to force Microsoft to implement a backdoor into their software? Would the NSA be able to use the AWA in conjunction with a NSL and a secret court to force the hand of companies? Politicians / the public don't really grasp what's at stake here. What we're really talking about creating a complete and real artificial handicap for all software companies located/based out of the US. Already there is pushback in China, Europe and Australia to ditch American-made software after the Snowden revelations. A ruling in favor of the FBI will only compound and accelerate this issue and will have a marked and measurable effect on the revenues of software and hardware companies located in the US.
While Google/Apple/Facebook/Microsoft/Cisco et al may not be able to relocate, this will definitely cause small and medium sized firms to relocate or possibly to never incorporate within the US to begin with. This may be effectively and preemptively scaring away the next Google. Law of unintended consequences and all that.
Also: Terrorism.
because it has nothing to do with the "free market".
I think what's coming out of this is that the Fbi is riddled with incompetence and inability to face modern threats, plus a silly hybris that is the foundation for silly strategical mistakes.
I also could imagine that Apple would aid such a case anyways.
So by not signing any requests for that particular firmware hash, Apple can effectively neuter that firmware and make sure it's never installed anywhere but on the target phone.
The problem is though: If apple can be compelled to do this once, they can also be compelled to do this any other time.
Quick googling seems to support this.
I mentioned that the most common method for uniquely identifying a handset (the IMEI) can be changed by switching a chip on the iPhone's main board. (At least this was true 6 years ago.)
So, unless Apple uses an interactive signature scheme or prevents the FBI/intelligence agencies from ever seeing the signature (using TLS with hard-coded certs), then the signature can be replayed.
If the signature can be replayed, then in order to prevent FBiOS being used on multiple phones, it must be tied to one or more unique identifiers, probably excluding the IMEI.
Many people understood my post as shorthand for the above. Responding to this with "[But] Apple firmware updates are signed on a per-install basis." doesn't add to the conversation unless you provide further details. At least, that's my best guess as to why you've been downvoted.
https://www.theiphonewiki.com/wiki/ECID Firmware updates use this, not IMEIs. And I think the IMEI is more commonly used to identify the radio, not the device itself. But I could be wrong about that.
>So, unless Apple uses an interactive signature scheme or prevents the FBI/intelligence agencies from ever seeing the signature (using TLS with hard-coded certs), then the signature can be replayed.
Every time you update an iPhone it generates a nonce, called APTicket. Apple signs that, your ECID and the firmware. The nonce essentially makes replay attacks impossible, even if you managed to swap a devices ECID.
> And I think the IMEI is more commonly used to identify the radio, not the device itself.
Across manufactures, I'm not sure another quasi-unique identifier in common use.
> Every time you update an iPhone it generates a nonce, called APTicket. Apple signs that, your ECID and the firmware.
This is one variant of interactive signature scheme.
Not turning over the encryption/signing keys would be followed up with jail time / contempt of court charges for any officers/developers/etc refusing to remand the keys into federal custody.
Also the FBI would want to use it on other phones as well. They might modify it themselves to work with other phones.
Seems just for a moment, because, via Reuters:
http://www.reuters.com/article/us-apple-encryption-congress-...
"FBI Director James Comey told a congressional panel on Tuesday that a final court ruling forcing Apple Inc (AAPL.O) to give the FBI data from an iPhone used by one of the San Bernardino shooters would be “potentially precedential” in other cases where the agency might request similar cooperation from technology companies."
"Manhattan District Attorney Cyrus Vance testified in support of the FBI on Tuesday, arguing that default device encryption "severely harms" criminal prosecutions at the state level, including in cases in his district involving at least 175 iPhones."
Still a good idea?
In the scenario you lay out, these security agencies are incapable of writing their own modifications to iOS, even though they possess the source to iOS.
Absolutely ridiculous. If they can steal the source and signing key, they certainly have access to the technical expertise to do it themselves.
I mean christ, exactly how complicated do you think this pin timeout logic is? If they can hire sufficiently skilled hackers, they can certainly hire sufficiently skilled developers.
The security of the system lies in the secrecy of the signing key. If they can meet that bar, they can surmount any other obstacle.
