Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

141–150 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#141
post #125
post #107

Earlier quoted context omitted.

The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.

How? TouchID is the less secure authentication than password/PIN anyway (which is shown by the fact that you need to enter PIN/Pass right after boot). How would just disabling TouchID auth be a worse option?

>TouchID is the less secure authentication than password/PIN anyway (which is shown by the fact that you need to enter PIN/Pass right after boot).

The fact that you need to enter PIN right after boot, just shows that they use "two factor authentication" to make it even more secure.

It doesn't IN ANY WAY show that TouchID is "the less secure authentication" method of the two.

Re: iPhones 'disabled' if Apple detects third-party repairs

#142
post #111
post #17

Earlier quoted context omitted.

It may even be against the law in Europe because the phone was working perfectly after the repair and only the later update locked the phone without the ability to unlock it. To keep with the care maker example, in Germany, the car makers used to void the 10 years guarantee on the painting of the car if the regular checks were done by an independent car shop. This was then declared as illegal. I suppose Apple will so…

It would be definitely illegal in France which has a law against planned obsolescence - but EU doesn't have it yet. https://en.m.wikipedia.org/wiki/Planned_obsolescence#Regulat...

Only if it was "planned obsolescence" and not "a security measure".

Re: iPhones 'disabled' if Apple detects third-party repairs

#143
post #107

Earlier quoted context omitted.

There's a lot of stuff that depends on the secure element - in fact the phone would be quite useless without it. In fact, when you first reboot your phone, even contacts cannot be accessed until you authenticate with your passcode to unlock the secure element. Incoming text messages only show the phone number. You're right, however - a Touch ID sensor that cannot be verified should not brick the phone. Apple should j…

The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.

> The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device.

The correct solution there would be to pop up a warning saying the TouchID hardware has been tampered with, and giving the user an option to validate it.

Re: iPhones 'disabled' if Apple detects third-party repairs

#144
post #4

It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…

>Imagine the same thing happening to your car.

That sort of exists now. There are parts, like the throttle control on Volvo's, ABS units on BMW's, etc, where the unit is coded to your vehicle.

You can't, for example, swap an otherwise identical throttle from a junkyard into a Volvo. It puts the ECU into limp mode, and the car is essentially useless.

Now, that's not the result of an over-the-wire firmware update, but that's really the only piece missing. When/If vehicles start regularly updating firmware over the wire, you'll start seeing stuff like this.

Re: iPhones 'disabled' if Apple detects third-party repairs

#145
post #125

Earlier quoted context omitted.

How? TouchID is the less secure authentication than password/PIN anyway (which is shown by the fact that you need to enter PIN/Pass right after boot). How would just disabling TouchID auth be a worse option?

> TouchID is the less secure authentication than password/PIN anyway (which is shown by the fact that you need to enter PIN/Pass right after boot). The fact that you need to enter PIN right after boot, just shows that they use "two factor authentication" to make it even more secure. It doesn't IN ANY WAY show that TouchID is "the less secure authentication" method of the two.

You can do anything you want on the phone without using Touch ID at all. The fingerprint sensor is not a necessary factor in their implementation, while the passcode is.

Re: iPhones 'disabled' if Apple detects third-party repairs

#146

Earlier quoted context omitted.

What would you suggest instead and why?

Call it what it actually is: short sighted, greedy, foolish, etc. Don't use a word that puts down people with disabilities.

Wow. It's 2016, and you're still saying bigoted words like "fool." My great grandfather was a court jester, and he was a very intelligent man. Why don't you read up on the history of tyrants and entertainment before you go throwing around such hateful speech.

Re: iPhones 'disabled' if Apple detects third-party repairs

#147
post #17
post #4

It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…

It may even be against the law in Europe because the phone was working perfectly after the repair and only the later update locked the phone without the ability to unlock it. To keep with the care maker example, in Germany, the car makers used to void the 10 years guarantee on the painting of the car if the regular checks were done by an independent car shop. This was then declared as illegal. I suppose Apple will so…

No, the phone did not work perfectly after the repair. The fact that the user didn't realise it didn't work perfectly doesn't change that. The repair compromised the security of the device.

Image if you have your tires changed by an independent car shop and a month later one of your wheels falls off on the highway. Do you start complaining about it to the car's manufacturer because 'it worked perfectly before'. No you don't.

The repair shop didn't repair it properly, if it was repaired properly the new TouchID sensor would be securely paired with the Secure Enclave and this issue would not occur.

Re: iPhones 'disabled' if Apple detects third-party repairs

#150

You DO have the right to repair your iPhone; it just has to be done by an official Apple repair centre. I completely understand the downsides of Apple's particular approach here, and totally get why people want the right to use 3rd party repair services. I've used them myself in the past to save (a lot of) money. But considering just how much of my life, financial and otherwise, is on my phone, I'm actually very glad…

> and totally get why people want the right to use 3rd party repair services. I've used them myself in the past to save (a lot of) money.

The BBC article talks about someone who was in Macedonia. Apple doesn't have repair centres there. What they did - try to repair their device in a non-Apple-served country - was about all they could reasonably do.

As Apple wants more of our life to be phone-oriented (payment details, wallet, physical data, etc) expecting 100% of people to be within X minutes of official repair centers 100% of the time is not workable, nor reasonable.

I get it - the home button is secure and might have been compromised. This was just horrible design - they failed to account for a failure mode, and default to a brick instead.

A warning bar or message on boot indicating "the touch id may have been compromised - all touch id features are disabled - please contact Apple" - while annoying - would have been reasonable.

Post reply on HN