FBI agrees to unlock iPhone for Arkansas prosecutor
abcnews.go.com
abcnews.go.com
Or rather, if one of those leads ends up being complicit in the charges, you have to prove as the prosecution how you came to that conclusion. You can't just say "we started investigations, then magic, then we interviewed this guy and figured it out."
Historically, when the FBI or some other organization helps but doesn't want to be named as part of the process (to protect their secret methods of accessing or collecting information), prosecutors will do something called "parallel construction," in which they build an alternative timeline to how they could have come by the information that led to the new interviews.
It's interesting that in this case, with the FBI publicly acting in support, they're giving up the ghost on that and opening themselves to perhaps being called for testimony. I'm curious how they'd use state secrets protections to get around having to explain their process, and whether a local/appellate/superior court justice(s) would allow it.
If you obtain information that is not reliable, you can act on it (and convince judge to give you warrants) just probably not use it in real trial.
I also think it depends if you want more information for the current suspect or you are on a fishing expedition
Failing to propose a believable narrative for each increase in magnitude in the burden of proof may cause the entire case to fail in the US.
If you collect evidence on someone that would ordinarily require probable cause when that person should be enjoying the presumption of innocence, that evidence is inadmissible, as is all investigation that depends on it to proceed.
Parallel construction is taking theatrical steps ex post facto to defraud the courts into believing that evidence is not only admissible at trial, but also a reasonable basis for further investigation. If the FBI performs mass suspicionless surveillance on presumed innocent victims, finds evidence of a crime, then notifies another agency to contrive reasonable suspicion, then probable cause, to uncover the same evidence via a legally plausible narrative, that is kicking civil rights square in the teeth. Furthermore, it encourages otherwise innocent activities to be considered as reasonable suspicion, and promotes aggressive police tactics to manufacture probable cause out of reasonable suspicion, or bully people into providing consent or confessions. You get "judge dog" approving search warrants whenever the K-9 cop signals him to provide probable cause. And it combines with forfeiture to become even worse.
When "accidental discovery" evidence is admissible, that is a significant weakening of the public's protections against government, as it provides additional avenues for parallel construction, such as dropping a smoke bomb through a window and pulling a fire alarm, such that responding fire department personnel can notice "drug paraphernalia" and tip the police, who get a warrant based on the tip and conduct a search for drugs. This encourages obstruction of services to promote public safety, such as disabling alarms or blocking emergency calls. When "clean hands" evidence is admissible, one "dirty hands" cop--or a paid informant--just needs to pretend to be an anonymous member of the public to tip off the "clean hands" cop. My own non-judge opinion is that poisonous fruit is when one law is broken in pursuit of enforcing another, not just when someone's rights are infringed.
Presumption of innocence isn't directly enshrined in the US constitution. Local prosecutors and governments can and do abrogate it.
The SCotUS opinion in Coffin v US stated the following:
"The principle that there is a presumption of innocence in favor of the
accused is the undoubted law, axiomatic and elementary, and its enforcement
lies at the foundation of the administration of our criminal law.
...the exclusion of an important element of proof can be justified by
correctly instructing as to the proof admitted. The evolution of the
principle of the presumption of innocence, and its resultant, the doctrine
of reasonable doubt, make more apparent the correctness of these views, and
indicate the necessity of enforcing the one in order that the other may
continue to exist."
Locals can and do get overturned by the federals.They can also get away with doing the exact opposite in their practice, only to be overturned at great personal expense to individuals with few resources.
Even in the case of illegally obtained evidence, there are techniques like parallel construction [1] that they can use to make their cases. They also have the so-called "clean hands" exception, which allows allows the government to introduce evidence into trial that was illegally obtained by a third party when the government did not play any role in obtaining that information [2].
The US legal system was designed to seem exceedingly fair on its surface, while allowing for unconscionable abuses by those skilled in maneuvering through its loopholes.
Proving this is very hard though.
You're probably thinking of "inevitable discovery", which says that illegally obtained information can be used anyway if the prosecution can show that they would have obtained it anyway. Parallel construction is something intelligence agencies do in order to hide how they obtained information in the first place (whether legal or otherwise).
