Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

“They’ve eliminated accessibility in order to market the product. Now that means we have to figure out how to solve a problem that we didn’t create.”

Ermm ... I'd argue that dragnet mass surveillance is exactly one of the causes. Good security should be the default position. That we've had poor security to date should be the considered the real aberration.



Isn't solving problems they didn't create exactly what police work is all about?


This is all bull. There are skilled IT forensics people who can access these devices without the permission of the owner as long as they seize them on.

As far as I know the key needs to be kept in ram which means it is vulnerable while the device is on.

This only prevents dragnet surveillance; nothing more.


There are proof of concepts to keep the key in registers, for example http://www1.informatik.uni-erlangen.de/tresor

That prevents coldboot attacks and other means of reading the key out of memory.


The Manhattan DA didn't invent dragnet surveillance. It's way beyond his capabilities and he probably has zero access to what the NSA has captured. Besides, the NSA is not stealing data from local storage. They're getting it from anyone site that's storing user data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: