U.S. Says It May Not Need Apple’s Help to Unlock iPhone
nytimes.com
nytimes.com
The All Writs Act goes back to 1789 and is used for all sorts of things, like wire tapping, obtaining call and ISP records, etc., and now trying to force Apple to make malware for their own phone.
It's definitely a risk for the FBI to fight this battle and potentially lose a tool they use all the time. Since there is probably no new info on the phone, it may not be worth the risk of making this a big fight with a motivated and well-financed adversary like Apple.
Remember when Snowden first revealed the Prism program? All the tech companies issued similar statements saying they want to tell people more, but did not have permission from the US government. For example, Apple said,
> Like several other companies, we have asked the U.S. government for permission to report how many requests we receive related to national security and how we handle them. We have been authorized to share some of that data, and we are providing it here in the interest of transparency. [1]
Also, I'm sure Yahoo would've loved to rally support from its users when the government was threatening to fine them $250,000 per day for refusing to hand over data, but they were not allowed to tell anyone [2]
I do believe the government was doing what they thought was right to protect public safety. However, they don't understand technology. Ted Lieu is about the only guy in Congress who does. We need a bit more representation there to have our voices heard, whether through electing Congressmen with CS backgrounds, independent lobbying like the EFF, or just better tech reporting and questioning in the White House daily briefs.
The existence of the FISA courts is something we should be scrutinizing more. Former NSA Director Hayden pointed out in one interview that we're the only country who has such secret courts. With these courts, democracy is circumvented. Currently, the public is not able to participate in the discussion of what's right on some major issues that have far reaching impact.
[1] http://www.apple.com/apples-commitment-to-customer-privacy/
[2] http://www.theguardian.com/world/2014/sep/11/yahoo-nsa-lawsu...
My understanding is people who are serious about security do not currently depend on Apple. Those folks use open source software and build it themselves. That said, I'm still interested in defending Apple's position (and not necessarily Apple) because I want our government to understand how to maintain public safety. Relying on access to people's phones, going forward, is not the right way to do that. You could argue that I am advocating privacy, but I'd say I am more in support of security.
There are extremists within any group. These folks do not want to bother fighting the government for rights because they think the public is too dumb and the government will win that fight. In thinking this way, they become apathetic themselves.
They're not all bad. Some of them contributed a lot to free software. But some times the ideas are toxic and hold people back from their best.
For example, many believe Snowden deserves a full pardon, and anything short of that is wrong. Well, Snowden himself has said he would return to face a fair trial. So it seems we are divided on some issues, and that can weaken our side in fighting for digital rights.
My response to these types of comments is precisely - when it is demonstrated that people make laws rather than governments in collusion with corporations - then I will pay attention.
Why the focus on property rights? Much libertarian thought is expended on equating freedom to how you/others interact with property. It hardly gives credence to other man made rights that should be equally, if not more, recognized.
When you look at the group of people it dogmatically and absolutely resolves, and who funds think-tanks promoting the ideology, it is the well-propertied.
I find it hard to believe that all other freedom can be derived from and ensured by deifying property rights.
That's interesting, since the National Laboratories employ tens of thousands of people who not only use Linux, but use Linux at work. Perhaps you should let the FBI know about this so they can revoke their security clearances?
> My response to these types of comments is precisely - when it is demonstrated that people make laws rather than governments in collusion with corporations - then I will pay attention.
This sounds like an excuse to selectively not follow any laws you don't like. The core law surrounding warrants in the US, which is sufficient for a lot of cases (no All Writs Act or FISA needed), are in the Constitution and some very early bills. Were these also made by collusions between the government and the corporations?
Plus, extremely large and powerful companies do not play by the same rules as the rest of us. You aren't going to see the government risk serious economic damage just to enforce some laws. Wall Street is a case in point. When huge companies decide whether to fight unjust laws or acquiesce, their choices have a major impact on the political equation.
For many years all tech companies have, as expected, complied with warrants. We don't expect otherwise.
Now, in this one case, Apple is fighting the warrant.
And some people are saying "Look how great Apple is; they really care about your privacy".
Well, no, not really. Apple isn't as bad as some, but they still gather too much data and they still (as they should) obey any warrant they're given.
Hate or support the game, not the player. Stand up for ideas, not people.
