Read The Times Australia

Daily Bulletin

Hacking the terror suspect's iPhone: what the FBI can do now Apple says 'no'

  • Written by: The Conversation Contributor

Tech giant Apple is standing firm behind its decision to refuse a US court order to help the FBI gain access to the iPhone used by one of the shooters in last year’s mass killing in California.

Fourteen people were killed and 22 seriously injured in a shooting in San Bernardino, on December 2, 2015. The incident was declared an act of terrorism.

The FBI has an iPhone 5C belonging to one of the shooters, but it does not have the necessary security code set by the user to unlock the phone. It wants Apple to create and provide it with firmware that would allow it to bypass the security features that protect the privacy of iPhone users.

Apple CEO Tim Cook has published “A Message to Our Customers” explaining why the company is not complying with the request.

Heated debate

It’s a topic that has been the subject of much debate over the past few days, with supporters for both sides. Many of Apple’s tech rivals have sided with the company, though Microsoft founder Bill Gates says companies should be forced to cooperate with law enforcement agencies in terrorism investigations.

From the FBI’s perspective, the contents of the phone may provide crucial clues, evidence and possibly even contact information of other terrorists and extremists.

From Apple’s point of view, creating firmware that has a backdoor could have significant impact on the security and privacy of its customers, because the US government would then have the ability to gain access to any iPhone in its possession.

In the wrong hands, this special firmware could be used to gain access to sensitive information on any iPhone. These devices are more versatile than ever before and are likely to contain anything from email, messages and contacts, to financial and credit card information.

Understandably Apple is firmly opposing compliance with this order. Because compliance could affect its reputation and result in loss of consumer confidence. There may also be international implications; would this firmware only work on US-issued devices? How might this affect international privacy laws?

We’ve had back doors before

This wouldn’t be the first time the US government has had a back door into secure systems.

In the 1980s, the US National Security Agency (NSA) developed an algorithm called “Skipjack”. Using an encryption device called the Clipper chip, which had a built in back door, Skipjack allowed law enforcement agencies to gain access to encrypted data and was intended for use by telecommunications providers.

The chip was introduced in 1993 and met with significant backlash and low adoption. It was defunct by 1996.

And in 2013, the New York Times published a story about how an encryption algorithm, called Dual Elliptical Curve Deterministic Random Bit Generator (Dual_EC_DRBG) contained a back door for the NSA.

People who used the algorithm, which could be any organisation that had the algorithm included as part of security devices or software they acquired, such as those that utilised the RSA Security BSAFE encryption libraries, were urged to stop using it.

What now for the FBI?

What other options does the FBI have? Could there be a place for ethical hackers to attempt to break into the iPhone? Would commissioning ethical hackers for this purpose itself be ethical?

Although Apple’s iOS firmware has already undergone significant testing by both Apple and the public, it is possible that vulnerabilities still exist.

One such vulnerability, which allows hackers to bypass the lock screen using Siri, was revealed last September. Although it only provided access to contacts and photos, it demonstrates that flaws in firmware can exist. In the FBI case at hand, photos and contacts may be useful evidence.

There is also the possibility that an ethical hacker may be able to reverse engineer the firmware. Doing this is explicitly forbidden by the Apple iOS Software license agreement so the ethics of doing it would be questionable.

Could it be justified given the US government would back the effort for the sake of national safety?

Any attempt to break into the device comes with its risks. Simply trying to brute force the security code by inputting every password combination would likely result in the device being erased, so it is important to preserve the device.

It would at least be necessary to maintain the current state of the device in some way. So, if a way of duplicating the device was created, it would be possible to use a brute force attack against its copies, without affecting the original phone.

Maintaining the forensic integrity of the device and not damaging it is of the utmost importance, something that was not demonstrated when the FBI attempted to access the iCloud account of the perpetrators.

It is also necessary for Apple to be able to prove that the back door maintains the integrity of the data. If this process becomes part of any court proceeding, it is highly likely that Apple would be called upon to prove this in open court.

It must already realise this and be very concerned about having to do so, as it would expose a great deal of proprietary information that it would not want to see in the public arena.

No hacking by the FBI?

One must ask why the FBI (or US government) doesn’t already have the ability to gain access to the encrypted data. It seems likely that with the supercomputers in its arsenal, and the funding available to it, the agency can take a copy of the encrypted data and attempt to decrypt it.

Given the standard encryption on iOS devices is AES-256 (approved and used by the NSA for storing top-secret data), and the key is fused in an unreadable format to the device, the amount of time to decrypt and the costs involved are likely to be the issue.

It’s also important to consider whether there should be any automatic right for any government to be able to read (or decrypt and read) any communications or stored data.

Whenever government ministers are interviewed, they seem to start with the presumption that they have the right to do this, yet that right is not established.

So it’s probably easier and more cost effective for the US government to try to get Apple to create a back door, despite the problem of Apple refusing to do so.

Creating this precedent would allow this process to be repeatable and to occur whenever the US government required. Perhaps Apple doesn’t want the same fate as Clipper and Dual_EC_DRBG.

Authors: The Conversation Contributor

Read more http://theconversation.com/hacking-the-terror-suspects-iphone-what-the-fbi-can-do-now-apple-says-no-55135

Business News

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...