First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple?
Annnyway, more importantly: are there any details about how their claims are even possible? I guess that somehow, in every case of both iOS and Android, the symmetric key with which the data directory is encrypted is somehow gleanable?
It's a bit puzzling, because it seems that something as simple as 15-year old LUKS (eg, using dm-crypt) is sufficient for this purpose... right?
I mean, this company isn't claiming it can perform the same attack on an off-the-shelf laptop that has FDE with dm-crypt, right?
What's the difference? Why are phones such a security nightmare? At least in terms of encryption at rest on a cold device, isn't this a solved problem?
Are you seriously shocked that there are people out there that would be willing to assist law enforcement? It's not like they are advertising this service for anyone to drop by with any arbitrary phone to unlock.
They are no worse than locksmiths advertising the ability to crack safes.
Are you seriously shocked that there are people out there that would be willing to assist law enforcement? ... They are no worse than locksmiths advertising the ability to crack safes.
It's more like a locksmith advertising the ability to break anyone's safe that contains details on every place you've ever been, purchase you've ever made, and person you've ever communicated with. Phones are far more ubiquitous and contain far more information than any family safe. Not a fair comparison.
Well for #1 & #2, they don't need your phone for that, just subpoenas to the relevant companies. And most people are not international globe trotters where the extra stuff outside of the country would be of much use.
I'm not saying "everyone" should help the police. I do think it's alright that a few companies, in specialized professions, exist to help the police (and other governmental organizations).
Yes, a lot of the effect is harmful, including in helping police do harm. But an argument that no-one should help the police is basically an argument the police shouldn't exist.
I'd argue that nobody should help the police as they exist in many modern implementations, because the police as they exist now are often bad actors. But it's not hard to imagine a police force that's held to a higher standard such that they actually are trustworthy. The argument doesn't have to be "police shouldn't exist"--it could be "police should be better".
But since we lack an individually actionable way of making the police better, doesn't the argument reduce to "we should not help the police as they are now"?
Yes, tautologically, "no-one should help the police" means "we should not help the police as they are now", but given that's obvious, I suspect that's not what you intend to say.
My previous post was responding to your claim "But an argument that no-one should help the police is basically an argument the police shouldn't exist", which is incorrect. The two are very different arguments.
The police could not exist if most people refused to help them. Arguing for people not to help the police is therefore arguing for the police to stop existing or to become less powerful or less effective.
I take "not helping" to mean not just not developing specialized products that only police can legally use, but also not calling the police in case of crime, not helping them with investigations as witnesses. Where the law permits, not selling them generic products and services (eg food). And where personal circumstances permit, not working for a company that does business with them, deplatforming them, etc.
Many reasonable people do indeed take the position that the recent development of a paramilitary force, professionally tasked with keeping domestic peace, has been a bad way to achieve law and order.
So sure, I'll make an argument that today's police - and the private companies who enable them to perform end-arounds on quintessential rights - are contrary to the western common-law tradition and that society will be better when we end this short experiment and move on to a different approach.
First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple?
Probably.
I've met a lot of people who argue against the right to privacy. Most of those people are in positions where they profit from trampling people's privacy in some way: social media integrations, profiting from advertising, law enforcement/spying, or simply deprioritizing security. Lots of those folks are on Hacker News.
What's the difference? Why are phones such a security nightmare? At least in terms of encryption at rest on a cold device, isn't this a solved problem?
One horribly annoying decision of Android is that the encryption passphrase cannot be different from the unlock pin, leaving users with two choices:
- Have a long, secure password that actually makes Android's encryption worth a damn. They then have to enter this password every time they want to unlock their phone. I don't think many people go for this option.
- Have a short usable password so you can painlessly unlock your phone. However, then encryption only provides a marginal benefit
(- I decided to use a long password with fingerprint unlock as a compromise, which creates its own security problems.)
It seems that they ignore that a powered off devices could easily provide much stronger protection by allowing a separate encryption password. And if the device is powered on, limiting unlock attempts might be somewhat useful to frustrate attacks against short lock screen passwords.
You are only forced to enter your passphrase when you turn on the mobile and once every X days. The rest of the time you can use your fingerprint to unlock the mobile. Seems like a good compromise.
True, except that fingerprint sensors can often be fooled and you cannot change your fingerprint once it becomes "compromised". For instance, anyone who ever visited the US, at least as a non-citizen, will have given their fingerprints to CBP.
I think this only works for an attacker model that excludes reasonably sophisticated attackers. I expect this to thwart pickpockets or muggers, but not the police or anyone more sophisticated than that.
First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple?
That's one way to look at it. Another is that they provide law enforcement the ability to catch and trial criminals (for instance sex offenders) who are using the phone manufacturer's naivete to hide their nefarious deeds.