I don't see how the prosecution has met the burden of proof, beyond a reasonable doubt, unless they show their work. Otherwise this is way too easy to frame people.
Maybe DNA from blood is a different matter, but when it comes to hair samples I don't think we can trust the FBI.
"The Justice Department and FBI have formally acknowledged that nearly every examiner in an elite FBI forensic unit gave flawed testimony in almost all trials in which they offered evidence against criminal defendants over more than a two-decade period before 2000."[1]
1. https://www.washingtonpost.com/local/crime/fbi-overstated-fo...
You show the recovered key and plaintext and demonstrate that they match the ciphertext.
The chance that several gigabytes of encrypted data accidentally happen to decrypt with wrong key to a different several gigabytes of perfectly valid data is rather slim, which means that any key which produces valid data is the key you are looking for.
"Deniable Encryption" is the term.
That's not what they said. What they said is that each particular case is about unlocking each particular phone. And mind you, these are phones that the government has every right to access if they can find a way, either because they have search warrants or are the legal owners (or have the permission of the legal owners) of the phone.
There is nothing controversial about this. The government has used vulnerabilities to extract info from devices gathered during legal searches for a long time. If they seize a safe from your home, they don't need special permission to crack it open.
The government still needs a search warrant or legal ownership of a device in order to perform a search. You're perfectly entitled to make your stuff harder to search, and they're entitled to all the hacking they need to extract the data.
The FBI may have said that, but it doesn't really address the issues substantively and I think they said much more: Remember Apple argued that a solution they provided for one phone would be used for others, and a court decision could be precedent for other cases. The FBI disagreed; I don't remember the details of what they said, however.
> these are phones that the government has every right to access if they can find a way
I agree, but that's not the issue here. The issue is the FBI's apparent attempt to deceive the public and the courts.
The FBI said Apple could maintain control over any tools they made. Apple said "oh noes, we can't ever make a master key [but don't look behind the curtain, where you'll find that we have a master key or three, which is why we can make one in the first place]"
Then the FBI found an alternative solution that doesn't require Apple's assistance, making the whole damn conversation moot -- including whether they'd use Apple's hypothetical "master key" on other phones.
Apple did not make their product weaker (We don't know what hole the FBI found, but it might require physical possession of the device, and Apple could fix it tomorrow. Either way, regardless of what flaws exist now, that number wasn't increased). In addition, there was a national conversation (albeit ignored by most) about whether Apple should make their product less secure. A conversation that actually hit some details. John Oliver did a bit on it, I know several other outlets tried to convey something beyond "Terrorists Bad!/Govt Bad!".
That's something I am glad that happened, and something that wouldn't have happened without the discussion you consider "moot". The answer may no longer be important, but the debate was.
Directory Comey very explicitly said that "The San Bernardino litigation isn't about trying to set a precedent or send any kind of message"
https://www.lawfareblog.com/we-could-not-look-survivors-eye-...
We can't seriously be expected to believe that over the next six decades it will come out that all these politicians and law enforcement folk were just, upright, moral citizens, acting in everyones best interests.
What we all knew, and what's leaked in the recent years. The answer is nobody really.
If you mean that because he's FBI Director therefore he's lying, I strongly disagree. Certainly, just like everyone else, FBI Directors don't always tell the truth; the world is much more complicated than that. He is a human being, not a saint or angel, who has dedicated his life to public service and has an extremely high pressure, difficult job. I don't always like what he says but he deserves a little respect.
Lying to the public to accomplish a goal is not admirable in my view; it is contemptible.
It seems clear to me that he lied to Congress but parsed his testimony in a way to provide deniability / accountability. You may choose to admire this but the rest of us don't have to share your view.
I'll side with Socrates and condemn the Sophists.
Given Apple didn't provide a solution, that seems rather moot...
Second, are you aware of what I mentioned, or you just whipping around HN expressing your opinion without any effort; if so, that's bit above trolling in my opinion.
Lastly, given your username, if you have any affiliation with the government, law enforcement, etc. - in my opinion that should be disclosed in a comment on related topics.
Obviously, they're an easier target so that's why people are attacking them but, honestly, what did they do other than stand for their (AND OUR) values?
By not building a backdoor, or by not helping at all?