What made this case different was that it was not about a simple warrant for data held by Apple.
Apple has already given them Farook's iCloud backups, just not recent ones since they don't exist. If Alice was murdered, and Bob was circumstantially implicated, but had an iPhone that had some kind of data recorded that placed him at the time and location of the murder, what law exists for Apple to protect Bob's data if that data was uploaded to Apple for backup purposes?
Sure, it would be nice for Apple to oppose even "valid" warrants for iCloud data backups, because I trust them to keep my data safe on my device, so why should I have a reduced expectation of privacy when using their services. After all, they have billions in cash in some Scrooge McDuck mansion just waiting to be spent on lawyer fees, right? /s
I agree that the second case - court order to create new software - is a lot more obvious and clear, and deserves opposition in court.
The reason I'm being so pedantic is that it's important to disagree with the notion that corporations should roll over in any situation that involves claims of terrorism. Lots of people think that, but it throws away an important part of our legal system.
I'm not saying they're wrong to obey court orders.
I'm saying that people will be saying that Apple fight against court orders when in fact they don't usually fight the court orders. They normally give out the information.
When warrants are clearly legal, there is nothing they can do to fight them.
They only give out the information they are legally forced to do, and are doing everything in their legal and technical power to reduce that as much as possible.
The idea that the Govt can only issue "valid" warrants is flawed. The Government is just people, and like everyday citizens like myself, we're perfectly capable of breaking laws, either unintentionally (eg, giving a lift to a friend who has undisclosed controlled substances on their person (state dependent)) or intentionally (eg, murder).
Remember, the requirement for a warrent doesn't apply to non-US persons outside the USA. Us europeans have no protection from the 4th amendment for data held in US servers. And in fact, the US gov is trying to claim we don't have protection if it's held in a non-US server run by a US company!
"nor shall any State deprive any person of life, liberty, or property, without due process of law; nor deny to any person within its jurisdiction the equal protection of the laws."
Which sounds like all people should have the same protection from unlawful searches ... as I'm a conditional law novice can someone briefly outline why this doesn't stand, what removed the protections for "all people" (note the preceding section refers to citizens, so all people is clearly a distinct class).
Is it that the federal nature of the FBI means they are above state law?
Specifically it says:
> With regard to EU citizens, the [US] Supreme Court has held that foreign citizens resident abroad are not covered by the Fourth Amendment.
It appears to be based on this Supreme Court case[2]: United States v. Verdugo-Urquidez
[1] http://www.europarl.europa.eu/RegData/etudes/STUD/2015/51921... [2] https://en.wikipedia.org/wiki/United_States_v._Verdugo-Urqui...
However, the FBI must abide by the 4th amendment, which specifies that warrants are needed for searches. The issue of whether data of foreigners located on US soil is subject to warrant-less search/inspection is a matter of interpreting the 4th amendment.
And the interpretation is that a warrent isn't needed. The 4th doesn't protect me.
If the 4th requires warrants and the 14th requires state to treat all people as having equal protection under the law in their jurisdiction I don't see where the FBI can go [legally speaking] to do warrantless search of foreign nationals.
In short, how then can a State allow the FBI to operate within its jurisdiction in a way that doesn't provide all people equal legal protections. The State would have to prevent the FBI from operating?
Thanks for any further insights.
That isn't good PR for Apple.
Whether the government is just lying, in order to save face, remains to be seen - somebody with more knowledge of the technology at hand may be able to comment.
They probably thought that if it came down to a PR battle, assuming Apple didn't just roll over for fear of the PR consequences of "obstructing a terror investigation," they had it in the bag. Turns out? Not so much.
Totally agree with the broader point (I think they're scared of a restrictive precedent), but I don't think a law that's been on the books for two hundred plus years is going to be out and out declared unconstitutional. It's extremely broad in the number of domains of application but that doesn't necessarily mean that it grants overly broad power.
A savvy judge would not allow the Department of Justice to cancel the hearing just to avoid setting a precedent.
It's not that the act is unconstitutional, it's that the interpretation of it that the DoJ has been selling to magistrate judges in ex parte hearings is extremely broad and would never survive appeal.
The Supreme Court has made it very clear in multiple rulings that A) The AWA is certainly constitutional and B) it is extremely narrow in its powers and it doesn't grant courts anything even remotely similar to the powers the FBI has been pressuring magistrate judges into believing it has.
