Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On a technical level I really don't understand something about this situation. All the discussion I see presupposes that the only option for Apple to comply with the FBI is to build & sign this new version of iOS, and then give it to the government, who will distribute it internally to unlock hundreds of phones held as evidence in local court cases across the country, at which point it may or may not (but probably will) be stolen.

It seems like there's another possibility, where Apple takes the phone, signs the compromised version of iOS on an air-gapped computer deep in Cupertino somewhere, decrypts the phone, sends the decrypted hard drive image to the FBI, and then erases the signed version of the software. Why would this process have any higher risk of being compromised than Apple's normal release process for signing new iOS versions?

I get the reason this case matters at a more fundamental level, the precedent it sets and whether or not the government can force Apple to spy on its customers. But there's been so much focus on the technical feasibility of it, and it seems like Apple is exaggerating the argument that it's absolutely impossible to build this new iOS version without it being hacked.



> Why would this process have any higher risk of being compromised than Apple's normal release process for signing new iOS versions?

It wouldn't. In fact, since every iOS restore contacts an Apple server to re-sign the firmware with a device-specific chip ID and unique nonce[1], all Apple would have to do is configure the signing server to sign the government firmware only for approved ECIDs (which might require some engineering effort to ensure that the internal process for adding images/ECIDs is secure and well-documented, but nothing unreasonable). Because the signing server is already connected to the Internet rather than, say, airgapped and brought out only when a new firmware needs to be signed, signing additional/alternate images wouldn't increase the risk of key compromise.

I support Apple's moral stance but hell if the "hacker risk" part of their argument isn't bullshit.

[1] https://en.wikipedia.org/wiki/SHSH_blob


Every DA and police department will show up with a stack of phones after the first unlock. Apple would now be responsible for decrypting phones day and night. This has already happened with a department in NYC that wants 100+ iPhones unlocked.


> and then erases the signed version of the software.

And the entire development tree? The local repos on the computer of every engineer that touches it?

You realize that even nuclear secrets get stolen, right? Even the NSA's dirty laundry got aired in public. No serious product remains in the dark forever.


All of which are useless if you don't have Apple's signing key.

The code to ignore the lockout is quite possibly a 1 line fix.

This case wouldn't be needed were that not the case, since otherwise it would be almost trivial to dump an iPhone's firmware image and hex edit the relevant code out.


The FBI don't want the data on the phone, it has nothing of value, it's a consent-to-monitor work phone the FBI already has 6 weeks iCloud backups of, that wasn't at the scene of the crime and Farook didn't attempt to destroy, unlike his personal phone which was both at the scene and destroyed.

The FBI didn't ask for the data because they don't want it, they're after the legal precedent that compels any Technology's own company resources against them to compromise the security of their own products so they can use it to compel the hundreds of other phones they have in their possession that they also want unlocked.

Despite having no chance of producing anything meaningful, the FBI chose this tragedy to break character and go Public on because they're using the tragedy for maximimum PR and Political effect to increase their surveillance powers - frankly I find it dispicable that a law enforcement agency is so transparent, egregious and has stooped to such lows to make be making personal statements against Apple they know to be completely false so they can enrich their political agenda.


I'll take this a step further. Ultimately Director James Comey and the FBI want a future where it is illegal or impractical to deploy strong encryption without key escrow.

Few companies, actually practically no one, will offer encryption if it's going to cost them tremendous amounts of money and engineer time to hack each and every device on a piecemeal basis. The siren call of key escrow or an alternate decryption key that they maintain will be irresistible. Or the industry will move back in the direction of unencrypted devices, which would be just fine by the FBI.

EDIT TO ADD - I've expanded my thoughts on this into a post on by blog https://rietta.com/blog/2016/03/16/its-not-just-one-iphone/


This is the smartest, most well consider comment on this whole topic, and I'm sorry to say you're likely to be down voted into oblivion :)


Not really. Consider this - right now a key part of the discussion is whether compelling Apple to write this software is an undue burden. Most reasonable people would agree that it would take quite some effort. However, if Apple did it once for the terrorist's phone (which no one objects to) then every subsequent request would have minimal burden attached to it. Thus they would have to comply to any subsequent request to unlock, even if the phone didn't belong to a terrorist. What if it only belonged to a whistleblower or humans rights activist? Too bad, minimal burden.

If it becomes common enough, Congress wouldn't face much opposition if they passed a law saying that the status quo (on demand unlocking) be maintained by smartphone manufacturers.

I suggest you actually read up on the filings from both sides before talking so much.


(Trying hard not to take the bait at the end)

But, by fighting this case on the all writs, they're basically staking their whole position on: "the govt can't compel a private firm to work on their behalf". If that wins, then what's to stop the govt requesting master keys for iOS? Much less work, bypasses all writs.

My point is: the FBI did this by the book (court order). You and most everyone else here makes the assumption that granting this means the FBI can do whatever the hell they like from there on in. That's not true. They would still need court orders.


It is about the future of encryption. If the FBI wins and gets Apple to unlock the phone, will Apple be held in contempt later when they make a phone that they makes them unable to comply with a court order?


Clearly not. It does raise the issue of whether you think this would be a good thing for Apple to do. I have not made up my mind on that topic.


De jure, you're right; de facto, we're fucked.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: