https://en.wikipedia.org/wiki/Responsible_disclosure
If the FBI wanted to protect the public, responsible disclosure of the exploit is a first step.
Sigh.
https://en.wikipedia.org/wiki/Responsible_disclosure
If the FBI wanted to protect the public, responsible disclosure of the exploit is a first step.
Sigh.
Responsible disclosure is a courtesy. Exploits are valuable. Information asymmetry is the name of the game. Apple is not entitled to free labor. If they don't like it they should hire researchers, as the FBI has.
• mining equipment: not dangerous :: enriched vein of uranium discovered using mining equipment : dangerous
• chemistry equipment : not dangerous :: nerve gas, napalm, etc. : dangerous
It's a strange situation where the equipment has a set of very legitimate uses, but once you allow it into people's hands, they now have complete unmonitored autonomy in how they use it, and might very well use it to bring about something dangerous with no-one the wiser.
This is unlike most experience we have with dangerous tools. Cars, for example, can easily be used as weapons—but that danger only applies in public where others can observe you using the car, and your driver's license can be revoked. Similarly, a HAM operator could, on a whim, pollute the RF spectrum around them with noise—but that's also an action that by its very nature is observable, and so their broadcast device could be tracked down and shut down, and their operator certification revoked.
But nobody sees you when you decide to mine for uranium, or produce chemical weapons, or develop software exploits. These aren't the tool being used as a weapon, being used to attack; these are instead cases of a tool being used to create a weapon, to create the potential for future violence, violence that—until it ever comes to pass—has no observable effects out on the world that will hint that this person is acting with malicious intent.
It really seems like the law doesn't know what to do about that category of things, generally.
You can use a hammer to construct something, or to bash someone's skull. That's human nature, and freedom. To not have that choice would mean we have lost a lot more than we'd have gained.
This moral ambivalence makes it (luckily) nearly impossible for any form of authority to make a definite statement or prevent usage. It ensures freedom.
And sometimes bashing someone's skull might be the "positive" action, and using a hammer to construct a building the "negative" result, as when the building is used predominantly to harm people. One could use hacking tools to get around totalitarian governments or locked-down operating systems, or even to get into a former lover's device but at the same time prevent that exploit to be used anywhere else because of the bug's exposure. Even the "criminal" might be the good guy in the long run – morality is highly complex.
IT security really ends up most often in ambivalent, shades of grey territory, and not in the clear black/white contrast preferred by many people and especially law- and policy-makers.
FWIW "enrich" in the context of uranium is the thing done by centrifuges. You don't get enriched uranium out of the ground.
And Napalm is basically styrofoam and gasoline. You don't need much in the way of chemistry equipment to make it.
> It really seems like the law doesn't know what to do about that category of things, generally.
The main problem with the concept is that it doesn't end. A person with malicious intent can cause quite a lot of destruction with only the stuff everybody already has. There is no point in restricting chemistry equipment when people already have gasoline (or olive oil or lard or alcohol or ...)
The only way to separate a person from the means to cause trouble is to eject them naked into the vacuum of space, and even then it's mostly because you can expect that to kill them.
Also, LA gangs used EV cars for modern drive-by's. Should EV cars now have a "gun tax"?
Think of the people with home automation systems, where they can press a button on their phone to turn the lights on and off in their living room. You are saying that they have installed a weapon. That is crazy. It could damage their washing machine, but so could a 2-liter of soda.
It's nearly impossible to enforce something like this because of anonymous markets and crypto currencies, but we should at least shame people that advocate for it or admit to doing it.
This seems a lot like saying, if someone pays you to do a structural analysis of a parking garage because they want to know if they can profit by shorting the company that owns it, and you discover that the garage is likely to collapse, you don't have any obligation to disclose the vulnerability.
Depending on how this exploit works, a simple denial of service when someone needs to call for emergency services may indeed represent an "imminent physical danger". People rely heavily on their phones, both for connectivity and to store important information. As this reliance increases in the future, the probability of a phone being part of a life threatening situation will approach one.
I didn't imply that it's inconceivable that the vulnerability eventually leads to danger. The point is that the safety issues at a garage directly lead to harm, while the safety issues with a phone don't. (Note that the garage doesn't require anyone to actively exploit it to harm people.) Also, there's no way for the garage collapsing to help people, while selling an exploit to the FBI can conceivably help people (not difficult to imagine scenarios).
Then why is the CFAA still a law?
> Also, there's no way for the garage collapsing to help people, while selling an exploit to the FBI can conceivably help people (not difficult to imagine scenarios).
What do you mean? I laid it out already. You can short the company that owns it. Quite profitable. And maybe you donate the money to cancer research. If the garage happens to collapse at night when it only damages millions of dollars worth of cars but no people then it's not difficult to imagine that could come out as a net positive (it's clearly a personal positive for the short seller), and of course we won't know the extent of the harm ahead of time in either case.
