Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

161–170 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#161
post #17

Earlier quoted context omitted.

It may even be against the law in Europe because the phone was working perfectly after the repair and only the later update locked the phone without the ability to unlock it. To keep with the care maker example, in Germany, the car makers used to void the 10 years guarantee on the painting of the car if the regular checks were done by an independent car shop. This was then declared as illegal. I suppose Apple will so…

No, the phone did not work perfectly after the repair. The fact that the user didn't realise it didn't work perfectly doesn't change that. The repair compromised the security of the device. Image if you have your tires changed by an independent car shop and a month later one of your wheels falls off on the highway. Do you start complaining about it to the car's manufacturer because 'it worked perfectly before'. No yo…

Except that the wheels didn't fall off the phone. This lockup happens due to code proactively added by Apple. You are confusing three different issues: the design of the system, the legality, and how security should work. In this case, none of those three items align. This is Apple's problem - they chose the easiest option for themselves, not what would benefit customers legally, functionally, or by securing the device properly.

You are fundamentally misunderstanding the threat model. What is the exact threat that Apple is guarding against? Is it an evil maid attack planting new sensors, switched devices, someone's fingers being cut off? All of these require different mitigations - none of which for a general purpose consumer phone are to brick the device when upgrading.

Re: iPhones 'disabled' if Apple detects third-party repairs

#162
post #68

Earlier quoted context omitted.

By the way, "dumb" means unable to speak, or mute. Using "dumb" as a synonym for stupid is as offensive as using "retarded" as a synonym for idiotic. Which, in my opinion, is not at all.

The words idiot, imbecile and so on used to have a technical meaning of someone landing in a specific IQ range. Idiotic is a synonym of retarded.

"Mentally retarded" used to be a medical term too. They just renamed it to "intellectual disability" after "retarded" became more widely used as a slur. https://en.m.wikipedia.org/wiki/Intellectual_disability

Re: iPhones 'disabled' if Apple detects third-party repairs

#164
post #5
post #2

The way they've reported on this seems a bit misleading. Isn't it just that the third-party repairers haven't reset the security mechanism after replacing the home button?

The problem is, Apple refuses to reset the security mechanism after such repairs have happened. Ergo, Apple is bricking phones as some sort of misplaced revenge-like behavior.

This doesn't follow. Apple refuses to reset the security mechanism because it can't verify the integrity of the repair.

Call it revenge like behavior is just you attacking Apple. It's certainly incompetent or unanticipated and poorly handled, but it's an attempt to maintain their security promises.

Re: iPhones 'disabled' if Apple detects third-party repairs

#165
post #157

Earlier quoted context omitted.

> The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. The correct solution there would be to pop up a warning saying the TouchID hardware has been tampered with, and giving the user an option to validate it.

That wouldn't really be a good idea. Someone could steal your phone and replace the TouchID hardware. Then this popup comes up and they say, oh yeah this hardware is totally legit! Then they get your data, impersonate you, charge stuff etc.

The prompt would have to be after you authenticated your phone in some other way, like via the passcode.

I think it's totally OK not to accept authentication from an unvalidated device, but a legitimate user should be able to do the validation.

Re: iPhones 'disabled' if Apple detects third-party repairs

#166
post #129
post #64

Earlier quoted context omitted.

> Remember the woman who proved that Apple consistently slows down sold iPhones with "updates" right before the launch date of a new model? No. Story linked from daily mail (that's not a "source") is more nuanced. http://www.nytimes.com/2014/07/27/upshot/hold-the-phone-a-bi...

From the link: "The important distinction is of intent. In the benign explanation, a slowdown of old phones is not a specific goal, but merely a side effect of optimizing the operating system for newer hardware" When we try to judge intent we do judge the context. So let's look at the context: people do know that iPhone updates will probably slow their device(even though Apple doesn't tell them that). And there's no…

Software getting slower with updates is a fact of life. It's been an obvious and expected thing since I started being aware of computers and updates in the late 1980s and I'm sure it was a thing even before that. The odds that Apple is doing this on purpose, rather than as a standard side effect of cramming ever more features into their stuff, are so low it doesn't bear more than a moment's consideration.

