Live data from Hacker News

Apple update looks like Czech mate for locked-out iPhone user

theregister.com

171–180 of 237 posts

Re: Apple update looks like Czech mate for locked-out iPhone user

#171
post #131
post #115

Earlier quoted context omitted.

Yes, and "his obsessive drive for perfection" as you put it is what would make him "rolling in his grave if he could see the software quality of the products that Apple releases today" as the parent put it.

He famously shipped the original Macintosh with a keyboard without arrow keys to force buyers to use the mouse. His vision of perfection didn't always match common sense. There are quite a few examples of this. I always cringe a little when I read these "jobs would have rolled over in his grave" comments.

Jobs was a perfectionist and a minimalist. Part of minimalism is that sometimes you delete marginal features (arrow keys) that you still end up wanting back.

If you never delete too many features, you aren’t deleting enough features.

Re: Apple update looks like Czech mate for locked-out iPhone user

#172
post #137

Earlier quoted context omitted.

Then an attacker could load an older, exploitable OS and gain access.

It should be then a switch in the settings.

What should we label it? “Waste time entering alphanumeric password that provides no security benefit”?

The particular use case you’re asking for here has no logical reason for existing

Re: Apple update looks like Czech mate for locked-out iPhone user

#173
post #54

Earlier quoted context omitted.

> how would you test if all existing passcodes remain inputable without knowing the passcodes of all iPhone users? You basically can't ever remove an available character. That includes emojis if they're allowed in IOS passwords.

Probably the better solution is to include some kind of special lock-screen keyboard that provides some fallback mechanism to input any character. Presumably there are similar edge cases where someone creates a password using one keyboard, then switches keyboard layout, and now can't re-enter it using the active layout...

Wonder if you can get it to enter effective. Power لُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣ 冗

Re: Apple update looks like Czech mate for locked-out iPhone user

#174
post #121

Earlier quoted context omitted.

He can upgrade, but not downgrade, for security integrity.

Doesn't this mean that no matter how securely your phone is locked, Apple (and probably the three-letter agencies) can always unlock it by installing an appropriate update?

If the data you care about is encrypted with a token locked behind your passcode input, and it's not theoretically brute forceable by being a 4 character numeric only thing, then not easily, no.

Could they produce an update that is bespoke and stops encrypting the next time you unlock, push it to your phone before seizing it, wait for some phone home to tell them it worked, and then grab it?

Perhaps, but the barrier to making Apple do that is much higher than "give us the key you already have", and only works if it's a long planned thing, not a "we got this random phone, unlock it for us".

(It's also something of a mutually-assured destruction scenario - if you ever compel Apple to do that, and it's used in a scenario where it's visibly the case that 'the iPhone was backdoored' is the only way you could have gotten that data, it's game over for people trusting Apple devices to not do that, including in your own organization, even if you somehow found a legal way to compel them to not be permitted to do it for any other organization.)

Re: Apple update looks like Czech mate for locked-out iPhone user

#175

Earlier quoted context omitted.

Biggest lesson is Apple should allow you to downgrade OS, especially on old devices. Or release some sort of open version once device is EOL'd.

Then an attacker could load an older, exploitable OS and gain access.

Not allowing downgrades is the biggest contributor to smartphones becoming e-waste.

Apple should be forced to do this by law, but only after they discontinue software support. If they're willing to continue making small, incremental patches when necessary (such as to fix this obvious bug) then it's fine that they can still block downgrades. But at EOL? They should be legally required to allow old software to be installed.

This also impacts software compatibility - any 64-bit device that is now EOL that got updated to iOS 11 or newer is forever barred from running 32-bit apps just because people are worried that someone might take that old device and downgrade it as an attack?

The average person should always stay updated to the latest version for security reasons. But the power users should be able to choose which version they run, at least on devices that aren't currently supported at all.

Daily reminder that the first two iPhones and the first iPod touch had zero firmware signing, and you could freely install any supported version at any time, and can still do so today. That being the case has probably harmed 0.00001% of people at most

Re: Apple update looks like Czech mate for locked-out iPhone user

#176
post #91
post #88

Earlier quoted context omitted.

> Majority of California based companies employee English only or English and Spanish speakers possibly with some Indian language as well [...] Never mind rarer languages like Czech or Greek. That may be generally true, in this case Apple actually has an engineering team in Czechia that works on biometrics and authentication: https://zpravy.aktualne.cz/ekonomika/apple-posili-v-praze-ty... https://jobs.apple.com/en-gb…

So could they finally fix their quotations marks in Czech? Probably no, they never cared, so why should they start caring now.

No but they might be able to fix authentication problems, which is what this is.

Re: Apple update looks like Czech mate for locked-out iPhone user

#177
post #66

Majority of California based companies employee English only or English and Spanish speakers possibly with some Indian language as well. This leads to lots of problems when you are bilingual or bilingual in other languages such as German in French. Neither Apple nor Microsoft under this sort of language swapping well. Never mind rarer languages like Czech or Greek.

I would not be surprised if Apple engineers are more likely to be bilingual than a random person selected from the world's population.

Re: Apple update looks like Czech mate for locked-out iPhone user

#178
post #119
post #70

Earlier quoted context omitted.

How? The article states: > For the same reason, plugging in an external keyboard is also a no-go since freshly updated iPhones are placed in what's known as a Before First Unlock state, which prevents wired accessories from working until the passcode is entered. The user can't even enter their passcode, how do you expect them to perform code execution?

Plugging in a USB keyboard is way higher level than what I'm talking about. You can contact a digital forensics firm, and they'll do it for you. It'd be custom hardware. Cellebrite-type stuff.

Why would they do it for free?

Re: Apple update looks like Czech mate for locked-out iPhone user

#179

Earlier quoted context omitted.

Netflix can't even auto-translate subtitles (in the age of genai where we are close to generating entire movies from scratch). Let alone ever imagine that you'd want to see subtitles in two languages at once. Language support is still such an enigma.

We run into this issue when watching Korean movies/dramas. My wife prefers Japanese subtitles and I prefer English/German. I haven’t found a way to enable two subtitles in Firefox (via extensions). So in those cases I usually download a release which contains subtitles in both languages and use a script to extract them via ffmpeg and then combine them into a single srt. Now the issue is that the lines of the differen…

mplayer supports displaying multiple subtitles

Re: Apple update looks like Czech mate for locked-out iPhone user

#180
post #99

Earlier quoted context omitted.

> how would you test if all existing passcodes remain inputable without knowing the passcodes of all iPhone users? You basically can't ever remove an available character. That includes emojis if they're allowed in IOS passwords.

You can but you have to tie it to actual devices and a point in time, not simply a specific OS version. Essentially, all devices that existed before the change must still support the old set of characters and devices produced (or sold or activated) afterwards can support the reduced set. Or wait until a future OS version that will not support any device currently in existence.

This fails if they let you keep your password migrating between devices, though, so you probably need a version somewhere in the middle that flags it as an issue and flags it as not allowing migration without changing the passphrase.
Post reply on HN