Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

31–40 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#31

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

Can these "features" be turned off by the user, and not enabled remotely?

Are these "features" off by default?

No? It's maliciously removing control from the user.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#32
post #6

So in short: Apple has back doors that they claim aren't really back doors since only Apple apps can use them. If the NSA hasn't been using them already, it is only a matter of time.

If it's a backdoor for Apple, then it's a backdoor for anyone who can figure it out (other apps, hackers, government agencies alike).

[deleted]

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#33

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

> It's good to know Apple has the power to look through your encrypted files given physical access (file relay).

So the requisites are: "be Apple" and "have physical access"? That's awfully little for what's supposed to be encrypted files.

It (seems to be) no secret that law enforcement sends devices to Apple when they can't handle them themselves. So if I'm understanding it right: you can't protect yourself with an iDevice, consider all your data compromised?

Sensationalist or not, it bothers me a little.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#34
This post appears to be gone. Here's Apple's (new) documentation on the matter: http://support.apple.com/kb/HT6331?viewlocale=en_US&locale=e...

If Apple is being truthful and transparent, calling this a "backdoor" is a bit like calling sshd a "backdoor".

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#35
post #27
post #18

Earlier quoted context omitted.

I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.

The fact that the other major mobile OSs gets 98% of the mobile malware (according to studies), makes this point about the "nonchalant attitude" rather week...

The attitude you exhibit towards iOS doesn't fly when Linux advocates mention that Windows is the target of 98% of PC malware.

And maybe it's true: 98% of the PC malware is targeted at Windows and 98% of the mobile malware is targeted at Android. I certainly take advantage of the Windows malware situation by running Linux, and not running any malware checkers.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#36
post #31

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

Can these "features" be turned off by the user, and not enabled remotely? Are these "features" off by default? No? It's maliciously removing control from the user.

welcome to the apple experience?

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#37
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

>Yet in the slides for his talk[1] under theories he writes: >"Maybe for Developers for Debugging? No." Followed by 6 bullet point reasons why this isn't a general excuse for all of the backdoors - it's mentioned in reference to all of his findings and not specifically pcapd (which is only mentioned on 2 consecutive slides out of 60, separated from this statement about debugging by 15 slides.) Your comment is far mor…

I was only providing an example for pcapd rather than all of the items he is classing as backdoors. The entire slide is:

    Maybe for Developers for Debugging? No.
     - Actual developer tools live on the developer image, and are only available when Developer Mode is enabled
     - Xcode does not provide a packet sniffing interface for developers
     - Developers don’t need to bypass backup encryption
     - Developers don’t need access to such sensitive content
     - Apple wants developers to use the SDK APIs to get data
     - There are no docs to tell developers about these “features”
To me all those points seem to be provided to systematically deny legitimate uses for pcapd, which is contrary to the blog entry where he states, "I mentioned in my talk that pcapd has many legitimate uses". However it's entirely possible I'm reading it wrong.

As I mentioned, there is good information in there. Adding extra, potentially misleading. fluff is unnecessary and counter-productive to my mind. That's just my opinion though.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#38
post #27
post #18

Earlier quoted context omitted.

I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.

The fact that the other major mobile OSs gets 98% of the mobile malware (according to studies), makes this point about the "nonchalant attitude" rather week...

> The fact that the other major mobile OSs gets 98% of the mobile malware (according to studies), makes this point about the "nonchalant attitude" rather week...

No it does not.

It's not acceptable when any company is nonchalant about any security problem on their device, product or service.

And, taking Android as an example, Google is very open about the malware and malicious app problem[1] -- and takes steps to help mitigate said problem.

Apple is just straight-up telling users it's not a problem. There is a key difference here.

[1] http://en.tempo.co/read/news/2014/03/01/240558528/Google-Adm...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#39

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

They don't need a backdoor when they have admin rights on your (their) device...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#40

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

No conspiracy is required for an intelligence agency to turn features into "features".
Post reply on HN