What's next, people say Apple deliberately destroys batteries after a few years, rather than being a natural consequence of battery chemistry? Apple deliberately makes their screens shatter when dropped?

Re: iPhones 'disabled' if Apple detects third-party repairs

#167
post #110

Earlier quoted context omitted.

People buy a high-end watch, like a Rolex. They can repair it if they have then knowledge. The problem is Rolex, and 99 percent of watch manufactures won't sell your, or your Watch Repair person the parts. You need to send the watch to the factory for service, at factory prices. So, when you buy a Rolex, your are actually leasing it? You don't truely own it, if you can't get the parts to fix it? It's just another way…

Actually a majority of the watches, besides Rolex, in the <$5000 range use standard unmodified Swiss ETA movements, which can be repaired by any competent watchmaker. Very few watches in this price range use in-house movements.

http://watchguy.co.uk/swatch-group-parts-policy/

Re: iPhones 'disabled' if Apple detects third-party repairs

#168
post #107

Earlier quoted context omitted.

There's a lot of stuff that depends on the secure element - in fact the phone would be quite useless without it. In fact, when you first reboot your phone, even contacts cannot be accessed until you authenticate with your passcode to unlock the secure element. Incoming text messages only show the phone number. You're right, however - a Touch ID sensor that cannot be verified should not brick the phone. Apple should j…

The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.

> The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device.

What are you even talking about?

If the fingerprint scanner is suspicious, just disable it and leave the rest running. And this is in fact what happens, until a software update is installed and then the phone suddenly decides to brick itself completely.

Re: iPhones 'disabled' if Apple detects third-party repairs

#169
There is a strong bias, and the amazing thing is that its very difficult for the people who have this bias to realize it. As far as they can tell it is fact, and this is in large part because they live in a filter bubble where they only see things that confirm their bias.

For example: Articles bashing Steve Jobs get upvoted a lot more than ones praising him. Exactly the opposite for bill Gates.

Now if you look at Slashdot a decade before Hacker news the results for bill gates would have been the opposite of what you see here.

Effectively, Bill Gates' millions in spending to improve his PR have changed people's perceptions (they will argue that its because he's such a generous benefactor, because that's politically correct, alas, they won't look too close at the activities of the Bill and Melinda Gates foundation lest they notice he isn't.)

Google Good, Apple Bad, Leftism Good, Socialism Good, Basic Income! Global Warming is FACT, and anything you post that goes against this narrative risks getting you slow banned or hellbanned.

Hell, I was once banned from here for relating how I met Grace Hopper as a kid (in a comment on an article about Grace Hopper.)

I have no clue why that was hell ban worthy, after all she was the original "GRrrl in tech!!11!"

Welcome to hacker news where there are no hackers.

Re: iPhones 'disabled' if Apple detects third-party repairs

#170
post #17

Earlier quoted context omitted.

It may even be against the law in Europe because the phone was working perfectly after the repair and only the later update locked the phone without the ability to unlock it. To keep with the care maker example, in Germany, the car makers used to void the 10 years guarantee on the painting of the car if the regular checks were done by an independent car shop. This was then declared as illegal. I suppose Apple will so…

No, the phone did not work perfectly after the repair. The fact that the user didn't realise it didn't work perfectly doesn't change that. The repair compromised the security of the device. Image if you have your tires changed by an independent car shop and a month later one of your wheels falls off on the highway. Do you start complaining about it to the car's manufacturer because 'it worked perfectly before'. No yo…

Your analogy is way off.

This is more like your Tesla car's keyfob misfunctioning and you get it repaired by a non-Tesla dealer. The dealer could've put in a backdoor to get into the vehicle.

Tesla releases a big new update for their car software and now your Tesla is completely bricked and Tesla refuses to repair it, saying you have to buy a new car.

Is that acceptable?

Post reply on HN