Live data from Hacker News

Apple confirms iOS kernel code left unencrypted intentionally

techcrunch.com

121–130 of 157 posts

Re: Apple confirms iOS kernel code left unencrypted intentionally

#121
post #81
post #56

Earlier quoted context omitted.

As a French person without the culture of corporate donations, I'm both wondering why it was seen as negative that Apple didn't match? Shouldn't they redirect donations to people they prefer?

Seems incredibly self entitled to me. Why should your employer shell out money for whatever their employees decide? I don't understand it at all. What if you want to donate a controversial charity? If you feel that strongly about a charity double your own donation.

You seem to have this notion that employees are asking for handouts. They aren't. They're saying, "Hey, I would like a $5k raise. I know you're planning on giving it to me anyway, but I wanted to point out that if you do it in the form of charitable matching, the company will only have to reduce its income by $4700 to give me that $5k raise, since the matching is tax-deductible."

The company essentially gets to offer me more money at no cost to them if they structure their compensation this way. You could be very transparent with this and simply allow employees to direct the company to put money into charity (with the tax going to the charity instead of the government) but it's probably easier for the accountants to simply do matching with a cap, which is why you see companies do it this way.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#122
post #97

Earlier quoted context omitted.

It's just another perk that's customary in large US corporations. By comparison, it's like the ticket repas and chèques vacances in the French companies—getting subsidies for food and vacations would look quite odd to Americans. Different cultures, different perks.

> getting subsidies for food and vacations would look quite odd to Americans Silicon Valley companies frequently subsidize food for their employees.

Certain teams at Apple get free dinners to boost morale when working late. This included a pretty nice catered meal once a week in my department. No doubt, this is common at industry leaders.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#123
post #86
post #81

Earlier quoted context omitted.

Seems incredibly self entitled to me. Why should your employer shell out money for whatever their employees decide? I don't understand it at all. What if you want to donate a controversial charity? If you feel that strongly about a charity double your own donation.

It's not everything. Usually there is a list of acceptable national charities for things like heart disease, diabetes, MS, education, poverty alleviation, etc. Chances are you'd recognize every one on the list. Sometimes employees vote on that list, sometimes it's mostly set by HR.

"Usually"? My experience with companies large and small has been that if it's a 501(3)c, they're on the "list". For instance, unless you live in western WA, I guarantee the "chances" you'd "recognize" the animal shelter to which we divert our employer match is zero. Now if your chosen charity is "Whitey Uber Alles", meh, maybe it might be an issue. Don't know from experience, who's going to say "no" to an animal shelter?

It boils down to a tax write-off that allows the company to look charitable. But there's a lot of benefit along the way, so who cares of the motivation?

Re: Apple confirms iOS kernel code left unencrypted intentionally

#124

Earlier quoted context omitted.

>The FBI situation clearly demonstrates that Apple does not only act in the interest of the bottom line. I don't think it does as I've explained in https://news.ycombinator.com/item?id=11959074

I agree with you. They're not altruistic at all and the FBI thing was likely a PR campaign. They already have a number of behaviors that hurt users, app developers, and people in the supply chain. Far as security, the hardware engineers know there were attacks all the way through the stack that can be mitigated with certain tech that would probably cost them a few million or tens of million one-time development. They…

This completely ignores the potential financial downsides of multiple vectors of consequences in the FBI case. For example:

- non-technical (i.e. most) people interpreting the situation as "Apple protects terrorists"

- provoking the creation of legislation that would impose backdoor requirements on their software

- potentially extreme financial consequences if the court were to take a hard-line pro-FBI stance (https://www.theguardian.com/world/2014/sep/11/yahoo-nsa-laws...)

Again, the refusal to admit that it is possible for a company to behave altruistically in the face of clear evidence is simply dogmatism.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#125

Earlier quoted context omitted.

> getting subsidies for food and vacations would look quite odd to Americans Silicon Valley companies frequently subsidize food for their employees.

Certain teams at Apple get free dinners to boost morale when working late. This included a pretty nice catered meal once a week in my department. No doubt, this is common at industry leaders.

That's not so much a perk as it is very cheap overtime pay. It would be a perk if they gave you dinner even when you leave at 5PM.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#126
post #22

This is stupid. Anyone interested in writing jailbreaks for iOS would have already had access to these binaries. People are blowing this way out of proportion.

not true. 64-bit kernel was previously not possible to examine. additionally: we now know what Watchtower looks like, something that was previously a mystery and even incorrectly thought to be something that ran on SEP instead of the AP.

