Ok, maybe some of you guys don't know...IF the iPhone 5c in question uses SIMPLE passcode, then it is 4 numbers. 1234, 4321, 1120, 3333, 9999, 3648, etc. So, if you have the correct 4 numbers that the terrorist use to get into his phone, then you unlock the phone and encrytion turns off. Therefore, the KEY to this iPhone encryption is the correct 4-digit passcode.
This is why Apple cannot just "copy" the key and open up the phone. Apple also cannot just "create" a key to open the phone.
Currently, if you guess wrong and type the passcode wrong "X" amount of times, the phone locks down permanently.... (I have no experience with this because this is not something i have tried.)
What FBI wants Apple to do is create a new secret iOS version that can be uploaded into this phone so that it does NOT lock down permanently even if you keep guessing the different combination codes a million times.
Basically, any hacker (FBI included) has special programs that can run really fast through all the possible 4-digit combinations until it randomly hits the right 4-digit passcode. This is called brute force entry in tech terms. Voila! The phone is now unlocked and FBI can see everything that is on the phone.
But, you cannot do brute force if the phone shuts down after 10 tries (for example). This is the problem at hand (i think).
The feature to erase data needs to be turned on, which any shady businessman, enterprising terrorist, and/or citizen not interested in sharing their private stuffs would presumably do. The other problem is that there's a delay built into the failed password attempts that further hampers brute force cracking. I believe it's something like up to 5~10mins once you've failed 7~9 times in a row, which makes brute forcing the phone even more troublesome.
I don't exactly see anything "conspiracy theory" about the fact that the US Government actively trades, harvests, and uses public and private information of it's citizens; much of which it gathers in less than legal ways to use for their own benefits. Not to mention that the US Government has and continues to operate in a two-faced manner in regards to the American people; the Public Face will say one thing, while the private face is off assassinating leaders of countries and giving away weapons to armed insurgent groups to fight our enemies under the table, or did you forget about the Cold War leading up to today? There's nothing conspiracy theory about that, it's just how the Government (and honestly any country's government to be honest) works since we've given up a lot of freedom and control (particularly in the last decade or so).
Nor is there anything fairy-tale esque about a private company, whose sole goal is seeking profit participating in the largest economy on the planet; information. It'd be absolutely idiotic for a digital goods company NOT to have some form of information selling/buying these days. Nor is Apple a shining example of a company to begin with, since they've done just as many unethical and borderline shady things as any other profiteering company.
As far as bypassing the "10 Fail Auto-Delete Function", from what I read; since the Key lives in the SE (Secure Enclave) and cannot be remotely obtained, you need to have access to the actual device. The other issue is that even if the auto-erasure wasn't activated, the default increasing delay per failed attempt (I am not entirely sure if it is exponential and/or if it hits a plateau) will increase the time required to brute force into the phone. In this particular case, the longer the US Government cannot access the phone, the less useful and critical the information stored is in locating the enemy; the longer it goes on the greater the chance the information is out-dated and the enemy can cover their tracks.
Setting aside the moral and ethical implications of creating a "back door" for a single government (that could either being used to continue the pattern of violation of citizen's rights and/or could be sold to a another government and/or organization by a corrupt official), let alone the fact that this is the phone of a terrorist; there is a strong possibility that such a "back door" could easily be made and/or already exists.
As I mentioned before, the Key exists in the SE, which is a combination of physical buses between a handful of hardware in the device and software coding. This makes copying/pulling the Key very difficult because specific buses are used for this data and the software controls where and how this data is managed on those data buses. The way the software is written, trying to copy/pull the Key out of the SE is very difficult and requires physical access to the device itself. Trying to Brute Force your way in runs into the two issues I pointed out above, these are strictly software issues and not hardware problems. As far as I have seen/read there's no data or statements from Apple that says they cannot simply use a custom firmware to disable these features and allow simple brute force to work as needed. If anything the case seems to be more a matter of "we don't want to do it" than "we can't do it". Which is why the US Government is pushing Apple to create this Firmware, realistically speaking though; all they need is a "Signed" firmware by Apple to make it work. Though one I suppose could somehow spoof the signature and force it to update with a non-Apple Officiated iOS; but that is beyond my technical knowledge and is something that is far from simple I would imagine. By the way, there's no data to support that Apple hasn't actually already programmed this "off-switch" into the Firmware coding; so it is entirely possible it may already exist or they may have an even more intricate backdoor that can be used remotely (this is something that isn't entirely conspiracy theory; nor would it be the first time a company has lied about manipulating their product's software for their own purposes and profit).
