FBI May Demand iOS Source Code, Signing Key
theverge.com
theverge.com
This statement reminds me of a time when a few companies tried to fix a road that the government refused to fix but kept awarding awarding contracts for yearly.
The government took em to court. The court said that building roads was not the job of civilians. And here is where things for interesting.
They asked the companies to give the government money so that the government would build that road
Lindsey Graham
[1] https://www.youtube.com/watch?v=uk4hYAwCdhU
Mike Lee
[2] https://www.youtube.com/watch?v=XOZLEhTlr6E
Dianne Feinstein - 51:00
[3] http://www.c-span.org/video/?406201-1/attorney-general-loret...
[4] https://www.google.com/search?safe=off&q=site:https://www.wh...
America is ruled by an unaccountable and corrupt elite.
The truth is that a large number of Americans believe that the FBI should have access through consumer encryption. Agree or disagree, but the existence of that public sentiment is a fact easily observable in public polling.
Security vs. freedom is a tradeoff. Different people have different opinions of what makes an acceptable trade.
The role of representative government is to adjudicate between differing opinions. That is why this is still an issue, and will continue to be an issue for the foreseeable future--not because there is some secret cabal who is working counter to the wishes of all Americans.
This is not a democracy, this is a republic. We should hold our elected (and appointed) officials to higher standards than we hold our voters. Just because our public is uneducated does not excuse the elected government taking advantage of an uneducated public to seize powers they did not have before.
I'm sick of reading this too.
We have a representative democracy in the U.S. We also have a republic. The two terms are not contradictory.
"Representative democracy" tells you how decisions are made--we select a few citizens to make decisions on our behalf. "Republic" tells you who is sovereign--in the U.S. the individual citizens have the right and power to rule, and have used that to construct our own government.
Counter examples:
The U.K. is a representative democracy, but not a republic. It's a monarchy.
North Korea is a republic but it's not a democracy. It's an autocracy.
Can you address anything I wrote that had substance?
http://lmgtfy.com/?q=define+democracy
> Can you address anything I wrote that had substance?
That our elected officials represent the disparate opinions of the people they serve might be their personal failing, in your view, because you disagree with them on this issue. I disagree with them too! Encryption should not be backdoored, the FBI is wrong--I agree on all those scores.
I just don't think that the only reason the encryption conversation continues is because of corrupt political elites. It's not. The conversation continues at the public level too.
The reason that matters, is what we can do about it. If public opinion is the problem, then a public campaign can try to move it. If corrupt political elites are the problem then... we throw up our hands? Isn't that just rationalizing despair and inaction?
edit: clarity
This definition is meaningless. Under this definition, every government is a democracy. People technically voted for Kim Jong Un.
> That our elected officials represent the disparate opinions of the people they serve might be their personal failing, in your view, because you disagree with them on this issue.
No, their personal failing is not thinking for themselves.
> I just don't think that the only reason the encryption conversation continues is because of corrupt political elites. It's not. The conversation continues at the public level too.
I do agree—however, the elected officials are still failing their constituents by not actually understanding what encryption is. They have a responsibility to be educated when their constituents are not.
I totally agree with you on this. Here's a sliver of hope that progress is possible...
Yes, they've been led to believe this by the "corrupt elite" you so casually brush aside. It's better characterized as a gradient of out-of-touchness rather than a well-bounded "elite" class [0], but the net effect is the same.
"Propaganda is to a democracy what violence is to a dictatorship" and all that.
[0] eg the skinjobs parroting the message on TV aren't directly reliant on the propaganda, but thinking too hard about it would lose them their employment.
When thinking about politics, remember: most hackers are more paranoid than the average person. A lot more. Because our training tends to show us what damage can be done, and that people will do damage for the hell of it [https://medium.com/@blakeross/mr-fart-s-favorite-colors-3177...]. When the Boston Marathon was bombed, the police put the city on basically a full-panic lockdown to catch two men; a lot of people were okay with this because it made them feel viscerally safer, not because they were trained wrong by a corrupt elite. You disregard the actual state of human nature to assume otherwise, which is probably disadvantageous.
