OPINION

The Technology at the Heart of the Apple-FBI Debate, Explained

Advertisement
By Christopher Soghoian, The Washington Post | Updated: 1 March 2016 17:09 IST
What if the FBI could force Samsung to covertly turn on the video camera in your smart TV? Or force Google to deliver a malicious security update to your web browser which actually spied on you and transmitted your passwords and other sensitive information back to the FBI? Sound like something from a dystopian sci-fi movie? If Apple loses its high-profile legal fight with the US government, these scenarios could become a reality. This will also threaten the security of all Internet users.

Until relatively recently, consumers were often nagged to look for and download software updates. This is something that many of us didn't do, promptly, or often, at all. As a result, many people ran out-of-date, insecure software, leaving them unnecessarily vulnerable to cyber-attacks and computer viruses.

In an effort to get prompt security updates to as many consumers and businesses as possible, the software industry has largely shifted to a model of automatic updates. As a result, our phones, computers and Internet of Things devices (such as thermostats and smart TVs) now regularly call their makers to look for updates, which are then automatically downloaded and installed.

Advertisement

The transition to automatic updates has significantly improved the state of cyber-security. However, the existence of a mechanism to quietly deliver software onto phones and computers without the knowledge or consent of a user could be misused by criminals, hackers and nation states.

It is for that reason that tech companies have built in an additional security feature, known as "code signing," through which companies can certify the software updates they've created are authentic. Without a digital signature proving the authenticity of the software update, it cannot be installed. This code signing mechanism ensures that only Microsoft can deliver updates for Word, only Apple can distribute updates for iOS, and only Google can deliver updates for its Chrome browser.

Advertisement

Earlier this month, the American public learned that the Department of Justice had sought and obtained a court order forcing Apple to help it hack into the iPhone of Syed Rizwan Farook, one of the San Bernardino shooters. The court ordered Apple to create a new, special version of Apple's iOS operating system that bypasses several security features built into the company's operating system. The court also ordered Apple to sign the custom version of the software. Without this digital signature certifying the software's authenticity, the iPhone would refuse to run it.

(Also see:  Apple Resisting Magistrate Order to Share iPhone Information)

Experts fear that the precedent that the government is seeking in this case - to be able to force Apple to sign code for the government - could allow the government to force other technology companies to sign surveillance software and then push it to individual users' devices, using the automatic update mechanisms that regularly look for and download new software.

Advertisement

(Also see:  Judge Sides With Apple in NY Drug Probe iPhone Case)

If consumers fear that the software updates they receive from technology companies might secretly contain surveillance software from the FBI, many of them are likely to disable those automatic updates. And even if you aren't worried about the FBI spying on you, if enough other people are, you will still face increased threats from hackers, identity thieves and foreign governments.

Advertisement

(Also see:  Apple vs. FBI: Is Your iPhone Safe?)

There are a lot of parallels between computer security and public health, and in many ways, software updates are like immunizations for our computers. Just as we want parents to get their children immunized, we want computers to receive regular software updates. Indeed, just as the decision by some parents to not vaccinate their children puts their entire community at risk, so too the decision to turn off automatic updates not only impacts the individual, but other users and organizations, as those vulnerable, infected users' computers will be used by hackers to target others.

The trust that Americans have placed in software companies is far too important to risk destroying to make it easier for the government to spy. And the precedent the government is seeking in this case will not just apply to Apple, but, in an age of Internet of Things, to the TVs, thermostats and other smart-devices with cameras and microphones we are inviting into our homes.

© 2016 The Washington Post

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, Encryption, FBI, Mobiles, Tim Cook, iPhone
Advertisement

Related Stories

Popular Mobile Brands
  1. How Instagram's Edits App Evolved Over the Past Year and What's Next
  2. Oppo F33 Pro 5G Review: The Best Looking Phone Under Rs. 40,000?
  3. Control Ultimate Edition is Now Available on iPhone and iPad
  4. Sennheiser CX 80U, HD 400U With USB Type-C Connectivity Launched in India
  1. NASA’s Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  2. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  3. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  4. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  5. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  6. Coinbase Announces USDC-INR Trading Services for Users in India
  7. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  8. Suyodhana OTT Release Date: When and Where to Watch This Telugu Mystry Thriller Online?
  9. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  10. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.