Live data from Hacker News

Apple update looks like Czech mate for locked-out iPhone user

theregister.com

131–140 of 237 posts

Re: Apple update looks like Czech mate for locked-out iPhone user

#131
post #115

Earlier quoted context omitted.

> Steve Jobs would be rolling in his grave if he could see the software quality of the products that Apple releases today. lol, nah he wouldn't. He would of upgraded his coffin to plush and got a big screen to watch the money roll in. I recommend reading up on his 80/90's antics. All he cared about was money and that the world was crafted by him. He was widely known for intense bullying, lacking empathy, and ruthless…

Yes, and "his obsessive drive for perfection" as you put it is what would make him "rolling in his grave if he could see the software quality of the products that Apple releases today" as the parent put it.

He famously shipped the original Macintosh with a keyboard without arrow keys to force buyers to use the mouse.

His vision of perfection didn't always match common sense. There are quite a few examples of this.

I always cringe a little when I read these "jobs would have rolled over in his grave" comments.

Re: Apple update looks like Czech mate for locked-out iPhone user

#132

It’s an annoying workaround, but could he connect a USB keyboard (via a USB to lightning adapter) with the ability to enter the character? Does the passcode screen accept input from attached keyboards?

Why can't people read stuff before commenting?

I wish we could just have comments removed where it's clear the author didn't even put in the minimum effort of reading the article. It's disrespectful to the rest of us.

Re: Apple update looks like Czech mate for locked-out iPhone user

#133

Earlier quoted context omitted.

The biggest lesson here is don't buy Apple products. Steve Jobs would be rolling in his grave if he could see the software quality of the products that Apple releases today.

> Steve Jobs would be rolling in his grave if he could see the software quality of the products that Apple releases today. lol, nah he wouldn't. He would of upgraded his coffin to plush and got a big screen to watch the money roll in. I recommend reading up on his 80/90's antics. All he cared about was money and that the world was crafted by him. He was widely known for intense bullying, lacking empathy, and ruthless…

> I recommend reading up on his 80/90's antics. All he cared about was money

Incorrect. Read the David Pogue Apple book. For example, after the iMac was released, the Apple board of directors offered Jobs a million shares and six million options if he switched from interim to permanent CEO. Jobs continued to refuse. “This is not about money. I have more money than I’ve ever wanted in my life.”

Most of Steve's wealth came from Pixar, which he ultimately sold to Disney, rather than from Apple.

Re: Apple update looks like Czech mate for locked-out iPhone user

#134
post #36
post #15

Earlier quoted context omitted.

[flagged]

I agree with you and don't really get what Apple gets from removing a valid Czech character, but how would you test if all existing passcodes remain inputable without knowing the passcodes of all iPhone users? The one way to do this that I could see is to include both the new keyboard and the old one and if someone fails to unlock with the new one auto report that to Apple (not the code, just that the unlock failed a…

There is a list of valid characters accepted for a passcode. That list was created, the characters debated, and a consensus reached by Apple engineers (I hope, for all our sakes. I don't want to imagine a world where this bare minimum level of engineering diligence wasn't done by a trillion dollar company)

Just have an automated keyboard test for every new release to ensure those characters aren't broken.

Re: Apple update looks like Czech mate for locked-out iPhone user

#135

Earlier quoted context omitted.

Weirdly I care more about my rights as the owner of the device than the rights of a theoretical attacker.

So don’t buy an iPhone if you don’t care about the security of your device and personal information. That would introduce a massive security hole that would negatively affect far more users than it would help.

I doubt that. The group of people you're talking about are those who have their phone maliciously stolen by people who are actively working to hack/exploit their way into the devices and then actively exploit the information stored on them. That is a utterly negligible percent of users, or even of users who have their phone stolen. The overwhelming majority of thieves of intent move the devices onto professional orgs that wipe them, jailbreak them, package them, and then ship them on to other entities that resell them.

The percent that might want to choose a different-than-latest version of OS would also of course be quite small, but I suspect it would be orders of magnitude larger than the other group we're speaking of just because that group of people is going to be so absurdly tiny.

Re: Apple update looks like Czech mate for locked-out iPhone user

#136

Earlier quoted context omitted.

Biggest lesson is Apple should allow you to downgrade OS, especially on old devices. Or release some sort of open version once device is EOL'd.

Then an attacker could load an older, exploitable OS and gain access.

This is not an excuse to let people choose if they allow os downgrades or not. Like bootloader unlock option on android devices.

Also people find exploits on newer OS versions as well. Downgrading makes it easier but not downgrading doesn’t make the device unhackable.

Re: Apple update looks like Czech mate for locked-out iPhone user

#137

Earlier quoted context omitted.

Biggest lesson is Apple should allow you to downgrade OS, especially on old devices. Or release some sort of open version once device is EOL'd.

Then an attacker could load an older, exploitable OS and gain access.

It should be then a switch in the settings.

Re: Apple update looks like Czech mate for locked-out iPhone user

#138

Earlier quoted context omitted.

Then an attacker could load an older, exploitable OS and gain access.

Weirdly I care more about my rights as the owner of the device than the rights of a theoretical attacker.

I’m all for a system that allows you to wipe the device to do a downgrade or upgrade (just like any PC with an unset bios password allows) but the idea that it’s a good design for someone without my OS password to be able to downgrade my OS or perform any operation on my OS is insane.

What’s even the point of setting a password if anyone can manipulate the system without entering it in?

The entire iPhone OS is on an encrypted volume and that is the right design choice. Not having the password means no access.

There is no general purpose encrypted volume operating system that allows unauthenticated users to perform OS manipulation. If you encrypt your FreeBSD, Linux, or Windows volume, the result is the same: no password, no access.

Your choice is to enter the correct password or wipe the disk.

The fact that Apple doesn’t allow you to set up a system without full disk encryption is not a user freedom issue, it’s a very sensible design choice especially for a device sold primarily to non-technical consumers who don’t understand the security implications of leaving the volume unencrypted.

The issue here isn’t that iOS security is designed wrong, the issue is that Apple broke basic password entry with an update.

Shame on Apple for having such lazy software development practices when it comes to implementing updates like this.

Post reply on HN