One way or another, they are facilitating (in fact profiting from) one human to forcibly access a sensitive device belonging to another human, with the consent of the latter.
The sex offender "spectre" completely changes that because privacy is a "qualified right" that is appropriate to violate in some circumstances.
Under the European Convention on Human Rights, the right to privacy is, in effect, contained in Article 8, the right to respect for family and private life. It is important to know that it is also a “qualified” right. That means it is not absolute, and can be interfered with in certain limited situations, for example to protect national security or freedom of expression. However, any interference has to be necessary and proportionate.
No, but "by law enforcement" aspect does. We gave government and specifically law enforcement the ability to disregard the privacy and certain rights of certain people in certain conditions - in this case a criminal's right to privacy after or during a criminal act.
It's like saying that because hidden recording devices can be abused it should be illegal (or at least one should be ashamed of) to create it.
For many, I bet the answer is yes. Plus I bet they sleep at night justifying their actions as helping to hunt down criminals and terrorists, (which I think some of them may be thinking of as having a close experience with).
Of course these are all post-hoc justifications for the primary motivator, money.
It’s only a solved problem if you’re using high entropy passwords (6 digit pins are not). Otherwise you’re relying on some sort of anti-hammering/auto erase to make up for it.
iPhones have anti-hammering already. The Secure Enclave counts password attempts and enforced a lockout period (and wipes the keys after 10 attempts if configured to do so).
There was an attack years ago, where you could kill power to the device after failing the attempt but before it incremented the attempt counter, but they fixed that, and that may have predated the Secure Enclave anyway (and required taking apart the phone, which I assume this on-premises device doesn’t do).
“what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>?”
Flaunting this is great advertising for them - and most importantly free advertising for them. Not saying it’s right, but this is how they get customers when direct word of mouth is too slow.
First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple?
If you ask around I'm sure most people think LE should be able to do this for security reasons. Not saying I agree or disagree but that's the way it is.
Comments
First of all, to give words to the obvious question here: what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>? They are literally trumpeting the ability for their clients to forcibly copy data without the permission of the owner of the device in question. Is it just money? Is it that simple?
Annnyway, more importantly: are there any details about how their claims are even possible? I guess that somehow, in every case of both iOS and Android, the symmetric key with which the data directory is encrypted is somehow gleanable?
It's a bit puzzling, because it seems that something as simple as 15-year old LUKS (eg, using dm-crypt) is sufficient for this purpose... right?
I mean, this company isn't claiming it can perform the same attack on an off-the-shelf laptop that has FDE with dm-crypt, right?
What's the difference? Why are phones such a security nightmare? At least in terms of encryption at rest on a cold device, isn't this a solved problem?
Are you seriously shocked that there are people out there that would be willing to assist law enforcement? It's not like they are advertising this service for anyone to drop by with any arbitrary phone to unlock.
They are no worse than locksmiths advertising the ability to crack safes.
It's more like a locksmith advertising the ability to break anyone's safe that contains details on every place you've ever been, purchase you've ever made, and person you've ever communicated with. Phones are far more ubiquitous and contain far more information than any family safe. Not a fair comparison.
Well for #1 & #2, they don't need your phone for that, just subpoenas to the relevant companies. And most people are not international globe trotters where the extra stuff outside of the country would be of much use.
#3 is the real treasure trove.
Are you suggesting a locksmith should refuse to help the police open safes that contain too many valuables or PII inside?
At the end of the day you live in a global world.
Is it acceptable for this company to sell it to Saudi Arabian police where it's a crime for a woman to run away from home?
https://www.businessinsider.com/saudi-arabia-imei-track-runa...
Or how about Australia raiding journalists for whistleblowing on abuses conducted by their arm forces in war: https://www.bbc.com/news/world-australia-48522729
Perhaps you agree or perhaps you don't. But the issue is more complex than saying that "everyone should help the police"
I'm not saying "everyone" should help the police. I do think it's alright that a few companies, in specialized professions, exist to help the police (and other governmental organizations).
Yes, a lot of the effect is harmful, including in helping police do harm. But an argument that no-one should help the police is basically an argument the police shouldn't exist.
No it's not.
I'd argue that nobody should help the police as they exist in many modern implementations, because the police as they exist now are often bad actors. But it's not hard to imagine a police force that's held to a higher standard such that they actually are trustworthy. The argument doesn't have to be "police shouldn't exist"--it could be "police should be better".
But since we lack an individually actionable way of making the police better, doesn't the argument reduce to "we should not help the police as they are now"?
Yes, tautologically, "no-one should help the police" means "we should not help the police as they are now", but given that's obvious, I suspect that's not what you intend to say.
