Apple is said to be working on an iPhone even it can’t hack
Apple engineers have already begun developing security measures that would make it impossible for the government to break into a locked iPhone using methods similar to those at the centre of a court fight in California, according to people close to the company and security experts.
If Apple succeeds in upgrading its security – and experts say it almost surely will – the company will create a significant technical challenge for law enforcement agencies, even if the Obama administration wins its fight over access to data stored on an iPhone used by one of the killers in last year’s San Bernardino, California, rampage. The FBI would then have to find another way to defeat Apple security, setting up a new cycle of court fights and, yet again, more technical fixes by Apple.
The only way out of this back-and-forth, experts say, is for Congress to get involved. Federal wiretapping laws require traditional phone carriers to make their data accessible to law enforcement agencies. But tech companies like Apple and Google are not covered, and they have strongly resisted legislation that would place similar requirements on them.
Companies have always searched for software bugs and patched holes to keep their code secure from hackers. But since the revelations of government surveillance made by Edward Snowden, companies have been retooling their products to protect against government intrusion.
Apple built its recent operating systems to protect customer information. As its chief executive, Timothy Cook, wrote in a recent letter to customers, “We have even put that data out of our own reach, because we believe the contents of your iPhone are none of our business.”
But there is a catch. Each iPhone has a built-in troubleshooting system that lets the company update the system software without the need for a user to enter a password. Apple designed that feature to make it easier to repair malfunctioning phones.
In the San Bernardino case, the FBI wants to exploit that troubleshooting system by forcing Apple to write and install software that strips away several security features, making it much easier for the government to hack into the phone. The phone in that case is an old model, but experts and former Apple employees say that a similar approach could also be used to alter software on newer phones. That is the vulnerability Apple is working to fix.
Apple officials alluded to this in a conference call last week when a journalist asked why the company would allow firmware – the software at the heart of the iPhone – to be modified without requiring a user password. One executive replied that it was safe to bet that security would continue to improve, and someone close to the company confirmed this week that Apple engineers had begun work on a solution even before the San Bernardino attack. A company spokeswoman declined to comment on what she called rumors and speculation.
Independent experts have offered possible solutions in both public forums and private, informal conversations with the company over the past few weeks.
“There are probably 50 different ideas we have all sent to Apple,” said Jonathan Zdziarski, a security researcher.
Apple regularly publishes security updates and gives credit to researchers who hunt for bugs in the company’s software.
“Usually, bug reports come in an email saying, ‘Dear Apple Security, we’ve discovered a flaw in your product,’” said Chris Soghoian, a technology analyst with the American Civil Liberties Union. “This bug report has come in the form of a court order.”
The court order to which Soghoian referred was issued last week by a federal judge magistrate and tells Apple to write and install the code sought by the FBI. Apple has promised to challenge that order. Its lawyers have until Friday to file its opposition in court.
In many ways, Apple’s response continues a trend that has persisted in Silicon Valley since Snowden’s revelations. Yahoo, for instance, left its e-mail service unencrypted for years. After Snowden revealed how the National Security Agency exploited the company, the company quickly announced plans to encrypt e-mail. Google similarly moved to fix a vulnerability that the government was using to hack into company data centres.
Apple’s showdown with the Justice Department is different in one important way. Now that the government has tried to force Apple to hack its own code, security officials say, the company must view itself as the vulnerability. That means engineers will have to design a lock they cannot break.
“This is the first time that Apple has been included in their own threat model,” Zdziarski said. “I don’t think Apple ever considered becoming a compelled arm of the government.”
FBI Director James Comey signalled this week that he expected Apple to change its security, saying that the phone-cracking tool the government sought in the San Bernardino case was “increasingly obsolete.” He said that that supported the government’s argument that it was not seeking a skeleton key to hack all iPhones.
The post Apple is said to be working on an iPhone even it can’t hack appeared first on eComBizCenter.