Some U.S. law enforcement agencies are using GrayKey to bypass iPhone encryption
motherboard.vice.com
motherboard.vice.com
Wow. That's very sleazy.
A thing that can be cracked will be cracked. If someone's good at something, they will probably look to sell their skills. If it is within the law for police to perform this kind of thing (it probably definitely shouldn't be), they're gonna use whatever contractor can do it best (if they can't do it themselves).
It just seems like the natural progression -- outside of the oddity of police being allowed to "break into" (in a sense) private property.
I think this argument devolves into the does-tech-hurt-people (guns, security research) argument, and maybe I'm just way off base, but I don't knock the iphone cracking people in this instance... I mean I wouldn't necessarily do it but this isn't bad enough to pass muster in my book as sleaze.
If you see modern society in a democratic environment with the (somewhat naive) outlook that a large enough group of people have consented to be governed by the laws of the land, then it's really up to the law on when this is allowed/disallowed. It's more of a reflection of the people (or.. who's making the laws), and what they've decided -- if people decide that personal privacy is protected under law then so be it. If people decide police are allowed to break the law (at all) then so be it. If people decide that police are somehow above what would normally be a law when they have certain piece of paper (search warrant) signed by the local wiseman (judge) who is likely looking out for the best interests of the community and country at large, so be it.
Things get blurry really quickly, and this is a gross oversimplification of how any of these systems work, but it's how I tend to think about it. I sometimes think that it can't be any other way -- once a bunch of humans attempt to work together, there are some fundamental problems that just end up best solved this way (in terms of efficiency and other factors).
This “if I don’t do it, someone else will do it” attitude really just highlights how much more ethics training do we need to have in part of becoming a software engineer.
Try that attitude in the medical community, or civil engineering, or aviation engineering, or physics or chemistry, and see where that will get you.
Computer Science as a field hasn’t encountered consequences: https://twitter.com/yonatanzunger/status/975545527973462016?...
It varies by case, but if you try to delineate where it's OK and where it's not, it will be endlessly subjective -- in the face of that, I lean in the "do what you want" direction.
I don't think there is a single discipline that's unscathed in this discussion, it's just the level to which the morals are shared in each. In the medical community, "do whatever you can to save a life" is a pretty strong propellant, but also the medical system in the US (for one) is really fucked, and if the medical community is as ethically pure as you propose them to be, I get the feeling that wouldn't have happened.
[EDIT] - Also, correct me if I'm wrong, but when I think of "ethics" I just think of agreed-upon shared moral values. That is inherently up to someone or some group to decide, at some point, is it not?
True. But that doesn't really free you from moral judgement.
> It varies by case, but if you try to delineate where it's OK and where it's not, it will be endlessly subjective -- in the face of that, I lean in the "do what you want" direction.
This really depends on your value system. Of course, you can do what you want (perhaps as long as it's legal), but again, moral judgement is a separate issue. It's totally okay to be immoral, and ethics itself doesn't really have any limitations on what you would do.
From a utilitarian perspective, yes, perhaps everything is endlessly subjective, but I think for most people their ethics system lies somewhere in between deontological and utilitarian, that is, there are certain moral guidelines that are more applicable even in subjective situations.
Again, I'm not saying you shouldn't do anything immoral. There are many other factors for one to consider: life, liberty, the pursuit of happiness, etc. Most of this have nothing to do with ethics at all, but none of it gives anyone a free pass for moral judgement.
> the medical system in the US (for one) is really fucked
That may be true, but we're not really talking about the system here. We're talking about the individual physicians.
> "ethics" I just think of agreed-upon shared moral values
Ethics is a system, sort of the "theory of morals". Ethics training is more about the logical study of these theories, and how one would apply a certain ethics system to evaluate a certain situation, rather than the "agreed-upon shared moral values". Endless engineering fields before us have faced these problem before, and the principles apply just fine in Computer Science.
I thought of this in the context of "if ethics to everyone einvolved, is worth a lot the system would never have gotten that bad". Clearly someone missed the forest for the trees if every doctor is considered ethical but can be part of such a huge system that's failing patients (and causing the outcomes they seek to prevent).
