Senator asks if FBI can get iPhone 5S fingerprint data via Patriot Act
arstechnica.com
arstechnica.com
As opposed to, you know, getting government to stop abusing its power.
Half of his questions are "what's Apple's legal interpretation of our abusive laws?" It doesn't really matter what Apple's interpretation is. What matters is the secret court's secret decisions about what those laws mean. It's good that Franken voted against renewing the Patriot act, but he should be sending this letter to his colleagues that voted for it, not Apple.
And, for the record, I'm very interested to know what Apple's interpretation of the law is, because that could be what informs the design of their products.
Only 3 of the 12 questions mention domestic spying laws. 1 question refers to "any government". Every single question seems legitimate to me. I can't understand why anyone concerned with privacy would be against asking Apple to answer these questions.
Your concern appears to be fixated on the "far left" and government spying. I can understand that concern, but I think the role of private corporations handling personal data should not be ignored.
Lastly, I'd like to point out that the far left and Al Franken likely did not author the laws referenced. Neither do the far left and Al Franken have the power to change these laws without support of moderates, Republicans, and the American public. Franken is pointing out, in a very open and public way, how these laws could be used to abuse TouchId. If nothing else it shines a much needed light on the relationship of spying laws to private corporations.
Because a government with the power to do that can and most likely will use that power to do things that aren't good for anyone but themselves and their stakeholders.
Not trusting the government with regards to privacy is understandable; trusting corporations to do the right thing for anyone but their shareholders is not.
So what I would like, is that after Apple comes out with the details, the question gets asked to the government. That would ensure that the government does behave according to the intent of Congress.
Second, how do you know Franken isn't sending letters to his colleagues? Just because you're losing on one front doesn't mean you shouldn't try to fight on another.
Plus, even if you curtail what the FBI can get, there will be circumstances when they legally should and will be allowed to get data from a business on an individual(e.g. with a subpoena/warrant). As such it makes since to make verify Apple's assertion that they can't hand over anything.
Finally, he's not just asking about the government, he is asking about any third party.
We can decide that since we can't stop the powerful from lying, we won't hand them the tools to further incentivize that lying.
It's perfectly reasonable for a polity to decide that no member should build land-mines, even if the most blame lies with the users of land-mines. This is not a public / private, left / right issue.
The letter to Apple came from his role as the Chairman of the Judiciary Subcommittee on Privacy, Technology and the Law. That committee was created to advocate for consumer privacy, which is probably as important as privacy from the government. How many lives could Google ruin with all of the personal information they have on hand? How many companies have your credit card and social security number on some poorly secured server?
As for broader government abuse, Franken introduced a bill to mandate the NSA to reveal the extent of their surveillance, which is supported by just about every privacy-focused organization in the country (ACLU, EFF, HRW, etc.). While he's not as strong of a critic as Merkley or others, pushing things in the right direction is worth supporting.
Given the privacy concerns that have been news lately, it's understandable that this would raise some eyebrows, but when combined with something like the iCloud keychain for generating strong online passwords, this could actually be a great benefit to individual privacy.
I.E. hash( hash(fingerprint) + stored key ) = actual password.
Fingerprints are obviously incredibly insecure. They're obviously identifiable. How is this news?
Fingerprint readers on phones are like locks on doors -- they deter casual people, but are totally worthless against anyone determined. But still pretty useful for their convenience in most situations.
Fingerprint readers on phones are for preventing your mother or your girlfriend or your son or your coworker from getting into your phone. And nothing more. It does zilch against police/government/espionage/etc. But it was never supposed to, any more than your front lock is supposed to keep a SWAT team out.
http://www.h-online.com/newsticker/news/item/CCC-publishes-f...
It's also possible that it may not be a "password" in the conventional sense. Maybe the fingerprint only serves as part of the private key of a public/private key pair where only the public key is stored on the device itself and the private key must be generated each time with a scan of the finger.
This is all speculation, of course.
I suppose that is why we have people asking the questions.
Read up on more details and critique about TouchID: http://arstechnica.com/security/2013/09/fingerprints-as-pass...
It's important to note the scanner isn't an imaging sensor (I.E. camera) so touch and skin conductivity are still fair game.
3D printers could provide that system as long as they are precise enough to print fingerprints at scale.
re-create some super VIP's prints and plant them in undesirable places they obviously did not go to; then publicize it. Render the whole 'fingerprint as an identifier' thing with uncertainty and doubt.
I believe Objet/Stratsys still have the highest resolution printers at 16 micron layers and 30 micron-width droplets.
A quick google search says the papillary ridges of a fingerprint could be safely assumed at between .020 and 2.0mm in height[1]; that might be printable now.
Fun thought, anyway.
Passwords are often static, shared, and relatively easy to crack.
It's like using your SIN as a secret.
I don't understand the big concern over this fingerprint sensor. I get the idea of some concern on a theoretical level, but compared to the rest of any smartphone's ready-made spying functions, like the ability to see where you are at any point in the day, the ability to record or even transmit live every conversation you have, the ability to steal every password you enter into the device, etc. etc., fingerprint theft seems completely unimportant. So far, I've yet to get a satisfactory answer to just what bad things would happen if the NSA was, in fact stealing everyone's iPhone fingerprint data. I'd rather they not, but it's minor compared to everything else that's going on.
So that would mean that even if someone stole your print (say the stored hash), it wouldn't work without the iPhone. At that point, in order to attack someone's AppStore account with a fingerprint, it becomes 2-factor security... and that "something to have" token can be revoked by remote wipe.
Did anybody think of using toes yet?
"The Touch ID-enabled home button feels invisible; it works with a tap, can recognize your finger from many angles, and feels like it has less of a fail rate than fingerprint sensors I've used on laptops. It's impressive tech. It worked on all my fingers, and even my toe (I was curious)."