Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

141–150 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#141
post #39
post #20

But all the software is closed source, and there is little to no opportunity to verify all these security claims. You don't have the encryption keys, so effectively the data is not under your control. If you want to see security done well (or at least better), see the GrapheneOS project.

Yes, how can we verify this? Who says three-letter agencies have no access?

We can't verify that the Pixel phones are safe. Nor can the GrapheneOS people, because they don't know everything that's running in the Google Tensor SoC, and they don't have the source code to the firmware running in the Samsung Exynos cellular modem.

Re: Apple Platform Security (Jan 2026) [pdf]

#142

Earlier quoted context omitted.

Some of these companies don't make money from you, the end user, but by selling ads and data to more effectively deliver said ads. Differences in capabilities, experience and implementation are all downstream from that. In other words, everyone pays lip service to privacy and security, but it's very difficult to believe that parties like Meta or Google are actually being honest with you. The incentives just aren't th…

Apple, Samsung and Google all earn money from ads on your phone, just with different monetization pathways.

My understanding though is that the monetization pathways for Samsung and Google are 3rd party—Apple keeps your data to itself.

Re: Apple Platform Security (Jan 2026) [pdf]

#143
post #58

Earlier quoted context omitted.

Apple sells some ads yes. But it’s a tiny fraction of their revenue. Would Google or Meta go bankrupt if they stopped selling ads? Yes. Apple wouldn’t.

As long as you don’t count the $25 billion that Apple gets from Google.

Are you suggesting that is what is keeping Apple afloat?

Re: Apple Platform Security (Jan 2026) [pdf]

#144

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

I still like their hardware. But let’s not pretend that there is any part of Trump’s body that he won’t kiss and sell out his customers for. If Trump asked Cook to put a backdoor in iPhones or impose tariffs on Apple, Cook would do it in a minute

My Mother Night hope is that Cook publicly shows obsequiousness only so that in private he can hold the line on backdoors, etc.

I know, I'm living in a fantasy world in my head.

Re: Apple Platform Security (Jan 2026) [pdf]

#146

Earlier quoted context omitted.

Apple, Samsung and Google all earn money from ads on your phone, just with different monetization pathways.

My understanding though is that the monetization pathways for Samsung and Google are 3rd party—Apple keeps your data to itself.

Apple sends your searches to Google for money. I would call search queries data?

Re: Apple Platform Security (Jan 2026) [pdf]

#147

Earlier quoted context omitted.

My understanding though is that the monetization pathways for Samsung and Google are 3rd party—Apple keeps your data to itself.

Apple sends your searches to Google for money. I would call search queries data?

> Apple sends your searches to Google for money. I would call search queries data?

Yawn. Changing your default search engine takes 5 seconds.

Re: Apple Platform Security (Jan 2026) [pdf]

#148
post #129

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. Both promise security, Apple promises some degree of privacy. Google stores your encryption keys, and so does Apple unless you opt in for ADP. Is it similar to Facebook Messenger (encrypted in transit and at rest but Meta can read it) and Te…

> Apple promises some degree of privacy.

Apple also makes it easier to achieve that privacy:

    - They put all the privacy controls in one place in Settings so you can audit
    - App developers are mandated to publish what they collect when publishing apps to the App Store.

Re: Apple Platform Security (Jan 2026) [pdf]

#149

Earlier quoted context omitted.

Enabling ADP breaks all kinds of things in Apple’s ecosystem subtly with incredibly arcane errors. I was unable to use Apple Fitness+ on my TV due to it telling me my Watch couldn’t pair with the TV. The problem went away when turning off ADP. To turn off ADP required opening a support case with Apple which took three weeks to resolve, before this an attempt to turn off would just fail with no detailed error. Other t…

That chimes roughly with my experience, but to be fair ADP is designed not just for encrypted backups, but to harden the ecosystem for people who may be under the greatest threat. Worth noting that it has been outlawed in the UK and cannot be enabled, which makes me think it's pretty decent

> Worth noting that it has been outlawed in the UK and cannot be enabled

For the record, there is an ongoing court battle between Apple and UK government about getting it overturned.

Which also says many positive things for Apple that they are willing to put their money where their mouth is and put up a fight.

Re: Apple Platform Security (Jan 2026) [pdf]

#150

Earlier quoted context omitted.

That analogy misses the asymmetry in claims and power. Microsoft does not sell Windows as a sealed, uncompromisable appliance. It assumes a hostile environment, acknowledges malware exists, and provides users and third parties with inspection, detection, and remediation tools. Compromise is part of the model. Apple’s model is the opposite. iOS is explicitly marketed as secure because it forbids inspection, sideloadin…

[flagged]

It’s not “a weakness.” It’s many weaknesses chained together to make an exploit. Apple patches these as they are found. NSO then tries to find new ones to make new exploits.

Apple lists the security fixes in every update they release, so if you want to know what they’ve fixed, just read those. Known weaknesses get fixed. Software like Pegasus operates either by using known vulnerabilities on unpatched OSes, or using secret ones on up to date OSes. When those secret ones get discovered, they’re fixed.

Post reply on HN