I agree with your general point about human nature of blindly trusting the biggest stick, but that doesn't mean we should avoid blaming the scumbag mass media for abdicating their traditional duty of critical analysis and turning into pravda.us. If someone wants to ascribe this to an explicit conspiracy with an evil cabal while I simply see panicked well-to-do ignorants promulgating their bubble, I'm not going to let disagreements about details get in the way of agreeing on the commonalities. Any such dissenting viewpoint is a step on the path of extricating oneself from the infopocalyptic centralization we're finding ourselves being pushed into.
iPhone data shouldn't be encrypted on the basis of a 4-digit PIN. It should have a much longer password that's entered at startup. The 4-digit PIN can be a "screen lock" to prevent casual friends grabbing your phone and swiping pictures but shouldn't be the thing that encrypts your data. There isn't enough entropy in a 4-digit PIN, period.
The iPhone then adds a feature to self-destruct after N attempts. This is where a modified OS comes in. This isn't true security. Get rid of the self-destruct feature and you have brute forcing ability and can decrypt the data in minutes.
In a truly secure system, I would be able to safely just give you an image of the flash storage and all the signing keys. You pick your tools, OS, hardware, and you would still have no shot at decryption, at least not with classical computers and as long as P!=NP.
A lot of the conversation happening in regards to this FBI case is only due to it being an older iPhone that doesn't have this special hardware. Which is why people are confused with the FBI chose this case as their poster child when it would have made a lot more sense with the most recent iPhone.
Is this same method employed across different generations of iPhones?
Thanks
Basically, the Secure Enclave contains a 256-bit AES key physically fused into the silicon during the chip fabrication process. Apple don't know this key, and neither do the manufacturers. It's different on every iPhone. The key cannot be read by any software, or the OS, or even firmware. All that can be seen is the result of using it in a crypto operation.
The key used for actual encryption on iOS is derived by taking an intermediate key derived from the PIN, and then entangling it with the Secure Enclave key (and, I believe, the CPU's key, which is also unique and fused into the hardware, but not quite so secretive). This effectively ties the crypto process to the phone - if you take a data dump of storage and try to brute force it on some more powerful kit, cracking the PIN isn't enough. You'll also have to crack both the AES keys.
This isn't universal across all iPhones - I think the 5S onwards have it.
As the iOS security documentation details, iOS uses a KDF to generate secure keys rather than just relying on a short PIN.
> The 4-digit PIN can be a "screen lock" to prevent casual friends grabbing your phone and swiping pictures but shouldn't be the thing that encrypts your data.
Photos ARE your data. You either require a full passphrase 100% of the time, or as Apple has done, only allow limited attempts with a PIN. Yes, they* could enforce a passphrase at all times, but this might make iOS less user friendly and drive regular consumers to less secure devices.
* A user can choose to always require a full passphrase/TouchID at all times. I don't use a short PIN on my iPhone.
Ideally my phone would go into "secure" locking mode (requiring my 7 word passphrase) after not being unlocked "casually" for more than X hours.
The only reason brute forcing is even potentially an option in this case is because the person in question didn't bother to use a secure passphrase.
So, it sure sounds to me like iOS is already doing what you describe. Do you just object to giving the user an insecure option?
Also is there a reason they can't just use this piece of hardware to brute force the phone?
https://www.intego.com/mac-security-blog/iphone-pin-pass-cod...
https://www.apple.com/business/docs/iOS_Security_Guide.pdf
The short version is that your passcode (whether four digits, six digits, or a full password) is combined with an encryption key embedded in the device in a way that's supposed to be impossible to extract, and used to derive the encryption key used to protect your data.
The device you linked to relies on a vulnerability in the US, where it would report that a passcode entry failed before recording that failure to nonvolatile storage. Normally, the device starts adding more and more delays to passcode entry after a few failures. By cutting power to the device immediately after it reported failure, it bypasses those escalating delays. As your link mentions, Apple fixed this vulnerability in a subsequent OS update, so that hardware only works on older OSes. This phone's OS is too new.
The question here is whether or not the law says the DoJ can compel Apple to hand over these items.
We do not need to allow the DoJ to win in order to get to a point where Apple and others provide us with self-controlled data security. We can both fight the DoJ's position and demand better security from Apple.
Let's focus on the DoJ for now because that is the immediate threat.
This case should be discussed in Congress, not the courts, and the American people should have a say in the matter.
