Live data from Hacker News

Apple Confirms “Back Doors”, Downplays Their Severity

zdziarski.com

1–10 of 114 posts

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#4
This sounds a bit like the same sort of customer-experience related hacks that MSFT used to (maybe still does) put in all their software and that caused so many holes in security. Poor attention to security won't just let US government intrusion, it'll also let in other governments and hackers. Seriously, letting a 'trusted computer' enable that data syncing? They're playing with fire. (feel free to let me know if I'm missing anything here)

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#6

So in short: Apple has back doors that they claim aren't really back doors since only Apple apps can use them. If the NSA hasn't been using them already, it is only a matter of time.

If it's a backdoor for Apple, then it's a backdoor for anyone who can figure it out (other apps, hackers, government agencies alike).

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#7
Kind of glad Apple just confirmed the services are there and ignored him otherwise. I'm sure he has a nice career ahead of him of complaining the cp command in the adb shell on Android isn't hard coded to ignore any path with DCIM (user pictures) in it next and other nonsense. Honestly, he isn't helping anything and he is just making it harder for Apple to fix broken phones and provide better customer service in general.

Wonder what he thinks of amazon MayDay showing your screen to custom support remotely. Users love it since the custom support can now guide you to exactly the right settings and other things, but I think privacy nuts like this will have seizures.

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#8
His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers:

    "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these"
Yet in the slides for his talk[1] under theories he writes"

    "Maybe for Developers for Debugging? No."
There are many examples of things like this in his writing, where actual facts are unsaid in order to gain the maximum melodrama for a particular statement.

On top of that he seems to continually avoid the point that to enable these you need physical access to the device (for the pairing process to have a machine marked as trusted). If you have physical access, enabling debug[2] features are probably the least of your worries.

Anyway, rant over. It just annoys me that genuinely interesting information often seems to be spun by personalities to give it artificial gloss these days, making it all feel a bit slimy and self-serving.

[1] https://pentest.com/ios_backdoors_attack_points_surveillance...

[2] Debug if you're Apple, Back Doors if you're Mr. Zdziarski

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#9

This sounds a bit like the same sort of customer-experience related hacks that MSFT used to (maybe still does) put in all their software and that caused so many holes in security. Poor attention to security won't just let US government intrusion, it'll also let in other governments and hackers. Seriously, letting a 'trusted computer' enable that data syncing? They're playing with fire. (feel free to let me know if I'…

That's an easy thing to say. But on the same token, if Apple required individual authentication to access the filesystem remotely, critics would scream about the privacy issues associated with linking a file transfer to a human identity.

The process of establishing "trust" between computer and iOS device probably needs a little work, but the concept itself isn't inherently insecure.

Why isn't the security press screaming about the scary inclusion of a massive black hole of security risk on OS X.... OpenSSH? All I need to do get physical access, click a checkbox in a preference pane and copy a public key to a user's home directory, and "poof" I own the box!

Re: Apple Confirms “Back Doors”, Downplays Their Severity

#10

So in short: Apple has back doors that they claim aren't really back doors since only Apple apps can use them. If the NSA hasn't been using them already, it is only a matter of time.

"back doors" that require approval from the user on the phone..??
Post reply on HN