> Ethics is a system, sort of the "theory of morals". Ethics training is more about the logical study of these theories, and how one would apply a certain ethics system to evaluate a certain situation, rather than the "agreed-upon shared moral values". Endless engineering fields before us have faced these problem before, and the principles apply just fine in Computer Science.
I clearly haven't read/don't know enough about it, could you recommend some good introductory texts?
I find things in this area to always devolve to the personal/private/corporate (in the sense of a group of people) freedom basic arguments. Would be great to read something that proposes something new.
Yes, it is your decision, but it is not simply a decision of "do I whichever I want in the moment." It is ("do I want to do this & "would I be okay with someone doing this to me). (That's a bitwise AND there)
Also, I think the way of thinking you're referring to is called universalism (roughly stated - "do a thing only if you're OK with everyone doing that thing"), but I think it has it's problems.
> Yes, it is your decision, but it is not simply a decision of "do I whichever I want in the moment." It is ("do I want to do this & "would I be okay with someone doing this to me). (That's a bitwise AND there)
Yeah that's basically integrity (at least the consistency part) though -- I don't agree with the example I gave (it's pretty devil's advocate-y and obviously against the mores of the HN crowd), but I don't know that I can call someone who draws the line a few steps away from where I might have drawn it "sleazy", especially when there are people out there that do way worse things in hidden places.
> medical community, or civil engineering, or aviation engineering, or physics or chemistry
Honestly, I think this conflates two very different problems.
If we're talking about Chris Wylie? Yeah, he built a thing that did real harm and said "I didn't think about the consequences, I just wanted to write the code." If people are disinterested in the harm they cause, or hiding behind "someone else would have", that's time for an ethics class.
But GrayKey? Or Prism, XKeyscore, Echelon, or whatever else? There's no shortage of people who believe they are doing the moral thing with projects like this. GrayKey (supposedly) doesn't sell to everyone - they request data to approve buyers first. It's not hard to imagine the people behind it think the government should have this access and believe they're the ones doing the right thing.
(And on the flipside, I'll bet some of the engineers on Greyball thought it was justified to fight harmful government regulation.)
I don't think this is an isolated example. Psychology has a strong code of ethics and associated training, but the American Psychological Association helped the CIA design a torture program. British aviation engineers design fighters that end up sold to Saudi Arabia. Hell, civil engineers design prisons to support widespread solitary confinement and other treatment many people consider unethical. Either their ethics training isn't working, or the people doing this stuff consider their behavior ethical.
There are programmers doing unethical things because they never thought about the consequences, or because they just don't care. But the focus on unethical software is rarely "somebody wrote ransomeware" - it's usually about controversial political applications. Calls for licensing and ethics training in the industry all too often look like an endrun around "what's moral?", attempting to settle moral disputes by treating disagreement as ignorance.
He got paid by Apple to secure them. Now he gets paid to do the opposite. After a couple of beers he will you the truth $$, but now he probably reasons it as "helping cops to catch bad guys."
What would be sleazy though is if he deliberately discovered a bug and didn't report it to apple while working there, and then took it with him to this job.
But if he simply made use of his general knowledge of the system for more effective pentesting, I think its pretty much fair, and expected
Obviously, you can't prohibit ex employees from getting a job elsewhere, you surely can stop them from peddling company secrets to the highest bidder.
That being said, the only way I can imagine that apple isn't already prepping a massive lawsuit is that the method they are using did not necessarily require insider knowledge.
Quite frankly, I think it's a relief to see a few "cracks in the wall" --- that not everyone working for Apple agrees completely with their authoritarian view of security.
That doesn't make it a good thing overall that the flaw exists.
Hacking Company: We've hacked the iPhone and are selling the tech to law enforcement.
Hacker News: Evil! Sleazy!
Having your cake and all that.
Hacker News: Hack everything!
Cracking company: We've cracked the iPhone and are selling the tech to law enforcement.
Ref: http://www.catb.org/jargon/html/meaning-of-hack.html http://www.catb.org/jargon/html/C/cracker.html
It wouldn't look out of place in the 80's. The LEDs in particular would fit right in.