I was heartened to see the video of Senator Lindsey Graham's questioning of US Attorney General Loretta Lynch today on this topic [1]. His delivery and conclusion was perfect. Mike Lee also did a good job [2]. Feinstein was scary to watch (51:00 in the C-Span full video).
[1] https://www.youtube.com/watch?v=uk4hYAwCdhU
[2] https://www.youtube.com/watch?v=XOZLEhTlr6E
[3] http://www.c-span.org/video/?406201-1/attorney-general-loret...
While i'm not a legal expert, it seems the major difference is the size and name recognition of the companies.
I'm not really a Apple fan but I hope they win on this.
Lavabit eventually decided to close instead of giving access to the data of their customers. Apple won't close but I wonder if they would go as far as leaving the USA, both the country and the market. That would be more than extreme but if they lose it would be the only alternative to caving in. My very safe bet: it's not going to happen (leaving the USA).
In other news, Apple has been complying all along with Chinese authority requests, including placing Chinese user data on Chinese servers and hand over relevant data when asked. In China if they made a fit over this they'd be thrown out and blocked along with Google and Facebook. For them, complying with Chinese authorities is a revenue-driven business decision.
In the absolute worst case outcome of the FBI case, I imagine they would end up complying with US authorities as well, as a business decision.
Sovereignty is a funny topic... If Apple "buys" a country with a land border the "abdication of existing government" could be considered by their neighbours over the border as grounds to consider the territory "vacant" ... If Apple "bought" an island nation or a country comprising multiple islands, then they would have to "defend" their new home from the newfound "enemy" of the USA ( and I hear the Navy is quite formidable ;-) ) who might be a little bit pissed off, or may just decide like to "consider" that Apple purchasing the country makes it not a country and they don't have to listen to Apple when they ask nicely not to enter their territory with aircraft carriers, or say ... submarines that tap into undersea cables...
Right now Apple has a fair amount of protection by virtue of being an American company, an American company that is also considered an American person with rights under the constitution, such as not being "compelled to speak", which is why we're hearing about this sort of possible change in tactics. The FBI can't force them to talk so they ask for the script so they can talk for them.
Furthermore, without good relations with other nations, you're not going to get very far with exports, internet connections, food, passenger transport, investment, and just about everything else you need to sustain basic life and business.
Iceland is already poised to take advantage of this. A little bit of legislation, a few moderate tax breaks, and they could court Apple rebasing their corporate home, at least mostly on paper, there.
The mathematics already impose an 80ms duration ("delay") of each attempt. The FBI knows there is no way around that.
Contrary to other replies, even phones without the secure enclave are protected in this way.
This is why Apple also implemented the brute forcing protections that the FBI is trying to bypass via a firmware update.
However, I do think that it should be impossible to update the firmware (including via DFU) without either a) the passcode, or b) wiping the phone. If the owner doesn't know their passcode they'll need to wipe the phone anyway. Anyone else doesn't have any business updating the owner's firmware without their permission.
[1] https://support.apple.com/en-us/HT204060 "Change your passcode. Enter a new, six-digit passcode. Or tap Passcode Options to switch to a four-digit numeric code, a custom numeric code, or a custom alphanumeric code"
http://www.nytimes.com/2016/03/02/technology/apple-and-fbi-f...
> “There was a mistake made in the 24 hours after the attack,” James B. Comey Jr., the director of the F.B.I., told lawmakers at a hearing on the government’s attempt to force Apple to help “unlock” the iPhone.
> F.B.I. personnel apparently believed that by resetting the iCloud password, they could get access to information stored on the iPhone. Instead, the change had the opposite effect — locking them out and eliminating other means of getting in.
> The iPhone used by Syed Rizwan Farook, one of the assailants in the Dec. 2 attack in which 14 people were killed, is at the center of a fierce legal and political fight over the balance between national security and consumer privacy. Many lawmakers at Tuesday’s hearing of the House Judiciary Committee seemed torn over where to draw the line.
http://www.latimes.com/local/lanow/la-me-ln-fbi--terror-susp...
> Had there been no reset on the iCloud password, investigators may have been able to get a more updated backup of Farook's iPhone without any need to unlock the device itself.
They simply aren't competent and every time someone suggests they need more power to cover for their incompetence they need to be called out on it.
The FBI having the ability to break in to NSA or DOJ machines is definitely not ok and I'm not sure anyone is going to say otherwise besides the FBI. Hell, we can't even trust the FBI agents with a few bitcoins.
