Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

171–180 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#171
post #170
post #162

Earlier quoted context omitted.

It has been on Swift and Apple's official documentation since the early days. People keep forgetting that Objective-C also had a full stack role on NeXTSTEP. And the same full stack approach was also a thing on Xerox PARC systems, which mostly failed due to mismanagement. Usually ends well for closed source platform vendors when developers aren't allowed to come up with alternatives like on FOSS operating systems. At…

>People keep forgetting that Objective-C also had a full stack role on NeXTSTEP. In terms of Apps and Low Level Stack Objective-C doesn't seems wrong in my book. The problem is Swift begin as a much larger language and evolve into a gigantic pile of a little of everything.

Doesn't seem to hinder C++, which modern C compilers are written with nowadays.

Despite all its complexity, LLVM and GCC aren't getting rewritten any time soon, or the OSes that rather use C++ subsets instead of being stuck with C.

Re: Apple Platform Security (Jan 2026) [pdf]

#172

Earlier quoted context omitted.

As long as you don’t count the $25 billion that Apple gets from Google.

Are you suggesting that is what is keeping Apple afloat?

No. But guess how much their stock would drop if one quarter they lost 20% of their profit?

Re: Apple Platform Security (Jan 2026) [pdf]

#173
post #47

Earlier quoted context omitted.

> teach apps who they should trust Ah, the apps^Wgovernment (look at that page, most of it is government IDs) should be able to discriminate against me for daring to assert control over my own device. And GrapheneOS is saying: Hey government! We pinky promise to oppress the user just the same, but even more securely and competently than Google/Samsung! > what does it matter to you It shows that the developers maybe d…

The way I look at it is that there is certain software that other entities aren't willing to let you run without assurances that it won't be tampered with. You don't necessarily have a right to be able to use that software if you cannot provide it suitable accomodations. It's your choice whether or not you want to run it or not, anything else is simply entitlement. This may seem annoying if it's your bank, but ultima…

> It's your choice

Ah, classic false choice. Do you know it is illegal to do cash transactions over a certain amount in most Western countries now? In my mind, if I have a right to do something (buy a home), and there is only one approved way to do it, then I automatically have the right to use the approved way.

Similarly, having a government ID might technically be a choice now, but it won't be soon with all these age verification BS rolling out. So no, this is not entitlement. Your argument would work for anticheat in online games or DRM media, but not banks or government services.

Re: Apple Platform Security (Jan 2026) [pdf]

#174

Earlier quoted context omitted.

Google paying Apple to be the default search engine is not the same as Apple selling $20 billion worth of ads to track you.

Yes it is.

Is this what you consider discourse? At least justify your position, don't shit out some drive-by popular opinion that I can't even begin to respond to.

Re: Apple Platform Security (Jan 2026) [pdf]

#175

Earlier quoted context omitted.

But it still isn't Apple doing the tracking or receiving the data about your Google searches. They aren't Apple's ads, they're Google's ads.

How does that matter? Apple is still seeing 20% of its profits from ads and Google is still tracking you through Apple’s browser and Apple is getting paid for it.

> How does that matter?

Keeping in mind the context of the overall thread we're in, where the OP said this:

> Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

And then further down somebody replies with this:

> Apple is an ad company now though

The implication was that, because Apple sells ads now, they must be tracking all of your personal data in the same way that Google does. And then that train of thought was further continued with the implication that, because Apple receives "20% of its profits from ads and Google" (lumping them both together), Apple ergo is receiving 20% of its profits through tracking all of your personal data. But it's not Apple tracking all of your personal data, it's Google tracking it, and they would track it whether they're the default search engine on iOS or not.

The distinction matters to me, and it's why I buy Apple products but not Google products.

Re: Apple Platform Security (Jan 2026) [pdf]

#176

Earlier quoted context omitted.

What happened in LA?

https://www.cnn.com/2025/10/03/tech/iceblock-apple-removed-t...

I forgot about that and hadn't tied it to LA specifically in my head. Thanks for reminding me, really shitty thing that made me a lot more sympathetic to alternative app stores where I'd been against them before.

