Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

131–140 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#131
post #100

Earlier quoted context omitted.

Nobody expects their text messages to be backed up. They get deleted and people shrug.

Or IOW, Googles solution affects only messages. Apple’s solution affects your whole digital life so the consequences are a lot more dire.

Google’s solution also ensures that they know all the metadata of your messages, except the content of the message itself.

Re: Apple Platform Security (Jan 2026) [pdf]

#132
post #129

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. Both promise security, Apple promises some degree of privacy. Google stores your encryption keys, and so does Apple unless you opt in for ADP. Is it similar to Facebook Messenger (encrypted in transit and at rest but Meta can read it) and Te…

Some of these companies don't make money from you, the end user, but by selling ads and data to more effectively deliver said ads.

Differences in capabilities, experience and implementation are all downstream from that. In other words, everyone pays lip service to privacy and security, but it's very difficult to believe that parties like Meta or Google are actually being honest with you. The incentives just aren't there.

With Apple, you get to fork over your wallet, but at least you seem the be primarily the user they've got to provide services to.

With Google/Meta, you're a sucker to bleed dry.

Re: Apple Platform Security (Jan 2026) [pdf]

#133
post #58

Earlier quoted context omitted.

Apple sells some ads yes. But it’s a tiny fraction of their revenue. Would Google or Meta go bankrupt if they stopped selling ads? Yes. Apple wouldn’t.

As long as you don’t count the $25 billion that Apple gets from Google.

I was wondering why Apple bought an identity clone patent that would wreck targeted ads and never used it. Maybe it’s a $25 billion insurance policy.

Re: Apple Platform Security (Jan 2026) [pdf]

#134
post #41

Earlier quoted context omitted.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

Enabling ADP breaks all kinds of things in Apple’s ecosystem subtly with incredibly arcane errors. I was unable to use Apple Fitness+ on my TV due to it telling me my Watch couldn’t pair with the TV. The problem went away when turning off ADP. To turn off ADP required opening a support case with Apple which took three weeks to resolve, before this an attempt to turn off would just fail with no detailed error. Other t…

That chimes roughly with my experience, but to be fair ADP is designed not just for encrypted backups, but to harden the ecosystem for people who may be under the greatest threat. Worth noting that it has been outlawed in the UK and cannot be enabled, which makes me think it's pretty decent

Re: Apple Platform Security (Jan 2026) [pdf]

#135

Earlier quoted context omitted.

They pay to be the default, not the only possible search provider.

They pay per click.

Again, they get paid a cut of Google's ad revenue from Safari users. This has one impact on Apple's design choices - Google remains the default search engine.

Notably, this hasn't stopped Apple from introducing multiple anti-tracking technologies into Safari which prevents Google from collecting information from Safari users.

If I open up a new tab in safari it tells me that in the last 30 days Safari prevented 109 trackers from profiling me and that 55% of the sites I use implement trackers. It also tells me that the most blocked tracker is googletagmanager.com across 78 websites

Re: Apple Platform Security (Jan 2026) [pdf]

#136
post #41

Earlier quoted context omitted.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

Apple's other emphasis is customer experience, and there are more "I forgot my code, help me recover my stuff" people than you can imagine. It would be bad PR for Apple if everybody constantly kept losing their messages because they had no way to get back into their account.

That’s all fine, but then show the sender whether their connection is actually end to end encrypted, or whether all their messages end up in Apple’s effective control.

One might consider differently colored chat message bubbles… :)

Re: Apple Platform Security (Jan 2026) [pdf]

#137
post #47

Earlier quoted context omitted.

You were not going to be able to use those apps anyways, so what does it matter to you? I, and I suspect many, agree with the purpose of attestation. The problems around it are strictly around establishing good ways to teach apps who they should trust, not around attestation itself. By putting your head in the sand, you'll never improve the situation.

> teach apps who they should trust Ah, the apps^Wgovernment (look at that page, most of it is government IDs) should be able to discriminate against me for daring to assert control over my own device. And GrapheneOS is saying: Hey government! We pinky promise to oppress the user just the same, but even more securely and competently than Google/Samsung! > what does it matter to you It shows that the developers maybe d…

The way I look at it is that there is certain software that other entities aren't willing to let you run without assurances that it won't be tampered with. You don't necessarily have a right to be able to use that software if you cannot provide it suitable accomodations. It's your choice whether or not you want to run it or not, anything else is simply entitlement. This may seem annoying if it's your bank, but ultimately it's their choice to make. The current approach makes certain things painful, like trying to customize your os, but that's a problem worth solving rather than just ignoring. More software will start relying on this over time. At the end of the day trust is a hard problem to solve.

Re: Apple Platform Security (Jan 2026) [pdf]

#138
post #100

Earlier quoted context omitted.

Or IOW, Googles solution affects only messages. Apple’s solution affects your whole digital life so the consequences are a lot more dire.

Google’s solution also ensures that they know all the metadata of your messages, except the content of the message itself.

How convenient...... indeed

Re: Apple Platform Security (Jan 2026) [pdf]

#139
post #129

Earlier quoted context omitted.

Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. Both promise security, Apple promises some degree of privacy. Google stores your encryption keys, and so does Apple unless you opt in for ADP. Is it similar to Facebook Messenger (encrypted in transit and at rest but Meta can read it) and Te…

Some of these companies don't make money from you, the end user, but by selling ads and data to more effectively deliver said ads. Differences in capabilities, experience and implementation are all downstream from that. In other words, everyone pays lip service to privacy and security, but it's very difficult to believe that parties like Meta or Google are actually being honest with you. The incentives just aren't th…

Apple, Samsung and Google all earn money from ads on your phone, just with different monetization pathways.

Re: Apple Platform Security (Jan 2026) [pdf]

#140
post #125

They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…

Yes, that is however a dialect, and one of the goals to Swift Embedded roadmap is to replace it.

So they were not joking when they say they want Swift to replace from Assembly to Javascript.

I dont think this will end well.

Post reply on HN