Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

311–320 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#311
post #179

Earlier quoted context omitted.

Almost, except the Tesla store just says you have to buy a new (authentic) key fob rather than a new car. Apple or other authorized repair shops can still fix phones that have been disabled due to security chain errors.

I don't think so, see my other comment. https://news.ycombinator.com/item?id=11048311

Hunh. My bad, I was under the impression (based off some other comments) that replacing the home button/finger scanner with a legit one and updating the security pair would make the issue go away, but looks like I was wrong.

Re: iPhones 'disabled' if Apple detects third-party repairs

#312
post #306

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

> A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could be used to unlock the phone and make purchases through Apple Pay without the owner's permission. Why in the hell would anyone bother with this, if it's trivial to get persons fingerprints and reproduce them to unlock the device ? [1] Even if you lack the touch ID, the device is still encrypted by the PIN and is…

I'm not sure it was over-engineered. Recall when Touch ID was introduced there was huge media backlash: Apple is stealing our fingerprints, how do we know there isn't an NSA backdoor to the fingerprint storage, and so on.

The Secure Enclave system was set up exactly to counter those concerns.

Interestingly, when other phone vendors later implemented fingerprint unlocking there was far less outrage. Even when the fingerprint images themselves were found as unencrypted raster images on device storage.

Re: iPhones 'disabled' if Apple detects third-party repairs

#313
post #258

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

Wouldnt it be more logical to simply disable the Touch Functionality and treat it like a Pre-TouchID button when not replaced by Apple with an OEM part?

I don't think that would solve the underlying problem of the TouchID sensor being compromised. The device would potentially be venerable to software based attacks that re-anbled the compromised TouchID sensor.

Re: iPhones 'disabled' if Apple detects third-party repairs

#314
post #227

Earlier quoted context omitted.

Hell, they could, on boot, display a message with something like "This phone contains contains a non genuine apple part" Then the question is, could the NSA/CIA/etc trick the phone into thinking the repair was valid?

On boot? Many naive users never boot their phones after the first time they open the box. So then, what, if not on boot, show it all the time, with no option to suppress? If you offer a way to suppress it, that will be used by the bad guys.

I say show a message whenever Touch ID is activated. Then again that would be really freakin' annoying. Still better than bricking the phone.

Re: iPhones 'disabled' if Apple detects third-party repairs

#315

Earlier quoted context omitted.

I speak quite a few languages, and most of them badly, good enough for communications needs but not precise enough to win me any literary prizes. If we were having this discussion in Dutch I would definitely not pick on you for using words that may not be precise enough or that might be offensive to you simply because I'd assume that you must have learned your Dutch from other people speaking it and using it in your…

I can appreciate the language barrier and I thank you for changing it when I pointed it out. As for having my work cut out for me, I definitely expected this to happen (maybe not to this scale). HN tends to attract the kind of person who thinks that anything is fair to say any time, regardless of who it might hurt, because HN tends to attract people of massive privilege, many of whom have never been the victim of soc…

This could go two ways. One way would be where people appreciate your efforts and change their tone. Another way this could go is that people will stop participating. Either way you will likely get what you want.

Re: iPhones 'disabled' if Apple detects third-party repairs

#316
post #183

Earlier quoted context omitted.

I don't think they are protecting against that scenario so much as not accounting for it. I expect Apple's assumption is that they provide all components for their devices. People who install unauthorised third party components can no longer have those devices serviced by Apple — so it no longer matters to Apple whether those devices are compromised, because they aren't really "Apple" devices at that point anyway. Th…

There is only one valid reason to authenticate the fingerprint scanner before using it, and that is to prevent the use of aftermarket replacements. No matter what the motives behind this mechanism were, it was put in place exactly to prevent 3rd party scanners from working. And if they implemented authentication and didn't even test what happens if it fails, then well... how do they know it works at all?

If you have a secure enclave within the device, then any hardware which has a direct connection to that secure enclave must be authenticated. It doesn't matter about aftermarket replacements.

The entire purpose of the secure enclave is defeated if it trusts any hardware connected to it.

I'm not saying they didn't test what happens when it fails. I'm saying they didn't do user testing on what happens when it fails. I'm sure the engineers tried out the hardware authentication system. They just didn't test the whole scenario once iOS was sitting on the end product.

So yes, it was put in place to stop any hardware that could not be trusted from accessing users' secure data. But no, it was not done to prevent aftermarket replacements.

The only reason I can see Apple caring about aftermarket replacements is because they are often low quality, and cause customers to go back to Apple with unauthorised repairs. (I've witnessed this more than once in an Apple store, someone coming in who had their screen replaced outside Apple and the touch digitiser was failing. Apple just sends them away.)

Re: iPhones 'disabled' if Apple detects third-party repairs

#317
post #306

Earlier quoted context omitted.

> A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could be used to unlock the phone and make purchases through Apple Pay without the owner's permission. Why in the hell would anyone bother with this, if it's trivial to get persons fingerprints and reproduce them to unlock the device ? [1] Even if you lack the touch ID, the device is still encrypted by the PIN and is…

I think it is definitely over-engineered. If it is a scare tactic to bring people to Apple repair centers why isn't this happening with other Apple products?

Oh you mean apart from all the glue and solder, non-replaceable batteries and the like?

Re: iPhones 'disabled' if Apple detects third-party repairs

#319

Earlier quoted context omitted.

No, the phone did not work perfectly after the repair. The fact that the user didn't realise it didn't work perfectly doesn't change that. The repair compromised the security of the device. Image if you have your tires changed by an independent car shop and a month later one of your wheels falls off on the highway. Do you start complaining about it to the car's manufacturer because 'it worked perfectly before'. No yo…

Your analogy is way off. This is more like your Tesla car's keyfob misfunctioning and you get it repaired by a non-Tesla dealer. The dealer could've put in a backdoor to get into the vehicle. Tesla releases a big new update for their car software and now your Tesla is completely bricked and Tesla refuses to repair it, saying you have to buy a new car. Is that acceptable?

In regards to warranty repairs automakers can (and often do) deny coverage due to the presence of non-OEM parts. Outside of warranty / safety repairs they are certainly not obligated to perform service.

Re: iPhones 'disabled' if Apple detects third-party repairs

#320

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

Don't worry. If there's any bullshit in the article, I'm sure Apple will help us discern which parts are true and which parts are false, the expensive way. Every time.
Post reply on HN