Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

91–100 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#91
post #63

Earlier quoted context omitted.

There are USB condoms built exactly for the scenario you describe. http://int3.cc/products/usbcondoms

It partially matches what he's talking about, but it's still a trinary choice. 1> Don't tether 2> Get only power 3> Give away the keys to the castle

FYI it's "ternary".

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#92
No, what's really disappointing is FUD directed at debugging tools. These sorts of "presentations" and "research" are pointless. Anyone who does IOS development knows about these tools, they're not secret. Apple has Tech Notes and documentation in Xcode on them going back years. Let's please try to focus our ire where it's needed.

And to whoever said that Google is "very open" about their malicious app problems, well, gosh, where to start...

Google's Android is the cause of the malicious app problem. By not allowing users to have fine-grained access control on the various entitlements in Android, Google is forcing users to adopt an all-or-nothing approach to every app they download. Don't like that this app wants access to your Contacts? Fine, then don't install it. The root problem here is not allowing the user to determine, after-the-fact, what privileges an app should have. Apple gets this right, Google fails miserably.

Of course there's also no one Android. You know that, right? There's a bunch of different Androids from a bunch of different carriers all of which run different hacked-up versions littered with a bunch of crap code from carriers that almost no one wants. Code which I imagine is also littered with security bugs because it's written by carriers who barely give a damn if this junk even works and wouldn't know "secure" if it hit them in the head.

And on top of all that, depending on your phone and depending on your carrier, that brand new phone you just bought might even be running an Android that's years out of date and full of known vulnerabilities. There's no comparison when it comes to timely IOS security updates and Android. The Android ecosystem is a complete fail on the security front at the moment. Period.

Google can play dumb if they want. Plausible deniability is oftentimes quite useful after all...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#93
post #92

No, what's really disappointing is FUD directed at debugging tools. These sorts of "presentations" and "research" are pointless. Anyone who does IOS development knows about these tools, they're not secret. Apple has Tech Notes and documentation in Xcode on them going back years. Let's please try to focus our ire where it's needed. And to whoever said that Google is "very open" about their malicious app problems, well…

well played fanboy. well played.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#94
post #92

No, what's really disappointing is FUD directed at debugging tools. These sorts of "presentations" and "research" are pointless. Anyone who does IOS development knows about these tools, they're not secret. Apple has Tech Notes and documentation in Xcode on them going back years. Let's please try to focus our ire where it's needed. And to whoever said that Google is "very open" about their malicious app problems, well…

These type of stories are up voted without being read because, despite intimations that iOS users are hipsters, the real hipsters are people who use Android because of some imaginary freedom. Most Android users don't care about fake hipster stances and just want a cheap phone. They are not willing to pay for security and they have none as any moderately talented hacker can own an Android easily even if the user only uses apps from Google's walled garden due to carrier foolishness. Pretty sad to see HN so taken in by this nonsense.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#95
post #92

No, what's really disappointing is FUD directed at debugging tools. These sorts of "presentations" and "research" are pointless. Anyone who does IOS development knows about these tools, they're not secret. Apple has Tech Notes and documentation in Xcode on them going back years. Let's please try to focus our ire where it's needed. And to whoever said that Google is "very open" about their malicious app problems, well…

These type of stories are up voted without being read because, despite intimations that iOS users are hipsters, the real hipsters are people who use Android because of some imaginary freedom. Most Android users don't care about fake hipster stances and just want a cheap phone. They are not willing to pay for security and they have none as any moderately talented hacker can own an Android easily even if the user only…

How could a cracker own my Android? I bought an unsubsidised Moto E. It has no carrier bloatware, and prompts me when there is a new version of firmware available. If it's not rooted, and I only install apps from Google Play, what are the known attack vectors?

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#96
post #92

No, what's really disappointing is FUD directed at debugging tools. These sorts of "presentations" and "research" are pointless. Anyone who does IOS development knows about these tools, they're not secret. Apple has Tech Notes and documentation in Xcode on them going back years. Let's please try to focus our ire where it's needed. And to whoever said that Google is "very open" about their malicious app problems, well…

What's really funny is that you turned an article completely about an Apple security problem that they should probably fix, into a completely off topic rant about Android.

Well played.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#97

Earlier quoted context omitted.

These type of stories are up voted without being read because, despite intimations that iOS users are hipsters, the real hipsters are people who use Android because of some imaginary freedom. Most Android users don't care about fake hipster stances and just want a cheap phone. They are not willing to pay for security and they have none as any moderately talented hacker can own an Android easily even if the user only…

How could a cracker own my Android? I bought an unsubsidised Moto E. It has no carrier bloatware, and prompts me when there is a new version of firmware available. If it's not rooted, and I only install apps from Google Play, what are the known attack vectors?

The answer is in the question: http://www.pcworld.com/article/2099421/report-malwareinfecte...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#98

What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access? You'd be pretty annoyed if the front door to your house, when you…

This is what is worrying me the most. Why can something even repeatedly ask for permission? (My iPhone was asking me every 5 seconds the other day due to a faulty cable.) Even if there's a reason for that, why isn't there a "don't ask again" button? Why doesn't such a thing need a pin code or iCloud password entry? Why isn't services like file_relay or pcap a setting deep inside the Advanced section of Settings.app t…

"Why doesn't such a thing need a pin code or iCloud password entry?"

It does - any passcode/fingerprint locked device needs to be unlocked before granting trust.

I would like a 'don't ask again' option though...

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#99

Earlier quoted context omitted.

How could a cracker own my Android? I bought an unsubsidised Moto E. It has no carrier bloatware, and prompts me when there is a new version of firmware available. If it's not rooted, and I only install apps from Google Play, what are the known attack vectors?

The answer is in the question: http://www.pcworld.com/article/2099421/report-malwareinfecte...

The definition of malware in that article is quite broad, and includes apps which are just 'collecting and sending GPS coordinates'.

Even if one of the apps I've installed from Google Play is malware (by the definition in the article) it doesn't mean my phone is 'owned'. An attacker can't run arbitrary code on the device or get copies of my data or send texts pretending to be me.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#100

Earlier quoted context omitted.

I don't see where they document how you disable or block these.

They aren't enabled by default. "requires the user to have unlocked their device and agreed to trust another computer" and "For users who have enabled iTunes Wi-Fi Sync on a trusted computer"

They absolutely are enabled by default, running as active daemons which cannot be disabled by the device owner.

The circumstances by which they may be accessed include user agreement to "trust another computer", but may not be limited to that.

Because DROPOUTJEEP.

Post reply on HN