So, essentially, by avoiding a highly publicized appeals smackdown, the FBI can still convince magistrates to issue wildly out-of-line AWA writs, and use those writs to pressure companies/people into doing things they wouldn't be held to if they had the time/money to actually appeal.
edit:
> The All Writs Act goes back to 1789 and is used for all sorts of things, like wire tapping, obtaining call and ISP records, etc
Also, I see this mistake a lot (I'm not saying you're making it, but it's a pretty common one). The AWA doesn't actually give the government the power to wire tap things, etc. There are separate statutes that authorize wiretapping. All the AWA does, per the Supreme Court, is give courts the authority to issue common law writs in the course of carrying out powers conferred by some other statute. The AWA is described as being a source of "residual" (secondary) power that only acts to help carry out some primary source of authority.
The DoJ has been pushing an argument that the AWA is a source of primary power in-and-of-itself in any area of law where congress hasn't passed a law saying a court can't do X thing, and the writs don't have to have antecedents in common law. This more-or-less contradicts any number of Supreme Court rulings. They've only been getting away with it because they get a magistrate Judge to issue them by asking for them in "emergency" ex parte hearings, meaning the other side isn't present to offer a competing argument, which the FBI excuses by arguing its a time-sensitive matter (even though it generally isn't). One of the amicus briefs in this case was submitted by 32 law professors, who pointed out that this violates due process.
While nuisance suits from private actors can totally be ruinous, the potential for harm from government actors is so much greater.
(1) See middle of page 5 here: http://www.nuff.ox.ac.uk/users/klemperer/WhyEveryEconomist.p... Where he debunks Dan Quayle's court reform ideas
That's not at all a similar question. We're talking about staking the following strategy through the heart:
* Some part of USGov makes an overreaching legal demand using a really shaky (perhaps unsupportable) legal argument.
* They get a magistrate to issue an order in an "emergency" ex parte hearing
Now either:
* USGov presents that court order to a small and/or legally clueless business who says: "This is a court order! I have to comply with it, else I get in trouble!". USGov gets what they wanted and gets to bully another unwary victim with the same bullshit tactic
or
* USGov presents that court order to a larger and/or legally savvy business who examines it and says: "No. This is bullshit."
* That company goes to the court and tells the court why the order is bullshit
* The court quietly mumbles: "USGov... they're right, looks like it's bullshit."
* USGov goes: "Oops! We really didn't need that anyway!", withdraws the request, and retries it at a later day with a less savvy victim
So, completely different situations.
If USGov had to keep pushing such cases through if the defendant demanded that they be pushed through, what you'd get is what we get when Newegg fights patent trolls: evisceration of bullies, thugs, and the chicanery that permits them to operate.
I'm pretty sure NewEgg was recently taken to court by a patent troll, and after the troll realized that NewEgg fights instead of paying, they backed off. Then NewEgg sued to get a judgement that would guarantee this couldn't happen to them again.
I know this is a different venue and there are topical differences. But are you absolutely certain that there is no counter-action Apple (or any company, for that matter) can pursue to get a judgment about this?
Newegg's actions were different, in that the patent owner's dropping the suit didn't actually resolve the question of infringement. It was still out there, and the patent owner could re-file suit at any point in the future. Between now and then, if Newegg were in fact infringing, monetary damages would continue to pile up. So the uncertainty can have a pretty significant impact on business decisions and impair their ability to operate. A request for declaratory judgment seeks to resolve that uncertainty so that both parties can get back to normal.
For Newegg, the request accomplishes a few things. It lets them clear the air, indirectly help solve the resulting from the remaining suits against retailers selling Rosewill products, and it's the legal equivalent of spiking the football and giving the troll a swift kick in the nuts. Minero Digital now gets to defend itself in a Delaware court, absent all of the little advantages of East Texas. It's a rather bad break for them.
Honestly, if I were a patent troll, I'd be scared shitless to send a letter to someone like Newegg. With their stance on patent suits, they're exactly the sort of company that would preemptively file a request for declaratory judgment after they were contacted.