Re: Apple Platform Security (Jan 2026) [pdf]

#177

Earlier quoted context omitted.

Cook couldn't personally put that backdoor in himself though. There would (presumably) be Apple employees who would blow the whistle if they received such a command.

In today’s market? You see how many tech workers have shut up about protesting every little thing inside large companies with all of the layoffs happening? I have been cocky for 30 heads with the thought that I could always find a job quickly - and have even in 2023 (3 offers within 2 weeks) after being Amazoned and in 2024 (just replied to one recruiter the day after a layoff). But even I shut up and keep my head do…

That's a good point. I'm lucky enough to be self employed, and I tell myself that if I were ever in the position to blow the whistle at a corporate or government job I'd do it in a heartbeat. But what we tell ourselves in our head and what we do when our family's livelihood is on the line aren't always the same.

Re: Apple Platform Security (Jan 2026) [pdf]

#178
post #164
post #74

Earlier quoted context omitted.

In their revenue report this week out of $140B, services made up 30B. 140B-30B = 110B. Thats pretty far from bankruptcy.

And that was just one quarter…

Run 12 quarters, for all I care. Service revenue accounts for more than 50% of Apple's YoY revenue growth: https://www.statista.com/chart/14629/apple-services-revenue/

Hardware sales aren't picking up the slack, and advertisement revenue is also following a growth trend. Apple's stock would indeed be cooked if they went balls-out against the government that guarantees them access to cheap hardware and software that has been declared illegally anti competitive by foreign sovereigns. Apple needs this.

Re: Apple Platform Security (Jan 2026) [pdf]

#179

Earlier quoted context omitted.

That analogy misses the asymmetry in claims and power. Microsoft does not sell Windows as a sealed, uncompromisable appliance. It assumes a hostile environment, acknowledges malware exists, and provides users and third parties with inspection, detection, and remediation tools. Compromise is part of the model. Apple’s model is the opposite. iOS is explicitly marketed as secure because it forbids inspection, sideloadin…

I am not sure if you missed my earlier comment, but it's directly applicable to this point you've repeatedly made: >If Apple believes this class of attack is no longer viable, that’s worth stating. To say it more directly this time: they do explicitly speak to this class of attack in the keynote that I linked you to in my previous comment. It's a very interesting talk and I encourage you to watch it: https://www.yout…

On some random YouTube video that is mostly consisting of waffle and meaningless information like "95% of issues are architecturally prevented by SPTM". It's a quite neat and round number. Come on dude.

Re: Apple Platform Security (Jan 2026) [pdf]

#180

Earlier quoted context omitted.

I still recommend Mr. Fart's Favorite Colors as a refutation, describing why all of these precautions cannot protect you in a real-world security model: https://medium.com/@blakeross/mr-fart-s-favorite-colors-3177... Unbreakable phones are coming. We’ll have to decide who controls the cockpit: The captain? Or the cabin?

I don't understand. That article (written in 2016) says that Apple will build unbreakable phones in the future. Now is the future. So it seems to imply that Apple phones today are unbreakable. Also, where does the article discuss "all of these protections"? (HSMs, rate limits, etc.)

> So it seems to imply that Apple phones today are unbreakable.

Indeed. If you don't control the "unbreakable" security though, then the lock is not for your benefit.

> where does the article discuss "all of these protections"?

You could read the danged article, it's pretty clear about the vulnerability of proprietary mitigations. I hate quoting spoilers verbatim but here you go:

  The sharper you get, the more important the work. But the more valuable the work, the craftier — and more determined — your adversaries. Every attack is more novel than the last. [...] By the time you land an engineering gig at Apple, you are a twitchy, tinfoily mess.

  And it is in this spirit that you develop one of the most secure systems the world has ever known. [...] So adversaries be damned: You finally win on the merits. But who said anything about meritocracy? During the champagne toast, Mr. Fart steps from behind the curtain and pulls the pistol of last resort:

  “Don’t ship this. Or else.”
Post reply on HN