7 ms·
"During his testimony today, Comey dismissed the notion that Apple’s assistance in the San Bernardino case would impact other phones, reiterating his belief tha
by Zizzle 11y ago
"During his testimony today, Comey dismissed the notion that Apple’s assistance in the San Bernardino case would impact other phones, reiterating his belief that any code Apple created to help in this case would only work on Farook’s phone."
And that belief is based on what exactly?
Apple has being saying the opposite. Apple doesn't know it's own code? FBI knows it better.
- jonlucc 11y agoIt's true, but very narrow, I think. FBI means that Apple could sign the update to only work on that phone. Apple means that once the compromised version of the OS is built, the only thing stopping it from being widespread is changing the device id check code to other phones or taking it out entirely.
- fidget 11y agoOnce you've changed the device id check code, you'd still need to sign it again if you wanted to distribute it widely
- theoh 11y agoIs it possible to change a phone's device id to match the initial target, though?
- KMag 11y agoI believe the FBI is suggesting that Apple tie the update to the phone's IMEI, which I believe phone thieves routinely change by desoldering and replacing a chip.
- ryanlol 11y agoApple firmware updates are signed on a per-install basis.
- ryanlol 11y agoNot sure why this got downvoted, I'm not too familiar with iOS but AFAIK this is exactly how the SHSH system works with the modern iPhones. Quick googling seems to support this.
- KMag 11y agoI didn't downvote you, but I think you're being downvoted because the information content isn't much more than "but cryptography something something!" I mentioned that the most common method for uniquely identifying a handset (the IMEI) can be changed by switching a chip on the iPhone's main board. (At least this was true 6 years ago.) So, unless Apple uses an interactive signature scheme or prevents the FBI/intelligence agencies from ever seeing the signature (using TLS with hard-coded certs), then the signature can be replayed. If the signature can be replayed, then in order to prevent FBiOS being used on multiple phones, it must be tied to one or more unique identifiers, probably excluding the IMEI. Many people understood my post as shorthand for the above. Responding to this with "[But] Apple firmware updates are signed on a per-install basis." doesn't add to the conversation unless you provide further details. At least, that's my best guess as to why you've been downvoted.
- ryanlol 11y ago>I mentioned that the most common method for uniquely identifying a handset (the IMEI) can be changed by switching a chip on the iPhone's main board. (At least this was true 6 years ago.) https://www.theiphonewiki.com/wiki/ECID https://www.theiphonewiki.com/wiki/ECID Firmware updates use this, not IMEIs. And I think the IMEI is more commonly used to identify the radio, not the device itself. But I could be wrong about that. >So, unless Apple uses an interactive signature scheme or prevents the FBI/intelligence agencies from ever seeing the signature (using TLS with hard-coded certs), then the signature can be replayed. Every time you update an iPhone it generates a nonce, called APTicket. Apple signs that, your ECID and the firmware. The nonce essentially makes replay attacks impossible, even if you managed to swap a devices ECID.
- 11y ago
- jonlucc 11y agoYes, but that is not nearly the same burden as actually writing the compromised OS. It's probably as easy to compel them to sign the update as it is to compel them to turn over iCloud data.
- marssaxman 11y agoSure, but once the FBI has forced Apple to write the code, forcing them to update the device ID and sign the new build is trivial by comparison, which means that breaking into any random iPhone will become routine.
- kenshaw 11y agoThey could easily request the device signing keys via a different case or again using the all-writs act stating that it's necessary for whatever. Not turning over the encryption/signing keys would be followed up with jail time / contempt of court charges for any officers/developers/etc refusing to remand the keys into federal custody.
- tfinniga 11y agoRight. If you look at it from a security point of view, once the compromised OS is created you've created a much more valuable and vulnerable target for hacking. Let's say that some attacker wants to create a compromised OS and install it on a certain device. If apple never creates the compromised OS, they would need to hack into apple, get all of the source code necessary to build iOS, figure out how to build it, figure out how to modify it in the desired ways, how to get it installed on a phone, steal the crypto keys necessary to do the signing, and sign the bad build. If apple has created the compromised OS, they would just need to hack into apple and get the compromised OS build, steal the crypto keys, and sign it. The first scenario is a large-scale software engineering project. Anyone that's been given a large source dump will tell you that it's horrible and takes forever to do anything, and iOS is going to be absolutely huge and tricky. You'd need a large, highly trained team of security/OS devs, which is hard to come by and would be extremely expensive. The second scenario could conceivably be done by a single hacker, if they can find vulnerabilities in apple's security.
