Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

11–20 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#11
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor.

It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit.

Not saying there aren't risks out there, just that the industry markets itself through bombast and sometimes exaggerates them.

Back to the infosec realm, the simple truth is that the only absolutely secure system is one that is off and the only absolute privacy is in your own head (maybe). Everything else is a matter of degrees of risk, and the curve is hockey stick shaped. It's relatively easy to mitigate the big risks, but that leaves a long tail of small risks and small vulnerabilities that require an exponentially increasing amount of effort and inconvenience to deal with.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#12

So in short: Apple has back doors that they claim aren't really back doors since only Apple apps can use them. If the NSA hasn't been using them already, it is only a matter of time.

"back doors" that require approval from the user on the phone..??

Backdoors that require the user to unlock their device and have paired with a PC in the past.

If a paired PC is compromised (a trivial task for a sophisticated hacker or the NSA, if the millions of windows pc bot nets are evidence), and wifi sync is enabled, and the device is unlocked and in use, then the compromised PC could theoretically harvest personal information from the device without any warning or notification to the user.

IMO it seems like the only requirements to compromise someone's iDevice is A) they use their iDevice with a compromised PC, and wifi sync seems to make it all much easier.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#13
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

>Yet in the slides for his talk[1] under theories he writes:

>"Maybe for Developers for Debugging? No."

Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.)

Your comment is far more misleading than what he's written.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#14
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

"Yet in the slides for his talk[1] under theories he writes..."

I think you may have misunderstood. He is at this point theorising why the service is enabled outside of developer mode, not why it exists at all.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#15
Most companies will downplay any negative aspect of their product; it's pretty normal, part of the survival aspect of an organization. Microsoft has done the same thing a few times as well. http://www.zdnet.com/blog/security/microsoft-downplays-bitlo... http://www.computerworld.com/s/article/9133248/Microsoft_con...

I'm more surprised at the fact that Apple decided to actually confirm the existence of a back door in their product (even though they are "misleading" (as stated in the article) about what really is at risk here). The fact that Apple was downplaying this tells me they haven't realized that a product, especially operating systems and computers, depends a lot on the userbase; if the userbase is kept ignorant then Apple will keep itself in its 'comfortable zone' since its not being pushed by the users to improve.

Nonetheless, its still pretty good that Apple has confirmed this, baby steps I guess.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#16
post #11
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…

Well, apparently, even that is not enough.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#18
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

>Yet in the slides for his talk[1] under theories he writes: >"Maybe for Developers for Debugging? No." Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.) Your comment is far mor…

I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#19
post #11
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…

every industry trumps up the usefulness of their product, it's called marketing. It's on the consumer to cut through the marketing-speak and understand what they actually need to pay for.
Post reply on HN