Earlier quoted context omitted.
I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…
It sounds like it'd be trivial to nop out the timer on repeated passcode attempts. Which makes sense... Leaving any short passcode trivially crackable.
A Message to Our Customers
271–280 of 1001 posts
Re: A Message to Our Customers
#272Re: A Message to Our Customers
#273https://assets.documentcloud.org/documents/2714005/SB-Shoote...
It is a PDF.
Re: A Message to Our Customers
#274Publicizing the case themselves in a very good move. However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode). The amo…
You can still enable full disk wipe after 10 failed password attempts[1]. That was available in iOS 7 I believe (but someone on here will correct me if I'm wrong). [1] - http://i2.wp.com/ioshacker.com/wp-content/uploads/2014/09/Pa...
Re: A Message to Our Customers
#275Earlier quoted context omitted.
Absolutely. I'm quite amazed they had the guts to go through with this and I applaud it. I will support them with my dollars as much as possible.
Talk is cheap and these internet posts - from Tim Cooke, you, and me - are just talk. The security of this nation depends on Apple (and Google et. seq.) supporting us with its dollars as much as possible. And I'm not optimistic that the stockholders care about anything more than doing the opposite.
AAPL is one of the most mainstream, widely-held stocks on the planet. Assumptions about the opinion of some homogeneous "stockholder" are useless.
I'm positive HN is filled to the brim with AAPL shareholders who care deeply about this issue.
Re: A Message to Our Customers
#276Does anyone have a decent architectural overview of iPhone (6)? Security - these enclaves etc sound good but devil is in the details
Re: A Message to Our Customers
#277While basically being on Apple's side here, as I understand it, jailbroken devices are unofficial builds of iOS that have some security features removed (e.g. limits on which apps can be installed). Is it not possible for law enforcement to get what they want from that, if all they want is a custom build of iOS that can be hacked around? And why is it even possible for that to work if the data is supposed to be kept…
I think jailbreaking requires you to erase the phone first.
I'm still waiting for JB for 9.2.1 or 9.3 when released but there are already semijailbreaks (browser based installs a temporary app) and some unreleased PoCs, but Cydia MobileSubstrate and other tools need to be ported / verified too.
Perhaps if Apple allowed the devices to be officially customer hackable (like flux, springboard replacements, transmission, 3G unrestrictor and changing fonts), there would be less need to develop exploits... Unfortunately, there is great demand from governments to buy exploits and keep those secret (not a conspiracy but tools in a market)
Re: A Message to Our Customers
#278Earlier quoted context omitted.
This is probably the reason why someone else wrote it. Because writing in "your voice" but without filling words is incredibly hard. But then, it's not the CEOs job to be a good writer.
It absolutely is the job of the CEO of the world's (second) most valuable company to be a good writer.
Writing != thinking != talking
Writing might make you a better communicator in general, maybe a better thinker, too. But clear thinking and talking don't make you automatically a better writer.
Re: A Message to Our Customers
#279Re: A Message to Our Customers
#280Even with the restriction of being plugged in, outside of Apple who needs to push iOS versions at tethered devices and will be hindered too badly by having to unlock them first?