- CydeWeys 11y agoApple also has a huge firewall (in the figurative sense) right now in that it is a large amount of effort for them to create this new security-relaxed version of the OS, and the government can't be compelled to force them to produce it. Now, let's say that they have written it for some reason, but it is restricted to a single device id. Well, it's now a lot easier for the government to compel Apple to hack another phone, because they can creditably argue that all Apple has to do is change some string constant and re-sign the package. The burden of work is now much, much less than if the tool itself doesn't already exist. Apple doesn't want to ever create the tool. If they have to create it for any reason, even if it starts out being locked to a single device id, they've lost the war.
- rtpg 11y agoExcept digital signing makes the compromised OS totally and utterly useless for other phones. Changing the OS would cause the signature check to fail. And if you can get around the digital signage, you don't need the compromised OS. Conway's technical interpretation of the Apple deliverables is right. There's a legal precedent which could cause reuse (and is rightly matter for debate/utter refusal of the FBI position), but if you just debate the technical merits Apple has been very misleading about the consequences.
- Synaesthesia 11y agoBut what it's really about is the legal precedent it would set, allowing the government to force companies to unlock devices for them.
- ethbro 11y agoIt's not the unlocking that's the precedent. It's the door into "modify your source code in such and such a way." Come to think of it, why aren't free market standard bearers rallying against this as government intrusion into market features?
- Synaesthesia 11y agoCorrect. That's what I should have written.
- strasser 11y ago"why aren't free market standard bearers rallying against this" because it has nothing to do with the "free market".
- 13years 11y agoThe answer is they are and this is somewhat a litmus test for who stands behind free markets and those who don't despite what they often claim. Example from organization supporting free markets. http://fee.org/articles/apple-defies-fbi/ http://fee.org/articles/apple-defies-fbi/ And then there is no shortage of examples from the presidential candidates who claim to support free markets, yet none are standing behind Apple.
- kenshaw 11y agoBecause it isn't politically expedient for them to do so, as Apple is very very successful, and as such, most people (voters in this case) who are uninformed love the theater and cheap political pot shots lobbed at Apple. It's clear that there is no discussion at a national nor international level of the actual implications of what this means for not just Apple, but indeed for the American economy and software built in the US. For instance, do you really think Microsoft will be able to sell Office software to the Netherlands Government if the DOJ/NSA/whoever can use the All-Writs Act to force Microsoft to implement a backdoor into their software? Would the NSA be able to use the AWA in conjunction with a NSL and a secret court to force the hand of companies? Politicians / the public don't really grasp what's at stake here. What we're really talking about creating a complete and real artificial handicap for all software companies located/based out of the US. Already there is pushback in China, Europe and Australia to ditch American-made software after the Snowden revelations. A ruling in favor of the FBI will only compound and accelerate this issue and will have a marked and measurable effect on the revenues of software and hardware companies located in the US. While Google/Apple/Facebook/Microsoft/Cisco et al may not be able to relocate, this will definitely cause small and medium sized firms to relocate or possibly to never incorporate within the US to begin with. This may be effectively and preemptively scaring away the next Google. Law of unintended consequences and all that.
- orionblastar 11y agoYes someone can modify the OS image to take out the check for phone ID and then it can work on any phone. Also the FBI would want to use it on other phones as well. They might modify it themselves to work with other phones.
- return0 11y agoApple releases updates for their phones often. They could engineer a hack that can then be patched by new versions of iOS.
- cbsmith 11y agoThere is nothing in the digital signature check that allows it to be locked to a device, so that's logic that has to kick in AFTER the trusted layer has validated the code. At that point, it is a simple matter of altering the device ID check in unsecured RAM and you've now got another cracked phone.
- xerxe-sans-s 11y agoSo would a signature check on the trusted layer against a signature generated with the device id (you'd need to distribute a different binary against every device id) permit the generation of an OS image that could only run on a single device?
- cbsmith 11y agoIt would, in theory. If there weren't any catches with this approach though... Apple could have avoided having itself in this position in the first place.
- pilif 11y agoActually, I would argue that this is not true. Before installing, the device wants a ticket to be signed by apple that contains a hash of the firmware to be installed, the phone's identifier and a nonce it has just generated. See here: https://www.theiphonewiki.com/wiki/SHSH https://www.theiphonewiki.com/wiki/SHSH So by not signing any requests for that particular firmware hash, Apple can effectively neuter that firmware and make sure it's never installed anywhere but on the target phone. The problem is though: If apple can be compelled to do this once, they can also be compelled to do this any other time.
- cbsmith 11y agoThat's not part of the boot chain. That's for OTA updates.