Which in the current world, is about as far from having an exploit as one can be. Digital signing works pretty well.
Think about this in the context of jailbreaking to understand why such a facility exists. Apple doesn't want users to install their own modifications to iOS, and they also don't want users to install old versions of iOS that have vulnerabilities that would allow people to modify the OS.
One way you could implement something like this is to have a public/private keypair within the device and have updates encrypted with the public key; then design the device to only run an OS that it could decrypt with its private key. To do this well, you would need a TPM that did not allow the private key to leave the device, nor to be reset.
if (unique_device_id != SAN_BERNARDINO_DEVICE_ID) {
halt();
}
If this code must be signed to execute then it can't be modified to work on another device without Apple signing it again.This assumes there's a unique device ID that is known to the FBI and can't be tampered with. Maybe the serial number or IMEI?
if (unique_device_id != SAN_BERNARDINO_DEVICE_ID) {
goto fail
}"Whatever the judge's decision is in California ... will be instructive for other courts, and there may well be other cases that involve the same kind of phone and the same operating system"
It's a little strange for him to dismiss the notion that this will set a precedent because it will just be for one phone and then imply that this case will set a precedent for other phones.
Here's the report that he confirmed the precedent:
"Comey told a congressional panel" "that a final court ruling" "would be “potentially precedential” in other cases where the agency might request similar cooperation from technology companies."
http://www.reuters.com/article/us-apple-encryption-congress-...
However, if they can be compelled to do this once for one phone, they can be compelled to do this many more times for as many phones as the FBI or everyone else wants.
I would say: Both are right in this case.
Apple would have to change some config files to unlock the other phones, resulting in new code.
I've written up a summary of the hearings at InfoQ here: http://www.infoq.com/news/2016/03/apple-fbi-congress
The general responses from Apple were that it wouldn't be possible to write this just for one phone; that once the FBiOS was available for one it would be available for any phone. Dr Landon also highlighted the fact that most people now use their phones as part of a two-factor authentication, and that the easiest way to break into a system (such as the IRS leak) is to compromise login credentials. The fear is, therefore, that once pandora's box is opened that the operating system would be installable on any device and thus potentially give access to any state actor to any account simply through device compromise.
The entire hearing was very well laid out, though in a few cases Apple's witnesses weren't quite as fluid as the FBI's.
The congress members have five days to ask additional questions, after which presumably a report will be made. More information is available at the House page here:
http://judiciary.house.gov/index.cfm/2016/3/the-encryption-t...
-Carl Sagan
There is a serious problem here. If you ask me any government official who forces a backdoor down the throat of a private company ought to be fired, yet he believes he should be fired if he DOESN'T do it.
There's a very big divide happening right now in the US. This is going to be a rough time.
Looking at it from the other angle, I think it's a bad precedent if the FBI were to refrain from pursuing an avenue which it believes it may have legal standing to pursue. At that point, it runs the risk of a downward spiral of second-guessing and apprehension.
What I do have a problem with is this little fucking PR parade Comey's going on to try to lobby the public against Apple in particular, and privacy and cryptography in general. He's been completely rhetorical this whole time, ignoring the fact that what he's asked for is a huge fucking deal, and forcefeeding "terrorism", "public safety" and other trigger words to get the public to rally behind something they couldn't possibly understand.
Make the request and shut your stupid mouth, Comey.
This ... creates certain elements of friction and pressure.
Not merely courts.
Yes, I expect that courts would be tasked with drawing boundaries where extraordinary discretion is required. But throwing up your arms and saying "hey, we're the executive branch, not my problem" doesn't cut it. In fact that can very well land your ass in gaol or at the receiving end of a civil rights lawsuit (modulo limitations on liability for government officials, but that's another worm of cans).
Incidentally, I strongly recommend developing at least one or two abstract thinking skills if you're going to play around here. Helps smooth things along.
Relevant personal attributes, especially those which address credibility, are generally in bounds (see also "the asymmetry of bullshit", a/k/a Brandolino's law).
And observations of personal character not used as basis for argument aren't ad homs. Full stop.
http://www.nizkor.org/features/fallacies/ad-hominem.html
If you're going to use logical fallacies, try to use them correctly.
And while the initial comment whose tone you disagreed with, and the paragraph above may not be seen as acceptable on HN (I tend to feel they skate within bounds), both point out a category of error, and steps a person might take to correct them. Insufficient abstract interpretation in the first case, incorrect use of specific terminology in this case.
Of course, you could simply insist on being wrong. But that's your call.
Cheers.
You can prove your point without being a dick, especially when being a dick does nothing to help prove your point. A little politeness goes a long way.
If this is your definition of "strictly following the law" imagine yourself in a scenario where the FBI brings a lawsuit against you: risk going to court, losing, and going to jail, or hiring a lawyer and fighting something with dubious constitution grounding.
There are so many different ways to lose when the FBI plays this game against private companies or individual. They sue you because they want to put you in jail, not clarify the law.
If you're a strongly opinionated CEO of a company with a war chest you fight it and at the very least stay out of jail. If you're the CEO of a small ISP/web hosting company you suck it up, do what they say, and follow the gag order.
I do agree it's not quite fair to put defense costs on the company/individual that needs to fight it, but the alternative I can think of is a public defender type system that I don't think many people would be happy with for corporations.
Isn't that what we expect from all people and institutions? moreover, we expect the people to be in control of "challenges" to the laws, and the laws themselves. Much of what's wrong with government comes from government creating self-serving laws.
The laws are what the courts interpret them to be; no more and no less. Like it or not, strict interpretation is a fantasy and has been since the late 1700s.
That's only true in a vacuum. In reality, every tinpot tyrant on the planet would like to have the US set a low bar so they can insist that US tech companies agree to their similar demands.
It's just as valid an argument to say they should be cautious about constitutionality and still get their job done.
No one said anything about probing constitutionality. There is a legitimate question about the limits of the All Writs Act. So they asked a court to issue the request.
Law enforcement must work within the confines of the law, but when there is a question of what those confines are -- and in the legal sense, that is most definitely an unanswered question here -- they ask the courts to decide.
Once the courts rule, I expect for the FBI/etc... to act in accordance with the ruling. And if you don't like the ruling, talk to Congress.
Upholding the Constitution is basically your primary job responsibility in Law Enforcement and the Military. No other duty should supercede that duty.
You are correct that law enforcement does not provide the authoritative interpretation of the Constitution, but you seem to imply that they should operate under ignorance of the Constitution. This is wrong.
Law enforcement must have an understanding of the Constitution, and they must uphold it. For example, it's a dereliction of duty to always argue that any search is reasonable.
Law enforcement must have an understanding of all laws (for their jurisdiction), including the Constitution. However, when there is a legitimate question, it's not up to law enforcement to make the final judgement calls. It's for the judiciary to make that call.
It's fair to say that this is an argument that has been building for a while.
As such, it's very appropriate for the courts to make this call. And once that decision is made, it's up to law enforcement to act accordingly.
Note: I think the California court will reach the same decision as the Brooklyn court. But I don't have an problem with the DoJ/FBI raising the issue.
That's not actually true. The executive and the legislature all have to swear to uphold/defend the constitution and it takes all three branches of government to violate it. If Congress says that something is unconstitutional and refuses to pass a law permitting it then the executive can't do it. (The FBI is nowhere in the constitution, its very existence is at the will of the legislature.) If the executive branch says that something is unconstitutional then they can refuse to do it. Nobody can force the executive to prosecute someone under a law they think is unconstitutional.
People only see the courts as the arbiters of the constitution because they're last. You only get there if the legislature is willing to pass the law and the executive is willing to enforce it. But that is a piss poor excuse for the other branches of government to neglect their oaths.
I [name] do solemnly swear (or affirm) that I will support and defend the Constitution of the United States against all enemies, foreign and domestic; that I will bear true faith and allegiance to the same; that I take this obligation freely, without any mental reservation or purpose of evasion; and that I will well and faithfully discharge the duties of the office on which I am about to enter. So help me God.
In order to support and defend the Constitution, you must have an understanding of what it means (unless you interpret the oath -- itself part of the Constitution -- to mean physical support and defense of the physical document.) To have an understanding, you must interpret. The oath, therefore, requires interpretation.
