Live data from Hacker News

Planned obsolescence: Apple attacked for the “serialization” of its spare parts

lemonde.fr

11–20 of 137 posts

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#12
post #10

I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...

When the camera fails you don't exactly have many options because you can't really order the official parts.

Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#13
post #10

I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...

When the camera fails you don't exactly have many options because you can't really order the official parts. Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?

Because the camera represents the analog hole. If you can replace the camera, you can hook the phone up to a computer and feed it pictures of faces instead, until the phone unlocks.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#14

Earlier quoted context omitted.

When the camera fails you don't exactly have many options because you can't really order the official parts. Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?

Because the camera represents the analog hole. If you can replace the camera, you can hook the phone up to a computer and feed it pictures of faces instead, until the phone unlocks.

If you find that attack vector so scary, I'm sorry to inform you that it is already possible to prop up an iphone against a pizza box and have it stare at a screen showing a feed of pictures.

Admittedly you might have to put the iphone on its side so you can get the charging cable in there, which means you might have to figure out how to rotate the pictures too.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#15

Interesting bit (translated) : > A practice contrary to the principle of the anti-waste law > In France, serialization is theoretically prohibited, according to Alexandre Isaac. Since the entry into force of the anti-waste law in November 2021, the consumer code mentions that "any technique, including software, by which a marketer aims to make it impossible to repair or recondition a device or to limit the restoratio…

Any technique with makes it impossible to repair or recondition by definition also makes it more difficult to pwn. See https://news.ycombinator.com/item?id=35954422 for one example.

That isn't a repaired product but a fake one.

You can also buy fake iphones today which are near indistinguishable from the real thing unless you have a deep knowledge into the product, you can have a look on youtube.

Preventing repairs did not help them on that aspect.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#16

Such considerations must incorporate public safety/crime considerations as well. Smartphones are often the most expensive thing we have on our person and became a huge target for thieves. Locking/bricking went a long way towards reducing this, and then limiting the value of resale parts did again.

Honestly I wish they would serial lock every single part of the phone possible. And then unlock them when you detach your apple account from it. Put up a message that says "This display is owned by another apple account" and refuse to function until it's removed or you contact the owner to have it unlinked.

Unless Apple is dealing with thefts at the factories before they make it in to a phone.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#17
post #10

I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...

When the camera fails you don't exactly have many options because you can't really order the official parts. Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?

> Why would the camera be of consequence, though?

Insisting on approved camera avoids making it easier for bad actors to stealthily capture's a victim's biometrics and then use a third party "camera" to replay that information and unlock the victim's phone without them being present.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#19
post #10

I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...

There are simple ways to allow hardware changes without losing security. One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware.

This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe you get some protection from wrench attacks by not having the authority to pair new internal hardware, but that seems like a very specialized use case...

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#20

Earlier quoted context omitted.

When the camera fails you don't exactly have many options because you can't really order the official parts. Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?

> Why would the camera be of consequence, though? Insisting on approved camera avoids making it easier for bad actors to stealthily capture's a victim's biometrics and then use a third party "camera" to replay that information and unlock the victim's phone without them being present.

Couldn't an attacker just swap the sensor? This seems like something that higher law enforcement likely already did.

Also couldn't you avoid this problem entirely be just making the dot projector use an unique pattern for each unlock attempt?

Post reply on HN