Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

321–330 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#321
post #258

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

Wouldnt it be more logical to simply disable the Touch Functionality and treat it like a Pre-TouchID button when not replaced by Apple with an OEM part?

We don't know the technical details behind. For all it's worth, the button might be like one of those thunderbolt ports that has direct memory access and can alter the firmware during a software upgrade.

Re: iPhones 'disabled' if Apple detects third-party repairs

#322
post #308

Earlier quoted context omitted.

What a malicious sensor could do is store user's fingerprint for retrieval by unauthorized parties. Of course, taking advantage of the exploit in question requires the phone to be stolen by an extremely sophisticated (if not state-level) bad guy, altered by installation of a malicious sensor that has never been documented to exist in the wild, then recovered by the owner, and then stolen again at a later date. All to…

> * A simple application of Occam's Razor suggests that Error 53 isn't a "security feature" at all, it's just Apple being a rent-seeking asshole.* I don't think you understand Occam's Razor.

There's always more to learn. What am I missing?

Re: iPhones 'disabled' if Apple detects third-party repairs

#323
post #157

Earlier quoted context omitted.

That wouldn't really be a good idea. Someone could steal your phone and replace the TouchID hardware. Then this popup comes up and they say, oh yeah this hardware is totally legit! Then they get your data, impersonate you, charge stuff etc.

The prompt would have to be after you authenticated your phone in some other way, like via the passcode. I think it's totally OK not to accept authentication from an unvalidated device, but a legitimate user should be able to do the validation.

I think the post is referring to a hotel maid scenario.

Re: iPhones 'disabled' if Apple detects third-party repairs

#324

All these comparisons to car warranties, and more specifically how in some countries there may be a question of legality. The U.S. has similar laws that car dealers can't deny warranty coverage because of third party repairs. IANAL, but it would be interesting to see how this translates to phones (or any other similar asset). http://www.consumer.ftc.gov/articles/0138-auto-warranties-ro...

Later updates from Apple have said that they'll replace the touch sensor and other hardware if necessary.

I'm curious; although auto makers can't decline warranty coverage, does an "authorized maintenance" shop change the dynamics?

Re: iPhones 'disabled' if Apple detects third-party repairs

#326
post #107

Earlier quoted context omitted.

The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.

Fingerprint scanners are useless for security. My fingerprints are everywhete, especially all over my phone. Touch id merely buys time, which can increase security but if they get my fingerprints, make a dummy finger then they need very little time to open my phone. If they are determined they'll do it. If they are not, probably they won't care about the data in my phone.

They have at most 48 hours (or perhaps 24?) and 5 tries to find your fingerprint and unlock the device. TouchID will discard the keys and require a passphrase if it is not used for a while or after the fifth invalid fingerprint attempt. The window of opportunity is not that big. I would not characterize it as useless at all.

Re: iPhones 'disabled' if Apple detects third-party repairs

#327

Earlier quoted context omitted.

> TouchID is the less secure authentication than password/PIN anyway (which is shown by the fact that you need to enter PIN/Pass right after boot). The fact that you need to enter PIN right after boot, just shows that they use "two factor authentication" to make it even more secure. It doesn't IN ANY WAY show that TouchID is "the less secure authentication" method of the two.

You can do anything you want on the phone without using Touch ID at all. The fingerprint sensor is not a necessary factor in their implementation, while the passcode is.

> You can do anything you want on the phone without using Touch ID at all

I believe ApplePay requires TouchID.

Re: iPhones 'disabled' if Apple detects third-party repairs

#329
post #169

There is a strong bias, and the amazing thing is that its very difficult for the people who have this bias to realize it. As far as they can tell it is fact, and this is in large part because they live in a filter bubble where they only see things that confirm their bias. For example: Articles bashing Steve Jobs get upvoted a lot more than ones praising him. Exactly the opposite for bill Gates. Now if you look at Sla…

> Hell, I was once banned from here for relating how I met Grace Hopper as a kid (in a comment on an article about Grace Hopper.)

I don't believe anyone was ever banned from HN for that. How about let's see a link?

There's a cottage industry of HN users who go on about why they were banned ("because I supported Bradley Manning!" "because of my unpopular opinions!"). Pay attention and you'll notice that these complaints are always linkless. They never supply links to their allegedly innocent and suppressed contributions. Why not? Because then people could see what they really did do, and make up their own minds.

We make mistakes, and we're happy to correct them. But no way do we ban people for "relating how I met Grace Hopper as a kid".

We detached this subthread from https://news.ycombinator.com/item?id=11048013 and marked it off-topic.

Re: iPhones 'disabled' if Apple detects third-party repairs

#330
post #308

Earlier quoted context omitted.

> * A simple application of Occam's Razor suggests that Error 53 isn't a "security feature" at all, it's just Apple being a rent-seeking asshole.* I don't think you understand Occam's Razor.

There's always more to learn. What am I missing?

Occam's Razor says that you should select the hyposthesis with the fewest assumptions. Saying Apple is a "rent seeking asshole" assumes that Apple did this maliciously, which is a huge ball of assumptions when they've literally put out a security paper[1] on how Touch ID and Security Enclave works.

[1]:https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Post reply on HN