Apple Says It Has Never Worked With NSA To Create iPhone Backdoors
techcrunch.com
techcrunch.com
Instead they should have released a PR statement like so:
"Apple's is unaware of any help it has provided the NSA in creating iPhone backdoors, but due to the presence of National Security Letters that would gag us if we had, we can neither confirm nor deny whether we have helped the NSA. If we have, no one in the company but those that aided the NSA would know. We urge the citizens of this country to challenge the constitutionality of NSLs so that we may be able to confirm whether or not we have aided in the creation of iPhone backdoors."
That's the only truthful statement that could be uttered at this point.
So are you suggesting they've received a NSL letter about nothing in particular forcing them to lie in this instance?
So whatever their true status is, it cannot be judged from their own statements, as long as we assume that nobody at Apple gives two shits enough to stick their neck out and risk incarceration for violating a NSL.
moron4hire seems to believe that they would force them to keep the statement (and thus lie), but I'm going to need a source on that.
Apple almost certainly has received many NSLs, which is why they can only disclose "1000-2000 account information requests" for the first half of 2013 in their transparency report. That number combines law enforcement and national security order requests in order to keep vague the exact number of the latter. If you take a look at that transparency report[1], you can see they come as close as you can to confirming that they have received NSLs when (so far) you can of course not confirm that you've ever received NSLs.
[1] https://www.apple.com/pr/pdf/131105reportongovinforequests3....
>The section carries a gag order stating that "No person shall disclose to any other person (other than those persons necessary to produce the tangible things under this section) that the Federal Bureau of Investigation has sought or obtained tangible things under this section"
A NSL is not a catch-all. It can only compel disclosure of metadata, aka non-content data, aka pretty much what's covered under Smith v Maryland (third party doctrine and all that). That alone is damaging, of course: when the police were getting phone number records in 1976, technology was very different from say, the ability to track your every movement just from the IDs of the cell phone towers that your phone connects to as you move around your city.
However, a NSL cannot compel someone to write a backdoor into a program, or force you to hand over your private encryption keys, or even hand over the content of a single email. There are many other legal approaches to these other things (like a real court order from a judge), and there is a decent chance that a company is completely spineless and rolls over for the government without any need for the request to be legal (a la AT&T and room 641A), but those approaches have nothing to do with National Security Letters.
I wish people would learn a little bit about this before thinking they know a lot about this...
Everything I've seen about NSLs says that they allow the government to compel production of (some) information about an individual or group if they say it's part of a national security investigation. As I understand it, the big objection to NSLs from groups like the EFF and ACLU is that they're outside the normal system of court order and subpoenas, lack enough restrictions on when they can be used and have the gag order provision...not that they give the government power to ask companies to do whatever they want.
"Apple has never worked with the NSA to create a backdoor in any of our products, including iPhone. Additionally, we have been unaware of this alleged NSA program targeting our products. We care deeply about our customers’ privacy and security. Our team is continuously working to make our products even more secure, and we make it easy for customers to keep their software up to date with the latest advancements. Whenever we hear about attempts to undermine Apple’s industry-leading security, we thoroughly investigate and take appropriate steps to protect our customers. We will continue to use our resources to stay ahead of malicious hackers and defend our customers from security attacks, regardless of who’s behind them."
Not that it will convince anyone around here, but at least they can be called liars if any evidence did turn up.
The document also doesn't claim this success remotely (only "A remote installation capability will be pursued for a future release", which really gives no clue as to how possible that was or is). We've always known that pretty much any mobile device can be vulnerable with physical access (that's what "jailbreaking" you phone is doing).
For example, iPhone 3GS released in 2009 can be jailbroken with 2010-era latest iOS 4: http://www.iclarified.com/jailbreak/iphone3gs/mac.php?firmwa...
I don't think you even need baseband access to do all the spying. I think all of that can be done on a jailbreak.
Not saying that they necessarily are. Based on what I've read about the NSA I think it's very plausible that the NSA both has a backdoor from Apple, one from the baseband software (http://www.osnews.com/story/27416/The_second_operating_syste...), as well as a several hacks they've developed on their own. Their strategy is not a single path but rather as many attack vectors as possible.
Apple most likely wouldn't work directly with the NSA but with an entity like the FBI. The contract wouldn't be with the FBI but with a company also contracted out to do some of the work like Booz Allen Hamilton.
I'm started to wonder who "we" actually means in these responses as well. Is this the stock-holder we, the CEO we, or we as in employees of Apple as a whole. I suspect it is not the latter one.
We still don't know the point of entry for this malware and I have no more reason to suspect it is done by the shipping carriers than I have reason suspect the hardware makers themselves.
Many believed that Google was doing the NSA's bidding. Many others felt that only the polar opposite could be true: That Google rejected the NSA's pleas and thus the data couldn't be seen.
It seems to have turned out that fact was somewhere in between -- Google was an involuntary partner, but the NSA could monitor virtually all of their data via the data center to data center links.
The same thing could be happening at Apple (or any business): They have all the best intentions in the world and want to build the most secure product they can, but there is a extrajudicial foe that answers to essentially no one.
Of course this is all talking about Google as a corporation voluntarily doing something. Was someone in Google (or Apple or any other company) working on behalf of the NSA? There was early debates about whether that could even be legal, but at this point it seems that "anything goes" is the pattern, so possibly.
It's sorta telling to me that Google decided to go encryption on all intra-data after Snowden. No doubt they would have been briefed by agencies that they cooperate with about what the exposures would be.
It's more likely that whatever chipsets common across smartphones or routers is the point of exploit. So the NSA and Samsung or whomever have to have a private agreement. Apple/Google don't have a need to know, but you think a few engineers might be curious.
WIGGLE ROOM ALERT: Apple might have worked with government contractors, just not the NSA directly.
"Additionally, we have been unaware of this alleged NSA program targeting our products. We care deeply about our customers’ privacy and security."
WIGGLE ROOM ALERT: They could very well be unaware of this program -- but aware of another program that hasn't been disclosed yet.
For more on sneaky talk, read this fantastic Atlantic piece that dissects deliberately misleading statements by NSA officials: http://www.theatlantic.com/politics/archive/2013/12/how-amer...
One key strategy they've had: they consistently deny specific programs, as opposed to general actions.
The NSA exploited a bug in the iPhone in the same way that the jailbreak community has been doing since the iPhone came out in 2007. The only difference is that the NSA installed malware where as the jailbreak apps install Cydia.
Remember jailbreakme.com? That is a browser based root vulnerability. Find an exploit in the iPhone's mail, sms, browser, or any other app, and you could too install malware. Of course this is not easy with the security of the iPhone, but with NSA like resources there is no such thing as bulletproof security.
Either way, quite the implication if the claims are authentic.
Plausible deniability can be an effective tool for a company too. It's certainly possible that Apple team members were indeed collaborating with the NSA (or FBI or some contractor equivalent) or that the NSA had access to Apple tech without the leadership aware of the specifics or even without any official corporate authorization/mandate in the first place.
Pretty sure it is January.
My money is on January.
Oila: a few million remote installations. (EDIT: .. on known-subversive phones. Only subversive types jailbreak.)
The only way to keep spy agencies out is to made data inaccessible to everyone.
Edit: HN's on-top guidelines "On-Topic: Anything that good hackers would find interesting. That includes more than hacking and startups. If you had to reduce it to a sentence, the answer might be: anything that gratifies one's intellectual curiosity."
Seriously, I would like to understand why you think this isn't HN appropriate.
The original story would have been on the front page in minutes, with dozens of comments.
In a word ... validation.