Live data from Hacker News

We are retroactively dropping the iPhone’s repairability score

ifixit.com

271–280 of 367 posts

Re: We are retroactively dropping the iPhone’s repairability score

#271
post #11

There is also another issue why Apple is restricting "part harvesting": theft. iCloud locks or Samsung's KNOX lock entered the field because the manufacturers were pretty pissed that customers using their devices in public became a target for "enterprising" robbers who'd factory-wipe the devices and flip them to a pawn shop or second-hand store in a matter of half an hour. When people are afraid to use your products…

While anti-consumerist practices such as this authentication mechanism sometimes accidentally protect the consumer, it is not the reason why companies do it. If it were, they would also allow you to say “yes this replacement is desired.” Similarly, if it was about security and preventing backdoored parts, they could allow you to authorize the replacement. But no, it is of course about money grabbing, and then the con…

The solution for a phone is put a vin on the display and other valuable parts and upload those to the carrier/manufacturer.

Imagine how happy someone would be if they had their display replaced with a stolen one and next thing they know their phone is both bricked and of no value even for parts.

Re: We are retroactively dropping the iPhone’s repairability score

#272

Earlier quoted context omitted.

> I get the iFixit point as well but if I have a 1500€ phone, I don't want to think about it being stolen, when I am on vacation, because someone needs some parts (oh the human trafficing/organ harvesting similarity...) Do you think thieves are that descending? I know someone whos iPhone 14 was stolen in London. If this helped protect against theft, then why did they steal the phone anyway?

I’m highly dubious of anyone claiming this reduces crime. Things being easy to steal and sell aren’t the _cause_ of crime, they’re a symptom. If someone has felt the need to resort to a life of crime for whatever reason, how is lowering their “salary” (so to speak) going to reduce crime? Surely they now need to steal more phones to make up the difference? I guess you could argue they might commit a different crime in…

Maybe people resort to a life of crime because it makes them money and they like money, not because they have no other option. People readily accept that rich people do morally wrong things (like exploit their employees etc) for more money. So why assume that the only reason people in general would do morally wrong things is because they need to to feed their family?

Re: We are retroactively dropping the iPhone’s repairability score

#273
post #268
post #7

Reminds me of a Louis Rossman video [0] where he shares his frustration with Apple's independent repair shop program. He says that to get access to genuine Apple parts (and the ability to pair them to devices), Apple requires that his shop not be able to do certain things like fix a broken angle detection sensor. It's utter BS, and the lip service companies are paying to right-to-repair bills in state legislatures ho…

> He says that to get access to genuine Apple parts (and the ability to pair them to devices), Apple requires that his shop not be able to do certain things like fix a broken angle detection sensor. is this a loaded framing for the proposition that "you can't perform component-level repairs if you're presenting yourself as an apple authorized service center"? because the point of apple authorized service centers is y…

But you do know that apple authorized service center service is often worse because instead of reflowing components they go for stuffing your device with shoe rubber to push chips with defective connections tighter to the pcb? https://www.youtube.com/watch?v=XaGHcBZjmWA

Re: We are retroactively dropping the iPhone’s repairability score

#274

Earlier quoted context omitted.

These restrictions also reduce pwnage. Zero trust has to be end-to-end, software and hardware.

If an actor with that sort of capability has physical access to your device for long enough to replace a part in it with a custom one, you are pwned pretty much no matter what you do at that point. They could just as well stick in a keylogger for touch inputs and know all your passwords.

well, that's why touch id/face id are a secure enclave and have largely replaced passwords.

but philosophically there's no reason the digitizer can't be a secure enclave too, and sign a message authenticating that it's really the digitizer that you think it is. unless you can force it to leak the secret or you can break RSA, it's as secure as any other cryptosystem.

remote attestation does work and I don't really get why people continue to assert that it doesn't. root-of-trust and remote attestation are solved problems, and detecting component swapouts (and other "hostile component" attacks) are one of the primary use-cases for these systems.

Re: We are retroactively dropping the iPhone’s repairability score

#275

Earlier quoted context omitted.

> I get the iFixit point as well but if I have a 1500€ phone, I don't want to think about it being stolen, when I am on vacation, because someone needs some parts (oh the human trafficing/organ harvesting similarity...) Do you think thieves are that descending? I know someone whos iPhone 14 was stolen in London. If this helped protect against theft, then why did they steal the phone anyway?

