Live data from Hacker News

A Message to Our Customers

apple.com

271–280 of 1001 posts

Re: A Message to Our Customers

#271
post #219
post #163

Earlier quoted context omitted.

I don't see how this "reassuring"; to me it's rather very confusing (as mentioned in many other comments). If Apple could in fact write a software backdoor, doesn't it mean that the backdoor exists, at least potentially? And how can one be sure that Apple is the only company able to build that door? At the very least, couldn't the right Apple engineer be either bribed or forced (by terrorists or the government) to bu…

It sounds like it'd be trivial to nop out the timer on repeated passcode attempts. Which makes sense... Leaving any short passcode trivially crackable.

Yes but like where would you nop? You can't statically analyse the code because the image is encrypted at rest (and potentially partially in ram also?)

Re: A Message to Our Customers

#274

Publicizing the case themselves in a very good move. However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode). The amo…

You can still enable full disk wipe after 10 failed password attempts[1]. That was available in iOS 7 I believe (but someone on here will correct me if I'm wrong). [1] - http://i2.wp.com/ioshacker.com/wp-content/uploads/2014/09/Pa...

It's been available for quite a while, long before iOS 7. It was at least available in iOS 5, probably available before that.

Re: A Message to Our Customers

#275

Earlier quoted context omitted.

Absolutely. I'm quite amazed they had the guts to go through with this and I applaud it. I will support them with my dollars as much as possible.

Talk is cheap and these internet posts - from Tim Cooke, you, and me - are just talk. The security of this nation depends on Apple (and Google et. seq.) supporting us with its dollars as much as possible. And I'm not optimistic that the stockholders care about anything more than doing the opposite.

>And I'm not optimistic that the stockholders care about anything more than doing the opposite

AAPL is one of the most mainstream, widely-held stocks on the planet. Assumptions about the opinion of some homogeneous "stockholder" are useless.

I'm positive HN is filled to the brim with AAPL shareholders who care deeply about this issue.

Re: A Message to Our Customers

#277
post #197

While basically being on Apple's side here, as I understand it, jailbroken devices are unofficial builds of iOS that have some security features removed (e.g. limits on which apps can be installed). Is it not possible for law enforcement to get what they want from that, if all they want is a custom build of iOS that can be hacked around? And why is it even possible for that to work if the data is supposed to be kept…

I think jailbreaking requires you to erase the phone first.

Most previous jailbreaks required an unlocked device with passcode disabled and find my iphone turned off (because passcode encrypts things).

I'm still waiting for JB for 9.2.1 or 9.3 when released but there are already semijailbreaks (browser based installs a temporary app) and some unreleased PoCs, but Cydia MobileSubstrate and other tools need to be ported / verified too.

Perhaps if Apple allowed the devices to be officially customer hackable (like flux, springboard replacements, transmission, 3G unrestrictor and changing fonts), there would be less need to develop exploits... Unfortunately, there is great demand from governments to buy exploits and keep those secret (not a conspiracy but tools in a market)

Re: A Message to Our Customers

#278
post #184
post #170

Earlier quoted context omitted.

This is probably the reason why someone else wrote it. Because writing in "your voice" but without filling words is incredibly hard. But then, it's not the CEOs job to be a good writer.

It absolutely is the job of the CEO of the world's (second) most valuable company to be a good writer.

Being a clear thinker (role of the CEO) and being a concise writer are two different things. The latter requires a lot of training. The CEO of the world's (second) most value company must be able to clearly articulate his goals and his vision, but he doesn't have to be a wordsmith to put his vision on paper.

Writing != thinking != talking

Writing might make you a better communicator in general, maybe a better thinker, too. But clear thinking and talking don't make you automatically a better writer.

Re: A Message to Our Customers

#280
I don't quite understand - what is the actual purpose of being able to push a new version of iOS while locked? Apple don't seem to use this - people stick to whichever version they're comfortable with on old devices and accept whatever limitations.. so why does the functionality even exist?

Even with the restriction of being plugged in, outside of Apple who needs to push iOS versions at tethered devices and will be hindered too badly by having to unlock them first?

Post reply on HN