Earlier quoted context omitted.
There's a lot of stuff that depends on the secure element - in fact the phone would be quite useless without it. In fact, when you first reboot your phone, even contacts cannot be accessed until you authenticate with your passcode to unlock the secure element. Incoming text messages only show the phone number. You're right, however - a Touch ID sensor that cannot be verified should not brick the phone. Apple should j…
The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.
iPhones 'disabled' if Apple detects third-party repairs
251–260 of 363 posts
Re: iPhones 'disabled' if Apple detects third-party repairs
#252Earlier quoted context omitted.
It would be definitely illegal in France which has a law against planned obsolescence - but EU doesn't have it yet. https://en.m.wikipedia.org/wiki/Planned_obsolescence#Regulat...
Only if it was "planned obsolescence" and not "a security measure".
Anyway, this confirms that I'll stay away from Apple stuff.
Re: iPhones 'disabled' if Apple detects third-party repairs
#253Earlier quoted context omitted.
Does this mean your fingerprint never leaves the scanners coprocessor and is inaccessible to iOS and the other processors and OSs within the phone?
Basically, yes. The Secure Enclave is hardware isolated from the rest of the chip. Apple's own security guide explains it best [1]: > The Secure Enclave is responsible for processing fingerprint data from the Touch ID sensor, determining if there is a match against registered ngerprints, and then enabling access or purchases on behalf of the user. Communication between the processor and the Touch ID sensor takes plac…
Except it could be defeated by a laser printed fingerprint on a piece of paper (initially).
Re: iPhones 'disabled' if Apple detects third-party repairs
#254Re: iPhones 'disabled' if Apple detects third-party repairs
#255If the validation fails, the device will function mostly fine, although with Touch ID disabled. However, the device will be prevented from restoring or updating to a new version. Restoring from backup still works. I'm not too sure why restoring or updating is blocked, but my guess is that they want to prevent malicious software from being uploaded in this process.
From the Daily Dot article, if a user encounters this error, Apple's current resolution is a full device replacement. It may be overkill I don't think Apple expected many people to encounter this issue, so it seems reasonable why they chose this option.
This is a great security feature for users, and I'm really glad Apple engineers considered this situation. Unfortunately the media is blowing this and leaving crucial details about what's happening and the reasoning behind it.
Here is Apple's statement on the matter:
We take customer security very seriously and Error 53 is the result of security checks designed to protect our customers. iOS checks that the Touch ID sensor in your iPhone or iPad correctly matches your device's other components. If iOS finds a mismatch, the check fails and Touch ID, including for Apple Pay use, is disabled. This security measure is necessary to protect your device and prevent a fraudulent Touch ID sensor from being used. If a customer encounters Error 53, we encourage them to contact Apple Support.
Re: iPhones 'disabled' if Apple detects third-party repairs
#256Re: iPhones 'disabled' if Apple detects third-party repairs
#257This is still not as bad as the newer laptops in which TPM is soldered onto motherboard and the OS won't boot if it's damaged. You can't even get it repaired, even by the manufacturer without getting a brand new motherboard. Hardware level security is important, but one must know that whenever you involve hardware into the equation you must allow for collateral damage. Trusting trust is hard. You can't expect the ver…
How often do you damage a chip on your motherboard? Or need to replace non-capacitor parts on it? This is such a problem because it's stuck to the screen, and people need to replace screens all the time.
Re: iPhones 'disabled' if Apple detects third-party repairs
#258I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…
Re: iPhones 'disabled' if Apple detects third-party repairs
#259I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…
Wouldnt it be more logical to simply disable the Touch Functionality and treat it like a Pre-TouchID button when not replaced by Apple with an OEM part?
Re: iPhones 'disabled' if Apple detects third-party repairs
#260I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…
The former doesn't seem like a secure solution that one should be really glad of. The latter would also be possible after a software upgrade so there is no need to disable the device completely. In short, they didn't choose a good solution.
Simply disabling a phone at some point well after a repair is just bad.
Edit: The parent post was edited a bit, so my point is now mostly covered. I still don't see a security-related reason to disable the complete device on a software upgrade. Maybe it could enable an attacker to modify the OS somehow in the process. However, I don't agree that this issue is "overblown". This presents a real problem for users that now have an unusable phone. It's important to note that Apple doesn't offer repairs everywhere in the world so many users now can't repair their phone at all.