Jump to content

Recommended Posts

Posted
It's not Apples fault, maybe the researchers were holding it wrong when they cracked through all its security, I'm sure if they were just holding it right with their hands over the firewire connector it would be perfectly secure :p
Posted
I expect there are similar things in Android and Windows phones/tablets tbh, if the NSA or other security agency want your info, they will get it. Freedom and privacy really are things of the past unfortunately.
Posted
Nokia 3210 here I come.

 

I hear they are using type writers in Germany.

 

Got one in a drawer somewhere, saving it for when they rocket in price on fleabay.

Posted
"Zsziarski does say that the iPhone is "reasonably secure" to a typical attacker and newer devices are generally more secure from everybody…everybody except Apple and the government."

 

So, from what can be gleaned from the article, the iPhone is pretty secure, particularly more recent ones. Except for those back doors that they have to provide to law enforcement or risk being shut down.

 

Anyone have memory of Lavabit? They were being forced to handover encryption keys to the govt. and decided to shut the doors instead. The big IT companies chose to handover data via court orders when required rather than shut the doors like Lavabit did. So, yeah not ideal, but Google, Microsoft, Apple, etc. haven't really been given much choice have they? Apple even outlines the process pretty clearly in public domain:

 

https://www.apple.com/legal/more-resources/law-enforcement/

 

Unless any of the big IT companies are willing to take a huge risk that's the way it is.

 

Apple, Google, Microsoft unite against NSA spying program - CNET

Posted

Sorry @seawolf, that just seems even more apologetic for Apple's behaviour than usual.

 

If you read through the article there are a variety of troubling things discussed.

 

1. The services are undocumented

2. The data produced is personal in nature

3. Companies do not *have* to gather all sorts of data on people's individual devices as far as I'm aware, just make it available if it exists when requested. If you can point me to laws that list things that have to be gathered on personal phones (and not at network level).

4. The encryption is useless as it doesn't seem to encrypt when the phone is locked, only when shut down. Not to mention it can be bypassed for a huge amount of data anyway.

5. Providing data when it is demanded by a law enforcement agency does not mean setting up your entire system to aid this. It means handing over whatever data is actually accessible for the request.

 

Listing it in some online document does not make it right.

  • Thanks 1
Posted
Sorry @seawolf, that just seems even more apologetic for Apple's behaviour than usual.

 

If you read through the article there are a variety of troubling things discussed.

 

1. The services are undocumented

2. The data produced is personal in nature

3. Companies do not *have* to gather all sorts of data on people's individual devices as far as I'm aware, just make it available if it exists when requested. If you can point me to laws that list things that have to be gathered on personal phones (and not at network level).

4. The encryption is useless as it doesn't seem to encrypt when the phone is locked, only when shut down. Not to mention it can be bypassed for a huge amount of data anyway.

5. Providing data when it is demanded by a law enforcement agency does not mean setting up your entire system to aid this. It means handing over whatever data is actually accessible for the request.

 

Listing it in some online document does not make it right.

 

You would prefer that Apple document how to hack the iPhone? Interesting perspective.

 

In any case, I'm simply stating how it is. I don't even own an iPhone anymore and have no plans to buy one in the future, or any other smartphone for that matter (I have a Nokia 106 a basic as u can get). So, I couldn't really give a rip how secure or insecure the iPhone is.

 

My view is that anyone who expects complete privacy in anything that is connected to the internet is delusional. That wasn't even true in 1988.

Posted
You would prefer that Apple document how to hack the iPhone? Interesting perspective.

 

Sorry, what? You are recommending security through obscurity then? Not a good choice.

 

In any case, I'm simply stating how it is. I don't even own an iPhone anymore and have no plans to buy one in the future, or any other smartphone for that matter (I have a Nokia 106 a basic as u can get). So, I couldn't really give a rip how secure or insecure the iPhone is.

 

My view is that anyone who expects complete privacy in anything that is connected to the internet is delusional. That wasn't even true in 1988.

 

You're stating how you think it is. Not the same thing as how things actually are.

Posted
Sorry, what? You are recommending security through obscurity then? Not a good choice.

 

So, how did that out in the open thing work out for OpenSSL? Heartbleed anyone? Obscurity plus good security frameworks are the ideal.

 

 

You're stating how you think it is. Not the same thing as how things actually are.

 

How things actually are is that you're dreaming if you think there is privacy on the internet. There hasn't been for a LONG time.

Posted
So, how did that out in the open thing work out for OpenSSL? Heartbleed anyone? Obscurity plus good security frameworks are the ideal.

 

Yeah, I'll take your word for that, over the words of pretty much *every* IT security professional on the planet. Security through obscurity is not security at all. Security with good documentation, and good frameworks means you can protect things properly...