Now the Chinese and every other country in the world can prepare and sign updates to most anyones iPhone, say the FBI directors iPhone.. Heck, if he's travelling in China it would likely even be trivial to push the update over the air to his phone...
I do.
Just to be clear it NEVER would have given them access to the phone. But the FBI claims to want the data on the phone. What iCloud would have allowed them to do is to connect the iPhone to a known WiFi network and have it backup-sync up to iCloud where the FBI could obtain it.
The problem is because they changed the iCloud password that caused the phone to fall out of sync with the service until the new password is entered, and to do that you need the pin.
The speculation has been that the FBI already has most of the key information on the phone (from NSA taps & existing iCloud backups) but this whole thing was never about protecting the public or getting key intelligence, it is a pretence to gain a backdoor or more importantly to establish legal precedent with a case that will gain public support/is sympathetic.
I was curious about you points regarding obtaining key information from taps and existing iCloud backups. How would the NSA get taps on someone manually keying in a PIN code?
Also it sounds like the iPhones PIN code is included iCloud backups is that correct? I wonder why they include that rather than requiring resetting your pin on a restore?
Does using the encrypted backups option via iCloud not make a difference here? I would hope selecting this option(its iTunes) would enable the backup to be protected by AES 128. Can anyone speak to these?
Yeah that was kind of the point of my OP. They really are that incompetent and since they won't admit it to that ... every time something goes wrong their response is "WE NEED MORE POWER" to deflect blame.
I don't believe this one single bit. I believe they already have salvaged whatever they could from the iCloud account.
They have been after the backdoor for a long time. Needing info from a "terrorist's" phone is the perfect cover.
The accidental reset is just bullocks
Tim Cook would go to jail.
That wouldn't quite be "destruction of evidence", but the government would likely try to bring "obstruction of justice" charges over that.
If this is bothering you, get out and vote for Sanders. These next few months are the only window where we have a chance to fix this before being locked into 8 more years of a power hungry DoJ.
The entire tech industry should be taking a stand right now. Setting the policy of the FBI & DoJ is more important than net neutrality or SOPA. Not to mention picking the judges that will be deciding these cases for the next 20 years.
I completely agree it should be political. And I think it would be a big win for any candidate to express support for backdoor-free encryption now that the facts are becoming clearer to the public. All we need is someone with some authority to stand up and share those facts.
Unfortunately, Sanders has yet to comment on it, and some feel that his comments about Snowden have been less-than-brave, so he might not weigh in on this. People within his campaign feel it isn't currently a major issue for American voters. I've tried to share some information a couple of times but it hasn't really generated much discussion in the Sanders subreddit [1]
If anyone has any contacts within his campaign, it would be a good idea to reach out to them and talk about the issue. There are two bills, one in NY [2] and one in CA [3], being proposed that would mandate backdoors in encrypted phones. These are based off of text originally produced by Manhattan DA Cyrus Vance in November 2015 [4]. It's just a matter of time until there is similar federal legislation [5]
> The entire tech industry should be taking a stand right now. Setting the policy of the FBI & DoJ is more important than net neutrality or SOPA. Not to mention picking the judges that will be deciding these cases for the next 20 years.
I think you also need to consider the powers that the US government does have over tech companies.
Remember 5 years ago when all the tech companies issued oddly similar statements saying, "we want to tell you more about our cooperation with the government, and we are asking the government for permission to do that." Whatever came of that? Do we know more now?
I think tech companies are timid because they know the DOJ can ruin them. We only found out much later the duress under which Yahoo found itself in 2008 [6]. And, Microsoft was slapped pretty hard under Bill for bundling IE etc. He pretty much always sides with the government now. Also, Apple was just fined fairly heavily in a loss to the DOJ over its ebook negotiations with publishers. Until the supreme court denied Apple's request to hear that case, it seemed like it could go either way. There are probably many more we don't know about. There is a big difference between fighting against the DOJ and fighting publicly with Congress over SOPA etc. Fighting the DOJ is often done behind closed doors where the public and Apple's users cannot have its back.
[1] https://www.reddit.com/r/SandersForPresident/comments/49otvu...
[2] http://arstechnica.com/tech-policy/2016/01/bill-aims-to-thwa...