Would they not need the passcode to install the new software? I seem to recall having to enter it every time I do an update.
I am not entirely sure, I would imagine that there is a way to force an update with user input; a bit above my technical knowledge. Though a lot of security experts seem to think it could be done without needing to input a Key. But in this case the US Government wants them to create this "back-door" for future use.
Though I will somewhat applaud Apple's efforts, be it because they don't want the government snooping in their information trading or simply because they don't trust the US Government not to screw them over (let's be honest that alone is a good reason), it's still a decent effort; hardly philanthropic, but commendable at the least. They're a global company not tied to the US in any significant manner besides a sales region (they use a holding company outside of the US To avoid Taxes like most large corporations these days).
Unfortunately there's the other-side of the coin where Apple becomes the premier product for the pedophile, terrorist, and/or other unsavory characters, which I suppose isn't a bad thing if you're trying to sell more product since the Apple sheeple will still buy it anyways. Though fairly true (I mean if you have a device that's safe from the government thanks to the company, why wouldn't you use it for illicit dealings?), the above statement is mainly fear-mongering and political BS some senators and politicians are using to try and force Apple to concede to the US Government.
The entertaining thing here is that the US is playing with a double edged sword here, as it is currently Apple can make themselves into a sort of "Swiss Bank" in the sense that since they refuse to obligate themselves to one government, they can serve multiple entities (criminal and non-criminal alike) and as such create a rough sense of immunity in the same way the Swiss Banking system is for the most part "Untouchable" because while many governments would want to get into the Swiss Banking records, no one wants their dirty laundry and illicit funding to be aired. If the US government creates a precedent that they need to make a "back-door" for their use, then other governments can mandate the same back-door be made for them; in which case Apple wouldn't be liable for say... the Russian Government illicitly accessing a US Government Official's phone because hey, if the US gets to do it why not Putin? So there is a "Slippery Slope" argument there and while Apple could have perhaps chosen a better case study than a confirmed terrorist to protect, there is benefit in making sure the Government can't meddle in the company's operations.
Post Note-
As for them disabling the iCloud back-up function, that's frickin' hilarious... yet unsurprising with how our Government works.
Also I'm not entirely against Apple holding out against the US Government (I'm mostly for it, again I think the case study they chose to fight them with is a bit poor, but the message is still there), but I doubt it's from sort of philanthropic place. If anything it's because Apple has leverage with this and it benefits them in multiple ways. It's just that there's enough reasonable doubt and failure from Apple to specifically show that it can't be done that is more of a "we don't want to do it" vs. "we can't do it"; again this is a nice encryption method, but hardly Quantum Encryption. That means it can and will be broken, it's just a matter of time (as we've seen) and I can't imagine the US Government wants to spend that type of money and effort when they can just force Apple to do it for them.
I'd be curious if we had a information specialist on the forum who's familiar with Apple's encryption more intimately; most if not all the information I posted above was from reading dozens of various articles on how Apple's system supposedly works, bypasses, and why it's not impossible. I'm not a programming guy by any means, but as the system is laid out I don't see why the software couldn't be manipulated in that fashion. Basically Apple's SE is just a enclosed network bus between specific chips specifically for encryption purposes controlled by software; much in the way Toyota uses an entirely separate communication bus between the ECM & Immobilizer System that is not actually connected to the OBDII port and can only be accessed via software in a scantool.
Was thinking about this a bit when snowboarding today.