 

How things actually are is that you're dreaming if you think there is privacy on the internet. There hasn't been for a LONG time.

 

May I point you at the Chewbacca defense. No-one has mentioned privacy on the internet it is completely unrelated. Why not bring up privacy walking down the street too? That's as irrelevant. This is a discussion of a personal device recording things it doesn't need to, and then making them available counter to the whole point of the built in encryption which is supposed to protect the owner. It is about the fact that the data tracked is accessible outside the protections for no good reason. Its about the lack of encryption when the phone is locked. Basically, I point you back at my first post and the individual points I made.

Posted
Yeah, I'll take your word for that, over the words of pretty much *every* IT security professional on the planet. Security through obscurity is not security at all. Security with good documentation, and good frameworks means you can protect things properly...

 

So, anyway how did this strategy work out for OpenSSL? Biggest known security flaw in the history of the internet sitting right there out in the open for years. Awesome stuff. Give me more of that!

Posted
So, anyway how did this strategy work out for OpenSSL? Biggest known security flaw in the history of the internet sitting right there out in the open for years. Awesome stuff. Give me more of that!

 

There were quite a few things at play there. It was discovered... because it was open source. If it hadn't been open source, would anyone have found it to fix it? We certainly wouldn't know if people were leveraging the vulnerability. Also, OpenSSL as a project was a mess.

 

Your arguments on this topic are very very weak. I could trot out the thousands of vulnerabilities in closed source software as a counter but it would be pointless.

 

Let's put it this way. Attackers find and use vulnerabilities, whether they're documented or not. That's well known. If we document those vulnerabilities, we can protect against them. Documentation aids security. It doesn't reduce is.

Posted (edited)
There were quite a few things at play there. It was discovered... because it was open source. If it hadn't been open source, would anyone have found it to fix it?

 

Bugs are discovered and fixed all of the time in closed source software. Like Windows for example. You know, that closed source, proprietary system you use all of the time? So, the bug may have been found and fixed much faster. On the other hand, it may have not. You accuse me of championing security through obscurity (I am not) while apparently claiming that open source is always more secure. It is not. It's much more complicated than that. Systems and code that are more used are generally improved more rapidly and have more people working on them - whether open or closed source.

 

Your arguments on this topic are very very weak. I could trot out the thousands of vulnerabilities in closed source software as a counter but it would be pointless.

 

And there about as many in open source. Let me improve my argument with a bit of empirical evidence showing that both closed and open source are pretty much equally vulnerable.

 

http://www.icsi.berkeley.edu/pubs/networking/securityof09.pdf

 

The worst thing though is to have good documentation and an open code base and having no one reviewing and updating that code regularly. That is a recipe for disaster as the documentation is just a gift to hackers (like Heartbleed) and there are quite a few open source projects that suffer from this sort of neglect (no one reviewing or updating code regularly or properly).

Edited by seawolf
Posted
Bugs are discovered and fixed all of the time in closed source software. Like Windows for example. You know, that closed source, proprietary system you use all of the time? So, the bug may have been found and fixed much faster. On the other hand, it may have not. You accuse me of championing security through obscurity (I am not) while apparently claiming that open source is always more secure. It is not. It's much more complicated than that. Systems and code that are more used are generally improved more rapidly and have more people working on them - whether open or closed source.

 

Nope, you've made a bit of an error there. I haven't said open source is always more secure or anything like that. I've merely discounted the concept of security through obscurity as a valid method for protecting software. There are plenty of security holes in both open and closed source software. They get fixed in both open and closed source software and they get exploited in open and closed source software. You're the one making the claim that closed source is somehow better.

 

The worst thing though is to have good documentation and an open code base and having no one reviewing and updating that code regularly. That is a recipe for disaster as the documentation is just a gift to hackers (like Heartbleed) and there are quite a few open source projects that suffer from this sort of neglect (no one reviewing or updating code regularly or properly).

 

And that is not an argument against open source or against avoiding security through obscurity. It is an argument for better project management and better code auditing. There's plenty of closed source software that suffers from similar neglect. It doesn't mean security through obscurity is a good thing.

Posted
Nope, you've made a bit of an error there. I haven't said open source is always more secure or anything like that. I've merely discounted the concept of security through obscurity as a valid method for protecting software. There are plenty of security holes in both open and closed source software. They get fixed in both open and closed source software and they get exploited in open and closed source software. You're the one making the claim that closed source is somehow better.

 

No, you made the error in assuming that I was preaching for closed source. All I asked was if you preferred Apple to document how to hack the iPhone. As in document all of the back doors and intentional vulnerabilities in iOS so that anyone and their brother could use them. That's what I said. Check it. Then see who jumped to the conclusion here.

