Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

181–190 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#181
post #100
post #4

It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…

What if that "repair" was done by NSA, CIA, etc? Should the phone boot like nothing happened? Seriously?

My thoughts exactly.

Re: iPhones 'disabled' if Apple detects third-party repairs

#182
I'm not sure I understand what exactly happened here. Was it previously possible for non-apple engineers to replace the home button or was it not? The guardian's article seems to suggest it was: "Indeed, the phone may have been working perfectly for weeks or months since a repair or being damaged."

If that is the case and it was possible to replace these sensors before, apple's narrative that the "error 53" code was introduced for security reasons doesn't seem to make a lot of sense: If the hardware sensor wasn't designed with secure authorization (e.g. via asymmetric cryptography) in the first place, all they could do now in a software update would be to add some kind of cosmetic device ID check.

However, any such newly introduced check in software could not actually prevent "malicious sensor" attacks but would only add a (possibly trivial) additional step to the attack where you have to spoof the correct device id.

Or maybe my reading of the guardian article is imprecise and replacing the home button has always meant loosing access to at least some security-relevant features?

Re: iPhones 'disabled' if Apple detects third-party repairs

#183

Earlier quoted context omitted.

The scenario they're protecting against appears (to me) to be a bad actor changing the hardware. If the Touch ID sensor is bad, and you propose falling back to a PIN, who's to say the digitizer isn't compromised too and is recording touches? Sounds a bit like a downgrade attack if they didn't fail fast and hard at the earliest opportunity.

I don't think they are protecting against that scenario so much as not accounting for it. I expect Apple's assumption is that they provide all components for their devices. People who install unauthorised third party components can no longer have those devices serviced by Apple — so it no longer matters to Apple whether those devices are compromised, because they aren't really "Apple" devices at that point anyway. Th…

There is only one valid reason to authenticate the fingerprint scanner before using it, and that is to prevent the use of aftermarket replacements.

No matter what the motives behind this mechanism were, it was put in place exactly to prevent 3rd party scanners from working.

And if they implemented authentication and didn't even test what happens if it fails, then well... how do they know it works at all?

Re: iPhones 'disabled' if Apple detects third-party repairs

#184

Damned if they do, and damned if they don't. "Anyone can access your private photos and emails! Just replace the home button with one programmed with your own fingerprints!" Can you imagine the comments if that were a story? The problem here is that Apple didn't find a way to tell repair shops and users that this could be an issue.

That works, if and only if you already know the user's pin to unlock the phone.

This attack you suppose Apple is defending against is not possible.

The only attack Apple is really defending against is the attack of non-Apple phone repair companies.

Re: iPhones 'disabled' if Apple detects third-party repairs

#185
post #117

Earlier quoted context omitted.

What would you suggest instead and why?

Using the word retard victimises a group that is already significantly marginalised while simultaneously not doing much to the intended victim. The word has a greater affect on unintended, innocent, victims than the intended target. If you're talking about IQ less than 70 use whatever is relevant in the country you're in. In the US this is usually intellectual disability (which is a subset of learning disability, whi…

Almost very proposed alternative means somethig exactly equivalent to "retarded", a medical word for a disability. It's a euphemism treadmill.

Dumb = mute

Idiot, moron = low IQ

Lame = non-functioning limb

The problem is not choice of words, the problem is insulting someone by calling them "low intelligence" instead of short-sighted (oops! That's a visual disability) or careless or selfish or unimaginative or impatient.

Re: iPhones 'disabled' if Apple detects third-party repairs

#186
All these comparisons to car warranties, and more specifically how in some countries there may be a question of legality. The U.S. has similar laws that car dealers can't deny warranty coverage because of third party repairs. IANAL, but it would be interesting to see how this translates to phones (or any other similar asset).

http://www.consumer.ftc.gov/articles/0138-auto-warranties-ro...

Re: iPhones 'disabled' if Apple detects third-party repairs

#187

Earlier quoted context omitted.

It doesn't have to be either or. Apple could provide a better fail over behavior for the home key, including a way for a consumer to validate the changed hardware. For instance: "IOS has detected a change in your Secure Home Key. Please contact apple secure support to confirm that your device is still secure!" add a 1-800 number and some security questions. Or automate it by requiring a login to your Apple account, e…

> Please contact apple secure support to confirm that your device is still secure There's no way the customer or Apple can do that with third party hardware installed. The only solution I can see is to disable all of the features relying on Touch ID.

If they can issue an auth code for apple hardware then presumably it's possible to issue one for non apple hardware. They just have to make some effort to confirm the owner of the phone has it rather than a thief.

Re: iPhones 'disabled' if Apple detects third-party repairs

#188

Earlier quoted context omitted.

What would you suggest instead and why?

Call it what it actually is: short sighted, greedy, foolish, etc. Don't use a word that puts down people with disabilities.

"Short-sighted" is a visual disability.

Re: iPhones 'disabled' if Apple detects third-party repairs

#189
post #13

Wouldn't a better idea be to simply display an error message to the effect of "your phone has undergone untrusted changes, please bring to your nearest Apple store" rather than bricking the whole thing?

Or just after you enter your PIN (which can override the fingerprint reader anyways) notify you that the sensor has been replaced and reset it.

Re: iPhones 'disabled' if Apple detects third-party repairs

#190
post #4

It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…

Seems more like short sightedness than "petty revenge." The new home button hardware can't be securely validated, and a future OS update fails on the unexpected condition of invalid Touch ID hardware. I can imagine that this wasn't a prioritised testing scenario, likely not even considered by Apple when developing iOS. It's a lousy way to fail — the phone should just disable Touch ID and Apple Pay, and anything that…

[deleted]
Post reply on HN