Security

Apple doesn’t consider government intrusion a primary iPhone security threat, yet

Comment

Image Credits: Justin Sullivan

Despite Apple’s highly publicized sparring match with the FBI over unlocking an iPhone that belonged to one of the San Bernardino shooters, security engineers pushed back against the idea of Apple as an opponent to the government in a meeting with reporters.

Senior Apple engineers feel that government intrusion is not their primary threat model when designing iPhone security and said they instead prefer to focus on fending off hackers.

The engineers also characterized Apple’s pushback against the FBI as motivated not by a desire to impede a terrorism investigation, but rather to defend its ability to protect users against non-governmental threats.

Apple recently revamped its internal security teams, which govern the security aspects of shipping products, conduct threat-testing against Apple’s own devices and act as a sort of filtration system that places security at the nexus of what it does. Given Apple CEO Tim Cook’s strong statements on security as a lynchpin of Apple strategy, that’s not shocking.

The security features of Apple’s iPhone have been highly scrutinized in the wake of the shooting at the Inland Regional Center in San Bernardino, CA, that killed 14 people. The FBI attempted to compel Apple to design custom software that would help unlock an iPhone belonging to Syed Farook, on the of shooters, but later dropped its case after it was approached by a third party offering another way into the phone. Law enforcement officials, from the Department of Justice to the Manhattan District Attorney’s Office, have argued that Apple goes too far in its efforts to encrypt customer data, locking out investigators along with criminal intruders.

But Apple engineers disputed the theory that the tech giant’s security features enable criminals to evade law enforcement, saying that data security is essential to the safety of society as a whole. Apple executives also pointed to the many other avenues of investigation that are available to law enforcement officials in the digital age — location data collected from cell phone towers, social media posts and transactional metadata attached to messages. The engineers’ remarks echoed a Q&A published by Apple in response to the FBI’s demands, in which the company called on the U.S. government to become an international leader in cybersecurity.

In its Q&A, Apple said the government should “form a commission or other panel of experts on intelligence, technology, and civil liberties to discuss the implications for law enforcement, national security, privacy, and personal freedoms.”

Engineers reviewed the features highlighted in the company’s Security White Paper today to explain to reporters how Apple secures its customers’ data, and stressed that Apple’s rigorous design philosophy doesn’t stop at the iPhone’s sleek rose gold exterior — it’s baked into the device’s security, too.

In particular, Apple emphasized its unique ability to build security into the iPhone starting at the silicon level — although other smartphone manufacturers sometimes outsource their chip production, Apple likes to keep everything in-house. Its latest phones ship with the Secure Enclave, a portion of the phone’s hardware that manages the keys used to encrypt the device, as part of the chip.

Apple also emphasized the role of the consumer in securing the iPhone, highlighting features like Touch ID and two-factor authentication for iCloud as ways for users to keep their devices and data safe from prying eyes. As Apple has previously highlighted, prior to the introduction of Touch ID, Apple found that only 49 percent of its customers protected their phones using a passcode. But after the introduction of Touch ID, passcode use jumped to 89 percent, Apple engineers said (users are required to set up a passcode in order to implement the Touch ID feature).

Although Apple has worked to build encryption into the iPhone from the beginning — it introduced end-to-end encryption in the earliest versions of iMessage and strengthened device encryption with the Secure Enclave — the iPhone’s security features have only begun to play a large factor in Apple’s marketing in recent years.

Consumer interest in encryption and security has risen in the post-Snowden era and spiked in the wake of the San Bernardino attack, which has influenced Apple to speak more publicly about the design and implementation of its security. It also means that it makes more sense now than ever for Apple to make sure that the press and public are well-informed when it comes to the technical and policy details of its security processes.

When the next San Bernardino case happens, Apple needs to make sure that the public understands the implications of the “it’s not just one iPhone” scenario.

One thing that bears consideration is how long any tech company, including Apple, can afford not to view government intrusion as part of its threat model. As mentioned above, Apple’s engineers do not currently do that, but any tech company that is the steward of huge stores of user information (or that manufactures those stores in the form of devices) has to at least be considering the “govtOS” vector.

In related news, Apple announced today that it will fight against unlocking an iPhone in a New York criminal case.

Fighting government demands to unlock phones puts Apple in a tough position — if investigators continue to demand Apple modify its iOS to allow decryption, the company will eventually have to decide whether or not to up its security even further and enable itself to refuse all government requests for data.

It’s not something that Apple wants to do — engineers say they don’t want to be viewed as government adversaries, and building in tougher encryption to the iPhone and services like iCloud might also mean abandoning some of the design and simplicity that is essential to Apple’s brand — but it may soon be time to include the government in Apple’s threat model, right alongside the hackers.

And as Apple has led the industry in smartphone innovation, it could lead in security innovation, as well. Silicon Valley widely supported Apple’s opposition to building a special operating system for the FBI, dubbed (by Apple) govtOS, in the San Bernardino case. It’s likely that other tech companies will follow Apple’s lead as it continues to advance its users’ security. As engineers said today, data security is an ever-evolving target.