 

My later comment about obscurity combined with great security frameworks being the ideal means that if you could take the community review of open source and combine it with the obscurity (and money for developers and testers) of closed source you'd have the ideal security. Disagree? It's impossible yes, but it would be the ideal.

 

Anyway, I'm done with it. Edugeek is a minefield of bias. Bye.

Posted
No, you made the error in assuming that I was preaching for closed source.

 

So, how did that out in the open thing work out for OpenSSL? Heartbleed anyone? Obscurity plus good security frameworks are the ideal.

 

You can't have obscurity and open source, its simply not possible by its definition. Therefore, the other option is closed source. Its a simple piece of logic based on your own words.

 

All I asked was if you preferred Apple to document how to hack the iPhone. As in document all of the back doors and intentional vulnerabilities in iOS so that anyone and their brother could use them. That's what I said. Check it. Then see who jumped to the conclusion here.

 

I want Apple to document all the bits of the phone, and what they're doing. Including the bits that track what you're doing and record data onto your device unencrypted. You've consistently ignored the actual points raised in my first post.

 

My later comment about obscurity combined with great security frameworks being the ideal means that if you could take the community review of open source and combine it with the obscurity (and money for developers and testers) of closed source you'd have the ideal security. Disagree? It's impossible yes, but it would be the ideal.

 

Your later comment is an extension of your comment I quoted above - if you are pro obscurity, using simple logic, you have to be anti-open source. You can't have an obscured open source project.

 

Anyway, I'm done with it. Edugeek is a minefield of bias. Bye.

 

What is with people who simply can't present good arguments stating this lately? Its happened in 3 or so threads when people fail to state their case properly and then get upset when called on it.

 

Your posts are consistent in being pro-Apple. Even in the face of industry standards, evidence and simple facts. It isn't bias to question Apple. It is bias to skip over points raised and start using arguments unrelated to the actual discussion, in order to distract from the original issue.

Posted

So does this mean China knew something we are just finding out. Seawolf says that both Apple and MS are closed security and it's both these companies that have been banned from Government use in China. Makes me wonder if the reason they gave was different from the real reason.

 

Also, with so many people using and editing the Android code base and Google offering the code online would it not be much harder to hide something like this?

Posted
So does this mean China knew something we are just finding out. Seawolf says that both Apple and MS are closed security and it's both these companies that have been banned from Government use in China. Makes me wonder if the reason they gave was different from the real reason.

 

Also, with so many people using and editing the Android code base and Google offering the code online would it not be much harder to hide something like this?

 

 

How hard is it to hard something in several million lines of code, especially if it is the difference of a single character pointer dereference in all of that.

Posted

When you have to have physical access to the device and for it to be unlocked, it's not really a bomb is it?

 

Security expert rejects Apple, NSA, iOS backdoor claims « ComputerWorld

 

Security researcher/hacker Jonathan Zdziarski (aka. "NerveGas") made the claims at the HOPE/X hacker conference, saying these "undocumented" services could be used by law enforcement. Typically, his story quickly became a cause célèbre among those who seek to damage Apple's robust reputation for security.

 

Apple swiftly rejected Zdziarski's accusations, pointing out that end users are in complete control of the claimed hacking process -- the person owning the device must have unlocked it and "agreed to trust another computer before the computer is able" to access the diagnostic data the claimed NerveGas attack focuses on.

 

In other words the NerveGas attack is a non-story. It's hot air.

 

The Apple backdoor that wasn't « ZDNet

 

Last weekend, a hacker who's been campaigning to make a point about Apple security by playing fast and loose with the now widely-accepted definition of "backdoor" struck gold when journalists didn't do their homework and erroneously reported a diagnostic mechanism as a nefarious, malfeasant, secret opening to their private data.

 

Speaking at the Hackers On Planet Earth conference in New York, Jonathan Zdziarski said that Apple’s iOS contains intentionally created access that could be used by governments to spy on iPhone and iPad users to access a user's address book, photos, voicemail and any accounts configured on the device.

 

As he has been doing since the Snowden documents started making headlines last year, Mr. Zdziarski re-cast Apple's developer diagnostics kit in a new narrative, turning a tool that could probably gain from better user security implementation into a sinister "backdoor."

 

The "Apple installed backdoors on millions of devices" story is still making headlines, despite the fact that respected security researchers started debunking researcher Jonathan Zdziarski's claims the minute people started tweeting about his HopeX talk on Sunday.

 

Regardless of the problems with Mr. Zdziarski's sermon, the (incorrect) assertion that Apple installed backdoors for law enforcement access was breathlessly reported this week by The Guardian, Forbes, Times of India, The Register, Ars Technica, MacRumors, Cult of Mac, Apple Insider, InformationWeek, Read Write Web, Daily Mail and many more (including ZDNet).

 

People were told to essentially freak out over iPhones allowing people who know the passcode and pairing information to use the device.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...