A box for which they can't make an individual key, only a master-key (at great cost of man-hours).
A box for which they can't make an individual key, only a master-key (at great cost of man-hours).
crypto = 5th Amendment. Locked safe analogy = search warrant. Thats their simple messaging.
Apple needs to do what they do best - market this brilliantly but simply.
The owner can refuse and suffer the legal consequences.
In such a case, has there ever been a precedent of going to the safe manufacturer and compelling them to break into the safe? Have they ever then required all safe makers to make exploitable safes with master keys?
Note that they can, however, force a third party to turn over a password. The privilege against compelled testimony only applies to self-incrimination.
That depends on what the gov't knows about what encrypted files you have. In the worst case, they don't need to ask you for your password, they just need you to decrypt your data.
In Re Boucher is the most famous case where the government ruled that the 5th amendment couldn't prevent the government from compelling someone to decrypt their data. On the flip side, Wikipedia has this short blurb on it's article on U.S. V Hubbell: "The Supreme Court ruled in favor of Hubbell. The Court held that the Fifth Amendment privilege against self-incrimination protects a witness from being compelled to disclose the existence of incriminating documents that the Government is unable to describe with reasonable particularity. The Court also ruled that if the witness produces such documents, pursuant to a grant of immunity, the government may not use them to prepare criminal charges against him."
I prefer to look at the history of cryptography. Unbreakable cryptography isn't new. PGP is 25 years old. Classic techniques like one-time pads and book ciphers go back a very long time. Yet they never forced these things to be made insecure.
The government can listen, we can try to hide things, and they can try to un-hide them (with a warrant). Their ability to un-hide them depends on how well we do the hiding. It has always been this way, but they're not happy with it.
What the president is proposing would allow a key for law enforcement that would, presumably, work on many or all devices. Once cracked, it would give hackers access to all of those devices. This elevates risk considerably because it's no longer impractical to reverse engineer the encryption.
https://en.wikipedia.org/wiki/One-time_pad
"If the key is truly random, is at least as long as the plaintext, is never reused in whole or in part, and is kept completely secret, then the resulting ciphertext will be impossible to decrypt or break"
To me, the really fun mental exercise is to identify when this would be acceptable. If there was a bomb about to go off and hypothetically the location was written on the phone, and only on the phone, would we agree that apple should break in? What if the bomb was a dirty bomb, what about a nuke? Now the slippery slope is where does that stop, a backpack bomb? Bomb making materials, texts to people about a bomb, what about a gun? What about a knife....
Sure, you could drill it but you wouldn't get anything useful.
The FBI wants a modified iOS that will allow them to rapidly try all possible passcodes without getting locked out after N attempts.
It would probably make all crooks use long passwords for keychain, but who knows, maybe it would help in some cases.
My understanding is that iOS's filesystem uses AES 256 encryption. Even if you physically removed the disk, brute force is not an option.
edit Apologies forgot to mention the passcode/fingerprint is tied into the 2 key process.