Apple Tells Judge FBI's Phone Unlocking Demands 'Burdensome' At Present, 'Impossible' In The Future

from the fresh-out-of-master-keys dept

Apple has entered its response to federal magistrate judge James Orenstein’s request that the company explain whether or not unlocking an encrypted iPhone would be “burdensome.” It was the judge calling the bluffs of everyone involved in the new Crypto War, but mainly the FBI’s.

A key issue in the encryption debate, part of a larger discussion of what the FBI calls its “going dark” problem, is to what extent the government can force companies to provide “technical assistance” under current law.

In the Apple case, the government asserted its request “is not likely to place any unreasonable burden on Apple.”

Orenstein said, “I am less certain.”

The DOJ is attempting to use a 1789 act to unlock a phone running a 2013 operating system. Orenstein made several points in his order requesting Apple’s participation, including the fact that the FBI’s abuse of an old law was at odds with director James Comey’s claim that he desired a “public debate” about encryption and public safety.

Apple’s brief points out that “burdensome” may soon become indistinguishable from “impossible.” As was noted earlier, this case concerns a phone running an older version of the iPhone’s system software. Apple admits it can access a certain amount of data if the judge signs off on the All Writs order.

For these devices, Apple has the technical ability to extract certain categories of unencrypted data from a passcode locked iOS device. Whether the extraction can be performed successfully depends on the device itself, and whether it is in good working order. As a general matter, however, certain user-generated active files on an iOS device that are contained in Apple’s native apps can be extracted. Apple cannot, however, extract email, calendar entries, or any third-party app data.

As for the question of whether this possibility veers into “burdensome” territory, Apple had this to say:

[T]he act of extracting data from a single device in good working order, running an operating system earlier than iOS 8, would not likely place a substantial financial or resource burden on Apple by itself. But it is not a matter of simply taking receipt of the device and plugging it into a computer. Each extraction diverts man hours and hardware and software from Apple’s normal business operations. And, of course, this burden increases as the number of government requests increases.

Apple then points out that the burden doesn’t end with unlocking the phone and retrieving whatever data it can. It would also need to send legal representatives and witnesses to court to explain the process and testify to the veracity of the retrieved data.

Apple also notes the “burden” would be felt in more than just man hours.

Apple has taken a leadership role in the protection of its customers’ personal data against any form of improper access. Forcing Apple to extract data in this case, absent clear legal authority to do so, could threaten the trust between Apple and its customers and substantially tarnish the Apple brand. This reputational harm could have a longer term economic impact beyond the mere cost of performing the single extraction at issue.

A footnote states that Apple has performed this sort of service for law enforcement on previous occasions, but only within the limited scope of warrants seeking specific data or information. It has never done so under the vague, broad authority of an All Writs order.

But the brief also points out that what is possible to achieve with this operating system version will no longer be possible going forward.

In most cases now and in the future, the government’s requested order would be substantially burdensome, as it would be impossible to perform. For devices running iOS 8 or higher, Apple would not have the technical ability to do what the government requests—take possession of a password protected device from the government and extract unencrypted user data from that device for the government. Among the security features in iOS 8 is a feature that prevents anyone without the device’s passcode from accessing the device’s encrypted data. This includes Apple.

Underscoring this point, Tim Cook spent the same day this response was delivered (Oct. 19th) being interviewed by Gerard Baker, the executive editor of the Wall Street Journal. Cook reiterated Apple’s stance on encryption: either it works and keeps everyone out or it doesn’t.

“We think encryption is a must in today’s world,” says Cook. “No back door is a must.”

“No one should have to decide privacy or security. We should be smart enough to do both.”

“If there was a way to expose only ‘bad’ people … that would be a great thing. But this is not the world,” says Cook.

“I think it would be in everyone’s best interest … if everyone is blocked out,” he says.

That’s the way it has to be if anything’s going to be truly secure. The FBI will have to find other routes to obtain data. It can no longer expect that running to the manufacturer of a phone will allow it obtain what it wants. It will have to find a new approach, one that engages with third-party applications and possibly even the owner of the phone, which is the way it should be.

Filed Under: , , , ,
Companies: apple

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Apple Tells Judge FBI's Phone Unlocking Demands 'Burdensome' At Present, 'Impossible' In The Future”

Subscribe: RSS Leave a comment
Anonymous Coward says:

I don't like a "closed garden". Period.

Good for Apple, I suppose. However, I don’t like the closed garden, I don’t like the way the product look and I have no desire whatsoever of ever thinking about owning an Apple product.

The only thing that I do like about the Mac OS is that you can drop to a shell but past that .. meh.

Anonymous Coward says:

I like a 'closed garden' if it's got a gate -- with a lock.

The closed garden isn’t so bad as long as you have the option to jailbreak.

However, it’s also nice to have a locked-down system that you have to tether to jailbreak — I tend to flip back and forth. But I may no longer be doing as much of that, now that Apple lets you compile and deploy your own projects. This means that we can now have an open ecosystem where people can provide full open-source projects on GitHub, and anyone can download and deploy/tweak them. This doesn’t get you root, but within the userland, you have pretty loose access these days. But for the most part, you still are protected against malicious actors.

The other thing you need for iOS is a VPN with privoxy on the other end, so you can use WiFi at any AP, and all the ads and potential malicious downloads get filtered out on WiFi AND cellular data.

With the iOS8+ encryption and these features/additions, it’s a pretty good (though still not perfect) solution to mobile computing.

Anonymous Coward says:

Re: I like a 'closed garden' if it's got a gate -- with a lock.

Argh; and I still missed the one other thing I meant to say: the walled garden’s downside is that anything deployed inside of it stays inside — so you can get App lock-in. Enabling open-source deployment now fixes some of that, as you can take a single project and target it for both iOS and Android. Couldn’t do that last year.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...