So, when it comes to wiretapping, there are specific statutes that authorize wiretapping in such-and-such circumstances. The court can then issue writs as needed to carry that out, provided the writs meet fairly narrow criteria (not overly burdensome, only targeted at an entity "close to" the case at hand, only targeted at an entity whose actions are "necessary" and where there's no other way to carry out the jurisdiction, rather than, say, just convenient) and the writ must have some kind of antecedent in common law, which is a somewhat fuzzy topic, but it boils down to "the writ can't just be pulled out of thin air, there's a set of traditional writs and it should appear to be consistent with that set".
The controversial part is what the AWA authorizes (if anything) beyond those pre-existing types of writs. Apple's position was "not much, if anything". The government's was, in effect, "anything not specifically denied by a law passed by Congress" -- which attracted heavy criticism, not only from Apple's lawyers, but also from many highly qualified lawyers who submitted amicus briefs.
http://www.usnews.com/news/articles/2016-02-23/bill-gates-on...
It's frustrating enough that code impact is completely unrelated to code size. I would rather our law not be the same way, but who am I to criticize.
Short answer: It really doesn't.
But if you can talk fast and convince magistrate judges to issue writs ex parte (no one is there to oppose you), you can get a lot of mileage out of writs that wouldn't survive an appeal. Most people won't have the time, money, or inclination to challenge them.
Even then, magistrate judges have been pushing back. The FBI's going to get slapped for this in the long run. But the long game here is that Comey was hoping public outrage against Apple would convince them to fold and play along with the writ, or nudge congress into giving it the powers it wants. The former clearly isn't working out, but the latter still may.
> The AWA seems to be a very small piece of law, and using it in the way it's being used seems against the spirit of it.
Bingo. It's also against established case law in the opinion of a very large number of people.
The mentioned brief is a very important read, and it's on the Apple's site here:
https://www.apple.com/pr/pdf/32_Law_Professors.pdf
From the INTRODUCTION:
"First, there is a jurisdictional problem. There is no basis in the record for this Court to assert Article III jurisdiction to issue or enforce the February 16, 2016 Order (“the Apple Order”). The search warrant’s authority is already exhausted and the government’s motion to compel recognizes that CALEA (“Communications Assistance for Law Enforcement Act”) does not provide sufficient authority to support the Apple Order. Rather, the government’s request rests solely on the All Writs Act. However, the All Writs Act is not an original source of federal jurisdiction and cannot support the government’s motion or this Court’s order. The All Writs Act merely provides a source of residual authority where such jurisdiction independently exists.
Second, the underlying Order is invalid because it deprives Apple of liberty and property without due process of law. The government initially took the time to seek Apple’s help outside the judicial process. Only after Apple declined did the government file its ex parte application, which did not allow Apple an opportunity to respond. Even though Apple has now had an opportunity to respond to the government’s motion to compel, the underlying Apple Order itself was issued in violation of due process and must be vacated.
Third, CALEA and ECPA (“Electronic Communications Privacy Act”) govern the substantive validity of the Order and set out telecommunications carriers’ obligations to assist law enforcement. Significantly, when Congress enacted CALEA, it exempted “information services,” which includes certain services that Apple provides, from that requirement. The Supreme Court has instructed that where a statutory scheme governs a particular subject matter, the All Writs Act’s residual power does not.
Finally, no court has ever issued a valid order that imposes an equivalent burden on a non-party. Our research has not found any case that uses the All Writs Act to require a third-party private entity to design and create new software. Some courts have compelled disclosure of already-existing information in cases where the All Writs Act is found applicable. In contrast, the order the government demands in this case would require substantial expenditures of time and talent above and beyond what is appropriate under the All Writs Act. This point is particularly alarming where Apple has made a deliberate decision to exclude the features that the government now demands."
But the weird thing is that, from the beginning, most legal experts thought the likely outcome would be that All Writs would be found too broad, so the FBI had to have been suffering from some hubris + bad legal council. So maybe someone with enough muscle finally called them out on it?
Don't they already have a precedent when they shut down Truecrypt some years ago?
There was a case where the FBI wanted to force someone to divulge his (I think) TrueCrypt keys, which was found to be a fifth amendment issue, in favor of the defendant.
https://www.apple.com/pr/pdf/32_Law_Professors.pdf
"No court has ever issued a valid order that imposes an equivalent burden on a non-party. Our research has not found any case that uses the All Writs Act to require a third-party private entity to design and create new software. Some courts have compelled disclosure of already-existing information in cases where the All Writs Act is found applicable. In contrast, the order the government demands in this case would require substantial expenditures of time and talent above and beyond what is appropriate under the All Writs Act. This point is particularly alarming where Apple has made a deliberate decision to exclude the features that the government now demands."
http://thehill.com/policy/cybersecurity/273482-senate-intel-...
https://www.justsecurity.org/29634/readers-guide-magistrate-...
