Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

191–200 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#192

Earlier quoted context omitted.

People don't always have enough Apple devices to justify confidence that they couldn't lose them all at the same time, which with ADP is a permanent death sentence if you don't have your recovery key. (Apple says you can also use a device passcode; I'm not sure if this works if the device is lost. Maybe it does?)

I have 2 or 3 yubikeys associated with my account. I think apple does a decent job at communicating the importance of having recovery keys to the point where they deter those who can’t be bothered. Yubikeys are great

I'm always put off by the incredibly low limits on yubikeys. What's the point of having a security key if you can only have 25 accounts in its lifetime? What are you supposed to do, buy tons of keys and then figure out a system to remember which key each account is? Like fucking hell just let me use passkeys in iCloud Keychain. My bank's mobile app specifically supports only security keys and explicitly not passkeys for literally no reason because passkeys are practically just as secure as any security key. It's actually harder to specifically exclude passkeys and allow only security keys than it is to just use passkeys which automatically include security keys.

Re: Apple Platform Security (Jan 2026) [pdf]

#193

Earlier quoted context omitted.

Yes it is.

Is this what you consider discourse? At least justify your position, don't shit out some drive-by popular opinion that I can't even begin to respond to.

Operating ads directly or reaping profits from renting out your platform to the highest bidder, it's still ad revenue and profit.

Re: Apple Platform Security (Jan 2026) [pdf]

#195
post #187

Earlier quoted context omitted.

> Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. By default, Apple offers you at no charge: email aliases, private relay, Ask No Track barrier. These are just the ones I can think of right now. I am sure there are more. A big thing with Apple is not that they offer different privacy serv…

Aren’t they part of iCloud+ only? Ask no-track can arguably compromise your privacy by fingerprinting. I agree that the privacy controls on Apple systems are well-organized. Still, it’s more important to have confidence that the privacy services are not smoke and mirrors with carefully carved-out loopholes. It’s one thing to provide something and hold the competitor as the litmus test, the other to sustainably live u…

Email relay at least is available to me, a non-iCloud user.

Re: Apple Platform Security (Jan 2026) [pdf]

#196

Earlier quoted context omitted.

The way I look at it is that there is certain software that other entities aren't willing to let you run without assurances that it won't be tampered with. You don't necessarily have a right to be able to use that software if you cannot provide it suitable accomodations. It's your choice whether or not you want to run it or not, anything else is simply entitlement. This may seem annoying if it's your bank, but ultima…

> It's your choice Ah, classic false choice. Do you know it is illegal to do cash transactions over a certain amount in most Western countries now? In my mind, if I have a right to do something (buy a home), and there is only one approved way to do it, then I automatically have the right to use the approved way. Similarly, having a government ID might technically be a choice now, but it won't be soon with all these a…

I know this argument is used a lot, but it it really doesn't make sense to me. A government is expected to give you reasonable accommodation, but it's not their duty to let you run their software via a means they don't trust. It's convenient to use their app, but again not required.

Having controls is part of participating in society. I don't believe you should be able to make large transactions in total anonymity either. It's robbing you of a freedom, but society has deemed it a worthwhile tradeoff for preventing crime via money laundering and what not.

Re: Apple Platform Security (Jan 2026) [pdf]

#197

Earlier quoted context omitted.

> Well that’s what Americans voted for. Americans are not one person. > So I don’t think anyone cares Clearly they do. > every CEO (definitely not just Tim Cook) is schmoozing with Trump. Tim Cook was (supposedly) principled. I guess it's hard to pretend that you care about privacy or human rights while eating dinner next to bin Salman.

> Tim Cook was (supposedly) principled. I guess it's hard to pretend that you care about privacy or human rights while eating dinner next to bin Salman. I guess if you thought he had principles then yeah that could be disappointing. Personally I've never tried to moralize corporations though, I just assume the only principle that every company and CEO operates by is whatever increases the stock price.

And me thinking company values actually meant something in all those trainings. /s

Re: Apple Platform Security (Jan 2026) [pdf]

#198

Earlier quoted context omitted.

Security is pointless if platform allows 90% users to be social engineered into running code disabling that security

What's funny is you could read that statement as being an argument for or against walled gardens, depending on what kind of social engineering is being referred to.

Also depending on whether review process is going to catch the bad code...

Re: Apple Platform Security (Jan 2026) [pdf]

#199

Earlier quoted context omitted.

Enabling ADP breaks all kinds of things in Apple’s ecosystem subtly with incredibly arcane errors. I was unable to use Apple Fitness+ on my TV due to it telling me my Watch couldn’t pair with the TV. The problem went away when turning off ADP. To turn off ADP required opening a support case with Apple which took three weeks to resolve, before this an attempt to turn off would just fail with no detailed error. Other t…

That chimes roughly with my experience, but to be fair ADP is designed not just for encrypted backups, but to harden the ecosystem for people who may be under the greatest threat. Worth noting that it has been outlawed in the UK and cannot be enabled, which makes me think it's pretty decent

You wouldn’t happen to work in North Norfolk would you?

Re: Apple Platform Security (Jan 2026) [pdf]

#200
post #41

Earlier quoted context omitted.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

Enabling ADP breaks all kinds of things in Apple’s ecosystem subtly with incredibly arcane errors. I was unable to use Apple Fitness+ on my TV due to it telling me my Watch couldn’t pair with the TV. The problem went away when turning off ADP. To turn off ADP required opening a support case with Apple which took three weeks to resolve, before this an attempt to turn off would just fail with no detailed error. Other t…

Huh, that’s crazy because ADP doesn’t break anything for me. Then again, I’m not trying to connect an Apple Watch to a tv. What a simple life I live.
Post reply on HN