Live data from Hacker News

It's your device, you should be able to repair it

bbc.com

541–550 of 566 posts

Re: It's your device, you should be able to repair it

#541
post #522

Earlier quoted context omitted.

What you have described completely destroys the security model. > In case of a running iPad, an Apple-authorized update could be pushed to the OS to unlock it and allow it to run binaries directly. Which of course an attacker would be able to do too. > Apple could also document any hardware features that would allow someone to put an iPad into "free-for-all" mode. Presumably this would require opening up the device t…

We're talking about a device that is completely unsupported by its manufacturer. You already have no expectation of security or integrity when the last available OS and security update is over 5 years old by now. Opening up access to install your own software would have great potential to increase the security of the device, not least because you can actually run current and patched versions of any software. What you…

The unlocking mechanisms you proposed would have to be present in devices right from the start. Not just in devices that are unsupported.

Nobody is talking about security through obscurity. This is about not introducing easily explored weaknesses into all devices, supported or not.

Re: It's your device, you should be able to repair it

#542
post #541

Earlier quoted context omitted.

We're talking about a device that is completely unsupported by its manufacturer. You already have no expectation of security or integrity when the last available OS and security update is over 5 years old by now. Opening up access to install your own software would have great potential to increase the security of the device, not least because you can actually run current and patched versions of any software. What you…

The unlocking mechanisms you proposed would have to be present in devices right from the start. Not just in devices that are unsupported. Nobody is talking about security through obscurity. This is about not introducing easily explored weaknesses into all devices, supported or not.

If you have physical access to a device, you can already tap the memory bus or countless other places. Relying on a device itself to be secure when it is in your adversaries' hands is futile.

Open the hardware, use secure software and keep your storage encrypted, preferably on removable storage.

Re: It's your device, you should be able to repair it

#543

Earlier quoted context omitted.

I was merely making the observation that the growth of the value of something is not necessary a linear function of the amount of materials used. I am not convinced, as an example, that the first iPhone caused drastically more waste to produce (or drastically less) than the last one. Yet the last one is clearly much better.

I'm not saying it's a linear function either. I think it varies. But I also don't think the value added per unit of resources used is growing exponentially. So the problem still remains, because anything short of exponential function isn't going to impact the overall trend long-term.

>value added per unit of resources used is growing exponentially

I would love to see the amount of resources that are used to produced each iPhone, because I don't have a big issue assuming that each phone brings, say 3 or 4 percent more utility to its user than the previous model would have.

So, assuming the battery is the most dirty part of the phone, I found the battery size for all the iphone models[0] and even if we exclude the the large ones, the iPhone 11 has a 54 percent larger battery.

The phones were released in 2007 and 2019, 12 years and 3 months apart[1]. That works out to a growth of approximately 3.3%.

So my original assumption was wrong, there has been an exponential growth in materials that nearly matches GDP growth.

[0]: https://itigic.com/how-much-battery-does-an-iphone-have-capa...

[1]: https://www.knowyourmobile.com/phones/every-single-iphone-re...

Re: It's your device, you should be able to repair it

#544

Earlier quoted context omitted.

RAM and storage is usually integrated on phones. The battery is usually not something you can pull out anymore because people like me prefer phones that I can use to find my way in the rain without risk damaging the phone, but even so they are pretty easy to replace, the same with the screen. On laptops you have a choice: buy a Thinkpad that is not an ultrabook, but even then you see people prefer thinner and lighter…

How do you use your phone in the rain? Whenever I try, I find it's pretty much impossible, because the screen gets all wet and slippery, I can hardly see anything on it because of distortion through individual drops of rain, and I get spurious clicks from raindrops falling onto it. So I have to shield it under an umbrella or something... And if I have to do that anyway, the phone being less than 100% watertight becau…

I only use it in the rain to look up maps and see directions or to quickly see a message and you are right that the distortions from the rain can make it hard to see, though I haven't had the issue of a slippery phone.

Maybe I am just paranoid, but I would like to know my phone doesn't die on me when it is exposed to rain.

Re: It's your device, you should be able to repair it

#545
post #541

Earlier quoted context omitted.

