> Apple: If we're forced to build a tool to hack iPhones, someone will steal it.
> FBI: Nonsense.
> Russia: We just published NSA's hacking tools
> Apple: If we're forced to build a tool to hack iPhones, someone will steal it.
> FBI: Nonsense.
> Russia: We just published NSA's hacking tools
Even popular anti-virus programs on Windows have been jimmied to allow state-sponsored malware through
[citation needed], and I mean a credible one with evidence, not tinfoil-hat raving.
Yes, we know that three-letter agencies look for, and probably have a stash of, zero-days for covert access. And they also do physical attacks wherever possible (like fiber taps at Google's datacenters). But those are two very different things from backdoors built in with the cooperation of the vendor. And despite how many people on the Internet treat "companies build in gov't backdoors" as just unquestioned fact, I've never actually seen any proof.
Our intelligence apparatus has cried wolf too many times, in terms of denying they do something and then it turns out they do it, to be trusted anymore. They've lost the benefit of the doubt and if they don't want people believing all the tin foil hat things, maybe they should stop doing so many of them.
This is true, but using it as a justification for "And therefore, my theory about what the intelligence community is doing is correct and does not need evidence" is a non sequitur fallacy that has become depressingly common in recent years. You still need evidence for individual allegations.
To show you what I mean, suppose I were to say, "The NSA has a constellation of mind-control satellites built with help from the lizard men!", and then responded to the deserved skepticism with "A lot of things that used to be tinfoil hat theories we now know to be true thanks to Snowden, so this is too!". That's obviously fallacious reasoning, but it's exactly what people are doing when they toss around allegations of backdoors with no proof. Again: there's no shortcut around the need for evidence.
> After Snowden, I no longer doubt the possibility of any realistically imaginable attack ie, assume that if they have the physical ability to do it, you should assume they do it and are not stopped by any ethical concerns.
I agree completely, but that's not what I, or the person I replied to, was talking about. The issue I was addressing in my comment was whether their backdoors are being built with the knowledge and cooperation of the vendors, which is very much unknown. Attacks like taps on cables are orthogonal to what I was saying.
Jimmy: a short crowbar used by a burglar to force open a window or door.
He didn't necessarily say it was collusion but I suppose it's fair to clarify. It seems narrow to suggest it's just a stash of 0-days. I suspect they've been heavily yet covertly involved in the popular software tool-chains and computing hardware.
Mind control satellites and lizard men are both so far away from our current science and technology that even assuming the NSA could be a few years ahead, it's not worth considering. If there really were mind control sattelites or similar precursor technology available or in research today, and there were lizard men who had a history of being good at working with those and willing to sell their skills, then I would agree that it's plausible they're doing it.
Also, I'm more interested in the /practical/ applications of this knowledge of whether the intelligence community does a certain thing X, not the philosophical certainty of whether they do a thing X. You lock your doors because someone /might/ break in /maybe/, not because you're certain John Doe is planning on doing so at 4:30am tonight. Even if no one ever does, it's certainly technically possible, so if locks are cheap it's a reasonable tradeoff, even if you'll never be sure if they really helped.
You're probably right though that I'm moving the goalposts around! :-) I'm not trying to have a formal debate, just idly shooting the shit on the net, so I'm OK with that.
Prepare for that scenario as a possibility, but there should still be a burden of evidence before possibility is accepted as reality.
That's a far cry from "Practically every major piece of software and hardware that's not open source has a backdoor embedded."
The pedantry around here can be infuriating sometimes. You take issue with my strictly true comment, and ignore Analemma_'s comment upthread (every product) which is strictly false.
I think The Puzzle Palace (https://www.amazon.com/Puzzle-Palace-National-Intelligence-O...) made the same argument as far back as 1982
1. https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...
Likewise, [citation needed]. That would be pretty stunning, if true.
The parent poster was suggesting (and I was questioning) this occurred at Google Data Centers, which would prove explicit cooperation by Google.
A whole different ballgame.
The closest I've seen are the PRISM slides which imply cooperation from Google and the other big companies, but this could be bad choice of wording.
Regarding PRISM cooperation, I'm not sure where your doubt is coming from there. http://imgur.com/a/wRKtL
The slide was explicit, and is now many years out of date so without doubt the number of providers has increased. The means by which these provider agreements are reached is well known (National Security Letters) as is the fact that organizations are fully barred from disclosing their existence.
https://www.schneier.com/blog/archives/2014/03/friday_squid_...
Do a search for "ibm lotus backdoor" or start from http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html
The math doesn't add up.
That argument is not true. Spy non-fiction taught me that intelligence services sort of rate their capabilities on what intel they can bring plus how secret they must remain. The idea being a capability might be so good and so hard to replace that you only use it on highest-risk cases that nothing else works on. Additionally, lower clearances will have greater number of infiltrators. They should see less than higher clearances to reduce damage of leaks. Further, I predicted that the tools themselves were developed in Special Access Programs (SAP's) that compartmentalized away from even TS clearances then selectively released to them. Sentry Eagle et al confirmed my prediction.
You can actually see the bullshitting in progress if you look at that. Each level of clearance is told something different with the lower levels often getting lied to with only highest getting the truth. In one case, it was implied they were attempting to use supercomputers against crypto then TS/SCI version said they got companies to backdoor it. Quite the difference. ;)
What you describe is how intelligence services actually work to develop and protect real tools for access. What the GP claims is a fantasy in which such work is not necessary.
