Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

51–60 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#51
post #19

Earlier quoted context omitted.

every industry trumps up the usefulness of their product, it's called marketing. It's on the consumer to cut through the marketing-speak and understand what they actually need to pay for.

> every industry trumps up the usefulness of their product, it's called marketing. It should be called lying and bullshitting, and I strongly believe that we tolerate it far too much as a culture.

Marketing can degrade into con artistry. It isn't always, but it certainly can.

That being said, I think in the long run people appreciate it if your marketing isn't scummy.

(Not directly aimed at the original article, though I do think there's a lot of deceptive, confusing, and overly hyperbolic FUD in the security sector.)

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#53
post #27
post #18

Earlier quoted context omitted.

I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.

The fact that the other major mobile OSs gets 98% of the mobile malware (according to studies), makes this point about the "nonchalant attitude" rather week...

Apple is a respectable company who cares about their brand image, so they're obviously allowing only high-profile adversaries' malware on your device!

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#55
post #6

Earlier quoted context omitted.

If it's a backdoor for Apple, then it's a backdoor for anyone who can figure it out (other apps, hackers, government agencies alike).

As I understand it, there is more than just figuring out how it works; one also needs to have physical access to the phone and be able to imitate Apple cryptographically. Not out of reach for the NSA maybe, but not exactly typical hacker stuff.

> and be able to imitate Apple cryptographically

Like impersonate them cryptographically with a forged/stolen ssl cert?[1]

> one also needs to have physical access to the phone

The user only has to pair the device with their PC for the PC to become a "trusted device", from which this exploit can be run.

[1] > Serious Security: Google finds fake but trusted SSL certificates for its domains, made in France http://nakedsecurity.sophos.com/2013/12/09/serious-security-...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#57

This post appears to be gone. Here's Apple's (new) documentation on the matter: http://support.apple.com/kb/HT6331?viewlocale=en_US&locale=e... If Apple is being truthful and transparent, calling this a "backdoor" is a bit like calling sshd a "backdoor".

I don't see where they document how you disable or block these.

They aren't enabled by default.

"requires the user to have unlocked their device and agreed to trust another computer"

and

"For users who have enabled iTunes Wi-Fi Sync on a trusted computer"

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#58
What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access?

You'd be pretty annoyed if the front door to your house, when you opened it, also opened up your document safe, emptied your wallet onto the floor and invited visitors to leave bugging devices to spy on you later.

Also, the defence of "just don't agree to pair your phone with an unknown USB device" can actually be tricky. On a flight, I plugged my phone into the USB port on the seatback to charge it. The phone repeatedly kept asking if I wanted to pair it with something (who knows what it was? the entertainment system, maybe?). If I had accidentally hit the wrong button only once (on a prompt that randomly appeared), my phone could have been owned, and there's no easy way to un-pair.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#59
post #55

Earlier quoted context omitted.

As I understand it, there is more than just figuring out how it works; one also needs to have physical access to the phone and be able to imitate Apple cryptographically. Not out of reach for the NSA maybe, but not exactly typical hacker stuff.

> and be able to imitate Apple cryptographically Like impersonate them cryptographically with a forged/stolen ssl cert?[1] > one also needs to have physical access to the phone The user only has to pair the device with their PC for the PC to become a "trusted device", from which this exploit can be run. [1] > Serious Security: Google finds fake but trusted SSL certificates for its domains, made in France http://naked…

That is about the browser CA system, which is a mess of questionable trust. It's not an attack that is applicable to Apple's own root certificate.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#60
post #33

I'm a little conflicted about this. On one hand it's good to learn about the security of your device, on the other hand he's far too partial and sensationalist about these iOS features. Yes, features. • It's good to know packet capture can be remotely enabled on your device from data collected on a computer the device has trusted. • It's good to know Apple has the power to look through your encrypted files given phys…

> It's good to know Apple has the power to look through your encrypted files given physical access (file relay). So the requisites are: "be Apple" and "have physical access"? That's awfully little for what's supposed to be encrypted files. It (seems to be) no secret that law enforcement sends devices to Apple when they can't handle them themselves. So if I'm understanding it right: you can't protect yourself with an…

Are we concerned about Apple here or just commercial phones in general?

To me that's a pretty good security model, if true. I can choose not to give Apple my phone and I can supervise them. I don't know of another commercial phone that protects us better at the moment.

Post reply on HN