(Now, the Constitution itself gives the judiciary the role of resolving controversies arising under the Constitution, which includes disputes arising from differing interpretations. But people -- including executive officers -- have to have interpretations before they can get to the point where such a dispute arises for the courts to settle.)
Technology will always be moving faster than courts can define how the law applies, and thus interpretation is a part of law enforcement's daily job.
Imagine using the same logic in gun control. Imagine there were no laws against certain kinds of ammunition and law enforcement just went around saying certain guns are illegal just because what was in the officer's coffee that morning. People always throw around the phrase "we're a constitutional republic, not a democracy" when I say the Connecticut compromise ought to be scrapped but the same people are for a massive overreach by law enforcement.
Imagine someone shot and killed you in the street for no reason and said they thought it was their right. Would that absolve them? No. Neither should this kind of overreach by the FBI be legal.
Clearly, gratuitously testing the limits of the Constitution is not demanded by the oath, but I don't think that that's the claim Comey was making. (Note, I'm not saying that I agree that this is a case where a rational expectation of the value of breaking into the phone in question to protecting the U.S. and its Constitutional order does justify testing the limits of law enforcement authority, I'm just pointing out that its not unreasonable to think that there are situations in which upholding the oath might reasonably be seen to require testing the boundaries of Constitutional authority.)
Which, while technically correct (The Best Kind Of Correct), isn't the sort of thing the FBI runs into very often. Because the FBI is not constitutionally obligated to succeed in apprehending every criminal. If the FBI wanted to embody the principle of letting 10 guilty men go free before convicting one innocent then they would in practice run into a lot fewer prickly constitutional edge cases.
Its already not merely a firing offense but a federal felony for law enforcement officers and other public officials, but the FBI is the lead agency enforcing that law, so its probably unlikely to be as effectively enforced when the Director of the FBI is involved. [0]
[0] https://www.fbi.gov/about-us/investigate/civilrights/color_o...
For example, the 4th Amendment protects against "unreasonable" search and seizure. There is a lot of leeway in what is or isn't reasonable.
If you believe in the system you should be glad it is going to the courts - it is the job of the judicial branch to interpret the law. And however it comes out will be a precedent for the future.
Let's take this on face value. He's suggesting POTUS would fire him for not fighting for backdoors, when POTUS has publicly come out against backdoors. So what is going on here?
I suspect Comey is just a fucking idiot. He's one of these old school guys who thinks LE should have an endless war on the citizenship. I suspect we're destined to have this fight every so often, and from a more practical perspective, not every company is Apple or has the financial and political power Apple has. How many others have agreed to the terms Comey demands? Perhaps many.
Some people (Comey) believe that what is said in public has no value? Or that those same people might instead believe that the POTUS is not their boss...
I'd argue that he's being intentionally deceptive. For example, he testified* that "he's not a good lawyer", when in fact he served as the Deputy Attorney General during the Bush administration.
* http://www.motherjones.com/mojo/2016/02/james-comey-ducks-mo...
I hate this kind of willful ignorance. That update, if properly signed, will work on similar phones. The software is distinct from the signing and it's the software that Apple doesn't want to create.
Or maybe Comey believes that every time his phone is updated, an engineer in Cupertino lovingly arranged the bits for him.
> "Apple has created a technology which is default disk encryption. It didn't exist before. It exists now. Apple is now claiming a right of privacy about a technology that it just created. That right of privacy didn't exist before Apple created the technology." [1]
Wrong. The first and fourth amendments grant rights to privacy. The exact transcripts of what we say in the privacy of our homes, prior to a warranted wiretap or without witness testimony, are not the subject of law enforcement's investigation. Our entire history of digital communications should not be open for government surveillance. It would be overreach to try to implement, and anyway it is impossible to guarantee without destroying the US tech industry and turning us into a big brother state.
There really isn't a fourth amendment issue.
I do still disagree with the District Attorney's statement. We can write something on a piece of paper and burn it, or think something in our heads, and keep it private. That this is now possible with digital communications via encryption is not a new right, it is simply a new means to protect that right. Further, Apple didn't invent encryption, and this statement further shows how little the DOJ understands about technology.
