Live data from Hacker News

iOS 10 Security White Paper [pdf]

apple.com

1–10 of 99 posts

Re: iOS 10 Security White Paper [pdf]

#2
This is one of the reasons why Apple is still great. Their designs are thoughtful and deeply-considered. They may disappear up their own asses with a fair amount of regularity, but that doesn't stop them from excelling in certain areas (such as, indeed, privacy and security).

Re: iOS 10 Security White Paper [pdf]

#3

This is one of the reasons why Apple is still great. Their designs are thoughtful and deeply-considered. They may disappear up their own asses with a fair amount of regularity, but that doesn't stop them from excelling in certain areas (such as, indeed, privacy and security).

It is sad that something like the iCloud Keychain is so poorly implemented across the different devices.

Re: iOS 10 Security White Paper [pdf]

#4

This is one of the reasons why Apple is still great. Their designs are thoughtful and deeply-considered. They may disappear up their own asses with a fair amount of regularity, but that doesn't stop them from excelling in certain areas (such as, indeed, privacy and security).

It is sad that something like the iCloud Keychain is so poorly implemented across the different devices.

How so? You mean from user access and usability standpoint?

I know I certainly wish there was a Keychain access app like on macOS available for iOS rather than only being able to access passwords via Safari settings.

Re: iOS 10 Security White Paper [pdf]

#7
post #6

http://www.cultofmac.com/280189/icloud-hacker-calls-apples-r... http://www.mirror.co.uk/news/technology-science/technology/a...

"There have not been any breaches in any of Apple’s systems including iCloud and Apple ID," the spokesperson said. "The alleged list of email addresses and passwords appears to have been obtained from previously compromised third-party services."

http://fortune.com/2017/03/22/apple-iphone-hacker-ransom/

Re: iOS 10 Security White Paper [pdf]

#8
I really do respect Apple's attention to security and privacy, however I was a little disappointed when I came across an Apple ID leak from their login form [0] last week. They patched a fix a couple days after I reported it, but still haven't responded to my initial report. It's quite concerning given how easy this simple flaw could have been used for malicious purposes to potentially collect millions of Apple ID's.

[0] https://github.com/zaytoun/Apple-ID-Data-Leak

Re: iOS 10 Security White Paper [pdf]

#9
post #5

Its previous edition was required reading for CS 161 at Berkeley. Would that it were required reading in Mountain View. http://www-inst.cs.berkeley.edu/~cs161/fa16/ (Yeah, it says optional on the syllabus but Weaver said required in lecture.)

Do they don't know/care about security, or is it simply the case that it is hard to have something like the secure enclave across all Android devices? Genuine question.

Re: iOS 10 Security White Paper [pdf]

#10
post #5

Its previous edition was required reading for CS 161 at Berkeley. Would that it were required reading in Mountain View. http://www-inst.cs.berkeley.edu/~cs161/fa16/ (Yeah, it says optional on the syllabus but Weaver said required in lecture.)

Do they don't know/care about security, or is it simply the case that it is hard to have something like the secure enclave across all Android devices? Genuine question.

It's probably a little bit of both - they don't care as much when it comes to Android (since Android's "open" nature is one of its primary selling points) and they also don't control the entire supply chain like Apple does.

The latter is important: at the end of the day, software can only be as secure as the hardware on which it is installed. For example if someone can tamper with the hardware random number generator then your crypto becomes compromised.

Post reply on HN