If Stefan says it will you believe me?

https://twitter.com/i0n1c/status/745922795977187329

You just used a kernel privesc that you probably already had to read it. NOT A BIG DEAL.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#127
post #111

Earlier quoted context omitted.

Because it's a tax writeoff and the more time workers are at the office, the more work is getting done. Or so the managerial thought process goes.

In many European countries it would probably be considered a taxable benefit for the employee, and would increase the employee taxes. Just as a background why some things are different across the pond.

It's a taxable benefit in the US too, I'm not sure where the parent's "tax writeoff" comment is coming from. Google actually got in some trouble recently for not reporting their free food to the IRS.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#128
post #54

“The kernel cache doesn’t contain any user info, and by unencrypting it we’re able to optimize the operating system’s performance without compromising security,” This is probably the only true part of the article, it means that they disabled a kernel feature of cache encryption to speed-up performances. It has nothing to do with source code nor binaries of the kernel.

Does the same count for the watchOS kernel? I mean, the performance enhancements they claim to have realized have to come from somewhere.

> the performance enhancements they claim to have realized have to come from somewhere

Even in the first beta, the performance enhancements are real. Numerous Apple folks, including Craig Federighi, have said that with WatchOS1 and 2 they 'overshot' how conservative they needed to be with RAM and CPU (out of respect for battery life), and with WatchOS 3 they have rebalanced that.

Time will tell how much of a hit battery life will take from this, but for a beta things look good so far.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#129

Earlier quoted context omitted.

I agree with you. They're not altruistic at all and the FBI thing was likely a PR campaign. They already have a number of behaviors that hurt users, app developers, and people in the supply chain. Far as security, the hardware engineers know there were attacks all the way through the stack that can be mitigated with certain tech that would probably cost them a few million or tens of million one-time development. They…

This completely ignores the potential financial downsides of multiple vectors of consequences in the FBI case. For example: - non-technical (i.e. most ) people interpreting the situation as "Apple protects terrorists" - provoking the creation of legislation that would impose backdoor requirements on their software - potentially extreme financial consequences if the court were to take a hard-line pro-FBI stance ( http…

I'm not rejecting that the act itself might have been altruistic. It may have been. I've merely suggested it might not be, that there's no proof it is except incidentally, and certainly doesn't support them being altruistic as a company. The evidence I offer is all the selfish or abusive practices they do at various levels for maximizing their bottom line. That's for them not being altruistic. Far as acts appearing altruistic, image management and public relations are huge, money-making fields. The reason is that big companies often do something altruistic (or seemingly so) to get people to buy their stuff. Apple has a history of doing that, including with fake security ("Macs can't get viruses!"), to get people to buy their stuff. Given that history & insecurity of their phones, it's right to question whether them championing secure, private phones is a move to create or continue demand for their products given main competition is backed by a surveillance-oriented company. Clear differentiator available that might make them billions.

So, your claim is that a company with many selfish, damaging behaviors fought a legal battle over a case whose consequences might cost or make their shareholders billions depending on outcome and press. That... is consistent with rational, corporate self-interest. Their position also had social value to many & maybe the CEO even paused to do the greater good. That's dogma or speculation at this point given they usually don't focus on public benefit plus are still misleading people about their security & privacy for profit that continues to be hoarded also with few or no investments benefiting the public.

Apple's not altruistic: they're a company that schemed and sued their way into billions in profits. Taking a privacy stance might make them billions more. Or maybe they're just a good citizen on one topic on a few occasions. I'm leaning toward the former but still glad their self-interest and the publics' aligned with them following through on it. All I'm saying on this topic.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#130
post #56

Earlier quoted context omitted.

A couple days after Tim Cook stepped into the CEO position, he reversed a Jobs policy and announced that the company would begin matching employee donations to charities. I considered this a fairly classy and subtle way to signal that he wasn't going to lie down on the job (it had been requested many times on company mailing lists). Source: I was on those lists.

As a French person without the culture of corporate donations, I'm both wondering why it was seen as negative that Apple didn't match? Shouldn't they redirect donations to people they prefer?

They just didn't donate to anybody, which looks bad when the founder of your biggest competitor is also the world's biggest-spending philanthropist.
Post reply on HN