Slashdot Mirror


Congressman: Court Order To Decrypt iPhone Has Far-Reaching Implications (dailydot.com)

Patrick O'Neill writes: Hours after Apple was ordered to help the FBI access the San Bernardino Shooters' iPhone, Rep. Ted Lieu (D-Calif.), a Stanford University computer-science graduate, wondered where the use of the All Writs Act—on which the magistrate judge based her ruling—might lead. "Can courts compel Facebook to provide analytics of who might be a criminal?" Lieu said in an email to the Daily Dot. "Or Google to give a list of names of people who searched for the term ISIS? At what point does this stop?"
Apple, so far, has vowed to fight the order that it decrypt the phone of San Bernadino shooter Syed Rizwan Farook, in no uncertain terms.

10 of 400 comments (clear)

  1. Re:Don't see the problem by Errol+backfiring · · Score: 4, Insightful

    And if you read the article, you see that Apple states that this is a backdoor.

    --
    Nae king! Nae laird! Nae yurrupiean pressedent! We willna be fooled again!
  2. Thanks Apple by Anonymous Coward · · Score: 5, Insightful

    I'm not an iPhone user but I appreciate you standing up for people's privacy. I have a better chance of winning the lottery than dieing at the hands of a terrorist. Why would I want to lose my privacy over those odds.

  3. Re:They aren't ordering Apple to decrypt it by bigpat · · Score: 4, Insightful

    This is the only good explanation I've seen of what the order is about:

    https://www.techdirt.com/artic...

    As long as Apple can install a signed update on the device without decrypting it first, this will be possible. They need to remedy that quickly.

    Yes, Apple has all along insisted that they can't break the encryption on the phone. But the FBI apparently knows they can and wants them to do it. That means there is already effectively a back door and they just need Apple to sign the software update. So Apple has been lying.

  4. Re:No uncertain terms? by TheCastro1689 · · Score: 4, Insightful

    You can't force a company to spend money and man hours making something that doesn't exist so that you can use their product they way you want to,

  5. Re:Shielding murderers and the accomplices by moronoxyd · · Score: 4, Insightful

    This isn't just about two terrorists.
    Once Apple complied and build the tools necessary, the tool can and will be used elsewhere.

    And what the LEOs don't understand or willfully ignore, is that if a backdoor exists, pretty much everybody can use it. If Apple creates this modified firmware for the US government, other governments around the world will demand access, too. And sooner or later, this firmware will get in the hand of non-government actors with criminal intend, too.

  6. Re:Unless Apple Lied by ugen · · Score: 5, Insightful

    It's a big deal because complying with *any* request to modify software for use of LEA now will mean that they (and other manufacturers) will have to comply with *all* requests to modify software in the future. In the eyes of the law there is no difference in what technical capability is being implemented, only that some sort of technical capability can be implemented at the direction of LEA. Once open, this door cannot be closed.

  7. Because politicians believe in magic... by gestalt_n_pepper · · Score: 4, Insightful

    There Is No Such Thing as Magic. If there is a known backdoor, it will be found and exploited. This can't be prevented, and honestly (Take not, politicians)...

    That means that the content on anyone's phone can be stolen. Not just anyone's phone, but the phone of every politician in the world.

    Be careful what you wish for.

    --
    Please do not read this sig. Thank you.
  8. Re:Unless Apple Lied by torkus · · Score: 4, Insightful

    And just to pound the point home, both are true:

    Once the legal door has been opened (it becomes OK to require companies build back doors)...
    Once the technical door has been opened (backdoor to firmware)...

    Open either door and there's no closing them. What's truly ironic is there was a huge uproar a year or so about backdoors in network gear coming out of china ... and now the US is literally asking for the same thing to be created for them.

    --
    You can get rich if you own a politician, but you have to be rich to buy one in the first place.
  9. What this (probably) means to you! by cfalcon · · Score: 4, Insightful

    The order implies that Apple is capable of delivering a remote update, or that forcing an update locally is possible if you have physical access. It also implies that portions of the security models are enforced by software that is vulnerable to "update", such as the wipe-after-ten-tries (presumably that code will be replaced with a no-op) and the code entry delay in excess of that which is enforced by hardware.

    Whether Apple is compelled to do this or not, the natural concern is "well how much of my data is shielded by math, how much by hardware, and how much by software"?

    You can't bargain with math, you have a devil of a time working out hardware, and software along is meaningless as a defense.

    It appears that your best bet for security is either:

    1)- A multi-character password that is easy to enter (and you'll remember it if its your phone password, lol), but reasonably short. This is if you trust that the 80ms hardware delay can't be broken. This precludes the use of 4 and 6 digit PINs, as a 4 digit PIN will usually fall after a few minutes of this treatment, and a 6 digit PIN after around half a day. An 8 digit password consisting of a completely random set of just the visible lowercase letters (aka, no actual english words) at this rate is hundreds of years, and adding stuff that's harder to enter quickly (capitals, numbers, special characters) makes it much more secure, as does lengthening the password slightly. The challenge here is that passwords are usually chosen to be words, greatly reducing the entropy. And again, this assumes that the 80ms hardware delay is not defeatable.

    2)- A fully secure crypto passhprase. This is the level of drama you would go through to password protect a drive or something you take very seriously, and as such it would be a lot more than 8 characters. Your passphrase is long, contains several unpredictable parts, and makes use of more than just a statistically predictable subset of words and characters. You can set this on the iphone, of course, but this kind of protection is not trivial to type in. In this case, you are trusting the math only, however, and assuming that the software will be compelled by the government, and the hardware will be owned by a team skilled in this matter.

    Going forward, Apple should probably move the "erase after 10 tries" into the secure portion of the phone, such that it has a protected portion that can't be overwritten without access to the PIN. This will also make them immune to this sort of order in the future.

  10. It's realy nice they're letting Apple fight it by HeckRuler · · Score: 4, Insightful

    I presume that some congressman pushed the FBI to make this request out in the open just for the purpose of fighting it in court. All in all it's a good thing. Defending civil rights and all that.

    But if the FBI ACTUALLY wanted this information they would have simply given Apple a gag order along with it. Or asked the NSA to do that for them. It's even their purpose, fighting terrorism, right? This falls SQUARELY under the domain of shit they've strong-armed and gagged companys into helping them with. The fact that we're even hearing about it has to be some sort of process manipulation.