I agree that's a crap claim. Tried to provide alternative that showed situation is almost as bad as crap claims like that with 0-days. What overlap I did see was the emanation threat. That secrets leak out of any device and TEMPEST protection of them is illegal means that they are all backdoored for that in practice. Good news is it's a highly-specialist attack only a few countries know how to do that requires targeting and close proximity. Other good news is that smartcards and EM compatibility testing reinvented some defensive practices.
Not really.
iOS already, today, for no other reason than to prevent downgrades, verifies every firmware upgrade/restore with an Apple server, which sends back a per-device signature. Technically, it would not be difficult for Apple to have that same server authorize a special spy firmware only for specific device IDs. The only way this could result in a mass compromise is if Apple were hacked, but hacking Apple already gets you that - the hard part isn't writing code to spy on people (especially if you've hacked them and thus have full iOS source code), it's signing it.
This is different from exploits for code vulnerabilities, where there's always at minimum a secret (the location of the bug) that can't get out, and in some cases going from there to a working exploit is also difficult.
At worst, if Apple went beyond compromising that one phone and set up an ongoing process to compromise phones as requested by law enforcement - then there might be some sort of online portal, and maybe it could be hacked either directly or by stealing a legitimate agency's credentials. Maybe then the spy system could be used by unsympathetic governments against their enemies, though only by stealthily submitting individual requests; there would be no way to exfiltrate something from law enforcement that would compromise everyone. I don't think that's what most people are thinking when they talk about a back door "getting out" or whatnot.
Personally, I agree with Apple's refusal to create and sign a spy firmware on ethical as well as pragmatic grounds. But there's a lot of misinformation about the issue.
Are we pretending now that the government couldn't MITM and fake the response? I think they've proven they can MITM pretty much ANYTHING their hearts desire.
Only if they have Apple's private keys or can break RSA...
http://www.theverge.com/2013/12/20/5231006/nsa-paid-10-milli...
Further, if people are paranoid of this, a crowdsource based mitm restore server could be setup (similar to saurik's) to watch the hashes and block restore + alert the user if a firmware file is about to be installed with a different hash than what it should be.
So I don't think this was the strongest argument for Apple. A better one is that once the US can compel Apple to do this, what's to stop Russia, China from demanding the same thing?
It is so simple to steal software, just like NSA's hacking tools were stolen.
If NSA cannot keep software safe, why can you think that Apple can? I think it's unreasonable to require Apple to have a higher level of security than NSA effectively has.
1: http://www.sfgate.com/nation/article/Apple-FBI-face-off-in-C...
If the "backdoor" in question is a malicious signed OS update, then it can absolutely be destroyed. There are plenty of reasons to avoid backdoors without imbuing them with mystical qualities like the inability to delete them.
And then recreate, and redestroy it for each of the >100 law enforcement requests in NY alone. Etc. Etc. Though the FBI says that, Apple pointed out in their brief that the reality of what that kind of situation would look like was absurd.
I'm not saying Apple is evil, merely that multinational corporations don't have to care about political boundaries.
As a multinational company, it's in Apple's interests to maintain a 'no backdoors' strong privacy stance, or it will both lose foreign markets (that are afraid of US/other nation's backdoors) and have to contend with increased requests from various governments for backdoors/audits (they got backdoor access, why can't we?), and the associated revenue lose.
Right. So if there is a backdoor, they won't commit the code to a repo, but write it from scratch every time FBI calls them.
Yes, very realistic.
From that we learn two things, both bad and which tells us not to listen to or work with FBI if possible:
1) FBI is stupid and doesn't know how these things work
2) FBI is malicious and is lying
Ethics aside, this seems like a very lucrative gig for software companies that bill by the hour
> 1). FBI is stupid...
While the tech industry like to cast aspersions about the FBI and how idiotic they are, I think this perception is wrong. I don't think they could possibly have access to the resources they do and be stupid. They may not always understand fully the technology they're working with, but I'm quite sure there are resources within their reach that would quickly set them straight where required. I'm sure at the very least they could create a GUI interface using Visual Basic to track their IP address.
> 2). The FBI is malicious and lying...
I'd like to believe they're neither but the more time goes on, the more my goodwill towards them fades... and while they're not the NSA, the doubt the NSA has cast on Government Agencies has tainted that with the "guilty by association."
I can't believe they're incompetent, I do believe they (largely) do what they do with good intent, I think their strategy is short sighted.
That leaves me asking the question: Have they lost sight of the future repercussions of the actions they take today or are they actively considering the future repercussions when making policy today?
If they're actively considering the future repercussions of policies they're making today, that is the greater cause for concern because they're actively making policy that ensures the state's ability to monitor (and in effect, censor) the future population - counter to the first and fourth amendments.
I responded to an FBI call for recruits to staff up their cybercrime divisions after 9/11, and was in their recruitment pipeline for two and a half years.
Based on my experiences during that period, I have no problem believing that they are stupid.
Dude! Just nine more months and they would have completed your SSBI and you could have been forwarded to the next stage!
God, it's like you don't want to put your life on hold for multiple years while an impersonal bureaucracy methodically sorts through your entire personal history.
What's to stop the FBI from repeating the same process in the future? Fighting future orders would be much harder after precedent is established.
Remember that after James Comey talked about spending "a lot" to get into the San Bernadino phone, he wanted a way into the phones that "doesn't involve spending tons of money in a way that's un-scaleable."[1]
[1] https://www.washingtonpost.com/news/post-nation/wp/2016/04/2...