(I'd read the links to the articles in the blog itself.)
It's up against the biggest companies in the world, the US public, and the international community. And now it's backing down with its tail btw its legs, and telling a silly story to save face.
If you are in the game of trying to sell something better than Apple, you better have a pack of actual wizards casting spells on your side ala Bewitched.
So after investing a lot of time and money in trying to get case law to expand the DoJ's power over corporations to conscript them into the War on the 4th Amendment, it become possible that they would see a judgement against them (especially if the Supreme court becomes more liberal with the next appointment).
So I suspect the risk/reward outcomes of pushing this to a conclusion flip flopped into more risk than reward and someone fairly high up said, "Ok kill this whole effort before it makes things worse than they are."
Just an opinion of course but I think it fits the observed actions.
The major weakness with this model of iPhone is that it keeps the number of failed attempts stored in the NAND flash, not on the CPU die, and is therefore vulnerable to having its state reset like this. It's a fairly obvious attack that the FBI must have known about, but failed to mention in order to try and set precedent.
Could you explain that a little for me?
Is it possible to screw that up and lose everything? Sure. Would they? No. Could you just send the data from the NAND flash to the NSA and have them brute force it? Maybe. Could you compel Apple to give you a copy of the source code to IOS so that you could write a simulator for yourself? Probably.
Or just replace one of the off-chip AHB/AXI devices and inject code via DMA. It won't work beyond the iPhone 5C, but I have yet to come up with a plausible reason why it wouldn't work there.
This is the only thing I'm not so sure about. This issue doesn't seem to divide neatly along liberal/conservative lines.
("Free speech" is another one of those--both parties have been pretty shitty on free speech since 9/11, but everyone plays down their own party's sins and screams about the other's.)
Scalia would have hated the DoJ's argument here, honestly. If the Supreme Court even agreed to hear the government's appeal here it might well have been 9-0 against.
And I say this as someone with a low opinion of Scalia, in general.
Also his dissent in Hamdi v. Rumsfeld was and will be fantastically important.
This doens't make sense to me. The FBI wants this precident, and they want it badly. I don't buy for a moment that they would back down here.
> The FBI wants this precedent, and they want
> it badly. I don't buy for a moment that they
> would back down here.
They do, they are also very cognizant of the ramifications if their motion is overturned. There is a constant calculus that goes on weighing the odds. It is very common to withdraw when that calculus indicates a possible loss.Sometimes it seems as though in Silicon Valley everyone assumes conservative = bad, liberal = good. The truth is always more complex.
We'll never have to prove it, so we win, Apple loses.
The iPhone 5C has an unsecured AHB or AXI bus. You can inject arbitrary code via DMA and trigger and interrupt to cause it to run. This went away with TrustZone (present in ARMs with a secure enclave including later iPhones).
FBI: We need Apple to hack this terrorist's phone Apple: We could, but we won't"
If I were Apple, I'd deploy a billion dollars and buy everyone in DC as necessary. Not exaggerating. Defense contractors, conglomerates, energy companies, etc. spend in the mere millions to get their way on things. Apple should purchase the entire Congress, aggressively, and destroy the All Writs Act as far as this type of situation is concerned, and push for favorable legislation that resolves the broader context of encryption and warrants in a rational way to preempt the FBI's next attempts.
Source: IANAL, but I've seen stuff on TV.
But who would do that, when it's unlikely to help them?
The evidence against them would likely stand, either a matter of inevitable discovery (Evidence gets tossed when it is "fruit of the poisonous tree", but if you can show that you'd have gotten that same evidence a different way, the evidence remains. Just like here: Had Apple folded, given the evidence, and then it was ruled inadmissible due to the methods, the FBI could just argue other hack options were available) or as a matter of "good faith" (where, if the cops didn't know what they were doing was illegal, they get to keep the evidence they obtained under "good faith"). My understanding is that good faith allowances have grown quite large in recent year, to the point of absurdity.
