Live data from Hacker News

Planned obsolescence: Apple attacked for the “serialization” of its spare parts

lemonde.fr

121–130 of 137 posts

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#121

Earlier quoted context omitted.

> That isn't a repaired product but a fake one. Wrong. It is a genuine piece of hardware but modified. With respect, did you read the linked article?

I did read the article, no it's not a genuine piece of hardware, they changed the microcontroller. And by the way, it's also possible to do the same exact thing in an iPhone right now, somebody could totally hook up a microcontroller with a microphone straight to the battery. If you want to go all the way, you can also replace the whole device straight with a fake iphone and record everything.

> I did read the article, no it's not a genuine piece of hardware, they changed the microcontroller.

They took the genuine piece and swapped some stuff out and modified firmware, not just made a straight up fake. That's why it was hard to detect, it was a completely genuine device on the face of it.

> And by the way, it's also possible to do the same exact thing in an iPhone right now, somebody could totally hook up a microcontroller with a microphone straight to the battery.

Yes. But that is tricky (not much free space in the body to add something new) and can probably be detected visually. However if somebody swapped an existing part like a camera for a fake camera that acts like a camera but also spies on you then it would be tricky to visually see, but the phone would warn you.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#122

Earlier quoted context omitted.

Not only that but ensuring genuine parts also goes a long way against hardware-based attacks.

That’s not a good reason to do this. If you really wanted to do it that much you could just modify the real parts and that isn’t really a thing that happens anyway. What’s a far bigger concern is giving one company complete control over whether you can repair your own phone or not, creating a monopoly where they can charge whatever they want, and they might not even do it at all because they’d prefer you to buy a new…

> If you really wanted to do it that much you could just modify the real parts

It seems like the phone would alert for any swapped part, no matter genuine or not. Maybe this is why. Makes sense to me now.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#123

Earlier quoted context omitted.

Maybe they don't trust their ability to identify a genuine part enough so they alert about any part that did not ship with your phone. Would I like it that my phone detects tampering and hardware integrity violation and spams me with alerts? Absolutely. Would I support some way of being able to repair my phone with legal genuine parts though? Totally. Are those exclusive options? I don't know. Which one I think is mo…

They already have cryptographic authentication for parts, they know it's a genuine part from a donor board, they just purposely reject it. > Are those exclusive options? I don't know. Which one I think is more important? I don't know. First they are indeed not exclusive options, locking parts when the phone is locked is a possible option. And then we have to think what's the most common for most people, a dropped iPh…

> They already have cryptographic authentication for parts

What if a genuine part is modified. I am not sure it is a solvable problem?

> First they are indeed not exclusive options, locking parts when the phone is locked is a possible option.

If that is technically possible I am all for it (but if I had to choose between no integrity protection and integrity protection that makes it harder to repair, I don't know what I would choose). However if you are a phone, how would you distinguish between a legitimate repair and malicious swapping out of parts? Sounds like incompleteness theorem would say you can't

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#124

Earlier quoted context omitted.

They already have cryptographic authentication for parts, they know it's a genuine part from a donor board, they just purposely reject it. > Are those exclusive options? I don't know. Which one I think is more important? I don't know. First they are indeed not exclusive options, locking parts when the phone is locked is a possible option. And then we have to think what's the most common for most people, a dropped iPh…

> They already have cryptographic authentication for parts What if a genuine part is modified. I am not sure it is a solvable problem? > First they are indeed not exclusive options, locking parts when the phone is locked is a possible option. If that is technically possible I am all for it (but if I had to choose between no integrity protection and integrity protection that makes it harder to repair, I don't know wha…

> What if a genuine part is modified. I am not sure it is a solvable problem?

Same problem as it is now, nothing changes.

> However if you are a phone, how would you distinguish between a legitimate repair and malicious swapping out of parts? Sounds like incompleteness theorem would say you can't

If your threat model is malicious swapping parts, an iPhone isn't for you anyway, you need a device more secure than that.

And I doubt that applies to more than an handful of individuals, even targeted attacks themselves usually don't go this far and prefer to just exfiltrate the data by software.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#125

Earlier quoted context omitted.

I did read the article, no it's not a genuine piece of hardware, they changed the microcontroller. And by the way, it's also possible to do the same exact thing in an iPhone right now, somebody could totally hook up a microcontroller with a microphone straight to the battery. If you want to go all the way, you can also replace the whole device straight with a fake iphone and record everything.

> I did read the article, no it's not a genuine piece of hardware, they changed the microcontroller. They took the genuine piece and swapped some stuff out and modified firmware, not just made a straight up fake. That's why it was hard to detect, it was a completely genuine device on the face of it. > And by the way, it's also possible to do the same exact thing in an iPhone right now, somebody could totally hook up…

> They took the genuine piece and swapped some stuff out and modified firmware, not just made a straight up fake. That's why it was hard to detect, it was a completely genuine device on the face of it.

