Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

101–110 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#101

Earlier quoted context omitted.

It partially matches what he's talking about, but it's still a trinary choice. 1> Don't tether 2> Get only power 3> Give away the keys to the castle

FYI it's "ternary".

Thanks!

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#102

I'm getting 404s for this link and the root. Cache: http://webcache.googleusercontent.com/search?q=cache:www.zdz...

Ah, thank you. It was a 500 earlier, and now it just says,

> Checking your browser before accessing zdziarski.com. > This process is automatic. Your browser will redirect to your requested content shortly. > Please allow up to 5 seconds… > DDoS protection by CloudFlare

And then refreshes indefinitely.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#103
post #71
post #18

Earlier quoted context omitted.

I don't own an iDevice, but Apple's nonchalant attitude regarding possible exploitable backdoors irks me.

I don't know what the situation is with Windows Mobile or any of the other mobile OS's, but with the big two it goes like this: iOS: You get updates for your device for a decently long time after you buy it, even after new devices come out. Android: You stop getting updates (all updates: security fixes are NOT backported) somewhere between 6 months to 2 years after getting your device, assuming it's a brand new produ…

Actually if you use an android open source based distro like cyanogenmod or ornirom, you will likely be able to continuously get nightly updates. Android is a code ecosystems...you should really be harping criticisms of lack of updates to the individual manufactures such as Motorola or Samsung or HTC if you are comparing to Apple.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#104

What's really disappointing is that there seems to be an all-or-nothing security model here. If I pair my phone with a computer, then suddenly it has complete access to spy on me, install monitoring tools that can continue to run, etc. Why can't there be a way where I can transfer music/photos to/from my phone without providing this full device access? You'd be pretty annoyed if the front door to your house, when you…

This problem is solved pretty easily: 1> Buy a shit Nokia, use the 2 pin charger. TBH if it goes flat it won't charge off USB anyway. Then use a microSD for transferring music/photos. 2> Buy an Android handset with USB OTG. Transfer files on and off via a USB stick that you control. Charge it with a USB cable with the data pins shorted (you can buy these off Amazon). Both of these ignore the main attack vector that I…

There are also solutions for iPhones: send via AirDrop, email, imessage, iCloud share, Dropbox, copy.com, etc. AirDrop works even without an Internet connection and will work that way with macs too.

It's not like it's 2003 again and the only way to share a picture or a album is with a cable.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#105
post #63

Earlier quoted context omitted.

There are USB condoms built exactly for the scenario you describe. http://int3.cc/products/usbcondoms

It partially matches what he's talking about, but it's still a trinary choice. 1> Don't tether 2> Get only power 3> Give away the keys to the castle

2> Get only power

Not really. the USB charging protocol requires data pins for chargers to communicate with the device about how much current it can draw. Suppose the data pins are left open, a compliant device can only draw <100mA, which is not even enough power to keep device from draining battery. Even if the data pins are shorted, I don't think it works with most apple devices, which use a different non-standard protocol.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#106

Earlier quoted context omitted.

This problem is solved pretty easily: 1> Buy a shit Nokia, use the 2 pin charger. TBH if it goes flat it won't charge off USB anyway. Then use a microSD for transferring music/photos. 2> Buy an Android handset with USB OTG. Transfer files on and off via a USB stick that you control. Charge it with a USB cable with the data pins shorted (you can buy these off Amazon). Both of these ignore the main attack vector that I…

There are also solutions for iPhones: send via AirDrop, email, imessage, iCloud share, Dropbox, copy.com, etc. AirDrop works even without an Internet connection and will work that way with macs too. It's not like it's 2003 again and the only way to share a picture or a album is with a cable.

How do you propose adding music to your iDevice like that?

Not all things are equal on iOS which is my point above.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#107
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

So if i understand correct, anyone who steals or temporarily has physical access to your iPhone can access your data including (email, etc)account passwords, which makes the encryption on the device completely useless.

If that's not a serious back door, i don't know what is.. the melodrama seems in order.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#108
post #42
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

Just to be clear, are you suggesting that if the details aren't provided in a slide somewhere, than those details were not mentioned in the talk?

No, definitely not. I was partially ranting :) I couldn't find a recording of any talks he gave, only the slides, so he may have covered that in those.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#109

Earlier quoted context omitted.

There are also solutions for iPhones: send via AirDrop, email, imessage, iCloud share, Dropbox, copy.com, etc. AirDrop works even without an Internet connection and will work that way with macs too. It's not like it's 2003 again and the only way to share a picture or a album is with a cable.

How do you propose adding music to your iDevice like that? Not all things are equal on iOS which is my point above.

iTunes sync via wifi those days, backup is done on iCloud.

There is not that many reasons to plug a cable other than charging nowadays.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#110
post #79
post #75

Earlier quoted context omitted.

This isn't an Android vs iOS issue -- I take issue when any company ignores or brushes off a security problem. That does not detract from the current situation at all.

What I wanted to highlight is that the "big picture" of security with Apple is one of taking things seriously, not ignoring or brushing things off.

Only if you compare certain aspects of it to certain (other!) aspects of other manufacturers.

That was the point. Saying "oh but other manufacturers do other things badly" needlessly polarizes the argument and detracts from Apple's fuck-up, which is the topic of discussion here.

Of course not providing security updates after a a relatively short time is a bad thing to do, but how is that even relevant to the backdoors in this article?

(edit: changed "Android" to read "manufacturers", as em3rgent0rdr rightly pointed out your complaint doesn't have anything to do with the OS, but the manufacturers providing locked devices with Android OS on it. with Apple/iOS this just happens to be the same party)

Post reply on HN