Live data from Hacker News

Apple confirms iOS kernel code left unencrypted intentionally

techcrunch.com

131–140 of 157 posts

Re: Apple confirms iOS kernel code left unencrypted intentionally

#131

Earlier quoted context omitted.

>altruism Then why does Apple avoid paying taxes? Let's not kid ourselves: Apple is a company, and companies are only "altruistic" if they expect that it will help their bottom line.

This is dogmatism. The FBI situation clearly demonstrates that Apple does not only act in the interest of the bottom line.

It would have cost apple time and money to do what the FBI requested. This wasn't simply 'send us a file', they asked them to make a custom version of the software.

And if they did it, the FBI would have made more future requests for apple to spend time and money.

And if the custom software somehow got out into the wild, that would threaten apple's bottom line as well.

The FBI situation was just another example of apple taking care of themselves.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#132

A move like this fits with a more general ideology Apple has been advocating for the last three years. Privacy, security, and ultruism. Tim Cook has put is mark on the company. One of the first things he did was apologize, (for maps) something unheard of in Apple's culture. I haven't drank the cool-aid and Apple has a lot of issues. I do see they however are making attempts at differentiating from the general corpora…

How does not encrypting the kernel translate into a narrative worthy of such admiration? I feel like Apple has spent a lot of money and research into how to do brand marketing so that you would write this comment. I don't see how technically this move means any such thing, and instead people are primed to fall into such a belief because they want that feel-good story about Apple being their privacy hero in scary time…

Yes, exactly. Remember how everyone jumped on those "apple recycles all the metal" stories, which proved to be almost entirely false? People just love feeling good about apple, even when those good feelings are based on falsehoods.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#133

Earlier quoted context omitted.

A couple days after Tim Cook stepped into the CEO position, he reversed a Jobs policy and announced that the company would begin matching employee donations to charities. I considered this a fairly classy and subtle way to signal that he wasn't going to lie down on the job (it had been requested many times on company mailing lists). Source: I was on those lists.

Was there a list of what were acceptable charities for the match?

There are a number of companies set up specifically to help with matching grants. See Benevity, Double the Donation, etc.

https://www.benevity.com https://doublethedonation.com

EDIT: They generally keep lists of charities that most companies find acceptable to donate to.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#134
post #133

Earlier quoted context omitted.

Was there a list of what were acceptable charities for the match?

There are a number of companies set up specifically to help with matching grants. See Benevity, Double the Donation, etc. https://www.benevity.com https://doublethedonation.com EDIT: They generally keep lists of charities that most companies find acceptable to donate to.

The first one has certificate problems and the second doesn't provide a customer list (probably a good thing). I was specifically asking if Apple had a list of charities that it found acceptable for matching donations.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#135
post #99

Earlier quoted context omitted.

My point is that it is impossible to know where the next code chunk is if it is properly encrypted. How does the page fault handler know which block to decrypt next without first decrypting the whole code module, where module is a closed piece of code without jumps outside. In my opinion every scheme to enable that will cripple the encryption.

the code is decrypted into internal SRAM. executed normally. then an entirely normal page-fault happens at which point the hypervisor catches the trap and decrypts the data again into internal SRAM and maps it appropriately then allows the access to continue.

Will SGX help this feature?

Re: Apple confirms iOS kernel code left unencrypted intentionally

#136
post #100

Earlier quoted context omitted.

Eh you know right that TC was more thaneager to comply if FBI had issued the request privately? All the thing was a PR show from both sides.

Your source for this allegation?

all trace back to this

http://www.nytimes.com/2016/02/19/technology/how-tim-cook-be...

"Apple had asked the F.B.I. to issue its application for the tool under seal. But the government made it public, prompting Mr. Cook to go into bunker mode to draft a response, according to people privy to the discussions, who spoke on condition of anonymity."

Re: Apple confirms iOS kernel code left unencrypted intentionally

#137
post #111

Earlier quoted context omitted.

Because it's a tax writeoff and the more time workers are at the office, the more work is getting done. Or so the managerial thought process goes.

I'm just saying, I don't think food subsidies look "quite odd" to Americans, I think they look fairly normal.

It's very unusual outside of Silicon Valley.

Re: Apple confirms iOS kernel code left unencrypted intentionally

#138

Earlier quoted context omitted.

Both statements could be true - I wouldn't be too surprised to see Apple stretch the truth; yes, it's true, performance on a 25 second boot (my iphone 6s) from cold was improved to 24 seconds. Doesn't really move the needle, but still true, to some degree. A second here, and a second there - starts to add up though, particularly on boot up, for those of us who end up doing that multiple times a day. Also, in general,…

iOS 10 running on my iPhone 6S Plus is currently booting in about 5 seconds. Not sure how though... Also that's when I hold down the home and lock buttons, in order to force-reboot. Perhaps now that doesn't fully reboot the phone.

I was curious so I benchmarked "decrypting" kernelcache.release.n66 on an iPhone 6S and it took about 60 milliseconds to decrypt. It wasn't encrypted in the first place so the decryption results in garbage, but it should be a valid benchmark. The quick boot time with iOS 10 sure is nice, but it isn't because the kernel isn't encrypted.

https://gist.github.com/jevinskie/40df60e3e9d76ad05304be9bd5...

Re: Apple confirms iOS kernel code left unencrypted intentionally

#139

Earlier quoted context omitted.

The spokesperson is talking out of their ass regarding performance. The kernel is decrypted by iBoot once at boot, using the hardware AES engine. It remains decrypted until the device is shutdown/rebooted. Decompressing and decrypting the kernel takes less than a second at boot. Also, TechCrunch fails to note that the kernelcache keys for most 32-bit kernels (and all iOS versions) are publicly available. Private indi…

Down further in the thread, BillinghamJ is seeing their iPhone 6S Plus boot in 5 seconds with iOS 10, as opposed to the 25 seconds for my iPhone 6S. How certain are you that it's only 1 second of processing that's been removed - that's a HUGE increase in speed, that I haven't seen written up anywhere else. Anybody else with iOS 10 on their phone able to confirm the new 5 second boot time?

I'm very nearly certain because I benchmarked decrypting the iOS 10 beta kernel using the code at [0]. The kernelcache is about 13 MB compressed and takes about 60 milliseconds to decrypt. Previous iOS versions encrypted the compressed kernelcache so benchmarking decryption of the compressed kernelcache should be correct. Unless Apple was doing something very stupid, kernelcache decryption should never have been much of a bottleneck in the first place. It is nice to see that they have found other ways to improve the boot time.

[0]: https://gist.github.com/jevinskie/40df60e3e9d76ad05304be9bd5...

Re: Apple confirms iOS kernel code left unencrypted intentionally

#140
post #81
post #56

Earlier quoted context omitted.

As a French person without the culture of corporate donations, I'm both wondering why it was seen as negative that Apple didn't match? Shouldn't they redirect donations to people they prefer?

Seems incredibly self entitled to me. Why should your employer shell out money for whatever their employees decide? I don't understand it at all. What if you want to donate a controversial charity? If you feel that strongly about a charity double your own donation.

Couldn't you say the same thing about any perk? "Oh, you want more vacation time? Seems incredibly self entitled to me." "Oh, you want free coffee? Seems incredibly self entitled to me."
Post reply on HN