If the latter, I'm not sure I fully agree.
At the end of the day, I personally like our prosecutors having criminals' data, given that there is a court-ordered warrant for it. I'm definitely not for building backdoors, but I'm all for the FBI picking the lock or breaking down the doors if the courts deem it necessary.
> The FBI has agreed to help prosecutors gain access to an iPhone 6 and an iPod that might hold evidence in an Arkansas murder trial, just days after the agency managed to hack an iPhone linked to the San Bernardino terror attacks, a local prosecutor said Wednesday.
http://www.latimes.com/local/lanow/la-me-ln-arkansas-fbi-pho...
Even Apple does not seem to know what the exploit was, as they are pursuing legal options (or dropping hints to that effect) to compel the FBI to reveal it to them.
Cellebrite describes [1] the solution as working for iOS 8.x on the following devices:
> Cellebrite's unlocking capability supports the following devices: iPhone 4S / 5 / 5C, iPad 2 / 3G / 4G,iPad mini 1G, and iPod touch 5G running iOS 8 ...
[1] http://www.cellebrite.com/Pages/cellebrite-solution-for-lock...
[1] https://en.wikipedia.org/wiki/United_States_v._New_York_Tele...
This is history rewriting, the request, in his least dangerous form, was to unlock a single phone from inside Apple labs by Apple people
Safes are drillable, and there may also be "password recovery" services available from the manufacturer.
^^ True, which is why Apple's systems and related security measures will likely never be publicly auditable.
The proposed FBI exploit would unlock any and all iPhones.
The San Bernardino litigation isn't about trying to set a precedent or send any kind of message... We simply want the chance, with a search warrant, to try to guess the terrorist's passcode without the phone essentially self-destructing and without it taking a decade to guess correctly. That's it. We don't want to break anyone's encryption or set a master key loose on the land.
https://www.lawfareblog.com/we-could-not-look-survivors-eye-...
It's possible, by some weird John Yoo-style contorted reading of the facts to say "FBI Director Comey said that, the US Government didn't say 'because terrorism'". That contorted reasoning would amount to lying by splitting hairs. Don't lie by splitting hairs.
If you're a programmer you'll understand - you can't argue generally about a class because of the properties of an instance of that class.
I see where you've gone astray: law is made on a case-by-case basis in the USA. The USA has a "common law" system (https://en.wikipedia.org/wiki/Common_law) where precedent (https://en.wikipedia.org/wiki/Precedent) is overwhelmingly important.
If I understand correctly, the FBI was attempting to set a precedent, using an instance that has lots of emotional appeal ("Terrorism!") and they were really working that emotional aspect ("Couldn't look the survivors in the eye") hard. Once that precedent is set, the USA's legal system would require some new laws to make the precedent go away (in a legal sense). The FBI could at the least operate under the legality of the precedent until the new law(s) take effect, if such new laws get made. They often don't, and the USA just rides on the precedent.
* Officially, because presumably it's been going on for a long time but not publicly discussed to the degree that it is being discussed now.
http://techcrunch.com/2016/02/25/apple-hires-developer-behin...
So yea, it's an iPhone 6.
http://www.latimes.com/local/lanow/la-me-ln-arkansas-fbi-pho...
Touch ID ends up working like this, where your fingerprint takes the place of that simple passcode. But for people who don't want to use a fingerprint, you're stuck using the same passcode or passphrase for each unlock.
I'm guessing it's been well over 48 hours since the suspect last had access to this phone, so that would no longer apply.
This is a ridiculous game - the government is refusing to disclose exploits they found in our devices with our tax dollars. I can't see this ending well.
See Page 12 on advantage of A7 or higher processor, but, in particular:
"On devices with an A7 or later A-series processor, the delays are enforced by the Secure Enclave. If the device is restarted during a timed delay, the delay is still enforced, with the timer starting over for the current period. "
The question still outstanding, is whether the Secure Enclave can be modified, and also, whether it can be modified without a passcode.
Edit: Any device that is nand cloned will not be using apple power anyway. And we have all kinds of low temperature, low voltage bit flip attacks anyway.