So our suspect, in this case, will only challenge the evidence if the chance of it helping THEM is high enough. They aren't going to do so for the good of society.
I don't like relying on the good will or desperation of suspects that have evidence against them to mold our legal rights.
Probably just a fantasy on my part.
1. The FBI is lying to save face,
2. Someone -- but probably needs to be some people -- from Apple is willing to help them,
3. There is an undisclosed vulnerability in iOS which Apple is unaware of.
I find it really hard to believe that someone would disclose a zero day exploit to the FBI without charging significant $ for it.
Am I missing something obvious?
John McAfee did promise to do it for free. /½ s
The guy is eccentric but I don't think he's an idiot and I do think he is likely talented, or at least rich enough to hire those who are.
That being said - he admits he was full of shit [0] and then claims that he has a proper method that isn't full of shit but which he didn't want to disclose. Chances are he's probably full of shit on that one too, given the track record, but who knows?
[0] http://www.dailydot.com/politics/john-mcafee-lied-iphone-app...
But of course, only if The Most Interesting Douchebag In the World™ is even remotely involved.
[1] http://www.businessinsider.com/john-mcafee-ill-decrypt-san-b...
http://arstechnica.com/security/2016/03/john-mcafee-better-p...
1. https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
So the FBI would have a lot of time before they had to worry about the consequences of a negative ruling, and they could drop the matter well before any precedent was set. Apple is in a trickier situation, in that once they've done the work, it becomes more likely that they'll face additional demands in other courts, or--and this is the worst case scenario--a few boneheaded legislators try to pass legislation on this issue. They've got a lot less room to work in, so if they could make this go away in front of a district magistrate without ever having to worry about setting any precedent (even if in their favor), they probably would.
0. http://www.law.georgetown.edu/academics/academic-programs/le...
1. http://faculty.law.lsu.edu/toddbruno/mandatory_v__persuasive...
But if there's an alternative method that's been proposed and the FBI is aware of it, the FBI can't claim that forcing Apple to act is the government's last resort. So that's the most likely reason they've halted proceedings and not any fear that they may lose.
Given the existence of these is disclosed now and the suspect's iPhone can be prevented from auto updating I think the FBI will have an easier time attacking it?
Looking at the first one itself they might just have to attach a malicious USB device to execute arbitrary code.
While it is likely true that nobody will give zero days to the FBI without charging, it is also basically certain that the NSA has a collection of them. And the NSA has enough interest in this problem, and enough willingness to share with the FBI, that that may be a tractable solution.
Furthermore the FBI certainly doesn't want to create a precedent they don't like, and the fact that we're only in this situation thanks to THEIR incompetence is not helping them.
> “Testing is required to determine whether it is a viable method that will not compromise data on Farook’s iPhone,”
Lacking the features introduced in later ARM releases it has an unsecured AHB or AXI bus allowing any device that can connect to perform arbitrary DMA (which can in turn allow arbitrary code execution).
It would require a certain degree of technical sophistication to execute that attack, but the resources required would be well within the reach of a state-level investigative service.
John McCafee and others (ex US govt officials IIRC) have mentioned decapping as a serious option for the NSA.
Snowden and Richard Clarke (advisor to bush on cyber security, advisor to Bill Clinton on counter terrorism, etc) have said the NSA has ways without being specific about how.
I don't think this counts as a serious vulnerability. If you have access to the kind of hardware and technical ability the US govt does, Apple probably isn't too concerned about you being able to break one phone at a time with significant effort involved.
The possibility that the Bureau is just plain dumb is not on your list. They are on record, many times, and in front ofa very serious congress, being very very stupid. Though I do not believe they are being stupid here, the possibility is not an edge case and should be considered.
iOS 9.3 was released today and included several fixes to vulnerabilities which allowed arbitrary code execution, including one with "kernel privileges" [1]
Now that these vulns are out in the open, maybe someone has offered to help the FBI use them to gain access to the phone.
Until that happens, it seems like a very real risk to Apple's security claims.
"So obvious no one will ever notice"
Apple removed their warrant canary about a year ago timed with press releases about "revamping their privacy policy for better security and user happiness" and a bunch of marketing bullshit. What I saw was the guarantees that they had done everything they could to protect your data was gone, replaced by "we'll follow the law" AKA they will screw you over willingly if they need to.
