No menu items!

COSTA RICA'S LEADING ENGLISH LANGUAGE NEWSPAPER

HomeTopicsBusinessThe technology at the heart of the Apple-FBI debate, explained

The technology at the heart of the Apple-FBI debate, explained

What if the FBI could force Samsung to covertly turn on the video camera in your smart TV? Or force Google to deliver a malicious security update to your web browser that actually spied on you and transmitted your passwords and other sensitive information back to the FBI? Sound like something from a dystopian sci-fi movie? If Apple loses its high-profile legal fight with the U.S. government, these scenarios could become a reality. This will also threaten the security of all Internet users.

Until relatively recently, consumers were often nagged to look for and download software updates. This is something that many of us didn’t do, promptly, or often, at all. As a result, many people ran out-of-date, insecure software, leaving them unnecessarily vulnerable to cyber attacks and computer viruses.

In an effort to get prompt security updates to as many consumers and businesses as possible, the software industry has largely shifted to a model of automatic updates. As a result, our phones, computers and Internet of Things devices (such as thermostats and smart TVs) now regularly call their makers to look for updates, which are then automatically downloaded and installed.

The transition to automatic updates has significantly improved the state of cybersecurity. However, the existence of a mechanism to quietly deliver software onto phones and computers without the knowledge or consent of a user could be misused by criminals, hackers and nation states.

It is for that reason that tech companies have built in an additional security feature, known as “code signing,” through which companies can certify the software updates they’ve created are authentic. Without a digital signature proving the authenticity of the software update, it cannot be installed. This code signing mechanism ensures that only Microsoft can deliver updates for Word, only Apple can distribute updates for iOS, and only Google can deliver updates for its Chrome browser.

Apple FBI iPhone
Mark Ralston/AFP

Earlier this month, the public learned that the U.S. Department of Justice had sought and obtained a court order forcing Apple to help it hack into the iPhone of Syed Rizwan Farook, one of the San Bernardino shooters. The court ordered Apple to create a new, special version of Apple’s iOS operating system that bypasses several security features built into the company’s operating system. The court also ordered Apple to sign the custom version of the software. Without this digital signature certifying the software’s authenticity, the iPhone would refuse to run it.

Experts fear that the precedent that the government is seeking in this case – to be able to force Apple to sign code for the government – could allow the government to force other technology companies to sign surveillance software and then push it to individual users’ devices, using the automatic update mechanisms that regularly look for and download new software.

If consumers fear that the software updates they receive from technology companies might secretly contain surveillance software from the FBI, many of them are likely to disable those automatic updates. And even if you aren’t worried about the FBI spying on you, if enough other people are, you will still face increased threats from hackers, identity thieves and foreign governments.

There are a lot of parallels between computer security and public health, and in many ways, software updates are like immunizations for our computers. Just as we want parents to get their children immunized, we want computers to receive regular software updates. Indeed, just as the decision by some parents to not vaccinate their children puts their entire community at risk, so too the decision to turn off automatic updates not only impacts the individual, but other users and organizations, as those vulnerable, infected users’ computers will be used by hackers to target others.

The trust that people have placed in software companies is far too important to risk destroying to make it easier for the government to spy. And the precedent the government is seeking in this case will not just apply to Apple, but, in an age of Internet of Things, to the TVs, thermostats and other smart-devices with cameras and microphones we are inviting into our homes.

The author is the Principal Technologist with the Speech, Privacy & Technology Project at the American Civil Liberties Union.

© 2016, The Washington Post

 

Trending Now

Costa Rica Says Ocean Conservation Must Benefit Fishing Communities

Costa Rica used a major international environmental finance meeting in Uzbekistan to present a marine conservation message built around coastal communities, fishing families and...

Costa Rica’s Capital Turns to 3,000 Trees to Cool San José

San José is moving to confront one of the capital’s most visible climate problems: heat trapped by concrete, asphalt and traffic. The Municipality of...

Guanacaste Faces One of Its Worst Droughts as Rain Hits Much of Costa Rica

Guanacaste is facing one of its worst drought situations in years, even as much of Costa Rica deals with heavy rain, saturated soils and...

Costa Rica Tax Revenue Keeps Falling as UNA Economists Urge Fiscal Reform

A public university research center has called a comprehensive fiscal reform "necessary and urgent," warning that Costa Rica's tax revenue has been sliding since...

Documentary Highlights Costa Rica’s Howler Monkey Crisis

There is a sound that defines the Costa Rican jungle before dawn: a deep, resonant roar that can carry for five kilometers through the...

Costa Rica Storm Cristina Leaves Five Missing Along Pacific Coast

Five people were missing off Costa Rica's Pacific coast on Tuesday after two small boats capsized in heavy surf whipped up by Tropical Storm...

Costa Rica Rolls Out Plan as El Niño Officially Arrives

El Niño is no longer a forecast for Costa Rica. It's here. The U.S. National Oceanic and Atmospheric Administration (NOAA) confirmed Thursday that the...

Canatur Criticizes Ride-Sharing Apps Being Used to Promote Costa Rica

Costa Rica’s main tourism chamber is pushing back against the use of ride-sharing platforms in official tourism promotion, arguing that public and private campaigns...

Costa Rica’s Forgotten WWII Role Echoes on D-Day’s 82nd Anniversary

Eighty-two years ago today, roughly 160,000 Allied troops landed in Normandy, France, launching Operation Overlord to liberate German-occupied Western Europe — the single day...
🌴 The Weekly Pura Vida

Costa Rica, Once a Week

The week's top stories, weather & insider tips — delivered every Sunday. One email, zero clutter.

🔒 Free. No spam. Unsubscribe anytime.

Loading…

Latest News from Costa Rica

Costa Rica Coffee Maker Chorreador
Costa Rica Car Rentals
Costa Rica Travel Insurance
Costa Rica Travel