Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

121–130 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#121
post #76
post #22

Sometime I wonder how much overhead all these security features take in terms of performance. I would really like to see a benchmark with and without security measures.

The ones I remember most affecting performance were zeroing allocated memory and the Spectre/Meltdown fix. Also, the first launch of a new app is slow in order to check the signature. Whole disk encryption is pretty fast today, but probably is a bit slower than unencrypted. The original FileVault using disk images was even slower.

It's not whole-disk encryption, it's file-level encryption which is better. (more security guarantees)

Zeroing allocated memory is complicated because it also has performance benefits, since it improves compressed swap.

Re: Apple Platform Security (Jan 2026) [pdf]

#122

Earlier quoted context omitted.

But it still isn't Apple doing the tracking or receiving the data about your Google searches. They aren't Apple's ads, they're Google's ads.

How does that matter? Apple is still seeing 20% of its profits from ads and Google is still tracking you through Apple’s browser and Apple is getting paid for it.

They pay to be the default, not the only possible search provider.

Re: Apple Platform Security (Jan 2026) [pdf]

#123

Earlier quoted context omitted.

How does that matter? Apple is still seeing 20% of its profits from ads and Google is still tracking you through Apple’s browser and Apple is getting paid for it.

They pay to be the default, not the only possible search provider.

They pay per click.

Re: Apple Platform Security (Jan 2026) [pdf]

#124
post #41

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

Enabling ADP breaks all kinds of things in Apple’s ecosystem subtly with incredibly arcane errors.

I was unable to use Apple Fitness+ on my TV due to it telling me my Watch couldn’t pair with the TV.

The problem went away when turning off ADP.

To turn off ADP required opening a support case with Apple which took three weeks to resolve, before this an attempt to turn off would just fail with no detailed error.

Other things like iCloud on the web were disabled with ADP on.

I just wanted encrypted backups, that was it.

Re: Apple Platform Security (Jan 2026) [pdf]

#125

They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…

Yes, that is however a dialect, and one of the goals to Swift Embedded roadmap is to replace it.

Re: Apple Platform Security (Jan 2026) [pdf]

#126

Earlier quoted context omitted.

Their net profit was a little over $100 billion last fiscal year. They get $20 Billion+ in pure profit from Google being their default search engine. That’s 20% of their profit

Google paying Apple to be the default search engine is not the same as Apple selling $20 billion worth of ads to track you.

Yes it is.

Re: Apple Platform Security (Jan 2026) [pdf]

#127
post #49

Earlier quoted context omitted.

It's all tempered by them ultimately controlling what you can put on your phone though. As was demonstrated in LA, it's starting to have significant civil rights consequences.

Security is pointless if platform allows 90% users to be social engineered into running code disabling that security

The ability for people to do stupid things is the inescapable price of freedom. That does not make freedom not worth it.

Re: Apple Platform Security (Jan 2026) [pdf]

#128

Earlier quoted context omitted.

ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences. How does Google manage this, such every normie on earth isn’t freaking out?

Nobody expects their text messages to be backed up. They get deleted and people shrug.

I keep my messages and would like them to not go away.

Re: Apple Platform Security (Jan 2026) [pdf]

#129

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups.

Both promise security, Apple promises some degree of privacy. Google stores your encryption keys, and so does Apple unless you opt in for ADP.

Is it similar to Facebook Messenger (encrypted in transit and at rest but Meta can read it) and Telegram (keys owned by Telegram unless you start a private chat)?

There are things Pixels do that iPhones don’t, e.g., you get notified when a local cell tower picks your IMEI. I mean it’s meaningless since they all do it, but you can also enable a higher level of security to avoid 2G. Not sure it’s meaningful but it’s a nice to have.

Re: Apple Platform Security (Jan 2026) [pdf]

#130

Earlier quoted context omitted.

Why? The obvious conclusion is that Apple is doing everything in its power to make the answer “no.” You might as well enumerate all the viruses ever made on Windows, point to them, and then ask why Microsoft isn’t proving they’ve shut them all down yet in their documents.

That analogy misses the asymmetry in claims and power. Microsoft does not sell Windows as a sealed, uncompromisable appliance. It assumes a hostile environment, acknowledges malware exists, and provides users and third parties with inspection, detection, and remediation tools. Compromise is part of the model. Apple’s model is the opposite. iOS is explicitly marketed as secure because it forbids inspection, sideloadin…

I am not sure if you missed my earlier comment, but it's directly applicable to this point you've repeatedly made:

>If Apple believes this class of attack is no longer viable, that’s worth stating.

To say it more directly this time: they do explicitly speak to this class of attack in the keynote that I linked you to in my previous comment. It's a very interesting talk and I encourage you to watch it:

https://www.youtube.com/watch?v=Du8BbJg2Pj4

Post reply on HN