[3] https://www.eff.org/deeplinks/2016/03/worried-about-apple-ca...
[4] https://cyber.law.harvard.edu/pubrelease/dont-panic/DA_Repor...
[5] http://www.politico.com/tipsheets/morning-cybersecurity/2016...
[6] http://www.theguardian.com/world/2014/sep/11/yahoo-nsa-lawsu...
My guess: exactly like Obama's.
His campaign thesis is that rich corporations have corrupted the political process. Apple is one of the richest corporations in the world. It's not clear to me what Sanders will think of their concerns.
Encryption is not an issue that breaks down easily along typical populist political lines, which are the lines that Sanders prefers to stay within.
That said, you are correct that it should be a political issue--particularly in Congressional elections.
Our collective vote beats both money and guns. When politicians are voted out, they are out of a job and their campaign funds dry up.
From the This American Life's episode on "Take the Money and Run for Office" [1]
Dick Durbin: I think most Americans would be shocked-- not surprised, but shocked-- if they knew how much time a United States senator spends raising money. And how much time we spend talking about raising money, and thinking about raising money, and planning to raise money. And, you know, going off on little retreats and conjuring up new ideas on how to raise money.
Barney Frank: If the voters have a position, the votes will kick money's rear end any time. I've never met a politician-- I've been in the legislative bodies for 40 years now-- who, choosing between a significant opinion in his or her district and a number of campaign contributors, doesn't go with the district.
[1] http://www.thisamericanlife.org/radio-archives/episode/461/t...
[1] http://www.reuters.com/article/us-usa-obama-china-idUSKBN0LY...
It might not even be in the US. I know that the code signing action of Microsoft Windows was done (and perhaps is still done) in Peurto Rico, for tax reasons.
. . . well, I suppose the courts could always compel a roomful of key holders to enter their codes. But it's much harder if some physical presence is required (do they handcuff you, fly you to the Caymans and force you to enter your key? Do they try to recover the hardware in question -- that could be made arbitrarily difficult).
Also, trap biometrics: Use a fingerprint or two as a duress code. Have an retina scanner, but only some of the participants should use it. Use that sensor for some folks, another one for others. "Sure, you can have my fingerprints! Hmmm... it was working last week, why does it say '30 day lockout' now?"
Much cheaper for them if they can get a judge to force Apple to work for them---they don't even have to pay Apple for it! ;)
Problem with that is that forgetting your master password would mean "no more updates for you". So, to be a bit safer, Apple should restrict that to updates to the secure enclave.
Also, Apple would have extra work creating a unique upgrade package for each device, and network traffic would increase, as Apple wouldn't be able to use CDN's for distributing those upgrades.
Edit: I'm not sure that would work. The device would still have to send their key to Apple, giving Apple the ability to create the package, and giving law enforcement the opportunity to request the keys.
How does the device owner control it? Apple doesn't want to be responsible for Genius Bar calls from customers who lost that strip of paper with the huge hexadecimal code on it and now can't ever upgrade their phone again.
Edit: honestly, if apple provided such a mechanism, they'd be winning on all fronts. 1) a user is in control of whether or not there are recoverable keys (simply don't print them out or burn them if you did) and how well-protected they are (are they in your bedside table? taped to the top side of a drop ceiling tile? in a safe?). 2) you have a good answer for the government: go find the keys at the guy's house if they exist. 3) it's possible to be really serious about security and use the device in a way that is the same as if the backup keys simply didn't exist.
The secure enclave (https://www.mikeash.com/pyblog/friday-qa-2016-02-19-what-is-...) could generate a public/private key pair, keep the private part for itself, and give up the public part when given the unlock password.
It could even generate a new key every time someone asks for one, and only accept the last one it sent out.
But yes, as I outlined, one problem with this is "no more updates for you".
A way halfway around that could be for the secure enclave to accept unsigned firmware updates, but to first destroy the device's encryption key ("sorry, no more updates for you, unless we are allowed to erase your device first")
Allow me to assume the DoJ supports the FBI and coerces Apple to be required to do what they're asking for: how is Apple, an organization, seriously going to be compelled to actually comply, exactly?
The developers don't have to work on the project and can technically request to work on something else, or quit out of spite.
