Live data from Hacker News

Apple’s iPhone 14 Redesign for Repair

ifixit.com

251–260 of 590 posts

Re: Apple’s iPhone 14 Redesign for Repair

#251

Odd article considering everything is still software locked to the phone. Sure it's easier to repair, but if you get your parts from anywhere else than apple's program directly, a lot of features will stop working. Hugh Jeffreys made a video interchanging parts on two brand new iphone's and it disabled a lot of things including auto-brightness. https://www.youtube.com/watch?v=K2WhU77ihw8

[deleted]

Re: Apple’s iPhone 14 Redesign for Repair

#252
post #168
post #61

Earlier quoted context omitted.

If you give your phone to an adversary with large amounts of resources it is game over. If you have to worry about that I most certainly would hope that you wouldn't leave your phone to a repair-shop.

Everyone keeps parroting this like it's 1995 but infinite resources doesn't really help you. In the US FBI case they happened to chain a few now patched exploits in the lightning port that did nothing except allow them the ability to brute force the password. Had the password been strong it would have been game over. Regular, run of the mill encryption you can download at every corner store can withstand attacks from…

Zero-days are a thing, as well as companies that find them specifically to sell to governments

Re: Apple’s iPhone 14 Redesign for Repair

#253
Does the iPhone 14 still have the battery glued to the back? Couldn't figure it out from reading the article. I recently replaced the battery on my old iPhone 6s using the ifixit repair kit. Of all the steps I found removing the tape attached to the battery was the flakiest/hardest operation. After many attempts I did remove it but I also ended up cracking the battery a bit :sigh:. Any changes that make the removal of the battery easier would be a great win for repairability.

Re: Apple’s iPhone 14 Redesign for Repair

#254

Earlier quoted context omitted.

That "unlimited" thing only impacts a very small number of devices. It is a better headline than reality. Previously you could have two accidental damage incidents PER YEAR, which means four for a standard Applecare+ 24 months plan. How many people, realistically, had over four accidental damage incidents in a two-year period wherein they benefit from this "unlimited" change? As I said, it is good marketing, a very n…

How many people, realistically, had over four accidental damage incidents in a two-year period My wife. Mostly because of the Minnesota State Fair.

Did she fall into the dunk tank?

Re: Apple’s iPhone 14 Redesign for Repair

#255
post #231

Earlier quoted context omitted.

> Why is there no way for me to (even temporarily) disable this feature if I actually want to fix my phone? You want to be able to temporarily disable a feature that Apple introduced to prevent from installing potentially stolen parts in your phone?

All parts are 'potentially stolen', that's just a scary thing that John Deere and Apple says to justify their first-party stranglehold on repairs. Louis Rossmann and co. use donor parts for repairs all the time. If they own and can unlock the donor Macbook/iPhone, they should be able to attest that the device is being used for parts/repair and disable the protection. I see no potential for abuse here, and it prevents…

The amount of uncritical comments in any post around apple on HN is usually quite something, I wouldn't get too excited about that. Its mainly US website so that's to be expected.

That being said, there are some good points raised here by folks. If you don't like how Apple does things overall, there are mighty fine competitors that provide even more in some areas and are not Chinese, but they do charge premium for their quality too. Just expect some similar/other limitations there too.

Re: Apple’s iPhone 14 Redesign for Repair

#256

Odd article considering everything is still software locked to the phone. Sure it's easier to repair, but if you get your parts from anywhere else than apple's program directly, a lot of features will stop working. Hugh Jeffreys made a video interchanging parts on two brand new iphone's and it disabled a lot of things including auto-brightness. https://www.youtube.com/watch?v=K2WhU77ihw8

This makes it easier for my technicians when customers lie by omission when they have had their device repaired someplace else and they bring it back to us for repair. It's not until we get into the repair and find out someone has stripped screws that can't be removed without extraction tools and replaced LSI's. It's also nice for consumers who get their devices stolen strictly for parts. Preventing someone from basi…

You can sign things without locking them though. The utility you're speaking of is identification, what's the utility for a user in locking a device against repair?

Apple probably report way more data than a list of part IDs already.

Re: Apple’s iPhone 14 Redesign for Repair

#257
post #211

Earlier quoted context omitted.

> To date, no HN discussion of this crypto-pairing of the phone to its parts has revealed an alternative solution that would be effective at Apple’s scale for preventing phones from being hacked by a parts swap while also allowing any part to be swapped in Random-ass repair shops are not going to expend the effort of putting in fake parts to hack you to.. hack a couple of thousand dollars off of your account and then…

Anyone crossing a border where a nation state takes physical possession of their device is, currently, protected. The US border authorities have a very awful policy of storing data they’ve stolen for up to 15 years, and other US federal authorities have been previously caught using hardware modifications to hack devices. Anyone within 100 miles of a US border is subject to seizure and search under US law, which is ap…

> Anyone crossing a border where a nation state takes physical possession of their device is, currently, protected.

