The timing of computer search warrants when it takes years to guess the password
reason.com
reason.com
That's a bit ad hominem.
Let's look at it another way. Should warrants be issued for indefinitely long periods of time? If so, what would keep limitless warrants from being used to harass people? Imagine if the cops just seized property and said it's just going to take them literally years to access it, and the owner can't get it back in the meanwhile. Also, imagine if this is done to extend the statue of limitations. There are so many ways this could be abused.
Then it becomes not too different for arresting someone even when they've done nothing wrong - sure, the charges might be dropped, or no charges brought at all, but spending the night in jail and missing work still has deleterious effects.
> Requiring the government to exercise "greater care" to make sure it is keeping up with a series of requests [...] seems exceedingly odd to me.
So... the author is advocating for rules being too hard, and for the government to not be required to follow them? This is similar to the common response to the simple question about privacy intrusions: why not just have investigators get warrants? "But terrorism! It takes too long! Do you want the terrorists to win?"
Most of the copterbation movies and shows on TV try to show us that cops often don't get the bad guy unless they're allowed to break the rules. It's all absolutely bullshit.
[0] https://www.washingtonpost.com/news/wonk/wp/2016/02/17/how-l...
So given that it took them three years, 3/5.5 means they went ≈54.5% of the way through all the possible combinations. That seems in line with the estimate (assuming all passwords are 6-char alphanumerics).
* A ton of people just take their 4 digit PIN and append 00 or 01
* Passcodes that are easily convertible to dates. Bonus points for targeting their particular birthday, their family’s birthdays, their pet’s birthday, significant historical dates etc
* Passcodes that make a nice pattern on the keypad like 084265
* Passcodes that have a numerical pattern like 024680
Sure, you have an enter key you have to press to submit the pin instead of having it auto-submitted with the sixth digit, but that’s a small price to pay.
So in this case, it would have been completely reasonable for the judge to authorize the police to spend as much time as they needed to crack the password, mirror the device, and then come back for another warrant to search the contents. But the judge's warrant didn't authorize that, and the evidence should be discarded for going beyond the scope of the warrant.
[1] Beyond the normal exemptions that allow warrant-less searches.
DOJ should have asked for more time at the beginning. If they did and didn’t get it, they should have objected to the district court judge. If they did and were overruled, and this was so important, they should have bothered to get the renewals.
To argue that a judge can’t or shouldn’t place a time limit on search warrants is unpersuasive.
Old evidence is evidence, e.g. DNA and that should be used to both prosecute and to set innocent people free.
I get the potential for abuse, that is why you need a time limit and process to extend it.
It should be noted that those two methods are not equivalent.
The "tap 5 times" methods starts a countdown to call emergency services, which you will need to cancel if you are just trying to temporarily disable biometrics. It can sometimes be a bit difficult to cancel that call.
Once when I used "5 taps" it opened Apple Pay after 2 taps (which is normal), opened the emergency screen and started the countdown after 5, and then switched back to the Apple Pay screen. I managed to get back to the emergency screen in time to cancel the countdown.
A couple other times when I've clicking cancel on the emergency screen it has turned on the flashlight.
The "hold power and a volume button" on the other hand brings up the emergency screen but down NOT start the countdown. If you keep holding the buttons for a few more seconds it will start the countdown. The phone vibrates when it brings up the emergency screen so it is pretty easy to wait for that and release the buttons so you don't start the countdown.
Also note that you can disable starting the countdown on 5 taps and/or on long power/volume hole in the Emergency SOS settings. 5 taps and long power/volume still bring up the emergency screen and still temporarily disable biometrics.
Right now, tapping power five times on my phone running iOS 16.1.1 opens an "emergency" mode, which allows anyone to call 911 or see my "Medical ID". It also has an option to "cancel" this mode, which returns the phone to a normal locked state but forces a passcode to unlock (i.e. Face ID will not unlock the phone in this state).
If those are off then they just open the emergency screen. If those are on then they open the emergency screen and start a countdown to automatically call emergency services.
On my phone they are on, but I don't remember if I set them to that or they came that way.
Essentially they set an max budget for cost-effective attacks on the hardware, "modding the console needs to be more expensive than 10 games" (about $600), and ignored attacks that cost more than that to for an end user to execute.
I wouldn't be so sure. Just because your phone is clean doesn't mean you're going to be set free from jail.
It would be funny though if OpenAI gets to that data and steals it, sorry, trains on it first. Like, before Palantir or whatever else is out there.
On one hand, it protects against widespread warrant-less searches (stop and frisk, border patrol, etc). On the other, law enforcement can get access to the data before the statute of limitations runs out if they deem the case to be worth the resources (presumably with a warrant).
I'd rather have Three-Letter-Agency proof encryption everywhere.
It's difficult to imagine evidence of the sort of crime that evidence for it easily goes on an iPhone or other commercial device and is so heinous that it should override this concern I've described. And of those exceptions (someone conspiring in chat messages to murder for hire) that they happen so frequently that might be the excuse.
When the government demands that encryption be crippled, it seems that they aren't doing this to protect me from any crime I might care about myself... but that they are primarily concerned with crimes against the government itself.
Meanwhile biometrics provide stronger keys combined with convenience, but are more prone to abuse (forcibly pressing users finger to unlock during stop and frisk, etc). Security would be better served if device manufactures encouraged pins over biometrics, even though they can be brute forced, since they better protect against the most common abuses, and put a price on whether it is worthwhile to brute force.