Live data from Hacker News

iPhones 'disabled' if Apple detects third-party repairs

theguardian.com

281–290 of 363 posts

Re: iPhones 'disabled' if Apple detects third-party repairs

#282

Earlier quoted context omitted.

That may be true but it does not cost me anything at all to change the text so that it does not offend and in that sense it is an improvement. At the same time I see HN slide towards reddit just one little bit more with all the 'you insensitive clod' comments lately and that is sad too.

At the same time I see HN slide towards reddit just one little bit more with all the 'you insensitive clod' comments lately and that is sad too. If you don't want HN to slide that way, then I suggest you not give in and change it back. After all, I think offense is entirely in the mind of the beholder.

> After all, I think offense is entirely in the mind of the beholder.

Especially when the beholder is not himself or herself part of the group.

Re: iPhones 'disabled' if Apple detects third-party repairs

#283
I love the sentence: >He had to pay £270 for a replacement and is furious.

He was so furious that he bought a second iPhone which had the same fundamental design decisions and would fail in the same way if he got it repaired by a non-Apple repairer. No wonder Apple doesn't give a damn about this - everyone is just buying a new phone from them.

Re: iPhones 'disabled' if Apple detects third-party repairs

#284
post #225

Earlier quoted context omitted.

It doesn't have to be either or. Apple could provide a better fail over behavior for the home key, including a way for a consumer to validate the changed hardware. For instance: "IOS has detected a change in your Secure Home Key. Please contact apple secure support to confirm that your device is still secure!" add a 1-800 number and some security questions. Or automate it by requiring a login to your Apple account, e…

The bad guy can then walk the user through that security verification process, and the user is screwed. Think it through.

[deleted]

Re: iPhones 'disabled' if Apple detects third-party repairs

#285
post #107

Earlier quoted context omitted.

There's a lot of stuff that depends on the secure element - in fact the phone would be quite useless without it. In fact, when you first reboot your phone, even contacts cannot be accessed until you authenticate with your passcode to unlock the secure element. Incoming text messages only show the phone number. You're right, however - a Touch ID sensor that cannot be verified should not brick the phone. Apple should j…

The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement. Without knowing if your replacement is secure the change potentially compromises the security of the whole device. IMO bricking on touch ID issues is extreme, but maximises the security of the device.

> The issue is Apple cannot verify a secure touch ID replacement over a compromised touch ID replacement.

Couldn't they just ask the user? Use the backup password to authenticate.

If it's my device, I want to be the one who chooses what I trust.

Re: iPhones 'disabled' if Apple detects third-party repairs

#286
post #225

Earlier quoted context omitted.

It doesn't have to be either or. Apple could provide a better fail over behavior for the home key, including a way for a consumer to validate the changed hardware. For instance: "IOS has detected a change in your Secure Home Key. Please contact apple secure support to confirm that your device is still secure!" add a 1-800 number and some security questions. Or automate it by requiring a login to your Apple account, e…

The bad guy can then walk the user through that security verification process, and the user is screwed. Think it through.

Wouldn't touchID get disabled until the verification process was finished? They would need the user's password.

Re: iPhones 'disabled' if Apple detects third-party repairs

#287
post #117

Earlier quoted context omitted.

Using the word retard victimises a group that is already significantly marginalised while simultaneously not doing much to the intended victim. The word has a greater affect on unintended, innocent, victims than the intended target. If you're talking about IQ less than 70 use whatever is relevant in the country you're in. In the US this is usually intellectual disability (which is a subset of learning disability, whi…

> Using the word retard victimises a group that is already significantly marginalised while simultaneously not doing much to the intended victim. The word has a greater affect on unintended, innocent, victims than the intended target. That clearly isn't what the word means today. "Our son was having trouble in school and his counsellor suspected he might be retarded. We brought him to a retard house with a reputation…

I'm not sure if you are correct or not but you just blew my mind. This is an amazing comment.

Re: iPhones 'disabled' if Apple detects third-party repairs

#288
post #277

I posted this earlier today, but the current article (from bbc.co.uk) does a poor job covering the issue. In summary, Apple iOS uses a validation system to ensure Touch ID sensor is not maliciously replaced or modified. The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. This could…

> The Touch ID sensor has access to the iPhone Security Enclave, where fingerprint data is kept. A malicious sensor could, hypothetically, steal fingerprints from an iPhone user unknowingly. No, the CPU reads encrypted data from the sensor and sends them to the SE for decryption and analysis. See the PDF linked here by somebody. What a malicious sensor could do is store user's fingerprint for retrieval by unauthorize…

What a malicious sensor could do is store user's fingerprint for retrieval by unauthorized parties.

Of course, taking advantage of the exploit in question requires the phone to be stolen by an extremely sophisticated (if not state-level) bad guy, altered by installation of a malicious sensor that has never been documented to exist in the wild, then recovered by the owner, and then stolen again at a later date. All to acquire personal biometric data that could just as easily be obtained with a piece of Scotch tape.

A simple application of Occam's Razor suggests that Error 53 isn't a "security feature" at all, it's just Apple being a rent-seeking asshole.

Re: iPhones 'disabled' if Apple detects third-party repairs

#289

This is still not as bad as the newer laptops in which TPM is soldered onto motherboard and the OS won't boot if it's damaged. You can't even get it repaired, even by the manufacturer without getting a brand new motherboard. Hardware level security is important, but one must know that whenever you involve hardware into the equation you must allow for collateral damage. Trusting trust is hard. You can't expect the ver…

How often do you damage a chip on your motherboard? Or need to replace non-capacitor parts on it? This is such a problem because it's stuck to the screen, and people need to replace screens all the time.

This only affects the home button. If you replace the screen and keep your original home button, there is no issue.

I co-own a repair shop. We have known about this for a while. We won't replace home buttons for this reason. But we replace hundreds of screens a month with no issues.

Re: iPhones 'disabled' if Apple detects third-party repairs

#290
post #225

Earlier quoted context omitted.

It doesn't have to be either or. Apple could provide a better fail over behavior for the home key, including a way for a consumer to validate the changed hardware. For instance: "IOS has detected a change in your Secure Home Key. Please contact apple secure support to confirm that your device is still secure!" add a 1-800 number and some security questions. Or automate it by requiring a login to your Apple account, e…

The bad guy can then walk the user through that security verification process, and the user is screwed. Think it through.

If you're targeted by a "bad guy" at this level of play, you have much bigger problems than an untrustworthy fingerprint sensor.
Post reply on HN