Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For me, the most interesting question I would have is absent from the article.

The court is basically ordering Apple to produce new firmware that doesn't block brute forcing. If Apple were to comply, who keeps this firmware after the fact?

There's no mention of this at all, but if the firmware image stays with the FBI then the implications are much more profound with regard to privacy.



They specify that the FW will be locked to the unique device's ID, so it won't be usable on any other one.

But once it's established that it can be required from Apple, Apple has to comply, and Apple effectively does comply, other judges in other cases will be able to request other FW, hard-coded against other IDs, as needed.

The middle-term solution to this is for Apple's security team to protect against this threat model, and implement encryption in such a way that _they_ can't bypass it under constraint. I'm not an Apple customer and I don't follow their products closely, but I understand that iPhones 6 already are harder to bypass than iPhones 5.


I would bet you all the money in the world that the very second such a firmware image was provided to the FBI it would find its way to the CIA/NSA. All with the assumption of course that the FBI has no rogue agents who work for foreign governments or criminal organisations.

Apple is right to be terrified at the thought of being asked to make such a firmware image.


Exactly this! Once it's in existence somewhere it's immediately part of the NSA/CIA/FBI basic iPhone toolkit.


>The SIF will be coded by Apple with a unique identifier of the phone so that the SIF would only load and execute on the SUBJECT DEVICE.

If I understand the cited order correctly the firmware is ordered to be constructed in a way that it runs only on the target phone.


I do wonder though that had Apple not predicted this exact scenario ahead of time (likely), how would they control this?

It's unlikely they can rely on hardware protections to provide this device locking, so is it the case that they would build the unique identifier into the image.

Optimistically some obfuscation could help but are the FBI/CIA/NSA really more than a few hops away from opening the binary image in a hex editor and changing it by hand?

If Apple firmware images for the iPhone are signed per-device then fine, but is that the case?

I don't know this but it seems unlikely to me that a custom device-signed build of iOS happens for every iDevice, and if that's not the case, I can't see how Apple can reliably restrict this with confidence.


I agree with you that this will be difficult or maybe impossible to implement. However the court has foreseen the upthread argument as the order shows.

As many here I believe that once this backdoor exists it will be somehow exploited (at the very least by further orders).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: