Live data from Hacker News

Apple confirms iOS kernel code left unencrypted intentionally

techcrunch.com

111–120 of 157 posts

Re: Apple confirms iOS kernel code left unencrypted intentionally

#111
post #97

Earlier quoted context omitted.

It's just another perk that's customary in large US corporations. By comparison, it's like the ticket repas and chèques vacances in the French companies—getting subsidies for food and vacations would look quite odd to Americans. Different cultures, different perks.

> getting subsidies for food and vacations would look quite odd to Americans Silicon Valley companies frequently subsidize food for their employees.

Because it's a tax writeoff and the more time workers are at the office, the more work is getting done. Or so the managerial thought process goes.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#112
post #91

Earlier quoted context omitted.

> I supported Apple's stand against the FBI, but believing it's purely altruistic would be simplistic and optimistic thinking at best. When safety and security are your perceived selling point Only safety and security weren't Apple's "perceived selling points". They were mostly touted for user friendliness, it just works, being the first to bring some technologies to market in a well-thought way (e.g. as opposed to c…

Safety and security are absolutely a selling point, although not one they lean hard on in their own marketing materials. But it comes up in any comparison between iOS and Android, and not without reason. (Incidentally, why the past tense?)

>Safety and security are absolutely a selling point, although not one they lean hard on in their own marketing materials. But it comes up in any comparison between iOS and Android, and not without reason.

I think security with regard to malware (of which Android has like 90+% of all mobile malware according to surveys) was a selling point, but not safety/security in the privacy/encryption/etc way that the FBI incident was about.

That wasn't, as you say, much on Apple's marketing materials, nor was it much of a factor for the majority of buyers.

>Incidentally, why the past tense?

Because safety and security have become something of a selling point for Apple as of late (I'd say post the FBI incident), but it's not long ago they weren't.

So the past tense was meant to convey that those other things were Apple's selling points "back then", but leave the door open for security being a selling point for them now.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#113

Earlier quoted context omitted.

>You can't blame anybody for only paying the legally required amount of taxes. Of course I can (and I do). Apple and various other companies go to great lengths to pay the least amount of taxes they can get away with.

Why would anyone - individual or corporation - pay more taxes than they are legally obligated to pay? Don't get me wrong: I believe that corporations should be obligated to pay much more in taxes than most currently do, but I'm going to assume that you don't knowingly pay more in taxes than you owe. If I'm wrong about that, then I'm interested in hearing your reasoning as to why you feel like the government is entitl…

> Why would anyone - individual or corporation - pay more taxes than they are legally obligated to pay?

Because they can't afford the accountants and lawyers required to pull of the funneling of funds through various bodies and countries to get said reduction in tax burden?

Re: Apple confirms iOS kernel code left unencrypted intentionally

#114
post #99

Earlier quoted context omitted.

page faults.... the hypervisor encrypts/decrypts on-demand. Much the same as virtual memory works (just that the plain-text data is only ever in the internal cache).

My point is that it is impossible to know where the next code chunk is if it is properly encrypted. How does the page fault handler know which block to decrypt next without first decrypting the whole code module, where module is a closed piece of code without jumps outside. In my opinion every scheme to enable that will cripple the encryption.

the code is decrypted into internal SRAM. executed normally. then an entirely normal page-fault happens at which point the hypervisor catches the trap and decrypts the data again into internal SRAM and maps it appropriately then allows the access to continue.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#115

Earlier quoted context omitted.

Safety and security are absolutely a selling point, although not one they lean hard on in their own marketing materials. But it comes up in any comparison between iOS and Android, and not without reason. (Incidentally, why the past tense?)

> Safety and security are absolutely a selling point, although not one they lean hard on in their own marketing materials. But it comes up in any comparison between iOS and Android, and not without reason. I think security with regard to malware (of which Android has like 90+% of all mobile malware according to surveys) was a selling point, but not safety/security in the privacy/encryption/etc way that the FBI incide…

Tim Cook has been taking swipes at Google and Facebook for privacy issues for at least a year, prior to the FBI issue: http://fortune.com/2015/06/03/tim-cook-attacks-facebook-goog....

Re: Apple confirms iOS kernel code left unencrypted intentionally

#116
post #70

Earlier quoted context omitted.

A company that Facebook acquired a couple of years ago (PrivateCore) realized that the L1 cache had grown large enough that you could run a hypervisor out of it. You use a TPM secure boot chain to ensure you are booting the code you need into the hardware you expect, load up the hypervisor and its keys, and then this hypervisor is used to encrypt _everything_. Now you have encrypted RAM, so physical possession of a r…

L1 had grown large enough? What do you mean? L1 was 32KB in the Pentium II days, and for the last ten years of Intel chips it's been an unchanging 64KB. Why would it have to fit into L1 specifically, rather than L2/L3? (If you do use L2/L3, that's also been big enough to spare the space for a hypervisor since the Pentium II, which had 512KB.)

Looks like they do use L3, alongside an number of other intel x86 features (not surprisingly things like AES-NI)

https://privatecore.com/wp-content/uploads/2014/02/pr-privat...

Sorry couldn't copy/paste relevant section; formatting went horrible.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#117
post #111

Earlier quoted context omitted.

> getting subsidies for food and vacations would look quite odd to Americans Silicon Valley companies frequently subsidize food for their employees.

Because it's a tax writeoff and the more time workers are at the office, the more work is getting done. Or so the managerial thought process goes.

I'm just saying, I don't think food subsidies look "quite odd" to Americans, I think they look fairly normal.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#118
post #111

Earlier quoted context omitted.

> getting subsidies for food and vacations would look quite odd to Americans Silicon Valley companies frequently subsidize food for their employees.

Because it's a tax writeoff and the more time workers are at the office, the more work is getting done. Or so the managerial thought process goes.

In many European countries it would probably be considered a taxable benefit for the employee, and would increase the employee taxes. Just as a background why some things are different across the pond.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#119
post #91

Earlier quoted context omitted.

I supported Apple's stand against the FBI, but believing it's purely altruistic would be simplistic and optimistic thinking at best. When safety and security are your perceived selling point, it's the best PR you can have. I'm not entirely sure about the validity of this nytimes article [1], but if we believe it, Tim Cook had asked FBI to submit their request 'in private' - but FBI did it openly, so Tim Cook 'had to'…

> I supported Apple's stand against the FBI, but believing it's purely altruistic would be simplistic and optimistic thinking at best. When safety and security are your perceived selling point Only safety and security weren't Apple's "perceived selling points". They were mostly touted for user friendliness, it just works, being the first to bring some technologies to market in a well-thought way (e.g. as opposed to c…

Most of the other things you're talking about, can now be seen with flagship products of other major companies.

User friendliness, style, high-end luxury - all major companies flagship - check.

It just works - Apple - uncheck. :) (It's largely a myth)

They were actually touting privacy as a differentiator from Android devices.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#120

Earlier quoted context omitted.

This is dogmatism. The FBI situation clearly demonstrates that Apple does not only act in the interest of the bottom line.

>The FBI situation clearly demonstrates that Apple does not only act in the interest of the bottom line. I don't think it does as I've explained in https://news.ycombinator.com/item?id=11959074

I agree with you. They're not altruistic at all and the FBI thing was likely a PR campaign. They already have a number of behaviors that hurt users, app developers, and people in the supply chain. Far as security, the hardware engineers know there were attacks all the way through the stack that can be mitigated with certain tech that would probably cost them a few million or tens of million one-time development. They used a weak, 3rd-party approach instead. They never brought up these weaknesses, which all commercial smartphones have, during the debate. They still don't.

So, let's recap. Tim Cook, already hit due to privacy issue, might have a personal stake in improving privacy in tech. They knew their products weren't secure. I knew third parties that could've cracked it as they cracked IC's designed for security w/ obfuscation & tamper-resistance. As I predicted, the FBI ended up finding a group that cracked it for a low, six digits. That means the attack was easy with much of that probably profit.

That Apple knowingly leaves their devices insecure despite having money and incentive to knock out low-hanging fruit means all this talk is mostly branding. They're just differentiating themselves with appearance of greater security/privacy. Like they did when they said Mac's were immune to malware back in the day. Except this time, they actually deliver a good chunk of what they claim at least. I'll give them that. :)

Post reply on HN