Tuesday Adi Shamir at the RSA conference said that this is not the right case for this issue and that Apple should help the FBI in this particular case and I completely agree. Apple also has screwed up as well and should admit it. Apple would not even be able to comply with the FBI's request with the proper security architecture. The iPhone should require user authentication before updating the software/firmware. If it had required authentication first, then the FBI would need to enter the pin before installing any software, preventing them from installing this vulnerable version of the software to crack the pin. Then Apple would not be capable of helping the FBI in this way aside from hacking the iPhone. I hope that Apple fixes this problem by requiring user authentication before software updates so they can put this issue to rest. And it looks like they probably are (
http://www.nytimes.com/2016/02/25/technology/apple-is-said-t... ) They can then avoid using this technique in the future and avoid putting their signing key at greater risk.
From a security risk standpoint, Apple's arguments are fairly weak. They argue that this binary could potentially be leaked and used on other phones, but this would not be possible if they implement the solution I have already stated. Maybe an adversary could infect an OS with this code using a security vulnerability, but if they can do that then there are worse things they could already do. The best argument I have seen is that doing this will result in Apple trying to comply with requests from the government in bulk, and in doing so create an environment in which Apple signs many copies of this firmware on a much more frequent basis, an environment which would put their signing key at greater risk. Again they would not need to do this in this case if they fixed the authentication problem.
Apple keeps trying to construe this as a backdoor but it isn't really a backdoor. It is a security vulnerability in Apple's security architecture and it is fixable. If Apple keeps pushing the backdoor issue then Congress may legislate on backdoors or the courts may make a decision on them, and likely not in our favor in this case.
This is not the right battlefield for Crypto Wars 2.0. This is a high profile and emotionally driven case with a mass shooting in which much of the public will side with the FBI simply on this fact alone. The phone is the property of the government, the gunman is dead and all of these facts work in the FBI's favor. We should be fighting this on our terms and not the FBI's.
Rep. Sessenbrenner was correct when he told Apple's lawyer during the hearing that "you are not going to like what will come out of Congress on this". If any legislation is passed we will most likely be in a worse situation than we are in now. The best thing Congress could do on this issue is nothing at all. And Apple is pushing them to take action.