I'm not even convinced that this should create a legal obligation to disclose it, especially in the cases where the most likely harm is financial or property damage. Otherwise that would pretty much ban half the stuff Wall St does. But not disclosing a vulnerability still makes you a jackass, which kind of implies that at least the government should not be doing it with tax dollars.
Plenty of things are illegal without directly causing physical harm to people. This is irrelevant.
I think I've made it clear what the relevant ethical difference between garage and exploit. If you think one still informs our ethics regarding the other, fine; I disagree.
Software runs our telephone networks and the telephones themselves. Are you suggesting the inability to contact emergency services isn't vital?
Software runs our cars. Is the ability to remotely disable a car something that won't hurt people?
Note that there's a difference between something that will cause a failure versus something that could be exploited to cause a failure.
There is a vital difference in that scenario: You paid the engineers who did the structural differences and thus have an expectation that they would disclose that information to you.
If someone comes around and pokes at your building without you having paid or told them to do so, I don't think there's any legal expectation whatsoever for them to tell you about any faults. (Ignoring the code of ethics professional Engineering societies have.)
It caused their professional society to condemn their acts and put in special ethics rules with regards to torture, etc.
And in any case, what does the FBI even have to disclose here? An exploit that they may or may not have that wold undoubtedly be contractually obligated not to share. In any case, everyone already knew that the crypto on that particular iPhone model was broken.
"... according to people familiar with the matter."
There is absolutely no proof of an exploit here. There are a lot of people 'familiar with the matter' that talk BS. For example I heard some expert say that they just bought 1000 iPhones and copied the ROM on each phone to try each pin combination.
Edit: to be clear: I'm talking about a software exploit. I think it's more likely the phone was cracked via a hardware exploit.
I'm not sure if Apple intended to rile up the Snowden/tin-hat wearing crowd who thinks the government is out to get everyone, but that sure didn't leave a nice aftertaste in the FBI's mouth.
Looking at this objectively, Apple shouldn't expect the curtesy of responsible disclosure. If this makes the public wary of Apple ability to protect their privacy, well, so be it. The FBI's duty is to actually protect the public, not to protect the customers of a single corporation.
I think this is brilliant counter-marketing on the part of the FBI and a real "fuck you" to Apple for turning a criminal investigation of a mass murder in to some fucking sideshow circus where they could show the public just how much more they care about privacy than the government.
EDIT: I'm sorry, but I have a rate limited account because my conservative opinions are not valued by the HackerNews community. I have some follow ups to your comments:
---
> That includes protecting the public's communication from criminal eavesdropping, which they are undermining when they keep an exploit secret instead of responsibly disclosing it.
I'm sorry, but this is not how the courts see things. Please see https://en.wikipedia.org/wiki/Third-party_doctrine
As far as I'm concerned and as far as the US government is concerned, as soon as you broadcast radio and electrical signals from your private person or property, it's been published. That's how it's been since the beginning of the country and that why Apple and Facebook are even allowed to sell your information to third-party marketers. Everything that leaves your devices legally has to be made public so our data can be legally sold.
This is also related to credit reports, doing-business-as, and many other kinds of public record keeping. You should not expect privacy when buying and selling goods in a public marketplace. How could you possible stop someone from monitoring what you're buying and selling? Consumer reporting, public record keeping, and public census data are incredibly important parts of our institutions.
We're going to need a newly defined set of laws and regulations to actual define what I've been calling "privished" works, that is, information that a third-party is liable to both the individual as well as the government, to make sure that the 4th amendment is still a two-way contract.
I suggest you brush up on some of your constitutional and common law interpretations of what privacy actually means with regards to mass communication. I think most of the HN threads are missing half of the social contract and fail to see the importance of granting the government the right to warranted search and seizure.
I prefer the theory that they wanted to improve their reputation in the international market with a show of defiance demonstrating that they weren't going to act as a front for US intelligence.
Although I have no idea whether Apple's reputation has actually been damaged overseas by increased awareness of American spying, it seems likely that American technology companies in the post-Snowden age will face a PR problem in the international market that Apple and other US tech companies should have a strategy for.
Source? Preferably the press release in question.
It's FBI who was pushing the polemic, and that's the same polemic you are now pushing.
Also, this isn't a show. These are legitimate privacy concerns that require active protection. The FBI is hardly in the business of protecting information from hackers. If they were, they probably wouldn't need Apple's help in the first place to penetrate their security. They simply don't have the expertise.
Again, I'd like to point out that it was the FBI who took to the PR stand to address the public directly in a political manner.
Insults are not good discussion.
> The FBI's duty is to actually protect the public
That includes protecting the public's communication from criminal eavesdropping, which they are undermining when they keep an exploit secret instead of responsibly disclosing it. The idea that they can keep it secret and nobody else will rediscover the exploit - and the "nobus" (nobody but us) attitude in general - is hubris.
> not to protect the customers of a single corporation.
I suggest reading older HN threads on this topic, because the fight against the FBI's order was not about a "single corporation".