Live data from Hacker News

Apple update looks like Czech mate for locked-out iPhone user

theregister.com

231–237 of 237 posts

Re: Apple update looks like Czech mate for locked-out iPhone user

#231

Earlier quoted context omitted.

Sure, but that'd be a waste. Part of the reason e.g. Cellebrite is obsessive about not telling people many specifics about their product capabilities outside of NDA is that Apple is quite serious about trying to fix these things, and "we can crack every iPhone before the 14" probably tells them a fair bit about what might have a flaw. Tools like that lose a lot of value if anyone paying enough attention can infer the…

There is a difference in targeted software supply attacks vs. weakening encryption for everyone by introducing a master key. Apple would be required to cooperate by US law, it may never become public either. But as I said, Apple doesn't have to know, or "know". This feature inherently compromises security. Contrary to device encryption, OS update security depends on a single key held by Apple (rather several devOps g…

None of those articles are inconsistent with the claim that Apple cares about security, though?

"We can be legally compelled to give up data we have" and "we thought letting people have custom kernel modules was a bigger threat" are not particularly incompatible with "we design things so we don't have keys to your data we can be compelled to give up" and valuing people's security. (I am not a fan of the latter, to be clear, but there are reasonable reasons you could argue for it.)

But yes, I would probably, at the moment, bet that if the NSA can sign a custom iOS build on consumer hardware, Apple doesn't know about how, both because that's a very hard secret to keep, and because you'd see a massive uptick in people avoiding Apple devices in governments that might be of interest to US intelligence if even a rumor of that got out.

Re: Apple update looks like Czech mate for locked-out iPhone user

#232
post #199
post #175

Earlier quoted context omitted.

Not allowing downgrades is the biggest contributor to smartphones becoming e-waste. Apple should be forced to do this by law, but only after they discontinue software support. If they're willing to continue making small, incremental patches when necessary ( such as to fix this obvious bug ) then it's fine that they can still block downgrades. But at EOL? They should be legally required to allow old software to be ins…

> Not allowing downgrades is the biggest contributor to smartphones becoming e-waste. Citation needed. My guess is the biggest contributor to smartphones becoming e-waste is gravity.

Any phone that gets more support than it should have, such that the only OS you can install is too slow to make using the device enjoyable, makes it more likely for the device owner to throw that device out, and then it becomes e-waste.

It also harms software preservation. Sure, we have IPSWs for every single public build of iOS that exists (and if you dig around, probably a ton of betas and even internal builds). But you can't really do anything with any of them once you get to the point in the iOS product line where things were sufficiently hardened

Re: Apple update looks like Czech mate for locked-out iPhone user

#233

Earlier quoted context omitted.

There is a difference in targeted software supply attacks vs. weakening encryption for everyone by introducing a master key. Apple would be required to cooperate by US law, it may never become public either. But as I said, Apple doesn't have to know, or "know". This feature inherently compromises security. Contrary to device encryption, OS update security depends on a single key held by Apple (rather several devOps g…

None of those articles are inconsistent with the claim that Apple cares about security, though? "We can be legally compelled to give up data we have" and "we thought letting people have custom kernel modules was a bigger threat" are not particularly incompatible with "we design things so we don't have keys to your data we can be compelled to give up" and valuing people's security. (I am not a fan of the latter, to be…

> None of those articles are inconsistent with the claim that Apple cares about security, though?

You are moving the goalpost.

> "We can be legally compelled to give up data we have" and "we thought letting people have custom kernel modules was a bigger threat" are not particularly incompatible with "we design things so we don't have keys to your data we can be compelled to give up" and valuing people's security. (I am not a fan of the latter, to be clear, but there are reasonable reasons you could argue for it.)

They do have the signing keys your iPhone will gladly accept to circumvent encryption, which is the argument.

Re: Apple update looks like Czech mate for locked-out iPhone user

#234

Earlier quoted context omitted.

None of those articles are inconsistent with the claim that Apple cares about security, though? "We can be legally compelled to give up data we have" and "we thought letting people have custom kernel modules was a bigger threat" are not particularly incompatible with "we design things so we don't have keys to your data we can be compelled to give up" and valuing people's security. (I am not a fan of the latter, to be…

> None of those articles are inconsistent with the claim that Apple cares about security, though? You are moving the goalpost. > "We can be legally compelled to give up data we have" and "we thought letting people have custom kernel modules was a bigger threat" are not particularly incompatible with "we design things so we don't have keys to your data we can be compelled to give up" and valuing people's security. (I…

> You are moving the goalpost.

I'm not the one moving the goalpost; my argument was that Apple's incentives are not in favor of them permitting even the appearance that they might allow that kind of compromise, your argument with that wall of articles appeared to be that Apple has a history of making decisions inconsistent with that, which I disputed. If that wasn't your intended argument, you might wish to be more explicit than a wall of links and "As if Apple users would care...".

> They do have the signing keys your iPhone will gladly accept to circumvent encryption, which is the argument.

Yes, and my argument is that the plumbing for either multiple release signing keys, one of which is never seen in the wild, or to avoid a second "iOS 13.1.5" or whatever with different build information showing up in various telemetry that would leak this existing, is very difficult to have built without far too many people who would spread rumors about it coming about, and even that rumor would be a problem.

So the most plausible thing, to me, would be that if such a capability exists, it's a "nuclear option" for whoever holds it to only use in a circumstance where it's so important they don't mind potentially never being able to use it again, whether that's because it's an exploit chain that will be fixed or because it's been coerced out of the target company and they will probably be compelled to fix it if it gets out.

Re: Apple update looks like Czech mate for locked-out iPhone user

#235

after Apple removed a character from its Czech keyboard I wonder what the thought process (or perhaps lack thereof) at Apple was. Did no one of the likely-somewhat-large team who did that think "wait, this could lock out our users who may have used that character"? In the immortal words of Linus Torvalds: "WE DO NOT BREAK USERSPACE!" Now one of the ways in might be those companies who claim to be able to break iPhone…

Sound like it’s not about removal from keyboard but rather ability to enter standalone?

It’s a combining accent character. It’s used to alter other characters (e.g. “c” to “č”). It doesn’t make sense to use it standalone.

Apple probably fixed a bug and https://xkcd.com/1172/ followed.

Re: Apple update looks like Czech mate for locked-out iPhone user

#236

As a non-English speaker I can really relate to this. I think the real mistake was Apple allowing to enter a non-ASCII password in the first place. E.g. on macOS the password fields have been locked to English character set, and I'm not sure why it changed on iOS.

But why should non-English speaking users be forced to use an ASCII password if the rest of the OS supports their language just fine?

It wouldn’t occur to a Czech speaker to use caron standalone - it’s not an alphabet character on its own. It’s a combining Unicode code point.

Re: Apple update looks like Czech mate for locked-out iPhone user

#237
post #44
post #27

Earlier quoted context omitted.

You can use emojis as passwords, do you think that's a good idea? They work now, there's a good chance that they won't be the same forever. See what happened to the family emojis

Did the underlying bits (hex/oct/… or whatever representation) actually change or just the visuals?

There's no way to enter the emoji "male adult female adult male child female child" but only "two adults two children". So it's kind of both.

It's like they realized that emojis really shouldn't need to deal with color and gender.

Post reply on HN