Apple vs FBI

More TechCrunch

Zen Educate, an online marketplace that connects schools with teachers, has raised $37 million in a Series B round of funding. The raise comes amid a growing teacher shortage crisis…

Zen Educate raises $37M and acquires Aquinas Education as it tries to address the teacher shortage

“When I heard the released demo, I was shocked, angered and in disbelief that Mr. Altman would pursue a voice that sounded so eerily similar to mine.”

Scarlett Johansson says that OpenAI approached her to use her voice

A new self-driving truck — manufactured by Volvo and loaded with autonomous vehicle tech developed by Aurora Innovation — could be on public highways as early as this summer.  The…

Aurora and Volvo unveil self-driving truck designed for a driverless future

The European venture capital firm raised its fourth fund as fund as climate tech “comes of age.”

ETF Partners raises €284M for climate startups that will be effective quickly — not 20 years down the road

Copilot, Microsoft’s brand of generative AI, will soon be far more deeply integrated into the Windows 11 experience.

Microsoft wants to make Windows an AI operating system, launches Copilot+ PCs

Hello and welcome back to TechCrunch Space. For those who haven’t heard, the first crewed launch of Boeing’s Starliner capsule has been pushed back yet again to no earlier than…

TechCrunch Space: Star(side)liner

When I attended Automate in Chicago a few weeks back, multiple people thanked me for TechCrunch’s semi-regular robotics job report. It’s always edifying to get that feedback in person. While…

These 81 robotics companies are hiring

The top vehicle safety regulator in the U.S. has launched a formal probe into an April crash involving the all-electric VinFast VF8 SUV that claimed the lives of a family…

VinFast crash that killed family of four now under federal investigation

When putting a video portal in a public park in the middle of New York City, some inappropriate behavior will likely occur. The Portal, the vision of Lithuanian artist and…

NYC-Dublin real-time video portal reopens with some fixes to prevent inappropriate behavior

Longtime New York-based seed investor, Contour Venture Partners, is making progress on its latest flagship fund after lowering its target. The firm closed on $42 million, raised from 64 backers,…

Contour Venture Partners, an early investor in Datadog and Movable Ink, lowers the target for its fifth fund

Meta’s Oversight Board has now extended its scope to include the company’s newest platform, Instagram Threads, and has begun hearing cases from Threads.

Meta’s Oversight Board takes its first Threads case

The company says it’s refocusing and prioritizing fewer initiatives that will have the biggest impact on customers and add value to the business.

SeekOut, a recruiting startup last valued at $1.2 billion, lays off 30% of its workforce

The U.K.’s self-proclaimed “world-leading” regulations for self-driving cars are now official, after the Automated Vehicles (AV) Act received royal assent — the final rubber stamp any legislation must go through…

UK’s autonomous vehicle legislation becomes law, paving the way for first driverless cars by 2026

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

SoLo Funds CEO Travis Holoway: “Regulators seem driven by press releases when they should be motivated by true consumer protection and empowering equitable solutions.”

Fintech lender SoLo Funds is being sued again by the government over its lending practices

Hard tech startups generate a lot of buzz, but there’s a growing cohort of companies building digital tools squarely focused on making hard tech development faster, more efficient and —…

Rollup wants to be the hardware engineer’s workhorse

TechCrunch Disrupt 2024 is not just about groundbreaking innovations, insightful panels, and visionary speakers — it’s also about listening to YOU, the audience, and what you feel is top of…

Disrupt Audience Choice vote closes Friday

Google says the new SDK would help Google expand on its core mission of connecting the right audience to the right content at the right time.

Google is launching a new Android feature to drive users back into their installed apps

Jolla has taken the official wraps off the first version of its personal server-based AI assistant in the making. The reborn startup is building a privacy-focused AI device — aka…

Jolla debuts privacy-focused AI hardware

The ChatGPT mobile app’s net revenue first jumped 22% on the day of the GPT-4o launch and continued to grow in the following days.

ChatGPT’s mobile app revenue saw its biggest spike yet following GPT-4o launch

Dating app maker Bumble has acquired Geneva, an online platform built around forming real-world groups and clubs. The company said that the deal is designed to help it expand its…

Bumble buys community building app Geneva to expand further into friendships

CyberArk — one of the army of larger security companies founded out of Israel — is acquiring Venafi, a specialist in machine identity, for $1.54 billion. 

CyberArk snaps up Venafi for $1.54B to ramp up in machine-to-machine security

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

2 days ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022

Creative Artists Agency (CAA), one of the top entertainment and sports talent agencies, is hoping to be at the forefront of AI protection services for celebrities in Hollywood. With many…

Hollywood agency CAA aims to help stars manage their own AI likenesses

Expedia says Rathi Murthy and Sreenivas Rachamadugu, respectively its CTO and senior vice president of core services product & engineering, are no longer employed at the travel booking company. In…

Expedia says two execs dismissed after ‘violation of company policy’