I’m highly dubious of anyone claiming this reduces crime. Things being easy to steal and sell aren’t the _cause_ of crime, they’re a symptom. If someone has felt the need to resort to a life of crime for whatever reason, how is lowering their “salary” (so to speak) going to reduce crime? Surely they now need to steal more phones to make up the difference? I guess you could argue they might commit a different crime in…

> Surely they now need to steal more phones to make up the difference?

Not necessarily. If they can't make enough money from stealing iPhones, they may quit and go into management.

Re: We are retroactively dropping the iPhone’s repairability score

#276
post #273
post #268

Earlier quoted context omitted.

> He says that to get access to genuine Apple parts (and the ability to pair them to devices), Apple requires that his shop not be able to do certain things like fix a broken angle detection sensor. is this a loaded framing for the proposition that "you can't perform component-level repairs if you're presenting yourself as an apple authorized service center"? because the point of apple authorized service centers is y…

But you do know that apple authorized service center service is often worse because instead of reflowing components they go for stuffing your device with shoe rubber to push chips with defective connections tighter to the pcb? https://www.youtube.com/watch?v=XaGHcBZjmWA

> But you do know that apple authorized service center service is often worse

it seems incredibly dishonest to frame that as being something that happens often. can you provide statistics about how many apple authorized repairs come back with shoe rubber inside?

like if I go to a best buy for apple authorized service, you're telling me they have a big box of shoe rubber in the back they're using for repairs? Doubt.

Re: We are retroactively dropping the iPhone’s repairability score

#277

Earlier quoted context omitted.

> If this helped protect against theft, then why did they steal the phone anyway? They are plenty of stories on Reddit and TikTok where the stolen phone ends up in China, and then the owner is phished into disabling iCloud so that the phone could be wiped. If not the sold is phone for parts. To me the very fact that you need an entire phishing ring to make stealing iPhones profitable means that there is some cost tha…

How do the thieves get the contact details of the person whose phone they stole to fish them? And why did they steal the iPhone I mentioned without having the contact details of the person?

https://krebsonsecurity.com/2023/05/re-victimization-from-po...

Granted, that's dealing with stolen iPhones getting sold and an entirely set of other problems. You'll note that 26.8% of them were either unlocked, easily guessable, or in one instance had the credentials there (compare shoulder surfing before stealing the phone).

> Of phones they won at auction (at an average of $18 per phone), the researchers found 49 had no PIN or passcode; they were able to guess an additional 11 of the PINs by using the top-40 most popular PIN or swipe patterns.

Re: We are retroactively dropping the iPhone’s repairability score

#278
post #35
post #19

Earlier quoted context omitted.

> If it were, they would also allow you to say “yes this replacement is desired.” How does that not completely bypass any of the reasons for wanting to do this? And it is “anti-consumerist” to make my property a less desirable target for theft?

> How does that not completely bypass any of the reasons for wanting to do this? Do it from your iCloud account. Presumably thieves will not hold you at gun point to log in to iCloud and allow pairing of your phone's components to a ready recipient iPhone

Truly, they could put up any roadblock---a time delay, requiring a phone call, MFA up one side and down the other---and it would be a much better look for them.

I don't buy the anti-theft angle that can only be solved by buying a brand-new genuine part direct from Apple.

Re: We are retroactively dropping the iPhone’s repairability score

#279
I tried to recall how many instances of theft vs damage there were in my social circle and the ratio is at least 10:1, with damage being the higher number.

I had one case of spontaneous malfunction, one bricking via repeated high humidity environment and one bonk against bare concrete, which resulted in the screen needing to be replaced so I have to ask: how bad is theft in your corner of the world?

Re: We are retroactively dropping the iPhone’s repairability score

#280

Earlier quoted context omitted.

If parts weren't so unnecessarily difficult to get in the first part, stealing phones for parts wouldn't be a thing. Apple created this problem, they don't get to get credit for "fixing" it in a way that harms consumers.

Stealing phones for parts is only a “thing” because any U.S. carrier would still block a stolen IMEI. If you steal a car, for example, you can use it to for its primary purpose which is to drive. If you steal a phone, you can only sell it for parts.

yeah, used cars apparently mostly get exported to ghana and some other countries that have extremely loose customs who don't care about stolen goods moving in.

https://www.cbc.ca/news/world/auto-theft-canada-1.6953242

if you could re-use a phone, people would just factory reset the phone after stealing it, and people did it. then apple locked that down. then people started stripping the phone for parts instead, and apple started serializing parts. Etc.

Post reply on HN