There is a strong bias, and the amazing thing is that its very difficult for the people who have this bias to realize it. As far as they can tell it is fact, and this is in large part because they live in a filter bubble where they only see things that confirm their bias. For example: Articles bashing Steve Jobs get upvoted a lot more than ones praising him. Exactly the opposite for bill Gates. Now if you look at Sla…
For me, the real question is where have all the hackers gone? Years ago, there were high quality contributors here. They all had to go somewhere. When slashdot was dying, it was clear where everyone went (HN and Digg). This time around, it's not clear at all.
iPhones 'disabled' if Apple detects third-party repairs
191–200 of 363 posts
Re: iPhones 'disabled' if Apple detects third-party repairs
#192Earlier quoted context omitted.
There's a lot of stuff that depends on the secure element - in fact the phone would be quite useless without it. In fact, when you first reboot your phone, even contacts cannot be accessed until you authenticate with your passcode to unlock the secure element. Incoming text messages only show the phone number. You're right, however - a Touch ID sensor that cannot be verified should not brick the phone. Apple should j…
The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.
Re: iPhones 'disabled' if Apple detects third-party repairs
#193I mean, not to gloss over it. I just got stung €320 for a screen repair, and I won't pretend I'm at all happy with that. But I have to accept we can't have it both ways - if we're demanding tough encryption, we have to accept the inconvenience that comes with it.
Re: iPhones 'disabled' if Apple detects third-party repairs
#194It's totally dumb that a functioning phone is bricked by an update because of repairs done in the past. Imagine the same thing happening to your car. "Sorry sir, the software update done to your car has now disabled the vehicle because in the past someone not related to x (insert name of car company here) has repaired it, your car is now junk (you can't even resell it) and you'll have to buy a new one". It's just pet…
What if that "repair" was done by NSA, CIA, etc? Should the phone boot like nothing happened? Seriously?
Then the question is, could the NSA/CIA/etc trick the phone into thinking the repair was valid?
Re: iPhones 'disabled' if Apple detects third-party repairs
#195Hardware level security is important, but one must know that whenever you involve hardware into the equation you must allow for collateral damage.
Trusting trust is hard. You can't expect the verifier to verify the security module you got changed from the guy in a basement. Might as well get the OS and kernel from the same guy too.
The reason this disables your phone is the same reason you see a red page when using self signed certificates. The guy vetting you isn't vetted himself. Now there is a case to be made that Apple should just show you a warning and let you use the phone. But this isn't about protecting your privacy, this is about protecting privacy of the guy whose phone you found.
Re: iPhones 'disabled' if Apple detects third-party repairs
#196Re: iPhones 'disabled' if Apple detects third-party repairs
#197Earlier quoted context omitted.
If I understand this correctly (not an iphone person), the touch ID sensor is just a fingerprint scanner? As a standalone measure, biometrics make a shitty password substitute because you can't change a finger print if it's compromised, so shouldn't the iphone be secured on the premise that the finger print scanner is already compromised, hence losing it should not qualify as a downgrade attack?
Touch ID is a fingerprint scanner, but the Touch ID system is paired with the "Secure Enclave" in Apple's AX chips. Secure Enclave is a separate coprocessor running its own L4-based microkernel. This hardware is directly paired with security-sensitive hardware (Touch ID, Apple Pay NFC chip, etc). It provides all cryptographic operations for data protection key management and maintains the integrity of data protection…
That would be a huge vulnerability, if there hadn't been thousands of other ways to record your fingerprint, and while most of them are less accurate than a trojan Touch ID, they're also much easier to pull off.
And at the very worst, if a sophisticated malicious actor got the chance to meddle with your phone, they could just skip the Touch ID sensor altogether and install a stealthy fingerprint digitizer in the touch screen or on the back of the phone.
So in short, Apple's security measure, if my understanding is correct, does absolutely nothing to protect the user.
Re: iPhones 'disabled' if Apple detects third-party repairs
#198Earlier quoted context omitted.
And how is that going for you so far?
Not sure what you are asking exactly (is that rethorical? Or do you expect a real answer?). If you really care :-) : I had the chance to be raised and still live in a very mixed part of Paris. There is racism, of course, and for example I can remember how kids of Portuguese descent were the object of mockery back when I was young. (That's significant because today it's put under the carpet as if it never occurred. It…
It's sad but that seems to be the state of affairs and I don't expect this to get any better in the next couple of centuries. Barring an alien invasion that gives us a reason to play 'us' against 'them' on a bigger stage I doubt humanity will be able to really overcome this particular hurdle. Which is sad because it is a large driver behind all the violence and misery in the world.
Re: iPhones 'disabled' if Apple detects third-party repairs
#199>retarded Don't say this.
To counter the explosion of "fuck you" kind of comments, and as the father of a child with a developmental disability, thank you for pointing out this impolite and linguistically lazy behavior. People who use "retarded", "gay", "autistic", "ghetto" (and so on) in a derogatory form are showing a lack of imagination, aren't introspective enough to consider how their choice of words makes others perceive them, and trivi…
What I don't quite understand is why it trivializes people to use a disability as a pejorative, but it apparently doesn't trivialize people to use a disease as a pejorative.
Re: iPhones 'disabled' if Apple detects third-party repairs
#200Earlier quoted context omitted.
The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.
>IMO bricking on touch ID issues is extreme, but maximises the security of the device. We are all smart people here and there are several ways to have security without bricking expensive hardware. First, the update can wipe the device instead of bricking it. Second, Apple can provide an option to replace the fingerprint chip and charge, $150-$200 or whatever it costs for it. There would be several better solutions th…
Second, Apple can provide an option to replace the fingerprint chip and charge, $150-$200 or whatever it costs for it.
At the end of the article, it said that affected customers should contact Apple Support. Are you sure they are not offering a hardware fix at that point? It doesn't sound to me like they're just letting people hang.