Wait, is he actually arguing that the right of privacy didn't exist until a few years ago? There's literally decades of precedent, including digital precedent, for a right to privacy.
What's at stake here is the power of government to compel testimony. They already have the phone, but they lack the power to compel its unlocking.
That's not how rights work.
I'm not saying criminals don't deserve rights. In fact, what's at stake here is that the Fifth Amendment does protect a mass murderer from revealing his passcode, so I'm not sure what you and all these downvoters are going on about. If criminals didn't have rights there wouldn't be an issue here.
If the passcode on the phone were crackable, it would be absolutely 100% legal to search it. And that kind of thing happens routinely. The issue at stake is not searching the phone, but compelling Apple to help with the search.
It also amazes me he thought it was a helpful metaphor to say that the FBI doesn't want a backdoor, just for Apple to take the “vicious guard dog away” and “let us pick the lock.” I think every American would prefer having a guard dog protecting their personal property and data than just let these liars pick the lock.
The reality is that he is asking Apple to weaken the front-door to the point where an average attacker can open it with a paper clip.
They [Apple] sell phones, they don't sell civil liberties, they don't sell public safety, that's our business to worry about. [1]
He thinks public safety is entirely his domain and private companies cannot help people keep themselves safe. That's as bad as "self-made" business owners who cannot see that roads and infrastructure helped make their businesses successful and cry socialism whenever taxes are levied.
You know, the sad part about this (paraphrased) quote is that it'll probably be used as justification by the California court system to rule on this case specifically rather than on the circumstance more broadly. I wonder if that's Comey's strategy in admitting the error.
"We are a rule-of-law country. The FBI is not cracking into your phone or listening to your communications except under the rule of law," says Comey (1:37). I suppose that's the NSA's job...
Truly, I'm getting weary of all the nearly-identical news of Uncle Sam's assault on digital privacy. If the strategy is to desensitize and wear down the US populace, it's working.
I can't understand why Apple are fighting this. They're essentially forcing the government into resorting to legal mechanisms that will have longer term impacts.
It's pretty clear to nearly everyone that this phone belonged to someone who committed a terrorist attack. The data on it may prove useful in preventing future attacks. If Apple were being cooperative, they could create the mechanism to get the data off the phone, have the FBI hand over the phone so they could do that for them, (optionally) delete that version of the OS if there's a problem with it even existing, and no legal precedent would be set. The question of whether the FBI should be able to compel them wouldn't arise, because they would have been cooperating off their own accord.
If the FBI asks them to do this to the iPhone of someone who is more likely to be innocent, perhaps then this debate should be had. For now, they have the means, can do it without setting a precedent, have a pretty good reason to do it, and can do it in isolation. They should just do it, in my opinion.
The data on it may also not prove useful in preventing future attacks. Especially as it was a person's business (not primary) phone.
The other issue here is that this will only grant safety insofar as terrorists don't do math or encryption themselves - and that could be through an app that they write or a foreign made android phone where they lock the bootloader with their own code signature.
Besides, once the software exists and is signed by Apple, it's very hard to prove that all copies have been deleted.
Proving all copies are gone isn't possible; you can't prove non-existence. Ensuring extreme unlikelihood seems relatively straightforward, though. Make fewer copies, trusted personnel only, isolate the development to a particular location with no network access, etc. Naturally there'll be a risk that a copy survives, just as there's a risk that a contingent of rogue Apple employees are already working on it for the FBI.
From a security risk standpoint, Apple's arguments are fairly weak. They argue that this binary could potentially be leaked and used on other phones, but this would not be possible if they implement the solution I have already stated. Maybe an adversary could infect an OS with this code using a security vulnerability, but if they can do that then there are worse things they could already do. The best argument I have seen is that doing this will result in Apple trying to comply with requests from the government in bulk, and in doing so create an environment in which Apple signs many copies of this firmware on a much more frequent basis, an environment which would put their signing key at greater risk. Again they would not need to do this in this case if they fixed the authentication problem.
Apple keeps trying to construe this as a backdoor but it isn't really a backdoor. It is a security vulnerability in Apple's security architecture and it is fixable. If Apple keeps pushing the backdoor issue then Congress may legislate on backdoors or the courts may make a decision on them, and likely not in our favor in this case.