Low voltage attacks:
A low-voltage fault attack is a fault attack where the fault is induced by feeding the hardware with a lower-than-normal voltage (in the "smart card" model, the card has its own CPU, RAM and ROM, but the current and clock signals are provided externally, i.e. are under the control of the attacker). For instance, if the card expect 3.3V, you give it only 2V. The real trick here is that the attacker can lower the voltage for only very short durations, a few clock cycles, so as to induce a fault in a specific part of the algorithm execution
We try to get the hardware crazy.
http://security.stackexchange.com/questions/69279/what-actua...
If you read through Apple's security document, you'll see that the Secure Enclave achieves separation from the rest of the system by encrypting everything with keys that can't be replicated on the outside, and by having its own secure boot verification. It's possible that there's some internal storage that they just don't mention, but it doesn't look like the way to bet.
This means that even devices with the Secure Enclave are still vulnerable to flash cloning. You can't understand the contents of the Secure Enclave's stuff, but you can still save and restore them once you desolder the flash.
The attack described in the comment you're replying to won't work, of course. The counter is stored in the flash, so cutting power won't do anything. There was a bug where the OS would report an unlock failure before updating the flash memory, so if you were quick to cut the power you could bypass the counter, but that's been fixed.
What does work (in theory) is to desolder the flash and hook it up so you can save and restore its contents. Then you turn on the phone, try a few passcodes, shut down, restore flash to original state, repeat until success.
Of course, this only works if the passcode is simple enough that a brute force is feasible. You can attack a four-digit passcode in a few days this way. A six-digit passcode would take maybe a year, and proper passphrase would still be completely infeasible.
1. One way would be for the SE to have it's own clock function. 2. The other would be for the SE to send a message to the main CPU and ask the CPU to let it know when x number of seconds has passed.
I believe that second option is more likely because of the way the feature works. On full phone reset it restarts the timeout period rather than continue it from where it was. This could be a feature, of course. But I am guessing that the way it works is that the SE asks the System to tell it when x seconds / min has past and sets a timeoutExpired flag to false. Once it get's the notification that the time has passed, it resets the flag to true.
If above is how it works, than screwing around with the System clock could be effective. If the system relies on system time, then it might be possible to shift the clock by doing adjustment through a fake cell tower. Not sure how effective that would be.
Just some thoughts really. Would be interesting to see if they can unlock the iPhone 6 or not.
This is the protection against search and seizure that you're entitled to within the US:
>The right of the people to be secure in their persons, houses, papers, and effects,[a] against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
Or more likely how to _market_ the next round of phones as being more secure and whether claiming the upgrade is essential for businesses ("our old phones are all broken now, you must upgrade") will lead to a gross increase in profits or not.
So, I think we can be reasonably sure that no info of value will come off that phone. It's possible, but it seems unlikely.
You know, just sample a few and then if nothing comes up, just infer that everything is kosher?
Is it just acceptable at this point to publish AP content with typos?
Would you pay anything at all for online journalism?
It is in Apple's best interest to find out what the exploit is, how long it's been out there, and fix it instead of playing legal games. Such an exploit in the wild is a security concern for every person who owns that phone, not just criminals. There is no telling how many people are out there accessing privileged information in the private and government sectors with that phone. It is a concern covering criminal activity all the way to foreign government spying.
As a bonus, if it's an exploit that's been known from before the FBI's claim that only Apple can help them breach the phone, then we know the FBI was full of it. The FBI has been known to use questionable tactics before and backed out of cases that weren't going their way to avoid revealing those questionable tactics. This whole iPhone thing reeks of this.
There is no oversight or limitations.
Complete and total lack of justification.
There's a word for this -- corruption.
Would it have pleased you more if, oh let's just for the sake of argument say: the government had to get some kind of a court order to get the information?
So, yeah. I believe it would please 'em more if there was a court order involved.
It's not like the court told Apple "you need to immediately start working on this" and Apple said "no, we refuse".
https://en.wikipedia.org/wiki/Parallel_construction
Once it is in their possession, for whatever cheap and loose justification, they will open it.
Your argument is under the assumption that they are not corrupt.
I can't see even a speculative 5th amendment argument. If they can crack your phone without your cooperation, how could they possibly be forcing you to incriminate yourself?