The unlocking mechanisms you proposed would have to be present in devices right from the start. Not just in devices that are unsupported. Nobody is talking about security through obscurity. This is about not introducing easily explored weaknesses into all devices, supported or not.

If you have physical access to a device, you can already tap the memory bus or countless other places. Relying on a device itself to be secure when it is in your adversaries' hands is futile. Open the hardware, use secure software and keep your storage encrypted, preferably on removable storage.

> If you have physical access to a device, you can already tap the memory bus or countless other places

This is complete bullshit.

iOS devices use an SOC so there is no way to ‘tap the memory bus’ without destroying the processor.

iOS decides do in fact resist access even when they are in the hands of an adversary.

Also it seems like you don’t know that the storage on iOS devices is already encrypted.

Re: It's your device, you should be able to repair it

#546
post #538

Earlier quoted context omitted.

Reread the thread. In this thread, the OP is speaking about design obsolescence.

> Reread the thread. In this thread, the OP is speaking about design obsolescence. I don’t need to reread it. My response applies to design obsolescence. Relatively few people upgrade every year these days. The fact that the old devices are still desirable negates the idea that people don’t want them because they look outdated . I.e. changes in design are not causing people to stop using the devices. For design obsol…

> Relatively few people upgrade every year these days.

[Citation needed]

Re: It's your device, you should be able to repair it

#547
post #545

Earlier quoted context omitted.

If you have physical access to a device, you can already tap the memory bus or countless other places. Relying on a device itself to be secure when it is in your adversaries' hands is futile. Open the hardware, use secure software and keep your storage encrypted, preferably on removable storage.

> If you have physical access to a device, you can already tap the memory bus or countless other places This is complete bullshit. iOS devices use an SOC so there is no way to ‘tap the memory bus’ without destroying the processor. iOS decides do in fact resist access even when they are in the hands of an adversary. Also it seems like you don’t know that the storage on iOS devices is already encrypted.

So an SoC-based device is simply impervious to physical attacks? That's impressive! The power of the RDF is still strong.

Re: It's your device, you should be able to repair it

#548
post #545

Earlier quoted context omitted.

> If you have physical access to a device, you can already tap the memory bus or countless other places This is complete bullshit. iOS devices use an SOC so there is no way to ‘tap the memory bus’ without destroying the processor. iOS decides do in fact resist access even when they are in the hands of an adversary. Also it seems like you don’t know that the storage on iOS devices is already encrypted.

So an SoC-based device is simply impervious to physical attacks? That's impressive! The power of the RDF is still strong.

> So an SoC-based device is simply impervious to physical attacks?

This is a straw man - nobody said ‘impervious’.

You said this:

> If you have physical access to a device, you can already tap the memory bus or countless other places

It is complete bullshit.

If it wasn’t, you’d be able to post a link to someone doing it.

Re: It's your device, you should be able to repair it

#549
post #536

Earlier quoted context omitted.

But it is different from GNU/Linux phones, which will be supported forever.

1. So why did you mention laptops? Seems like a false comparison. 2. What 11 year old GNU/Linux phone is supported today let alone ‘forever’?

> 1. So why did you mention laptops? Seems like a false comparison.

Linux laptops have a proven track record of being supported for >10 years. Since the GNU/Linux phones also run mainline Linux, they are effectively the same kind of devices. There is no reason to expect that GNU/Linux phones will stop being supported.

> 2. What 11 year old GNU/Linux phone is supported today let alone ‘forever’?

Nokia N900? See also: https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...

Re: It's your device, you should be able to repair it

#550
post #548

Earlier quoted context omitted.

So an SoC-based device is simply impervious to physical attacks? That's impressive! The power of the RDF is still strong.

> So an SoC-based device is simply impervious to physical attacks? This is a straw man - nobody said ‘impervious’. You said this: > If you have physical access to a device, you can already tap the memory bus or countless other places It is complete bullshit. If it wasn’t, you’d be able to post a link to someone doing it.

Backdoors into iPhones already exist, here's one that was used for a while, before Apple closed it: https://www.nbcnews.com/tech/tech-news/cat-mouse-fight-fix-e...

If you think that is the only way into an Apple device, and that police or even nation states are now helpless against the mighty "hack resistant" iPhone, then you may be interested in this bridge I happen to have for sale.

Post reply on HN