Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

341–350 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#341
post #338
post #250

Earlier quoted context omitted.

> The alternative would be at some point a headline like "compromised Touch ID sends fingerprints to bad actor". There would be no such headline. Before update to iOS 9, the affected phones functioned normally, but with disabled Touch ID. And if you have to know why people come up with theories like that - either Apple didn't think what happens to users who already had this hardware replaced or they thought about tha…

> Before update to iOS 9, the affected phones functioned normally, but with disabled Touch ID. This is irrelevant. The problem is that those affected phones could still have had compromised fingerprint sensors. Apple did the right thing in protecting people from this, but did communicate about it poorly. The only malice in this situation is on the part of the people accusing apple of being motivated by 'revenge'.

> This is irrelevant. The problem is that those affected phones could still have had compromised fingerprint sensors.

... which wouldn't be used after the phone determines it's an aftermarket part. Equally well the attacker may have installed a malicious piece of brick inside.

> Apple did the right thing in protecting people from this

Sure, they protected users from using phone with replaced home button and disabled fingerprint scanner by bricking the phone completely.

Hard to tell in what proportions malice and/or stupidity were involved in this case, but either way it wasn't "doing the right thing".

Re: iPhones 'disabled' if Apple detects third-party repairs

#342
post #183

Earlier quoted context omitted.

There is only one valid reason to authenticate the fingerprint scanner before using it, and that is to prevent the use of aftermarket replacements. No matter what the motives behind this mechanism were, it was put in place exactly to prevent 3rd party scanners from working. And if they implemented authentication and didn't even test what happens if it fails, then well... how do they know it works at all?

If you have a secure enclave within the device, then any hardware which has a direct connection to that secure enclave must be authenticated. It doesn't matter about aftermarket replacements. The entire purpose of the secure enclave is defeated if it trusts any hardware connected to it. I'm not saying they didn't test what happens when it fails. I'm saying they didn't do user testing on what happens when it fails. I'…

> If you have a secure enclave within the device, then any hardware which has a direct connection to that secure enclave must be authenticated.

Consider reading the description of iOS security features linked somewhere in this thread.

Because what you are describing is a disaster, not security. If some off-chip sensor had access to fingerprint data or crypto keys, anybody capable of installing such chip would also be able to simply dump all the data himself in the comfort of his lab.

Re: iPhones 'disabled' if Apple detects third-party repairs

#343

Earlier quoted context omitted.

> There's a lot of stuff that depends on the secure element - in fact the phone would be quite useless without it. Disclaimer: I don't own an iPhone with Touch ID. However, it seems to me that the phone should still work if you logged on with your PIN instead of with TouchID. It should therefore be as useful as most phones that didn't have TouchID in the first place (which happens to be all my Android and iOS smartph…

On TouchID phones, the PIN is held in the same secure enclave as the TouchID data.

OK, thanks! Can you reset the PIN without knowing the original?

If you can't, there's no need to brick the phone...

Re: iPhones 'disabled' if Apple detects third-party repairs

#344
post #297

Earlier quoted context omitted.

What if the "owner" of the device, i.e. the person who paid her hard-earned wages to "own" it, is not interested in using the "TouchID" feature? Is there an untapped niche for a similarly-sized single board computer (not several computers, baseband processor, SIM card that runs code, etc. jammed into a hermetically sealed casing that is worthy of being in the Museum for Modern Art) that just does simple simpler, "bor…

> A pocket-sized computer that a user can not just rent but _pwn_ Then don't buy an iPhone. Simple. You and the other dozen people on the planet will surely be missed. The rest of us absolutely want Apple to be as aggressive about security/privacy as they possibly can be. Especially with even moderate countries e.g. UK, Australia being equally aggressive about invading privacy.

Looks like we got a fanboy.

Re: iPhones 'disabled' if Apple detects third-party repairs

#345

Earlier quoted context omitted.

> TouchID is the less secure authentication than password/PIN anyway (which is shown by the fact that you need to enter PIN/Pass right after boot). The fact that you need to enter PIN right after boot, just shows that they use "two factor authentication" to make it even more secure. It doesn't IN ANY WAY show that TouchID is "the less secure authentication" method of the two.

Fingerprints are impossible to change and can be brute-forced. Therefore, fingerprint security is less secure than a password that can be changed.

Brute forced with what? Trying different fingers?

Re: iPhones 'disabled' if Apple detects third-party repairs

#346

Earlier quoted context omitted.

Fingerprints are impossible to change and can be brute-forced. Therefore, fingerprint security is less secure than a password that can be changed.

Brute forced with what? Trying different fingers?

A fingerprint, like any piece of data, is handled at the lowest levels as a number. A number with some constraints, but a number.

By feeding numbers into the scanner instead of fingers, you can accomplish the same effect as feeding random strings into a password box. Further, it's also possible to take fingerprints through social engineering, or by getting at the database of a company that uses fingerprints as security. Five bucks says someone's already storing a bunch of fingerprint data as plaintext.

Re: iPhones 'disabled' if Apple detects third-party repairs

#347

Earlier quoted context omitted.

Brute forced with what? Trying different fingers?

A fingerprint, like any piece of data, is handled at the lowest levels as a number. A number with some constraints, but a number. By feeding numbers into the scanner instead of fingers, you can accomplish the same effect as feeding random strings into a password box. Further, it's also possible to take fingerprints through social engineering, or by getting at the database of a company that uses fingerprints as securi…

>By feeding numbers into the scanner instead of fingers, you can accomplish the same effect as feeding random strings into a password box.

Isn't this exactly why they DON'T allow you to use the iPhone with a potentially tampered with HW/TouchID -- e.g. the very feature/issue we're discussing?

Re: iPhones 'disabled' if Apple detects third-party repairs

#348
post #337

Earlier quoted context omitted.

That does sound ridiculous. But please don't comment like this and https://news.ycombinator.com/item?id=11047606 on HN. That just makes the threads worse. Instead, please stay civil even when some people are being silly.

You are, as ever, totally right; there's no reason to be rude. Sorry.

> You are, as ever, totally right

Good lord no. But thank you for the polite response and intention to change. It really is a collective effort.

Re: iPhones 'disabled' if Apple detects third-party repairs

#349

Earlier quoted context omitted.

> A pocket-sized computer that a user can not just rent but _pwn_ Then don't buy an iPhone. Simple. You and the other dozen people on the planet will surely be missed. The rest of us absolutely want Apple to be as aggressive about security/privacy as they possibly can be. Especially with even moderate countries e.g. UK, Australia being equally aggressive about invading privacy.

Looks like we got a fanboy.

When people visit countries and come back finding screws on their laptops removed, they don't need to be "fanboya" to want more security.

Re: iPhones 'disabled' if Apple detects third-party repairs

#350
post #124
post #50

The stated rationale is that it's reasonable for a security-critical device to self-destruct if it thinks it may have been tampered with. Unfortunately this is a phone which costs a lot of money and has much of the user's life stored on it. I wouldn't be surprised to see Apple sued over this; I don't know what the interaction of the Sale of Goods Act and remote-bricking is. I was thinking along similar lines recently…

Apple have been accused of copper-bottoming the rules when relatives want to get access to a dead person's phone. Apple only really need a death certificate and certificates of probate; but Apple insist on different court orders. So I'm not sure if SOGA etc will affect Apple here.

> Apple have been accused of copper-bottoming the rules when relatives want to get access to a dead person's phone.

> Apple only really need a death certificate and certificates of probate; but Apple insist on different court orders.

Huh? Why should next of kin automatically be entitled to all someone's personal information?

Post reply on HN