Assuming you are a normal person, you already are. Rapidly click the lock button 5 times and they cannot extract any data with normal means. If you are someone worthy of nation-state attention, why are you crossing the border without a wiped device, as has been the adviced standard practice for years?

Again: these draconian repair protections should be tied to Lockdown mode. There is no reason to destroy repairability to protect a tiny group that isn’t giving their device out for repairs anyway if they’re following opsec.

Re: Apple’s iPhone 14 Redesign for Repair

#258

This has got to be one extremely expensive toolchain and supply chain redesign to do, but since they have done it a few times before (instead of incremental changes) I suppose the money department has worked out when it is feasible to do that kind of thing while keeping the people in charge happy. I'm curious to see if this is a 'test' to see if this doesn't have too many downsides, I imagine ingress area increasing…

I disagree that integrity protection is necessary across many components of the phone. There should be integrity protection on the SoC, and then all other components should be untrusted. Sure, that means someone can proxy the fingerprint sensor or put on a fake screen that shows a fake consent dialogue. But I think that is an acceptable risk - after all, you can never protect against someone making an entirely new de…

> But I think that is an acceptable risk

And I think it is unacceptable.

That doesn't mean that you also have to think the same thing, but I would rather not have that option taken away from me. I also don't think that you have made a case for any similar-security implementation for integrity protection.

I think distributed trust is the only way to make trustworthy components, and the only known-good way to do that is using PKI, and the only proven way to do that is to have a CA.

> [..] after all, you can never protect against [..]

That's the kind of thinking that gets you stuck in "we have already lost so we should stop trying".

If you can make sure that your finger print never leaves the secure enclave, and you can make sure that the Secure Enclave cannot be replaced, you can trust the device a whole lot more than a fake security measure that can be circumvented at every stage. What is the point of an insecure security control? You don't send your passwords plain-text over the internet, do you? Just because TLS is imperfect, and your CA store can be compromised, and your screen might be recorded using a camera and a telescope doesn't mean that therefore we should stop improving TLS...

Re: Apple’s iPhone 14 Redesign for Repair

#259

Earlier quoted context omitted.

You know, I bet somebody responded very similarly to a complaint about the first game studio to put loot boxes in their games. Now we are plagued by them. "Don't like it? Well just make your own ____!" is another classic.

If you play AAA games or mobile games, sure, you're plagued by them. I don't play either. The games I do play don't have much in the way of that sort of thing at all. And I think they're more fun games besides.

I don't understand your point, which effectively seems to be "not all games!"

This is actually a zero sum scenario, games that are pay-to-win would have been something else had the concept not been popularized. Even games that are completely structured around these gambling mechanics... no, they wouldn't necessarily be different games in an alternate reality - they'd just be a different use of the dev's time. So maybe a birdhouse. Also, if this was a derail attempt - well done, I'm now thinking about carpentry instead of how much I dislike Apple.

Re: Apple’s iPhone 14 Redesign for Repair

#260
post #211

Earlier quoted context omitted.

It also considerably reduces the ability of nation-state attackers to replace parts with modified hardware without your knowledge, as Apple can detect and terminate misuse of the tool that creates new cryptographic signing keys for the pairing of phone and part. We saw signed-pairing appear with the Touch ID system in response to Apple learning of nation-state attacks on the iPhone that used hardware modifications. T…

> To date, no HN discussion of this crypto-pairing of the phone to its parts has revealed an alternative solution that would be effective at Apple’s scale for preventing phones from being hacked by a parts swap while also allowing any part to be swapped in Random-ass repair shops are not going to expend the effort of putting in fake parts to hack you to.. hack a couple of thousand dollars off of your account and then…

The "your X has been replaced" pop-up doesn't handle the situation where an attacker knows your passcode.

I think you might also be failing to account for situations where you aren't in possession of your phone for an hour or two. Imagine if police in a foreign country take your phone for a couple of hours and then give it back to you. Or you leave your phone in a hotel room to charge for a few hours. Or your phone gets "misplaced" for an hour after going through the airport x-ray machine.

There are many targets other than journalists too, such as people in the USA who develop export controlled technologies, certain tech company employees, defense contractor employees, other government employees, etc. I don't think you can expect every potential target to constantly set their iphone to lockdown mode.

Post reply on HN