Live data from Hacker News

iOS 10 Security White Paper [pdf]

apple.com

51–60 of 99 posts

Re: iOS 10 Security White Paper [pdf]

#51
@computerality extracted the sections that changed between the iOS 9 and 10 security white papers here:

https://gist.github.com/computerality/3e0bc104cd216bf0f03f8d... tl;dr:

https://twitter.com/computerality/status/844652877058625536

https://twitter.com/computerality/status/844654500141060096

https://twitter.com/computerality/status/844655868377550848

Re: iOS 10 Security White Paper [pdf]

#52
What's lacking is a requirement that Apple Store apps must cooperate with user privacy settings. If the user denies an app access to location services, contacts, or calendars, Apple should require that the app still run. For example, if the user denies the Uber app location information when the app is not being used, Uber car ordering should still work. Apps should not be allowed to demand access they do not need to serve the user.

Re: iOS 10 Security White Paper [pdf]

#53
post #13

Earlier quoted context omitted.

Do they don't know/care about security, or is it simply the case that it is hard to have something like the secure enclave across all Android devices? Genuine question.

Mmm? Secure enclave is present on most Android devices and is mandatory since Android 6.0. (It's just called something else.) Historically Android has been lagging behind a bit from iOS devices when it comes to security, but Pixels and their software have a very similar security model and design (with some exceptions - less granularity with file-based encryption and some other mostly minor details). Non Google device…

Nexus 5x and 6p have dm-verity as well.

Re: iOS 10 Security White Paper [pdf]

#54

Earlier quoted context omitted.

Yes, IMHO they know. Their Chrome security model was required reading in CS 261. https://people.eecs.berkeley.edu/~raluca/cs261-f15/ But to me, they seem to be trying to find a moderate level of security with a profitable cost of goods. It doesn't seem that their heart is in it the way Apple's is with the Enclave. iOS is still breakable at the nation state level but well that's quite a high bar. Nation states are bre…

Do you have a source on the "breakable at the nation state level"? Last I heard they've only been able to compromise models before the 6.

"Breakable" and "have been broken" are different budgets.

Re: iOS 10 Security White Paper [pdf]

#55
post #30

Earlier quoted context omitted.

How so? You mean from user access and usability standpoint? I know I certainly wish there was a Keychain access app like on macOS available for iOS rather than only being able to access passwords via Safari settings.

Probably referring to the key distribution process, where to enable iCloud Keychain you have to approve from another device. It's a sound design in theory - the keys are only stored locally, so even Apple can't access them - but I've personally experienced issues several times where the approval notification wouldn't show up on my other devices, or the UI was in an inconsistent state, etc.

It's true- I think one of Apple's main stumbling points lately has been failing to consider the user experience in cases where, for example, a good Internet connection isn't available, or a particular piece of data has an unexpected attribute.

Re: iOS 10 Security White Paper [pdf]

#56

Earlier quoted context omitted.

There's nothing wrong with disclosing a security bug immediately. https://hn.algolia.com/?query=author:tptacek%20responsible%2...

Wow, he's nothing if not consistent... you gotta respect that. Same opinion and phrasing going back 4+ years!

Closer to 24.

http://www.securityfocus.com/blogs/906

Re: iOS 10 Security White Paper [pdf]

#57
post #32

Earlier quoted context omitted.

> Anyone here on an Android phone ever been hacked? You must be new, but here's some resources I suggest you review before you go on a crusade in future Apple articles: https://en.wikipedia.org/wiki/Stagefright_(bug) https://arstechnica.com/security/2016/06/godless-apps-some-f... https://arstechnica.com/security/2016/10/android-phones-root... http://blog.elevenpaths.com/2016/07/another-month-another-ne... Also, keep…

Anyone who knows how to use a smartphone properly simply won't have security problems to deal with. What difference does any of this make with iOS when we all know the US Gov't can simply access backdoors whenever they please? Don't fall for this security meme. What does any of this matter when iCloud is a hacker's dream?? And I didn't ask if HN readers' phones CAN be hacked, I simply asked if they WERE asked. F off…

We've banned this account for violating the site guidelines.

Re: iOS 10 Security White Paper [pdf]

#59
post #52

What's lacking is a requirement that Apple Store apps must cooperate with user privacy settings. If the user denies an app access to location services, contacts, or calendars, Apple should require that the app still run. For example, if the user denies the Uber app location information when the app is not being used, Uber car ordering should still work. Apps should not be allowed to demand access they do not need to…

Use a service that respects that then. Lyft.
Post reply on HN