They could have also made a complete fake as well instead of a partial fake just by keeping the plastic enclosure, this device isn't exactly complicated.

> Yes. But that is tricky (not much free space in the body to add something new) and can probably be detected visually. However if somebody swapped an existing part like a camera for a fake camera that acts like a camera but also spies on you then it would be tricky to visually see, but the phone would warn you.

That's kind of a ridiculous threat model anyway, those targeted attacks are just going to hack the iPhone and stream the camera in software whenever they want with some custom payload.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#126

Earlier quoted context omitted.

> I did read the article, no it's not a genuine piece of hardware, they changed the microcontroller. They took the genuine piece and swapped some stuff out and modified firmware, not just made a straight up fake. That's why it was hard to detect, it was a completely genuine device on the face of it. > And by the way, it's also possible to do the same exact thing in an iPhone right now, somebody could totally hook up…

> They took the genuine piece and swapped some stuff out and modified firmware, not just made a straight up fake. That's why it was hard to detect, it was a completely genuine device on the face of it. They could have also made a complete fake as well instead of a partial fake just by keeping the plastic enclosure, this device isn't exactly complicated. > Yes. But that is tricky (not much free space in the body to ad…

> They could have also made a complete fake as well instead of a partial fake just by keeping the plastic enclosure, this device isn't exactly complicated.

In case of this device, sure. But it would be much more costly and error-prone, build your own PCBs etc. But in case of iPhone we don't worry about them building fakes from scratch, because those would be easy to tell on the spot. We worry about a genuine phone with fake parts.

> That's kind of a ridiculous threat model anyway, those targeted attacks are just going to hack the iPhone and stream the camera in software whenever they want with some custom payload.

As it is now these phones are not so easy to hack without user proactively installing malware and many of them would survive only until the next OS update or security response payload. A hardware attack is more compelling.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#127

Earlier quoted context omitted.

> They already have cryptographic authentication for parts What if a genuine part is modified. I am not sure it is a solvable problem? > First they are indeed not exclusive options, locking parts when the phone is locked is a possible option. If that is technically possible I am all for it (but if I had to choose between no integrity protection and integrity protection that makes it harder to repair, I don't know wha…

> What if a genuine part is modified. I am not sure it is a solvable problem? Same problem as it is now, nothing changes. > However if you are a phone, how would you distinguish between a legitimate repair and malicious swapping out of parts? Sounds like incompleteness theorem would say you can't If your threat model is malicious swapping parts, an iPhone isn't for you anyway, you need a device more secure than that.…

> Same problem as it is now, nothing changes.

Now the phone warns you about a replaced part. Even if it is a genuine one.

> If your threat model is malicious swapping parts, an iPhone isn't for you anyway, you need a device more secure than that.

This is a thread model of many people in many countries today. Sorry for stupid question but is there a usable phone that is more secure, seriously?

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#128

Earlier quoted context omitted.

That’s not a good reason to do this. If you really wanted to do it that much you could just modify the real parts and that isn’t really a thing that happens anyway. What’s a far bigger concern is giving one company complete control over whether you can repair your own phone or not, creating a monopoly where they can charge whatever they want, and they might not even do it at all because they’d prefer you to buy a new…

> If you really wanted to do it that much you could just modify the real parts It seems like the phone would alert for any swapped part, no matter genuine or not. Maybe this is why. Makes sense to me now.

I don’t think that’s why, I’ve never heard of that ever happening

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#130

Earlier quoted context omitted.

> They took the genuine piece and swapped some stuff out and modified firmware, not just made a straight up fake. That's why it was hard to detect, it was a completely genuine device on the face of it. They could have also made a complete fake as well instead of a partial fake just by keeping the plastic enclosure, this device isn't exactly complicated. > Yes. But that is tricky (not much free space in the body to ad…

> They could have also made a complete fake as well instead of a partial fake just by keeping the plastic enclosure, this device isn't exactly complicated. In case of this device, sure. But it would be much more costly and error-prone, build your own PCBs etc. But in case of iPhone we don't worry about them building fakes from scratch, because those would be easy to tell on the spot. We worry about a genuine phone wi…

> But in case of iPhone we don't worry about them building fakes from scratch, because those would be easy to tell on the spot.

I suggest having a look to Youtube. Some fake iPhones are so good that unless you have a deep knowledge of the product, you can be fooled. I certainly would be fooled.

> As it is now these phones are not so easy to hack without user proactively installing malware and many of them would survive only until the next OS update or security response payload. A hardware attack is more compelling.

I'm confident those state actors have the payloads ready whenever they want to use it on high value targets, this is kind of naive. Pegasus NSO could be a public example of that.

You are not valuable enough to require such an exploit but that's a thing right now.

Post reply on HN