Congressman: Court Order To Decrypt iPhone Has Far-Reaching Implications (dailydot.com)
Patrick O'Neill writes: Hours after Apple was ordered to help the FBI access the San Bernardino Shooters' iPhone, Rep. Ted Lieu (D-Calif.), a Stanford University computer-science graduate, wondered where the use of the All Writs Act—on which the magistrate judge based her ruling—might lead. "Can courts compel Facebook to provide analytics of who might be a criminal?" Lieu said in an email to the Daily Dot. "Or Google to give a list of names of people who searched for the term ISIS? At what point does this stop?"
Apple, so far, has vowed to fight the order that it decrypt the phone of San Bernadino shooter Syed Rizwan Farook, in no uncertain terms.
Apple, so far, has vowed to fight the order that it decrypt the phone of San Bernadino shooter Syed Rizwan Farook, in no uncertain terms.
And if you read the article, you see that Apple states that this is a backdoor.
Nae king! Nae laird! Nae yurrupiean pressedent! We willna be fooled again!
I'm not an iPhone user but I appreciate you standing up for people's privacy. I have a better chance of winning the lottery than dieing at the hands of a terrorist. Why would I want to lose my privacy over those odds.
This is the only good explanation I've seen of what the order is about:
https://www.techdirt.com/artic...
As long as Apple can install a signed update on the device without decrypting it first, this will be possible. They need to remedy that quickly.
Yes, Apple has all along insisted that they can't break the encryption on the phone. But the FBI apparently knows they can and wants them to do it. That means there is already effectively a back door and they just need Apple to sign the software update. So Apple has been lying.
If I read Apple's "customer letter" correctly, they very well have the ability to create the software that is demanded of them, and decrypt that phone. Whether that software already exists or not is immaterial. If it is possible to create the software and use it on existing devices, then for all intents and purposes the backdoor is already there. Apple just doesn't want to open it, because they rightly fear losing the trust of their customers - trust which, following this interpretation, is unfounded.
This isn't just about two terrorists.
Once Apple complied and build the tools necessary, the tool can and will be used elsewhere.
And what the LEOs don't understand or willfully ignore, is that if a backdoor exists, pretty much everybody can use it. If Apple creates this modified firmware for the US government, other governments around the world will demand access, too. And sooner or later, this firmware will get in the hand of non-government actors with criminal intend, too.
It's a big deal because complying with *any* request to modify software for use of LEA now will mean that they (and other manufacturers) will have to comply with *all* requests to modify software in the future. In the eyes of the law there is no difference in what technical capability is being implemented, only that some sort of technical capability can be implemented at the direction of LEA. Once open, this door cannot be closed.
There Is No Such Thing as Magic. If there is a known backdoor, it will be found and exploited. This can't be prevented, and honestly (Take not, politicians)...
That means that the content on anyone's phone can be stolen. Not just anyone's phone, but the phone of every politician in the world.
Be careful what you wish for.
Please do not read this sig. Thank you.
And just to pound the point home, both are true:
Once the legal door has been opened (it becomes OK to require companies build back doors)...
Once the technical door has been opened (backdoor to firmware)...
Open either door and there's no closing them. What's truly ironic is there was a huge uproar a year or so about backdoors in network gear coming out of china ... and now the US is literally asking for the same thing to be created for them.
You can get rich if you own a politician, but you have to be rich to buy one in the first place.
You joke, but many people there are actually saying things like this. I see comments calling for Tim Cook to be charged with treason, saying Apple shouldn't be able to do business in the U.S., etc.
To be fair, you see these same exact comments on Slashdot; just for different reasons.
the correct action would be to cooperate fully right now, and patch the back door. That way current case proceeds, and future similar situations are not feasible because the backdoor doesn't exist.
they'll have to open up a very public case "forcing" Apple to put in a back door, where apple would have a lot firmer leg to stand on as opposed to not cooperating with this investigation.
The problem is the FBI then have this version of iOS with stripped out security that they can then theoretically install on any iphone they want to grab all the data. They say it will only be used this one time for this one thing but if you believe that there's a lovely bridge I have for sale.
Wanna buy a shirt?
https://www.redbubble.com/people/stealthfinger/shop?asc=u
The order implies that Apple is capable of delivering a remote update, or that forcing an update locally is possible if you have physical access. It also implies that portions of the security models are enforced by software that is vulnerable to "update", such as the wipe-after-ten-tries (presumably that code will be replaced with a no-op) and the code entry delay in excess of that which is enforced by hardware.
Whether Apple is compelled to do this or not, the natural concern is "well how much of my data is shielded by math, how much by hardware, and how much by software"?
You can't bargain with math, you have a devil of a time working out hardware, and software along is meaningless as a defense.
It appears that your best bet for security is either:
1)- A multi-character password that is easy to enter (and you'll remember it if its your phone password, lol), but reasonably short. This is if you trust that the 80ms hardware delay can't be broken. This precludes the use of 4 and 6 digit PINs, as a 4 digit PIN will usually fall after a few minutes of this treatment, and a 6 digit PIN after around half a day. An 8 digit password consisting of a completely random set of just the visible lowercase letters (aka, no actual english words) at this rate is hundreds of years, and adding stuff that's harder to enter quickly (capitals, numbers, special characters) makes it much more secure, as does lengthening the password slightly. The challenge here is that passwords are usually chosen to be words, greatly reducing the entropy. And again, this assumes that the 80ms hardware delay is not defeatable.
2)- A fully secure crypto passhprase. This is the level of drama you would go through to password protect a drive or something you take very seriously, and as such it would be a lot more than 8 characters. Your passphrase is long, contains several unpredictable parts, and makes use of more than just a statistically predictable subset of words and characters. You can set this on the iphone, of course, but this kind of protection is not trivial to type in. In this case, you are trusting the math only, however, and assuming that the software will be compelled by the government, and the hardware will be owned by a team skilled in this matter.
Going forward, Apple should probably move the "erase after 10 tries" into the secure portion of the phone, such that it has a protected portion that can't be overwritten without access to the PIN. This will also make them immune to this sort of order in the future.
And, the US (and US made products) will irrevocably cease to be trustworthy.
Once the US does this, everyone in the world MUST assume these companies have built this in, that the US government can access it, and that Apple will be forced to roll over for any other government.
I'm not sure people understand just how much of a global clusterfuck of undermining rights and freedoms the US is doing here -- it's time to stop pretending to be champions of freedom and liberty when you have actively decided to do the opposite.
If Apple caves on this, every piss-pot dictator will insist on the same access.
What the FBI is demanding is full Big Brother status.
Lost at C:>. Found at C.
I presume that some congressman pushed the FBI to make this request out in the open just for the purpose of fighting it in court. All in all it's a good thing. Defending civil rights and all that.
But if the FBI ACTUALLY wanted this information they would have simply given Apple a gag order along with it. Or asked the NSA to do that for them. It's even their purpose, fighting terrorism, right? This falls SQUARELY under the domain of shit they've strong-armed and gagged companys into helping them with. The fact that we're even hearing about it has to be some sort of process manipulation.