Apple Platform Security (Jan 2026) [pdf]
11–20 of 205 posts
Re: Apple Platform Security (Jan 2026) [pdf]
#12Re: Apple Platform Security (Jan 2026) [pdf]
#13No mention of Pegasus and other software of such sort. Can latest iOS still be infected? There is no point creating such document if elephant in the room is not addressed.
Why? The obvious conclusion is that Apple is doing everything in its power to make the answer “no.” You might as well enumerate all the viruses ever made on Windows, point to them, and then ask why Microsoft isn’t proving they’ve shut them all down yet in their documents.
Microsoft does not sell Windows as a sealed, uncompromisable appliance. It assumes a hostile environment, acknowledges malware exists, and provides users and third parties with inspection, detection, and remediation tools. Compromise is part of the model.
Apple’s model is the opposite. iOS is explicitly marketed as secure because it forbids inspection, sideloading, and user control. The promise is not “we reduce risk”, it’s “this class of risk is structurally eliminated”. That makes omissions meaningful.
So when a document titled Apple Platform Security avoids acknowledging Pegasus-class attacks at all, it isn’t comparable to Microsoft not listing every Windows virus. These are not hypothetical threats. They are documented, deployed, and explicitly designed to bypass the very mechanisms Apple presents as definitive.
If Apple believes this class of attack is no longer viable, that’s worth stating. If it remains viable, that also matters, because users have no independent way to assess compromise. A vague notification that Apple “suspects” something, with no tooling or verification path, is not equivalent to a transparent security model.
The issue is not that Apple failed to enumerate exploits. It’s that the platform’s credibility rests on an absolute security narrative, while quietly excluding the one threat model that contradicts it. In other words Apple's model is good old security by obscurity.
Re: Apple Platform Security (Jan 2026) [pdf]
#14[flagged]
> In this table, in the "iCloud Backup (including device and Messages backup)" row, under "Standard data protection",
> the "Encryption" column reads "In transit & on server". Yes, this means that Apple can read all of your messages
> out of your iCloud backups.
In addition to the things you mentioned, there's certainly a possibility of Apple attaching a virtual "shadow" device to someone's Apple ID with something like a hide_from_customer type flag, so it would be invisible to the customer.This shadow device would have it's own keys to read messages sent to your iCloud account. To my knowledge, there's nothing in the security model to prevent this.
Re: Apple Platform Security (Jan 2026) [pdf]
#15Re: Apple Platform Security (Jan 2026) [pdf]
#16[flagged]
This is your blog post, so I'll ask you a question. What are you trying to state in Belief #1? The message is unclear to me with how it's worded: > In this table, in the "iCloud Backup (including device and Messages backup)" row, under "Standard data protection", > the "Encryption" column reads "In transit & on server". Yes, this means that Apple can read all of your messages > out of your iCloud backups. In addition…
However, iCloud backups actually are listed as "End-to-end" if you turn on the new Advanced Data Protection feature.
Re: Apple Platform Security (Jan 2026) [pdf]
#17Earlier quoted context omitted.
don't worry, they set the allow_pegasus boolean to false
Apple did create a boolean for that. They call it lockdown mode. > Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats. Most people are never targeted by attacks of this nature. When Lockdown Mode is enabled, your device won’t function like it typically…
Re: Apple Platform Security (Jan 2026) [pdf]
#18[flagged]
Re: Apple Platform Security (Jan 2026) [pdf]
#19[flagged]
This is your blog post, so I'll ask you a question. What are you trying to state in Belief #1? The message is unclear to me with how it's worded: > In this table, in the "iCloud Backup (including device and Messages backup)" row, under "Standard data protection", > the "Encryption" column reads "In transit & on server". Yes, this means that Apple can read all of your messages > out of your iCloud backups. In addition…
Re: Apple Platform Security (Jan 2026) [pdf]
#20If you want to see security done well (or at least better), see the GrapheneOS project.