Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

301–310 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#301

Earlier quoted context omitted.

>when one is actually expressing an opinion that the person or thing is not worthy of merit, and history is rife with abuses that result from trivializing a group of people by distilling that group to a pejorative. What I don't quite understand is why it trivializes people to use a disability as a pejorative, but it apparently doesn't trivialize people to use a disease as a pejorative.

Since you don't seem to be arguing, I would like to understand what you mean? Did I use such a pejorative? I'd sincerely like to know - if, that is, your query is sincere as well.

I'm just musing, and hoping someone might have an explanation. Language is complicated, and emotionally-loaded words are especially so.

Let me put it this way. If I call someone cancerous, I'm not trivializing the group of people that have cancer and distilling them to a pejorative. In general, if I use a disease as an insult it's fine, but if I use a disability as an insult it's usually offensive. They're both afflictions, but they're treated differently in uncountable ways.

I could list some reasons, but none of them really feel like they get at the root cause of the difference. Do you have any insight?

Re: iPhones 'disabled' if Apple detects third-party repairs

#303
post #297

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

What if the "owner" of the device, i.e. the person who paid her hard-earned wages to "own" it, is not interested in using the "TouchID" feature? Is there an untapped niche for a similarly-sized single board computer (not several computers, baseband processor, SIM card that runs code, etc. jammed into a hermetically sealed casing that is worthy of being in the Museum for Modern Art) that just does simple simpler, "bor…

> A pocket-sized computer that a user can not just rent but _pwn_

Then don't buy an iPhone. Simple. You and the other dozen people on the planet will surely be missed.

The rest of us absolutely want Apple to be as aggressive about security/privacy as they possibly can be. Especially with even moderate countries e.g. UK, Australia being equally aggressive about invading privacy.

Re: iPhones 'disabled' if Apple detects third-party repairs

#304

Earlier quoted context omitted.

What a malicious sensor could do is store user's fingerprint for retrieval by unauthorized parties. Of course, taking advantage of the exploit in question requires the phone to be stolen by an extremely sophisticated (if not state-level) bad guy, altered by installation of a malicious sensor that has never been documented to exist in the wild, then recovered by the owner, and then stolen again at a later date. All to…

Today's state-level agency is tomorrow's small town police department, and next week's street criminal. Attacks only get better. Also, Apple is not only designing phones for you and me, but for businesses who nowadays are the target of state-level security agencies. Clearly Apple fudged the implementation of this feature, and it's a PR nightmare, but all evidence points to their intentions being genuine.

Exactly this.

Do you really think Apple hasn't been shocked/annoyed at how China/US/et al have actively tried to hack their customers including attempt to compromise their own servers ?

Re: iPhones 'disabled' if Apple detects third-party repairs

#305

Earlier quoted context omitted.

I don't think they are protecting against that scenario so much as not accounting for it. I expect Apple's assumption is that they provide all components for their devices. People who install unauthorised third party components can no longer have those devices serviced by Apple — so it no longer matters to Apple whether those devices are compromised, because they aren't really "Apple" devices at that point anyway. Th…

There's no need to be so hostile and assume malice when there's plenty of perfectly sound explanations otherwise. Apple is a fairly security conscious company now so security tradeoffs should not be a surprise.

Assume malice? How do you mean?

Re: iPhones 'disabled' if Apple detects third-party repairs

#306

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

> A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could be used to unlock the phone and make purchases through Apple Pay without the owner's permission.

Why in the hell would anyone bother with this, if it's trivial to get persons fingerprints and reproduce them to unlock the device ? [1] Even if you lack the touch ID, the device is still encrypted by the PIN and is functioning (and is secure) normally without it.

Either it's really over-engineered or is what it is - scare tactic to bring people to Apple repair centers.

I wish they'd use rather this media attention to inform the public that fingerprint authentication isn't there for security, but conveniency first. Apple Pay would function just fine without it. But would it have it's appeal of easy payment ? Probably not.

[1] https://www.youtube.com/watch?v=2u4ZLGsw1zo

Re: iPhones 'disabled' if Apple detects third-party repairs

#307

Earlier quoted context omitted.

Since you don't seem to be arguing, I would like to understand what you mean? Did I use such a pejorative? I'd sincerely like to know - if, that is, your query is sincere as well.

I'm just musing, and hoping someone might have an explanation. Language is complicated, and emotionally-loaded words are especially so. Let me put it this way. If I call someone cancerous, I'm not trivializing the group of people that have cancer and distilling them to a pejorative. In general, if I use a disease as an insult it's fine, but if I use a disability as an insult it's usually offensive. They're both affli…

Perhaps it's related to self-identification? People don't self-identify as cancerous, the cancer (or disease?) is an external actor invading the body. Whereas a disability is a feature or aspect of one's body.

(I don't have first hand experience with either, so I'm just musing too..)

Re: iPhones 'disabled' if Apple detects third-party repairs

#308
post #277

Earlier quoted context omitted.

> The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. No, the CPU reads encrypted data from the sensor and sends them to the SE for decryption and analysis. See the PDF linked here by somebody. What a malicious sensor could do is store user's fingerprint for retrieval by unauthorize…

What a malicious sensor could do is store user's fingerprint for retrieval by unauthorized parties. Of course, taking advantage of the exploit in question requires the phone to be stolen by an extremely sophisticated (if not state-level) bad guy, altered by installation of a malicious sensor that has never been documented to exist in the wild, then recovered by the owner, and then stolen again at a later date. All to…

> * A simple application of Occam's Razor suggests that Error 53 isn't a "security feature" at all, it's just Apple being a rent-seeking asshole.*

I don't think you understand Occam's Razor.

Re: iPhones 'disabled' if Apple detects third-party repairs

#309
post #100

Earlier quoted context omitted.

What if that "repair" was done by NSA, CIA, etc? Should the phone boot like nothing happened? Seriously?

Looking at teardowns, like the one at ifixit [1], the touch id sensor seems to be a pretty standard imaging sensor that heads to an NXP chip. I'd be willing to bet that the encryption of the print happens on the nxp chip instead of the imager, so if the NSA/whoever were doing a "repair", they'd probably just put an MiTM chip on that insecure path for later playback. Against a state actor, Touch ID is a triviality. [1…

Maybe they want to move encryption onto the sensor chip in future generations, because the scheme you described is indeed a joke.

But to be honest, it's not like fingerprints are such a hard to obtain secret in the first place.

Re: iPhones 'disabled' if Apple detects third-party repairs

#310
post #306

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

> A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could be used to unlock the phone and make purchases through Apple Pay without the owner's permission. Why in the hell would anyone bother with this, if it's trivial to get persons fingerprints and reproduce them to unlock the device ? [1] Even if you lack the touch ID, the device is still encrypted by the PIN and is…

I think it is definitely over-engineered. If it is a scare tactic to bring people to Apple repair centers why isn't this happening with other Apple products?
Post reply on HN