- grey-area 11y agoEven worse than that, the precedent will be set that government agencies can ask any tech company to subvert their own security. So TVs, phones, echoes, webcams, computers, analytics.js could all legally be modified to become surveillance devices, and if doing one, why not do them all?
- camillomiller 11y agoMy question is: why hasn't the fbi gone after a smaller player to set this kind of precedent? One that wouldn't have had the huge legal resources to oppose the request that Apple has. I think what's coming out of this is that the Fbi is riddled with incompetence and inability to face modern threats, plus a silly hybris that is the foundation for silly strategical mistakes.
- chopin 11y agoPresumably because smaller players don't have such elaborate security. Those can always argue that the government should use one of the well-known exploits. I also could imagine that Apple would aid such a case anyways.
- occamrazor 11y agoMoreover, once the compromised OS is created, Apple will be compelled to unlock iPhones in every country where it does business, including countries like China and Russia.
- tlrobinson 11y agoApple is talking about source code, the FBI is talking about a signed binary. I'm fairly certain Apple has the technical ability to create a signed binary that only executes on a single phone.
- HillRat 11y agoMore importantly, once "GovtOS" (as Apple's filing calls it) is developed -- even if the government is billed $800K for the privilege -- each subsequent writ will be much less expensive to fulfill, creating a tidal wave of LEO requests to unlock phones. So Apple wants to head this off right now, because otherwise the floodgates will open.
- AnkhMorporkian 11y agoNot necessarily. Apple could simply delete all code modified to make that change, necessitating a similar amount of work for each phone unlocked.
- adventured 11y agoApple has said that for legal reasons, it may be forced to keep the code permanently and will have to secure it permanently out of concern for future legal/court obligations specific to this case.
- jonlucc 11y agoI'm sure defense counsel would want to be able to verify that it isn't modifying file access times, or deleting data, or planting data, or otherwise disturbing evidence when the update is put in.
- rplst8 11y agoIn support of this, someone forwarded me a very interesting article written by someone who creates forensic software for a living. The legal requirements surrounding the creation of a software tool for forensic purposes, which this proposed effort requested by the government might fall under, are nothing less than herculean in scope. http://www.zdziarski.com/blog/?p=5645 http://www.zdziarski.com/blog/?p=5645
- acqq 11y ago> Comey dismissed the notion Seems just for a moment, because, via Reuters: http://www.reuters.com/article/us-apple-encryption-congress-idUSKCN0W33G7 http://www.reuters.com/article/us-apple-encryption-congress-... "FBI Director James Comey told a congressional panel on Tuesday that a final court ruling forcing Apple Inc (AAPL.O) to give the FBI data from an iPhone used by one of the San Bernardino shooters would be “potentially precedential” in other cases where the agency might request similar cooperation from technology companies." "Manhattan District Attorney Cyrus Vance testified in support of the FBI on Tuesday, arguing that default device encryption "severely harms" criminal prosecutions at the state level, including in cases in his district involving at least 175 iPhones."
- jotux 11y agoComey in testimony today: "Whatever the judge's decision is in California ... will be instructive for other courts, and there may well be other cases that involve the same kind of phone and the same operating system" It's a little strange for him to dismiss the notion that this will set a precedent because it will just be for one phone and then imply that this case will set a precedent for other phones.
- acqq 11y ago> It's a little strange for him to dismiss the notion that this will set a precedent Here's the report that he confirmed the precedent: "Comey told a congressional panel" "that a final court ruling" "would be “potentially precedential” in other cases where the agency might request similar cooperation from technology companies." http://www.reuters.com/article/us-apple-encryption-congress-idUSKCN0W33G7 http://www.reuters.com/article/us-apple-encryption-congress-...
- kenshaw 11y agoClearly its based on his deep and extensive 30 year work experience as a information security and cryptology developer at Apple. Additionally, I believe Comey was the first person to jailbreak the original iPhone. (sarcasm)
- st3v3r 11y agoNo, he's right. Apple would have to change some config files to unlock the other phones, resulting in new code.
- return0 11y agoActually he didn't. I dont remember the exact words, but he made it clear that they were interested to set a precedent with this case, and that's what this whole case is about.
- pilif 11y agoI think apple signs every single OS installation operation by using a mechanism Jailbreakers refer to as SHSH (https://www.theiphonewiki.com/wiki/SHSH https://www.theiphonewiki.com/wiki/SHSH), so it could be argued that, yes, Apple is in full control over what phone the firmware gets installed on. However, if they can be compelled to do this once for one phone, they can be compelled to do this many more times for as many phones as the FBI or everyone else wants. I would say: Both are right in this case.
- greggarious 11y agoComey's magical thinking knows no bounds.