Live data from Hacker News

A Message to Our Customers

apple.com

251–260 of 1001 posts

Re: A Message to Our Customers

#251
post #73

Earlier quoted context omitted.

Not too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.

Or, said differently, Play Services are already a backdoor. They can (and do) install updates or other software pushed by server automatically, without you being able to do anything about it. And they have access to anything on the phone.

F-DROID

Re: A Message to Our Customers

#252
post #101

Earlier quoted context omitted.

Not all of CyanogenMod is free software (you still have a bunch of binary blobs, and everyone has to use Google Play Services anyway because every app seems to implicitly require it). Replicant would be a much better alternative if it actually supported anything newer than 2G.

> and everyone has to use Google Play Services anyway This isn't true. You can stick to app repositories like F-Droid and use Raccoon to download Play Store apps via your desktop without using a Google account on your phone.

It is true that you can get Play Store apps without a Google Account, but the Place Services framework does a lot more than this. Many apps rely upon the framework for certain pieces of functionality from Google's libraries.

Re: A Message to Our Customers

#253
post #91

Earlier quoted context omitted.

Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.

> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)

Although replicant currently can't do free software on the modem and bootloader, everything else is: http://www.replicant.us/supported-devices.php

Re: A Message to Our Customers

#254
post #91

Earlier quoted context omitted.

Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.

> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)

> including the radios We no for a fact that they don't because that's illigal in the US.

Re: A Message to Our Customers

#255
post #91

Earlier quoted context omitted.

Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.

> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)

> including the radios We no for a fact that they don't because that's illigal in the US.

Re: A Message to Our Customers

#256

If the UK record on anti-terror scope creep is anything to go by, not creating this backdoor is a very good idea. In the UK, laws originally intended for surveilling terrorists were/are routinely used by local councils (similar to districts I think) to monitor whether citizens are putting the correct rubbish/recycling into the correct bin. [1] This is a pandora's box, and the correct answer is not to debate whether w…

And that was eight years ago - the state of affairs has since worsened - and the sheer irony of those same tory critics now spearheading the push for even broader surveillance powers. It's like crack for the political class (except rob ford) - once they start they want more and more.

Re: A Message to Our Customers

#257

Publicizing the case themselves in a very good move. However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode). The amo…

You can still enable full disk wipe after 10 failed password attempts[1]. That was available in iOS 7 I believe (but someone on here will correct me if I'm wrong).

[1] - http://i2.wp.com/ioshacker.com/wp-content/uploads/2014/09/Pa...

Re: A Message to Our Customers

#258
post #249
post #201

Earlier quoted context omitted.

In the world of cryptography, it is always possible, because you can always be lucky and guess the right "unlock" code. In fact, social engineering is normally used to find the right "unlock" code[0]. The FBI can also unsolder the components in the phone, make a full image of the content, find the encrypted section and then brute-force. This is what is done for SSD. They do not power up the drive, unsolder, put the m…

It's kind of hard to social engineer dead people, though.

This is why the "normally" in my sentence. But the point I really wanted to make is that you have no "impossible" with encryption.

Re: A Message to Our Customers

#259

Earlier quoted context omitted.

> and everyone has to use Google Play Services anyway This isn't true. You can stick to app repositories like F-Droid and use Raccoon to download Play Store apps via your desktop without using a Google account on your phone.

It is true that you can get Play Store apps without a Google Account, but the Place Services framework does a lot more than this. Many apps rely upon the framework for certain pieces of functionality from Google's libraries.

You mean Google Apps specifically?

I don't use them personally but I imagine Goole Now, GMail and Google Maps would need Play Services.

The apps I do use (non-google) tend to function well enough without Play Services though.

Re: A Message to Our Customers

#260
post #75

Earlier quoted context omitted.

See other comment: https://news.ycombinator.com/item?id=11116439 Potentially, Apple cannot circumvent their own protections on some models (in software anyway), and could in others.

Thanks. This explains it. I was just thinking about my old Thinkpad X41. That had TPM module and hardware encryption. There's nothing that IBM or the TPM manufacturer could've done to decrypt it (unless the TPM module already had backdoors, haha). Latest iPhones are basically the same?

I don't get it. How would they be load the backdoor is the phone is still locked?
Post reply on HN