I would not be surprised to find an actual $1 micro controller driving this. Or to find that out the box wasn't really required at all – and that during development the software ran in a normal laptop, but they needed a physical product to charge the big bucks...
Though, one wonders whether a simple tap on the lightning cable couldn't spill the device's secrets.
If anyone can extract keys from the actual secure enclave processor, it would be them.
> Wray is not telling the whole truth.
I wish there was some punishment for Government officials for lying to the public. You can be prosecuted for lying to the FBI, so why shouldn't they be prosecuted for lying to you (the voter, who is supposed to have the power in a democracy)
(1) Whether LE agencies are actually finding it more-and-more difficult to access devices that employ encryption. I think this is plausibly true, simply because there are more such devices being sold than ever before (from the perspective of senior LEOs).
(2) Which LE agencies is he talking about? If he is refering to all agencies, then he might be right. Many LE agencies have very limited budgets. However, if he is talking about the more well-funded and competent agencies, then he is probably wrong
>I wish there was some punishment for Government officials for lying to the public. You can be prosecuted for lying to the FBI, so why shouldn't they be prosecuted for lying to you
Get rid of the punishment for lying to LEOs and it is all fair and equal. They lie to us and we lie to them, both without punishment. It would still be illegal to lie to judges.
>(the voter, who is supposed to have the power in a democracy)
The purpose of democracy is to use elections to legitimize a limited group of persons to use the power of the State. The power of voters is limited to selecting who will be in that group. The rest of the power of the State is in the power of the hands of those who were selected.
It looks like it runs third party code on the device. Only needs to be connected to the black box for two minutes and then unplugged for the remainder of the process.
https://en.m.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
It seems likely that Apple could just buy one of these, find the bug and fix it. Unless it is using some very low level exploit which I suppose is possible and might explain why it is hardware rather than software (though that might also be to justify its cost and prevent piracy).
Nobody would ever sell it to them.
So if you care about securing against this, use a longer passcode (and alphanumeric) is the message I guess.
I don’t know the details: is it as simple as grounding the “password entered incorrectly” pin? Or is it about injecting so much noise on a signal line that the message to increment the PIN attempt count never gets through? I don’t know.
So use a passphrase, not a PIN.
Security and a focus on user privacy protection (from other entities, at least) is definitely a differentiator for apple devices
EDIT: Pretty sure this is the one I'm thinking of: https://www.digitaltrends.com/mobile/cambridge-researcher-ha...
I guess it was two years ago.
Yeah but "normal" people don't think that cops will have a reason to look at their phone. Until it's too late.
Cat and mouse game, let's hope Apple does something. Typing 10 characters a gazillion times a day can become frustrating
It is still a 24h block (let's use the default) where the device is vulnerable. In many countries there are no protections against pressing your finger on the phone, or worse yet, turning it to face you.
It also disables biometric unlocking until the password is entered.
I would guess Apple already has one. But if they’ve tried to get one, and been foiled somehow, there must be a fascinating cloak-and-dagger story there that we’ll probably never hear...
There are extremely good reasons for police officers to want access to an iPhone (which could be time dependent). At the same time there’s a lot of potential for misuse of the ability to gain access by agencies or malicious actors.
It’s a trade-off. I err on the privacy side of the issue because things can be misconstrued in a legal setting. I can see why some people don’t have the same viewpoint and lean the other way.
So couldn't you avoid this by, say, having a longer PIN? Maybe even a password?
I wonder if this is doing some sort of timing or voltage related validation of the code without needing to actually submit it. Ie the equivalent of 1234,backspace,5,backspace,6 etc without sending whatever is the equivalent of 'submit'
> GrayKey can unlock an iPhone in around two hours, or three days or longer for 6 digit passcodes
> 'GrayKey' ... can break into iPhones, including the iPhone X running the latest operating system iOS 11.
> The device comes in two versions: a $15,000 one which requires online connectivity and allows 300 unlocks (or $50 per phone), and and an offline, $30,000 version which can crack as many iPhones as the customer wants.