---
Also, the FBI is NOT dumb. "Poor legal council" was mentioned in this thread. With their budget, why would you not assume they have Grade AAA legal council?
---
If you didn't build it, you can't trust it.
The warrant canary! The warrant canary! It vanished. We really don't know what they're up to now.
Then the congressional hearing happened, where Issa (R - Calirfornia) knew more about the technical details of the phone than Commey. Given that Commey didn't bring a technical aide with him, and him saying things like 'this software would be obsolete because of newer iPhones, and wouldn't work on the 6 and 6S' were completely false and hard to imagine were made with merely negligence (i.e. He was very clearly lying).
And after all that, and the FBI and DOJ PR machine trying to fight back, it became clear that media was starting to side with Apple (Morning Joe on MSNBC is a perfect example of what a 2-3 week time span can do to an opinion).
I even suspect the Judge would have also sided with Apple and the FBI would be fighting for the appeal, and they would have known that. It's smart for the FBI to drop the case, but timing + intentions to bring up the case in the first place were scummy.
Let's remember that Commey, the director of the FBI, was a NY prosecutor. Given that the current NY prosecutor wanted to unlock phones with ease (as they don't have the resources of the FBI and access to the NSA), Commey was "simply" trying to help a friend by deceiving the public and forcing Apple to do something it didn't want to, that Apple knew it shouldn't. It simply wasn't worth the fight, and I do believe it put the FBI in their place, as even a terror attack couldn't even get them the mandate they sought. This is likely not the end, and the FBI knows that any company that has the reach they need will likely set a precedent against them, so it'll be interesting to see what they do next.
All in all, what the FBI got out of this mess: making a whole lot of devices and services more secure.
Pure 100% unpasteurized bullshit.
In some ways I suspect that the FBI's arguments are a smoke-screen to keep us from talking about the fact that unknown 0-days exist and perhaps the NSA even has a few.
I will clue you in: NSA has a lot of vulnerabilities vendors don't know about.
At least one security expert reported they were rebuffed by the FBI when they offered to help, so I seriously doubt the "outside party" is outside the government.
I've wondered if the NSA already had the phone cracked, and Apple's help was just parallel construction to not reveal capabilities.
So by writing a new update, they could remove some of the ancillary security features that reinforce short passcodes: the "wipe after 10 tries" feature, and the "progressively longer delay between tries" feature. Without these, a numeric (short) passcode can be brute-forced in a day or two. This is what the FBI has been trying to force them to do: write a new update to remove these features. That's what Apple has been refusing to do.
BTW, if you use a long alphanumeric passcode, then it wouldn't matter if Apple was forced to push this update. A 15 character passcode with upper case, lower case, numbers, and symbols would probably be safe from brute forcing no matter how fast someone tries. But most folks are not willing to remember or type in 15 characters on their phone.
Or are we just left to petitioning and lobbying Congress to rewrite parts of it?
The 3rd party was probably NSA and they did not intervene up until because it would reveal the existence of a cracking technique.
What changed is that weighed against a possible court verdict that would tell every terrorist that no U.S. made device or encryption could possibly be secure, (causing targets to avoid using broken crypto) revealing the existence of a possible forensic technique was low risk.
The belief that it is possible to communicate securely is the most important thing for spies to maintain. The FBI wants to discourage people from believing it because they think it will make people less likely to commit crimes. The spies want to encourage the belief because it ensures they can collect the intelligence they need to maintain the status quo.
Will Obama now stop seeking "middle ground" as he mentioned at SXSW? Will Burr-Feinstein halt their work on a backdoor bill? Nothing has changed on this front, and there are still a host of reasons why a backdoor law is a bad idea.
1) Have zero-day ([0]) that can be used to deliver executable payload over SMS (think Stagefright). iOS devices can receive text messages before the filesystem is decrypted. Perhaps Apple should close this vector.
2) Deploy dylib that patches the SpringBoard UI (where the lock screen lives), disabling the code that counts incorrect passcode attempts
3) Brute force the passcode
[0] http://www.wired.com/2015/11/hackers-claim-million-dollar-bo...
Perhaps. However, it's very likely that receiving SMS before decryption is not a bug, but a feature.
The problem is a systemic one too, a lack of actual leadership, a personnel problem if you will.
