Live data from Hacker News

Apple Letter on iPhone Security Draws Muted Tech Industry Response

nytimes.com

81–90 of 204 posts

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#81

Earlier quoted context omitted.

This isn't the same thing at all.

Yes, it is. Apple's fight with the US is based on the fact they facilitate the encryption of user data so that even Apple doesn't see content. When the other titans don't have that feature, they have less of a stake in the argument at hand.

Is Google or Microsoft's business model dependent on selling your info to anyone other than themselves? Do you think if they did that they would stand to lose business?

Their business model is to sell ads to 3rd parties based on the information they have about you. Selling your info itself would be detrimental to their business.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#82
post #71

Earlier quoted context omitted.

This just made me realise that Apple is a true "do no evil" company and not Google, for all its technology powress and fancy marketing. A sad realisation as I have been using Google products for almost everything-- they pitch up everything under the F/OSS banner and it's so tempting. I think I should consider moving to iOS pretty seriously. I had been dismissing it for being over-priced and not being OSS. But the tru…

>This just made me realise that Apple is a true "do no evil" company and not Google, for all its technology powress and fancy marketing. A sad realisation as I have been using Google products for almost everything-- they pitch up everything under the F/OSS banner and it's so tempting. There's nothing evil about wanting to provide contextual information and to do that they need the context. Its just the nature of the…

There's nothing evil about wanting to provide contextual information and to do that they need the context.

The argument you've presented is ends justifying the means. I don't mean to imply that there is no convincing arguments to be made involving the points you present, but this is not it.

The face value reading of purely "providing contextual information" is benign af. But that does mean evil can not lurk in implementation constraints, and/or the design decisions made in service of making that presentation monetizable.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#83
post #60

Earlier quoted context omitted.

This is a recent development. Apple only started to care about iOS security around 2012 for example.

Oh really? iOS has page-based executable code hash/signing since at least iOS 2 (2008); Android still doesn't have any runtime code integrity protections.

Of all the random security issues in the past 8 years you'd be hard pressed to find one where this was relevant.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#84

Gotta love how some are using this as a marketing tool for Apple! For quite some time after Snowden we know well that Microsoft and Google at least believe the same as Apple - you can wax judgmental over strong or weak, loud or muted but fact of the matter is it is quite well known through their actions that both MS and Google are in opposition to government back doors and sweeping collection of information. But yeah…

"This is an Apple marketing ploy" is the absolute dumbest take on this issue. Please drop the tech horse-race bullshit for two minutes, sheesh

Explain then to me how it is not. (Note that I did not say Apple is doing the marketing for themselves - media and bloggers are. FTR I think obviously Apple's is the right stance to have.) There is no basis to paint the other horse race participants as complicit - especially when Google's CEO publicly agreed with Apple's stance and they and MS both have history of opposing this sort of stuff.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#85
post #28

John McAfee has posted his response: http://www.businessinsider.com/john-mcafee-ill-decrypt-san-b... As usual for him, it's hyperbolic and over the top. It starts with this... > This is a black day and the beginning of the end of the US as a world power. And snowballs into this: > And why do the best hackers on the planet not work for the FBI? Because the FBI will not hire anyone with a 24-inch purple mohawk, 10-gaug…

Not too far off. Obviously nobody would smoke at work for the same reason they probably wouldn't drink, illegality aside. But, what people do outside of work is their own business. If my boss started seriously inquiring about my vices, first thing I'd do that night is update my resume. I've considered federal work before but every time I think hard about it, I keep coming back to the scene in Snow Crash where the fed…

> I've considered federal work before but every time I think hard about it, I keep coming back to the scene in Snow Crash where the fed works at a place where every little action - the time you arrive, the time you leave, whether you take the stairs or use electricity by taking the elevator - is scrutinized and judged. Yuck.

Wasn't that the corporate guy that did that to his employees? Intruding into their homes, even?

I can't speak for all federal jobs, but I doubt any involve anything like that level of busybody-ness unless a very high level of security clearance and access is involved.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#86

What sets Apple apart from Googles and Facebooks is that it's the only company that stores the data in way that Apple itself cannot read it. This is why the others have little to say on the subject - there is no issue of a "backdoor", because there is no wall to begin with when it comes to Google or FB, their business model depends on reading and analyzing your emails and posts.

I'm not sure what you are talking about here. Apple's _Cloud Services_ i.e. iCloud, do not prevent Apple accessing the data, and Apple does comply with 'valid' requests for that data, just like Google and Facebook.

As for data stored on user's devices, Google also ships their phones with full disk encryption which Google cannot bypass - the implementation isn't as good as Apple's, but the concept is the same. Facebook doesn't sell any end-user devices so I'm not sure why they are even in your comparison.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#87

Earlier quoted context omitted.

This article explains the situation nicely: http://blog.trailofbits.com/2016/02/17/apple-can-comply-with... The short answer is, Apple compensates for the low entropy of 4 digit PINs by rate-limiting the number of guesses you can make.

But that is the root of the problem. Apple can control how the system is unlocked, they can update it, so they are able to circumvent their own measures. I wouldn't be surprised if they are able to do it with secure enclave too. So apple didn't provided their users security. They provided security with potential backdoor in the design. So I say - it is good if FBI can force apple to exploit their own backdoors - to l…

> They provided security with potential backdoor in the design.

I'm not certain what you're asking for here. A device that is completely impregnable?

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#88
post #7

Earlier quoted context omitted.

Don’t the modern Android phones with Trusted Execution Environment do about the same?

> Don’t the modern Android phones with Trusted Execution Environment do about the same? Not from what I've been able to determine doing some research today. Or at leaast they're very poor at advertising it if they do. Samsung KNOX uses the ARM TrustedZone to provide remte-attestation of running software, but I can't see anything similar to Apple's Secure Enclave for filesystem encryption keys. If anyone does know an…

They probably mean this. https://source.android.com/security/encryption/

Pretty sure anything made in the last few years has had a secure element because you needed it for Google Wallet. That might have changed for Android Pay though.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#89

Gotta love how some are using this as a marketing tool for Apple! For quite some time after Snowden we know well that Microsoft and Google at least believe the same as Apple - you can wax judgmental over strong or weak, loud or muted but fact of the matter is it is quite well known through their actions that both MS and Google are in opposition to government back doors and sweeping collection of information. But yeah…

"This is an Apple marketing ploy" is the absolute dumbest take on this issue. Please drop the tech horse-race bullshit for two minutes, sheesh

That's actually not what blinkingled said. They said that some people here are using it as marketing for Apple, not that Tim Cook or others at Apple intended for it to be taken that way.

Re: Apple Letter on iPhone Security Draws Muted Tech Industry Response

#90
post #25
post #7

Earlier quoted context omitted.

Don’t the modern Android phones with Trusted Execution Environment do about the same?

I think what gtrubetskoy is talking about is Google (namely: search, Gmail, calendar, contacts, Plus--which are all tied to your Google account) and Facebook (namely: relationships, posting content, private messages, what you look at, etc) is information which is then mined or allowed to be targeted by advertisers for a handsome profit. Apple doesn't do that. Their iAds are nothing in comparison to Google/FB's data m…

Regardless of whether Apple profits from iCloud user data, the key question how well they protect the data on iCloud. Do they encrypt the data at rest? Are the links between data centers encrypted?
Post reply on HN