My previous post was responding to your claim "But an argument that no-one should help the police is basically an argument the police shouldn't exist", which is incorrect. The two are very different arguments.
The police could not exist if most people refused to help them. Arguing for people not to help the police is therefore arguing for the police to stop existing or to become less powerful or less effective.
I take "not helping" to mean not just not developing specialized products that only police can legally use, but also not calling the police in case of crime, not helping them with investigations as witnesses. Where the law permits, not selling them generic products and services (eg food). And where personal circumstances permit, not working for a company that does business with them, deplatforming them, etc.
Many reasonable people do indeed take the position that the recent development of a paramilitary force, professionally tasked with keeping domestic peace, has been a bad way to achieve law and order.
So sure, I'll make an argument that today's police - and the private companies who enable them to perform end-arounds on quintessential rights - are contrary to the western common-law tradition and that society will be better when we end this short experiment and move on to a different approach.
No, as I said, it's the flaunting it that surprises me.
Probably.
I've met a lot of people who argue against the right to privacy. Most of those people are in positions where they profit from trampling people's privacy in some way: social media integrations, profiting from advertising, law enforcement/spying, or simply deprioritizing security. Lots of those folks are on Hacker News.
One horribly annoying decision of Android is that the encryption passphrase cannot be different from the unlock pin, leaving users with two choices:
- Have a long, secure password that actually makes Android's encryption worth a damn. They then have to enter this password every time they want to unlock their phone. I don't think many people go for this option.
- Have a short usable password so you can painlessly unlock your phone. However, then encryption only provides a marginal benefit
(- I decided to use a long password with fingerprint unlock as a compromise, which creates its own security problems.)
It seems that they ignore that a powered off devices could easily provide much stronger protection by allowing a separate encryption password. And if the device is powered on, limiting unlock attempts might be somewhat useful to frustrate attacks against short lock screen passwords.
You are only forced to enter your passphrase when you turn on the mobile and once every X days. The rest of the time you can use your fingerprint to unlock the mobile. Seems like a good compromise.
True, except that fingerprint sensors can often be fooled and you cannot change your fingerprint once it becomes "compromised". For instance, anyone who ever visited the US, at least as a non-citizen, will have given their fingerprints to CBP.
I think this only works for an attacker model that excludes reasonably sophisticated attackers. I expect this to thwart pickpockets or muggers, but not the police or anyone more sophisticated than that.
That's one way to look at it. Another is that they provide law enforcement the ability to catch and trial criminals (for instance sex offenders) who are using the phone manufacturer's naivete to hide their nefarious deeds.
It depends on your point of view.
One way or another, they are facilitating (in fact profiting from) one human to forcibly access a sensitive device belonging to another human, with the consent of the latter.
The sex offender spectre doesn't change that.
The sex offender "spectre" completely changes that because privacy is a "qualified right" that is appropriate to violate in some circumstances.
https://rightsinfo.org/the-right-to-privacy-and-why-it-matte...
No, but "by law enforcement" aspect does. We gave government and specifically law enforcement the ability to disregard the privacy and certain rights of certain people in certain conditions - in this case a criminal's right to privacy after or during a criminal act.
It's like saying that because hidden recording devices can be abused it should be illegal (or at least one should be ashamed of) to create it.
For many, I bet the answer is yes. Plus I bet they sleep at night justifying their actions as helping to hunt down criminals and terrorists, (which I think some of them may be thinking of as having a close experience with).
Of course these are all post-hoc justifications for the primary motivator, money.
It’s only a solved problem if you’re using high entropy passwords (6 digit pins are not). Otherwise you’re relying on some sort of anti-hammering/auto erase to make up for it.
iPhones have anti-hammering already. The Secure Enclave counts password attempts and enforced a lockout period (and wipes the keys after 10 attempts if configured to do so).
There was an attack years ago, where you could kill power to the device after failing the attempt but before it incremented the attempt counter, but they fixed that, and that may have predated the Secure Enclave anyway (and required taking apart the phone, which I assume this on-premises device doesn’t do).
Right, they have it, but whether it's secure/bug free is uncertain. Much more uncertain than say, wether AES-CBC is secure/bug free.
“what leads a group of people to flaunt their insanely unethical desire to profit from <insert antonym of freedom>?”
Flaunting this is great advertising for them - and most importantly free advertising for them. Not saying it’s right, but this is how they get customers when direct word of mouth is too slow.
If you ask around I'm sure most people think LE should be able to do this for security reasons. Not saying I agree or disagree but that's the way it is.
What? There are a lot of careless people not creating backups not setting up iCloud, but storing valuable data on their phone.
Why shouldn't they be able to access their data?