Live data from Hacker News

Apple hires one of the developers behind Signal

techcrunch.com

21–30 of 119 posts

Re: Apple hires one of the developers behind Signal

#21
post #6

Earlier quoted context omitted.

No, but this is very likely to be them tightening up other parts of their software stack.

Oh right. All the other insecure parts of their software stack. You know, all that other insecure stuff that's notoriously insecure. That one guy who wrote a chat app is going to tighten up. Come on. Don't pretend this is anything more than it is. A really hard-working guy worked hard and built a thing that worth while. Apple said, "hmmm, it would be easier to buy this person than to hire him." So they did. There is…

> Apple said, "hmmm, it would be easier to buy this person than to hire him."

Those two things sound the same to me. The guy was hired. What are you saying here?

> There is no one-person fix to secure enclave or any of Apple's other problems

Nobody said he's going to work on that.

> Apple's problems, such as they are, are systemic and cultural. Apple cannot buy its way into better cloud services or better Siri, or better security, and certainly not with the purchase of a such a small company.

You seem to know a lot about Apple's culture. Do you have some evidence to support your claims?

Re: Apple hires one of the developers behind Signal

#22
post #9

Conjecture: Isn't Apple's private signing key already a "master key to turn 100 million locks"? I.e. the key they use to sign software updates. With that key, someone could create malware and sign it... Apple creating the malware just saves them a step. Ergo the "target on that piece" is already pretty high value, yet Apple is able to keep it secret / prepared for contingencies (like rotating the key..) Thoughts?

Well, this is true for any form of authentication. If you have information you need to update, you need to have a form of authentication, and authentication data can get lost. You just need to have good routines limiting the access to this data.

This is a problem for signing software, but also things like updating their webpage and content on the App Store. All these systems need to have authentication data exist, and if lost to people with malicious intent it could be lost.

Re: Apple hires one of the developers behind Signal

#23

Earlier quoted context omitted.

It's not idiotic, it's interesting news given the climate. They didn't say what his role or project will be. What's wrong with reporting on Apple hiring a developer of one of the most popular secure messaging tools?

Are you blind to the difference between reporting an event and interpreting the event badly?

Please quote the article where you feel it interpreted events poorly. And be civil.

Re: Apple hires one of the developers behind Signal

#24

I can understand how people want to put puzzle pieces together, but this is completely idiotic. Whatever remaining security holes there are with secure enclave, they have nothing to do with a software chat app. This is entirely coincidental and has nothing to do with anything. TechCrunch should be ashamed of itself (again) for being such a douchebag. Edit: I'm not saying Apple hiring the guy is stupid. I'm responding…

Is it idiotic to assume a company embroiled in a debate about privacy and security for a communication device-- the biggest driver of revenue for the company, hired someone in the secure communications space to work on communications products? Also, Apple has a PR problem and can't operate without secure systems. Article title notwithstanding, it is a pretty big deal that while an intelligence agency is coming at the…

I will argue that this guy has none of the skills needed to up the ante on the current security model of the latest versions of iOS. What's not known is how security enclave works. But what is known is that it's firmware.

Something very much outside what we know about the secure chat app.

We also know that iMessage has never been known to have any fundamental security flaws.

I tried to clarify above, and I'll do so here again. I don't think the hire was idiotic. I think TCs characterization of hiring a security messiah was idiotic.

That is not anywhere close to reality.

Re: Apple hires one of the developers behind Signal

#25
post #9

Conjecture: Isn't Apple's private signing key already a "master key to turn 100 million locks"? I.e. the key they use to sign software updates. With that key, someone could create malware and sign it... Apple creating the malware just saves them a step. Ergo the "target on that piece" is already pretty high value, yet Apple is able to keep it secret / prepared for contingencies (like rotating the key..) Thoughts?

Yes, Apple has never denied that it is possible for Apple to create a signed build of iOS with some of the security stripped out. They just point out, rightly that it is not a good idea.

It follows that this is a pretty thin layer of security.

And it seems that Apple's signing keys are well-protected high value targets. Has Apple been "able to keep it secret" ? As far as we know, yes. But we don't know everything.

Re: Apple hires one of the developers behind Signal

#26

Earlier quoted context omitted.

Are you blind to the difference between reporting an event and interpreting the event badly?

Please quote the article where you feel it interpreted events poorly. And be civil.

I don't really take orders from students, rob. Especially ones who don't read the article and are named studentrob. :)

Re: Apple hires one of the developers behind Signal

#28

Earlier quoted context omitted.

Is it idiotic to assume a company embroiled in a debate about privacy and security for a communication device-- the biggest driver of revenue for the company, hired someone in the secure communications space to work on communications products? Also, Apple has a PR problem and can't operate without secure systems. Article title notwithstanding, it is a pretty big deal that while an intelligence agency is coming at the…

I will argue that this guy has none of the skills needed to up the ante on the current security model of the latest versions of iOS. What's not known is how security enclave works. But what is known is that it's firmware. Something very much outside what we know about the secure chat app. We also know that iMessage has never been known to have any fundamental security flaws. I tried to clarify above, and I'll do so h…

"I will argue that this guy has none of the skills needed to up the ante on the current security model of the latest versions of iOS."

What are you basing that assertion on?

Re: Apple hires one of the developers behind Signal

#29

Earlier quoted context omitted.

Please quote the article where you feel it interpreted events poorly. And be civil.

I don't really take orders from students, rob. Especially ones who don't read the article and are named studentrob. :)

I read it, Ian. I didn't see them call him a messiah anywhere. Is the word transparent like your comments are now?

Also, I'm no longer a student in the traditional sense. That's sort of a life mantra of mine, to be perpetually learning. You can think of it as the opposite of your world, in which you think you know everything.

Re: Apple hires one of the developers behind Signal

#30

I can understand how people want to put puzzle pieces together, but this is completely idiotic. Whatever remaining security holes there are with secure enclave, they have nothing to do with a software chat app. This is entirely coincidental and has nothing to do with anything. TechCrunch should be ashamed of itself (again) for being such a douchebag. Edit: I'm not saying Apple hiring the guy is stupid. I'm responding…

It does make sense to hire a guy who has had great success in Security. The chat app is just one of the use cases which he handled, and a good experience in designing secure software always helps.
Post reply on HN