5 ms·
The backdoor is already present, through Apple's design. The FBI are just requesting to use it.
by geographomics 11y ago
The backdoor is already present, through Apple's design. The FBI are just requesting to use it.
- TruthSHIFT 11y agoWhat backdoor is that?
- geographomics 11y agoBeing able to load arbitrary firmware onto the device without requiring user authentication, so long as it's signed by Apple.
- mirimir 11y agoThis is just how Apple does things. Indeed, Apple expects you to trust it more than you trust yourself.
- newjersey 11y agoHow can we fix it? Easiest I can think of is wipe storage if updating without user authentication. Any better way?
- mirimir 11y agoWho is "we" here? Apple could do that, for sure. In the present contest, I can see why they'd want to. It would be a great move to forestall this sort of attack in future. But "we", as in you and I, cannot easily do this. Because we can't sign stuff as Apple. But maybe it's doable.
- bshep 11y agoI think this is where things are headed. I think we will soon see a new version of iOS by Apple with more stringent security (no updates without authentication or information is wiped when you force an update). If this doesn't happen, I would highly suspect there is an NSL (or something similar) involved forbidding it.
- nihonde 11y agoYou can vote with your dollars, you know. Feel free to buy devices from those other manufacturers that you trust.
- mirimir 11y agoMe, I'm waiting on openFAB devices. Could be a long wait.
- MichaelGG 11y agoHas Apple addressed this? I was under the impression the PIN was needed to update the OS. Why isn't it? Some sort of recovery method that doesn't wipe data?
- sitharus 11y agoOS updates OTA need your PIN, but using DFU mode connected to iTunes doesn't. I assume this is so a broken OS upgrade can't brick your phone.
- legulere 11y agoIf I get it right you're calling update functionality a backdoor?
- Crito 11y agoWhether we want to call it a backdoor or get senselessly pedantic about terminology and call it a "front door", the practical reality is yes; it is that functionality that the FBI is asking Apple to take advantage of.
- geographomics 11y agoThe way it is currently implemented, by which Apple can - if in physical possession of the device - unilaterally force new firmware onto it without the consent of the user, yes.
- niels_olson 11y agoYou misunderstand, or at the very least, misrepresent the situation. The only threat Apple apparently didn't design for is the threat of the most powerful nation on earth overreaching their authority by ordering Apple to write and sign an entire operating system with the express purpose of defeating their own safeguards. Which is next-level crazy.
- geographomics 11y agoNonetheless, if Apple had designed the update mechanism to require both a signed firmware image, and authentication by the user, then the FBI's request would not be possible. Such a design would also help to mitigate the end-user effects of an insider attack at Apple, where a rogue employee signs malicious firmware, or leaks the signing key to some adversary.
- pdkl95 11y ago> then the FBI's request would not be possible. While that may be a good design for various practical reasons, the technical properties of Apple's security design are not very relevant. This is a political issue about how far Apple (and eventually, any of us) has to go in creating access for law enforcement. Right now the FBI is being reasonably diplomatic and "asking" (formally, through the court) to create this backdoor. If the situation were as you suggest and no update capability existed, they would simply skip the current step and move on to the next step: forcing Apple to include explicit "lawful intercept" capabilities. It is very important for us to win this earlier stage of the fight, because it will be much harder to fight a law. In case you've forgotten, the traditional telcom industry already lost that fight (CALEA).
- vdek 11y agoThis is an iPhone 5c, not a 6/6s. The newer models with the secure enclave chip are more secure.