Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

91–100 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#91

This is just the beginning. High prices and resale values have spawned a substantial and apparently growing 3rd party repair and refurbishment market for Apple mobile devices. Beyond the dodgy corner unlock shops, multiple national chains have sprung up over the last 2 years where I live that advertise heavily on broadcast TV. Apple clearly sees this as money left on the table and they're concerned about the emergenc…

People buy a high-end watch, like a Rolex. They can repair it if they have then knowledge. The problem is Rolex, and 99 percent of watch manufactures won't sell your, or your Watch Repair person the parts.

You need to send the watch to the factory for service, at factory prices.

So, when you buy a Rolex, your are actually leasing it? You don't truely own it, if you can't get the parts to fix it?

It's just another way to make money.

I didn't think Apple would irritate their customers at this particular point in time?

And yes, I too believe, "This is just the beginning."

Re: iPhones 'disabled' if Apple detects third-party repairs

#92
post #80

Earlier quoted context omitted.

Touch ID is a fingerprint scanner, but the Touch ID system is paired with the "Secure Enclave" in Apple's AX chips. Secure Enclave is a separate coprocessor running its own L4-based microkernel. This hardware is directly paired with security-sensitive hardware (Touch ID, Apple Pay NFC chip, etc). It provides all cryptographic operations for data protection key management and maintains the integrity of data protection…

Does this mean your fingerprint never leaves the scanners coprocessor and is inaccessible to iOS and the other processors and OSs within the phone?

Basically, yes. The Secure Enclave is hardware isolated from the rest of the chip.

Apple's own security guide explains it best [1]:

> The Secure Enclave is responsible for processing fingerprint data from the Touch ID sensor, determining if there is a match against registered ngerprints, and then enabling access or purchases on behalf of the user. Communication between the processor and the Touch ID sensor takes place over a serial peripheral interface bus. The processor forwards the data to the Secure Enclave but cannot read it. It’s encrypted and authenticated with a session key that is negotiated using the device’s shared key that is provisioned for the Touch ID sensor and the Secure Enclave. The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption.

Regarding the actual fingerprint storage, it looks like the encryption key is kept in the Secure Enclave and the entire decryption and verification process occurs within the Secure Enclave. However the encrypted data itself may be stored outside the Secure Enclave:

> The raster scan is temporarily stored in encrypted memory within the Secure Enclave while being vectorized for analysis, and then it’s discarded. The analysis utilizes sub-dermal ridge flow angle mapping, which is a lossy process that discards minutia data that would be required to reconstruct the user’s actual fingerprint. The resulting map of nodes is stored without any identity information in an encrypted format that can only be read by the Secure Enclave, and is never sent to Apple or backed up to iCloud or iTunes.

[1] https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Re: iPhones 'disabled' if Apple detects third-party repairs

#93
post #80

Earlier quoted context omitted.

Touch ID is a fingerprint scanner, but the Touch ID system is paired with the "Secure Enclave" in Apple's AX chips. Secure Enclave is a separate coprocessor running its own L4-based microkernel. This hardware is directly paired with security-sensitive hardware (Touch ID, Apple Pay NFC chip, etc). It provides all cryptographic operations for data protection key management and maintains the integrity of data protection…

Does this mean your fingerprint never leaves the scanners coprocessor and is inaccessible to iOS and the other processors and OSs within the phone?

[deleted]

Re: iPhones 'disabled' if Apple detects third-party repairs

#94
post #80

Earlier quoted context omitted.

Touch ID is a fingerprint scanner, but the Touch ID system is paired with the "Secure Enclave" in Apple's AX chips. Secure Enclave is a separate coprocessor running its own L4-based microkernel. This hardware is directly paired with security-sensitive hardware (Touch ID, Apple Pay NFC chip, etc). It provides all cryptographic operations for data protection key management and maintains the integrity of data protection…

Does this mean your fingerprint never leaves the scanners coprocessor and is inaccessible to iOS and the other processors and OSs within the phone?

[deleted]

Re: iPhones 'disabled' if Apple detects third-party repairs

#95

This is just the beginning. High prices and resale values have spawned a substantial and apparently growing 3rd party repair and refurbishment market for Apple mobile devices. Beyond the dodgy corner unlock shops, multiple national chains have sprung up over the last 2 years where I live that advertise heavily on broadcast TV. Apple clearly sees this as money left on the table and they're concerned about the emergenc…

I think IPhone owners intend their device to last longer than the typical Android. Making it harder to repair could undermine that. Apple need to make users believe that an IPhone is not just a disposable thing that lasts for 1 year in order to justify the high price.

Re: iPhones 'disabled' if Apple detects third-party repairs

#96
post #39
post #4

It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…

Remember the woman who proved that Apple consistently slows down sold iPhones with "updates" right before the launch date of a new model? [0] Apple is in the business of selling (overpriced/overengineered) hardware. Their tactics make that very clear. The only problem with that is that there is no real competition in mobile phones anymore, it's just a giant duopoly. Sure, you can switch to Google/Android, which as th…

No, it doesn't -- It just shows that people google "iPhone slow" more when new models come out / Apple releases major versions.

> No matter how suggestive, he says, the data alone doesn't allow anyone to determine conclusively whether their phone is any slower.

> There are other explanations for why an older model iPhone may slow down, he claims.

> For instance, the latest version of the Apple operating system, iOS, is always tailored to the newest device and may therefore not work as efficiently on older models.

Re: iPhones 'disabled' if Apple detects third-party repairs

#97
post #11

Albeit necessary to check the authenticity of components such as the TouchID sensor for security reasons, bricking the phones seems extreme. Why not simply disable Touch ID? This is them asking for a lawsuit.

I wonder if it's really bricked -- could a downgrade to the previous OS version help? (Admittedly, it's not that straightforward for normal consumers.)

Re: iPhones 'disabled' if Apple detects third-party repairs

#98

Correct me if I'm wrong, but from what I understand this is done to protect the customers from tampered with Touch ID sensors. It may be overly paranoid but I can at least understand the motivation behind this. Changing the display also involves disconnecting the Touch ID sensor so technically a malicious person might have done something that exposes the user of the device in some way. Statement from an Apple spokesw…

> "the device remains secure."

A non functioning bricked device is more secure than a functioning device. Yes.

Re: iPhones 'disabled' if Apple detects third-party repairs

#99
post #68

Earlier quoted context omitted.

I'm sorry, I did not mean to offend anybody but my reading of the word is that it has two meanings, one of which is 'stupid or dumb'. I'll update the comment.

By the way, "dumb" means unable to speak, or mute. Using "dumb" as a synonym for stupid is as offensive as using "retarded" as a synonym for idiotic. Which, in my opinion, is not at all.

The words idiot, imbecile and so on used to have a technical meaning of someone landing in a specific IQ range. Idiotic is a synonym of retarded.

Re: iPhones 'disabled' if Apple detects third-party repairs

#100
post #4

It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…

What if that "repair" was done by NSA, CIA, etc? Should the phone boot like nothing happened? Seriously?
Post reply on HN