How do you force someone that works for a company, of which is compelled to do complete an action as a legal obligation, such that an individual isn't the one that would receive the jail time for failing to perofrm the request. Sure, I suppose they could make Apple pay a fine, but outside of trying to ruin them financially, I really don't see how they can hold any of the employees under any legal threat of jail-time or punitive damages for being in contempt.
In the case where they order Apple the company to make a backdoored OS, the engineers who have the skills to do that can quit, and Tim can order it all he wants but the company isn't able to comply anymore.
But if they want the source and the keys, theoretically Tim Cook himself could clone the source repo and put the keys on a thumb drive. They can hold him personally accountable, so they can send him to jail if he doesn't.
Some engineer will do it for a million dollars, just knowing that the next guy after him will be offered the same amount. And Apple will be happy to pay that amount because to disobey a finalized court order is suicide for everyone.
A better argument for why this won't work as the DoJ would like is that criminals will just use some other method of encrypting their data. It's as easy as downloading an app. Meanwhile, the rest of us will be using devices whose security is compromised. This leaves the criminals safe, our data more vulnerable to theft, and the DoJ with their hands in the air wondering what happened.
[1] http://www.theguardian.com/world/2014/sep/11/yahoo-nsa-lawsu...
And now the FBI may simply demand apple hands over the signing key, providing them with the backdoor that apple already has.
I asume Apple will now prepare for the worst and I wonder how. I think they have two options:
- Consede with FBI that civilians can't have security against their respective nation, and start building some backdoor-per-jurisdiction feature that will allow states to decrypt iPhones within their jurisdiction.
- Take the principled approach and decide they want to offer their customers security, even if nation states don't allow this. They can build strong blockchain / tor type encryption into the OS and hardware, behind an easy checkbox. But this will collide with government interests, they may get into problems in big markets, comparable to Google pulling back from China and WhatsApp company representative being arrested in Brazil. Apple shareholders certainly won't be happy with this approach.
The question we should ask ourselves is who would they share the source code with?
NSA, MI6, CIA, IDF? Are these guys incompetent? Would the Chinese not simply pick it off the safe?
I really, really do.
Note -- To make things clear (in regard to the -1): While it may look like it I wasn't trolling. I'm just wondering when tech people after all the shit happening the last few years have had enough. Because there must be a last straw somewhere, right?
http://techcrunch.com/2016/01/14/no-backdoors-but-uk-governm...
So, yes I did my research.
Also, while none of the governments in Europe are close to perfect, there are probably also good reasons why several people on NSAs watchlist (Jacob Appelbaum and Laura Poitras come to mind) have decided to set up residence in Germany, which is home to the BND -- supposedly one of the closest partners of the NSA in Europe.
I really, really do.
The dystopian future isn't so future anymore, and things continue to play out much in the way that Huxley thought they would. For the most part, Orwell got it wrong. People will continue to let the government do what they will so long as they are entertained.
We are headed to a future where if you don't know how your systems work and control them yourself someone else will.
The inherent complexity of a modern computer outstripped that possibility ages ago. At best, you have a chain of trust you believe in.
I did leave the US 5 years ago with some idea in mind that our government doesn't know how to govern and guide technology. I was fed up with reading about small software companies getting pummelled by patent trolls, so I jumped ship, took my savings and floated around for awhile.
More importantly, as actual lawyers here and all over the internet always remind us, the law does not work in terms of nerd technicalities. I'm harmlessly changing numbers on a computer as I type. If I were changing numbers on a computer that keeps track of your bank account, I could go to prison.
It's not all legal speak. There's some reason in judgements and magistrates are generally verbose in their statements.
I'm not a lawyer either but I think any reasonable person could see that forcing Apple to give away its source code and signing key would present Apple with some significant security burdens.
It's very similar to what Apple was previously arguing, except the DOJ just made Apple's case stronger because there's the added element of risk that the FBI could now be the ones to let the modified signed software get out into the wild.
In the former situation, Apple was in charge of security of the back door, so there was only one escape hatch, so to speak, and they're the experts (which the FBI Director has noted many times). If Apple were to hand over the source code, the FBI's systems become another target of attack by hackers.
It was a really dumb statement by the DOJ. They intended to sound commanding, but they just weakened their case and helped Apple.
The reason you have second amendment is people genuinely believe crap like that.
If there's a more substantive URL for this story, let us know and we'll change it again.
Impudent serf! We'll demand more then!