Interesting bit (translated) : > A practice contrary to the principle of the anti-waste law > In France, serialization is theoretically prohibited, according to Alexandre Isaac. Since the entry into force of the anti-waste law in November 2021, the consumer code mentions that "any technique, including software, by which a marketer aims to make it impossible to repair or recondition a device or to limit the restoratio…
Any technique with makes it impossible to repair or recondition by definition also makes it more difficult to pwn. See https://news.ycombinator.com/item?id=35954422 for one example.
Planned obsolescence: Apple attacked for the “serialization” of its spare parts
51–60 of 137 posts
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#52I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...
There are simple ways to allow hardware changes without losing security. One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware. This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe…
I don't think most users are capable of auditing their generic hardware to be sure it is free of backdoors.
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#53Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#54Earlier quoted context omitted.
When the camera fails you don't exactly have many options because you can't really order the official parts. Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?
> Why would the camera be of consequence, though? Insisting on approved camera avoids making it easier for bad actors to stealthily capture's a victim's biometrics and then use a third party "camera" to replay that information and unlock the victim's phone without them being present.
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#55What a shitty company. Time and time again they shaft consumers yet people buy into the ecosystem. Marketing works unfortunately.
Perhaps, but their policies and support for old hardware far exceeds anything you see in the Android world. But you point out THIS "shitty company" while not throwing your gaze towards all the other "shitty companies" like Samsung, or Google, or Sony, or Microsoft. Could it be that your disdain for the type of people that buy Apple products just rings through? The tried and true "them" vs "me" attitude. Personally, I…
Samsung does shitty things, but they are open and honest about it.
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#56I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...
There are simple ways to allow hardware changes without losing security. One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware. This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe…
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#57Interesting bit (translated) : > A practice contrary to the principle of the anti-waste law > In France, serialization is theoretically prohibited, according to Alexandre Isaac. Since the entry into force of the anti-waste law in November 2021, the consumer code mentions that "any technique, including software, by which a marketer aims to make it impossible to repair or recondition a device or to limit the restoratio…
Huh, I wonder if a lawyer could win the argument that printer companies who restrict 3rd-party cartridges violate this law... Next on eBay: "Buy French ink for HP printers, use VPN to download the French drivers!". "PC CHARGER LA LETTRE?! WTF does that mean?"
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#58I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...
I'm pretty sure it's not. The number of people which would be targeted by this is too small to justify the additional costs. The vast majority of people which would be targeted by this are pretty much screwed anyhow since the adversary already has physical access. It's much more likely a brand protection scheme to ensure there are fewer items out there with sub-par hardware.
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#59Interesting bit (translated) : > A practice contrary to the principle of the anti-waste law > In France, serialization is theoretically prohibited, according to Alexandre Isaac. Since the entry into force of the anti-waste law in November 2021, the consumer code mentions that "any technique, including software, by which a marketer aims to make it impossible to repair or recondition a device or to limit the restoratio…
Huh, I wonder if a lawyer could win the argument that printer companies who restrict 3rd-party cartridges violate this law... Next on eBay: "Buy French ink for HP printers, use VPN to download the French drivers!". "PC CHARGER LA LETTRE?! WTF does that mean?"
It seems clear to me though that they violate this law, we just lack enforcement.
[0]https://www.bleepingcomputer.com/news/hardware/hp-will-pay-c...
Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts
#60Earlier quoted context omitted.
There are simple ways to allow hardware changes without losing security. One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware. This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe…
I don't think this is quite that simple, because one user's authority could potential trump everyone else's in a company or group, once a vulnerable device infiltrates the system. Having trusted authorities works well when everyone has to rely on the security of the device. Once you can bypass that authority you effectively have a cheap MITM attack.