Essentially you can just automate the backup/restore of the eMMC flash storage and brute force the PIN. :)
Since the All Writs Act has as a test, necessity, to stay within the law they're required to notify the courts if that changes.
A few weeks ago they couldn't figure out how to unlock the phone, when it's blatantly obvious the security weaknesses of the 5c, and today they suddenly have seen the light but it just needs more testing? Department of Homeland Security has been funding research into NAND-blockers for at least 6 years now.
In a fair and adversarial system, the court would somehow sanction the FBI for their prior sworn testimony that they couldn't do this themselves. But of course when Federal agents lie under oath, it's not a crime, just a misunderstanding.
If they find nothing, the perceived motive that they just wanted a backdoor more than the device's data would feel all but confirmed.
I would probably bet theyre getting in via an exotic side channel attack of some sort to spy on the keys.
Anybody have any ideas what this 3rd party method could be?
1. NSA and any other govt. organization do not need a help from Apple to gain necessary information
2. Most probably Apple and govt. are working together for the face of good PR
3. Now after Apple keynote, seems like sales are ok, now they can publish actual story step by step
In summary: digital is not secure enough to rely on, all other things are PR
Snowden said the FBI is full of shit[1] and of course the phone is hackable, citing an ACLU report.[2] This report states that one could "easily" bypass the auto-erase-after-10-attempts function by popping out the Flash memory chip, copying its contents into some sort of test rig wired in its place, and then restoring it whenever it gets erased.
This is an interesting modification of an attack scenario laid out in an excellent review of iPhone/iOS8 security by Matthew Green:
"Since only the device itself knows UID -- and the UID can't be removed from the Secure Enclave -- this means all password cracking attempts have to run on the device itself. That rules out the use of FPGA or ASICs to crack passwords. Of course Apple could write a custom firmware that attempts to crack the keys on the device but even in the best case such cracking could be pretty time consuming, thanks to the 80ms PBKDF2 timing."[3]
What this theoretical rig changes is it essentially allows a custom chip to run on the device (namely a delete-proof Flash chip), bypassing the need for Apple to write custom firmware. So a typical 6 digit one would take under a day to crack, based on the 80ms cost per attempt.
So, it does seem possible to crack the pre-A7 phone in question with this rig.
However, and here is where it gets interesting, Apple has said conflicting things about current phones. One the one hand, ever since the A7 they've added a hardware-level escalating time delay between failed passcode attempts:
"On devices with an A7 or later A-series processor, the delays are enforced by the Secure Enclave. If the device is restarted during a timed delay, the delay is still enforced, with the timer starting over for the current period."[4]
This would in theory make it infeasible to attempt this kind of rig on a current iPhone. Even a typical weak passcode would encounter an hour-long delay at least once every 10 attempts. It could take years to bruteforce all but the most predictable passcodes.
However, Apple has also said that "Yes, it is certainly possible to create an entirely new operating system to undermine our security features as the government wants."[5] This would seem to suggest that software alone could enable bruteforcing, and this implication is in stark contrast to the statement on hardware defenses within the secure enclave. (Did they mean possible only on pre-A7 phones? It sure feels like they feel there's more at stake than that.)
So I don't know what to believe at this point. The ACLU seems wrong in suggesting that this particular rig would work on anything but old pre-A7 iPhones, based on the current secure enclave's time delay. But Apple has outright stated that GovtOS could enable the cracking of iPhones. So... how?
[1] https://twitter.com/Snowden/status/707299113449230336
[2] https://www.aclu.org/blog/free-future/one-fbis-major-claims-...
[3] http://blog.cryptographyengineering.com/2014/10/why-cant-app...
[4] https://www.apple.com/business/docs/iOS_Security_Guide.pdf
Yes, very much so. That way we can put this behind us rather than to wait for the inevitable re-run with conditions carefully arranged to be more favorable in order to set precedent.
See also:
http://www.npr.org/2016/03/14/470347719/encryption-and-priva...
That has been known to be false since day one, as methods of bypassing the reset have long been known that don't require Apple's help. The problem for the FBI is that these methods can't be used on a large scale, or without the targets' knowledge.
What statements can you point to that lead to the conclusion that the FBI is acting in good faith?
Just cause it's cynical does not mean it's not accurate.