It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…
What if that "repair" was done by NSA, CIA, etc? Should the phone boot like nothing happened? Seriously?
iPhones 'disabled' if Apple detects third-party repairs
181–190 of 363 posts
Re: iPhones 'disabled' if Apple detects third-party repairs
#182If that is the case and it was possible to replace these sensors before, apple's narrative that the "error 53" code was introduced for security reasons doesn't seem to make a lot of sense: If the hardware sensor wasn't designed with secure authorization (e.g. via asymmetric cryptography) in the first place, all they could do now in a software update would be to add some kind of cosmetic device ID check.
However, any such newly introduced check in software could not actually prevent "malicious sensor" attacks but would only add a (possibly trivial) additional step to the attack where you have to spoof the correct device id.
Or maybe my reading of the guardian article is imprecise and replacing the home button has always meant loosing access to at least some security-relevant features?
Re: iPhones 'disabled' if Apple detects third-party repairs
#183Earlier quoted context omitted.
The scenario they're protecting against appears (to me) to be a bad actor changing the hardware. If the Touch ID sensor is bad, and you propose falling back to a PIN, who's to say the digitizer isn't compromised too and is recording touches? Sounds a bit like a downgrade attack if they didn't fail fast and hard at the earliest opportunity.
I don't think they are protecting against that scenario so much as not accounting for it. I expect Apple's assumption is that they provide all components for their devices. People who install unauthorised third party components can no longer have those devices serviced by Apple — so it no longer matters to Apple whether those devices are compromised, because they aren't really "Apple" devices at that point anyway. Th…
No matter what the motives behind this mechanism were, it was put in place exactly to prevent 3rd party scanners from working.
And if they implemented authentication and didn't even test what happens if it fails, then well... how do they know it works at all?
Re: iPhones 'disabled' if Apple detects third-party repairs
#184Damned if they do, and damned if they don't. "Anyone can access your private photos and emails! Just replace the home button with one programmed with your own fingerprints!" Can you imagine the comments if that were a story? The problem here is that Apple didn't find a way to tell repair shops and users that this could be an issue.
This attack you suppose Apple is defending against is not possible.
The only attack Apple is really defending against is the attack of non-Apple phone repair companies.
Re: iPhones 'disabled' if Apple detects third-party repairs
#185Earlier quoted context omitted.
What would you suggest instead and why?
Using the word retard victimises a group that is already significantly marginalised while simultaneously not doing much to the intended victim. The word has a greater affect on unintended, innocent, victims than the intended target. If you're talking about IQ less than 70 use whatever is relevant in the country you're in. In the US this is usually intellectual disability (which is a subset of learning disability, whi…
Dumb = mute
Idiot, moron = low IQ
Lame = non-functioning limb
The problem is not choice of words, the problem is insulting someone by calling them "low intelligence" instead of short-sighted (oops! That's a visual disability) or careless or selfish or unimaginative or impatient.
Re: iPhones 'disabled' if Apple detects third-party repairs
#186http://www.consumer.ftc.gov/articles/0138-auto-warranties-ro...
Re: iPhones 'disabled' if Apple detects third-party repairs
#187Earlier quoted context omitted.
It doesn't have to be either or. Apple could provide a better fail over behavior for the home key, including a way for a consumer to validate the changed hardware. For instance: "IOS has detected a change in your Secure Home Key. Please contact apple secure support to confirm that your device is still secure!" add a 1-800 number and some security questions. Or automate it by requiring a login to your Apple account, e…
> Please contact apple secure support to confirm that your device is still secure There's no way the customer or Apple can do that with third party hardware installed. The only solution I can see is to disable all of the features relying on Touch ID.
Re: iPhones 'disabled' if Apple detects third-party repairs
#188Re: iPhones 'disabled' if Apple detects third-party repairs
#189Wouldn't a better idea be to simply display an error message to the effect of "your phone has undergone untrusted changes, please bring to your nearest Apple store" rather than bricking the whole thing?
Re: iPhones 'disabled' if Apple detects third-party repairs
#190It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…
Seems more like short sightedness than "petty revenge." The new home button hardware can't be securely validated, and a future OS update fails on the unexpected condition of invalid Touch ID hardware. I can imagine that this wasn't a prioritised testing scenario, likely not even considered by Apple when developing iOS. It's a lousy way to fail — the phone should just disable Touch ID and Apple Pay, and anything that…