This is not the right battlefield for Crypto Wars 2.0. This is a high profile and emotionally driven case with a mass shooting in which much of the public will side with the FBI simply on this fact alone. The phone is the property of the government, the gunman is dead and all of these facts work in the FBI's favor. We should be fighting this on our terms and not the FBI's.
Rep. Sessenbrenner was correct when he told Apple's lawyer during the hearing that "you are not going to like what will come out of Congress on this". If any legislation is passed we will most likely be in a worse situation than we are in now. The best thing Congress could do on this issue is nothing at all. And Apple is pushing them to take action.
The issue here isn't the reusability of the technology—the issue is the reusability of the legal precedent. And this is certainly a very scary precedent to set!
http://www.reuters.com/article/us-apple-encryption-congress-...
"Manhattan District Attorney Cyrus Vance testified in support of the FBI on Tuesday, arguing that default device encryption "severely harms" criminal prosecutions at the state level, including in cases in his district involving at least 175 iPhones."
(2)The FBI wants 3 things: disable 'erase after 10', disable delay between attempts, create possibility to enter PINs programmatically so they can be brute forced.
(1) If this would be created, criminals/terrorist could easily defeat this by (instead of 6 digits) enabling alphanumeric passwords and creating strong passwords that cannot be brute forced (which isn't even a usability problem since you can easily unlock your iPhone with your fingerpint most of the time.)
So the end result of (2): security is lowered for 99% of all people (innocent) and criminals/terrorist (1%) can still easily avoid being caught by this measure.
Any iPhone <5 running iOS <8 is comically exploitable. This should drive home the point that as time progresses, older vulnerabilities become easier to exploit, so that leaving them unpatched becomes irresponsible.
If the FBI asks Apple to create new software to grant the FBI the ability to unlock the phone, they are effectively asking Apple to exploit a vulnerability in their software. By definition, Apple will know that vulnerability exists. In the "arms race," when Apple identifies a vulnerability, they fix it. In this case, when Apple identifies the vulnerability, will the FBI allow them to fix it? Or would the FBI prefer that Apple have a responsibility to "maintain" the vulnerability and ensure it remains exploitable?
I skipped around the video. I mostly saw support for Apple, with a few exceptions, one being Mr. Sensenbrenner.
Mr. Sensenbrenner, a House republican of Wisconsin, asked Apple what legislation they would support, and Mr. Sewell, Apple's general counsel, said they support debate on the subject [1]
The congressman was clearly bullying Mr. Sewell here and using his position as congressman to make it appear as though Apple is not being agreeable. Well, encouraging debate before writing one-sided legislation sounds like great teamwork to me.
The congressman should have been reminded that not supporting new legislation is a valid position, and that every problem we face need not be solved with new laws.
Perhaps Mr. Sewell is trying to be respectful to the congressman. But I think he should not shy from responding in kind. Treat others as they treat you. No one will judge you for it. I think Apple missed an opportunity here to say they do not feel new legislation is needed, since guaranteeing back doors into devices would be an abridgement of consumers' right to privacy, and Apple's right to create safe products for consumers as it sees fit.
Overall though this seemed like a productive session.
Mr. Gowdy, a House republican of South Carolina, also bullies Sewell in the same manner [3], literally asking Apple to lobby for legislation.
In other words he is saying, get some lobbyists, do my work for me, pay for my next election campaign and solve your own problem. I don't know how you could be more blatantly obvious about being a corrupt, useless politician.
[1] https://youtu.be/g1GgnbN9oNw?t=3h59m30s
EDIT transcript here, though no speaker names are given and quotes are cut short
[2] http://www.c-span.org/video/?405442-1/hearing-encryption-fed...
[3] https://youtu.be/g1GgnbN9oNw?t=4h36m35s
EDIT list of participants:
[1]http://digiday.com/publishers/wall-street-journal-paywall-go...
https://support.google.com/news/publisher/answer/40543?hl=en...
Some sites refuse to serve content if an adblocker is installed.
So there is a lot of subscription models with some websites that try to force people to pay for articles. It is not that they don't want you to read, they want you to pay to read.