Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

201–205 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#201
post #140
post #125

Earlier quoted context omitted.

Yes, that is however a dialect, and one of the goals to Swift Embedded roadmap is to replace it.

So they were not joking when they say they want Swift to replace from Assembly to Javascript. I dont think this will end well.

Why? There's no particular reason why a language can't span low-level to high-level. C# is a good example of that: normally you deal with garbage collected objects and references, but if you need to drop down to explicit stack allocations, raw pointers, unions etc, you can - though of course the resulting code looks very different from idiomatic high-level code.

Re: Apple Platform Security (Jan 2026) [pdf]

#202
post #41

Earlier quoted context omitted.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

Enabling ADP breaks all kinds of things in Apple’s ecosystem subtly with incredibly arcane errors. I was unable to use Apple Fitness+ on my TV due to it telling me my Watch couldn’t pair with the TV. The problem went away when turning off ADP. To turn off ADP required opening a support case with Apple which took three weeks to resolve, before this an attempt to turn off would just fail with no detailed error. Other t…

FWIW I've been running ADP for over a year now, and so far I haven't noticed any problems.

iCloud on the web not being available is kind of expected; how would it work with E2EE?

Re: Apple Platform Security (Jan 2026) [pdf]

#203

Earlier quoted context omitted.

Cook couldn't personally put that backdoor in himself though. There would (presumably) be Apple employees who would blow the whistle if they received such a command.

In today’s market? You see how many tech workers have shut up about protesting every little thing inside large companies with all of the layoffs happening? I have been cocky for 30 heads with the thought that I could always find a job quickly - and have even in 2023 (3 offers within 2 weeks) after being Amazoned and in 2024 (just replied to one recruiter the day after a layoff). But even I shut up and keep my head do…

> As long as we ain’t killing kids

Even that level of non-involvement is getting increasingly difficult with anything Big Tech given their IDF involvement, although Apple might just be a rare exception.

Re: Apple Platform Security (Jan 2026) [pdf]

#204

Earlier quoted context omitted.

How does that matter? Apple is still seeing 20% of its profits from ads and Google is still tracking you through Apple’s browser and Apple is getting paid for it.

They pay to be the default, not the only possible search provider.

It was a direct listing at $250 and now the price is $179.

Compared to the S&P 500 which has gained around 75% since then

Re: Apple Platform Security (Jan 2026) [pdf]

#205

Earlier quoted context omitted.

I don't understand. That article (written in 2016) says that Apple will build unbreakable phones in the future. Now is the future. So it seems to imply that Apple phones today are unbreakable. Also, where does the article discuss "all of these protections"? (HSMs, rate limits, etc.)

> So it seems to imply that Apple phones today are unbreakable. Indeed. If you don't control the "unbreakable" security though, then the lock is not for your benefit. > where does the article discuss "all of these protections"? You could read the danged article, it's pretty clear about the vulnerability of proprietary mitigations. I hate quoting spoilers verbatim but here you go: The sharper you get, the more importa…

That quote is about building security vs not building security. It's about the government potentially ordering Apple to not build security. It's not about proprietary security vs non-proprietary.

Nothing in the article is saying that HSMs, rate limits, etc are weak.

Post reply on HN