Live data from Hacker News

Under iOS 11, authorities won’t be able to image your device without a passcode

arstechnica.com

151–160 of 296 posts

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#151
post #36

Earlier quoted context omitted.

You can't run a mass maket open platform without security or privacy issues as Users will install things that cause problems.

...and IMHO those "security or privacy issues" are an acceptable cost of freedom, the same way that I see crime in general: no one wants to be a victim, but you can see that, as long as crime still exists, so does freedom. If no one can do "bad things", then everyone has already had the essence of life taken out of them. I wrote this comment a few months ago when (almost) everyone was wondering what could be done, in…

As I mentioned in a sibling comment, and it's almost ironic thinking about it, this "freedom for security" tradeoff we're making here is not what it seems.

I see your point in the context of e.g. WannaCry and WTC attacks emboldening authoritarians, however this privacy move we're discussing is actually an anti-authoritarian move. It gives the user more privacy and more freedom.

Advocating more lax privacy/security in this case is siding with authoritarian tendencies.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#152
post #44

Earlier quoted context omitted.

How? Sideloaded apps would still be sandboxed.

It's more than just sandboxing: Apps going through the App Store have to meet a stringent set of requirements, chiefly being no private API usage, no circumvention of features intended to give the user control/privacy, and no third party web engines (and all the performance and security implications that come with those). Apple regularly rejects apps that violate the first two, and while I'm sure some get through the…

Apple's checks are not very deep. They suffice to keep honest people honest but do little against an actual adversary.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#153

For anyone concerned that authorities force you to give up your password to them (thus allowing them to image your device), you can pair your iPhone to a computer with a MDM (managed device profile), which will prevent any other device from connecting to it. iOS security researcher (now Apple employee) Jonathan Zdziarski has 2 blog posts on this: Counter-Forensics: Pair-Lock Your Device with Apple’s Configurator: htt…

That's a great idea! Does anyone know if this technique works with iOS 10? The linked blogpost is for iOS 7 and 8

It still works great, however the linked post uses Configurator and Apple has since replaced it with Configurator 2, so some of the options and workflow are different now.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#154
post #45

Earlier quoted context omitted.

This change alone is tempting me, and I have been diehard anti-apple for about a decade now for walled-garden reasons. I know, I know, walled garden prevents users from opening their phone to vulnerabilities or guaranteeing a secure experience. I guess I wish I could have my cake and eat it too.

Android has required the user to enter the unlock code to back up the device for years now. This is Apple playing catch-up.

How hard is it to jailbreak with ADB shell and get root on a random phone? Does that always require a code?

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#155

Earlier quoted context omitted.

No. There are open source Android phones. There are no open source ios phones

Yeah? The baseband and chip ROMs are open source? Really?

Or the proprietary kernel patches and binary blob drivers?

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#156

With it being such a closed platform, what are the odds this is actually true? There's no way to verify that they don't have a skeleton key.

You think they lie to the US government every time it asks them to decrypt phones and they can't?

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#157

I have never seen a company both so technically capable and supportive of user privacy as Apple. It stands completely apart from all of the tech giants of today.

I agree. But it's merely the consequence of them being a tech giant whose product is not their user's privacy.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#158
post #140

Earlier quoted context omitted.

Google Fi only allows Their Nexus and Pixel phones on their network. It is like an ISP seeing that you are running Linux and not letting your traffic through, just a bit more complicated than that. (SIM Card, Modems, Frequencies)

This sounds a bit misguided. IIUC, Google Fi is really a mechanism of accessing two carriers from the same device. It consists of 1. A partnership between Google Fi (the cellular provider), T Mobile, and Sprint, and 2. A special radio hardware on the phone that is capable of working with two different "channels" at the same time. Since my Nexus device broke, I have personally been using "Google Fi" (the provider) on…

Is it actually a special radio, or just features which normally get disabled by e.g. Verizon programming the baseband? I'm assuming that the "special" radios are simply NOT using crippleware and setting some other registers which could be enabled on many more devices...if carriers played ball, which they don't want to for obvious reasons.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#159
post #157

I have never seen a company both so technically capable and supportive of user privacy as Apple. It stands completely apart from all of the tech giants of today.

I agree. But it's merely the consequence of them being a tech giant whose product is not their user's privacy.

There is no “merely” about it when it is a conscious choice to pursue this business model.

Re: Under iOS 11, authorities won’t be able to image your device without a passcode

#160
post #151

Earlier quoted context omitted.

...and IMHO those "security or privacy issues" are an acceptable cost of freedom, the same way that I see crime in general: no one wants to be a victim, but you can see that, as long as crime still exists, so does freedom. If no one can do "bad things", then everyone has already had the essence of life taken out of them. I wrote this comment a few months ago when (almost) everyone was wondering what could be done, in…

As I mentioned in a sibling comment, and it's almost ironic thinking about it, this "freedom for security" tradeoff we're making here is not what it seems. I see your point in the context of e.g. WannaCry and WTC attacks emboldening authoritarians, however this privacy move we're discussing is actually an anti-authoritarian move. It gives the user more privacy and more freedom. Advocating more lax privacy/security in…

Apple is only shifting the authority to itself. They still have the signing keys and control what you can or cannot do with the device you "purchased".
Post reply on HN