Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

111–114 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#111
post #11
post #8

His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…

You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…

Well, yes, but without this huge marketing effort on the side of the infosec industry, we'd still be running the web on http instead of https, and we'd still have to convince people that XSS is bad and not just a "neat trick".

Those are just the first two things from the top of my head that IMO rightly took great effort to be taken seriously by the mainstream (developers and consumers alike).

Also I disagree with the "Uncertainty & Doubt" part of FUD. Security researchers are generally extremely clear about what exactly the issues and risks are, with few exceptions when required for responsible disclosure.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#112
post #82
post #77

Earlier quoted context omitted.

> again, this requires physical access The only physical access that is required is for the user to pair with a/some pc -- which then said pc can be used as a vehicle for attack... Other users in this thread have mentioned airport USB chargers wanting to pair with their iDevice, etc. That's not very far-fetched really...

I thought this required me to unlock my phone and say 'I trust this computer' before anything else could happen, are you saying that is not the case? I'll yield to the fact that I cannot remove trust from a computer, that seems like a now obvious shortcoming.

you can remove trust by changing your passcode.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#113
post #33

Earlier quoted context omitted.

> It's good to know Apple has the power to look through your encrypted files given physical access (file relay). So the requisites are: "be Apple" and "have physical access"? That's awfully little for what's supposed to be encrypted files. It (seems to be) no secret that law enforcement sends devices to Apple when they can't handle them themselves. So if I'm understanding it right: you can't protect yourself with an…

I think this is relevant; Apple says "diagnostic info" while others say that it's the users' personal encrypted files. I haven't found confirmation on whether the list Zdziarsky has in his presentation is exaggerated, completely true, or false.

What's the difference? Are personal files never ever diagnostically relevant?
Post reply on HN