Live data from Hacker News

Planned obsolescence: Apple attacked for the “serialization” of its spare parts

lemonde.fr

51–60 of 137 posts

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#51

Interesting bit (translated) : > A practice contrary to the principle of the anti-waste law > In France, serialization is theoretically prohibited, according to Alexandre Isaac. Since the entry into force of the anti-waste law in November 2021, the consumer code mentions that "any technique, including software, by which a marketer aims to make it impossible to repair or recondition a device or to limit the restoratio…

Any technique with makes it impossible to repair or recondition by definition also makes it more difficult to pwn. See https://news.ycombinator.com/item?id=35954422 for one example.

Huh? What about a glued battery in a rootable phone? How did the battery help?

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#52
post #10

I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...

There are simple ways to allow hardware changes without losing security. One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware. This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe…

One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware.

I don't think most users are capable of auditing their generic hardware to be sure it is free of backdoors.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#53
post #5

Wonder how Renault is handling it. All of their spare electronic parts have vin locks that only the dealer is supposed to be able to modify.

[flagged]

Sorry to the Renault folks - I was just trying to highlight an egregious bit of whataboutism. I failed!

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#54

Earlier quoted context omitted.

When the camera fails you don't exactly have many options because you can't really order the official parts. Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?

> Why would the camera be of consequence, though? Insisting on approved camera avoids making it easier for bad actors to stealthily capture's a victim's biometrics and then use a third party "camera" to replay that information and unlock the victim's phone without them being present.

Arguably if you anticipate someone targeting you who is capable of attacks this sophisticated, you are very far outside the norm and should probably have an entirely different relationship with your devices than most people.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#55

What a shitty company. Time and time again they shaft consumers yet people buy into the ecosystem. Marketing works unfortunately.

Perhaps, but their policies and support for old hardware far exceeds anything you see in the Android world. But you point out THIS "shitty company" while not throwing your gaze towards all the other "shitty companies" like Samsung, or Google, or Sony, or Microsoft. Could it be that your disdain for the type of people that buy Apple products just rings through? The tried and true "them" vs "me" attitude. Personally, I…

The problem is Apple pisses on your head and tells you is clean water from a natural spring that is helping save the environment.

Samsung does shitty things, but they are open and honest about it.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#56
post #10

I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...

There are simple ways to allow hardware changes without losing security. One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware. This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe…

I don't think this is quite that simple, because one user's authority could potential trump everyone else's in a company or group, once a vulnerable device infiltrates the system. Having trusted authorities works well when everyone has to rely on the security of the device. Once you can bypass that authority you effectively have a cheap MITM attack.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#57
post #7

Interesting bit (translated) : > A practice contrary to the principle of the anti-waste law > In France, serialization is theoretically prohibited, according to Alexandre Isaac. Since the entry into force of the anti-waste law in November 2021, the consumer code mentions that "any technique, including software, by which a marketer aims to make it impossible to repair or recondition a device or to limit the restoratio…

Huh, I wonder if a lawyer could win the argument that printer companies who restrict 3rd-party cartridges violate this law... Next on eBay: "Buy French ink for HP printers, use VPN to download the French drivers!". "PC CHARGER LA LETTRE?! WTF does that mean?"

I think it's possible and it would be a good thing. Although I wonder...I use a slightly older brother printer (prob. 4-5 years old) with 3rd-party cartridges without problems. Is it different with other printers?

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#58
post #10

I don't mean to be the devil's advocate, but I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks...

> I'm pretty sure that disabling Face ID when replacing the camera with a generic one is primarily a measure to thwart potential hardware-based attacks.

I'm pretty sure it's not. The number of people which would be targeted by this is too small to justify the additional costs. The vast majority of people which would be targeted by this are pretty much screwed anyhow since the adversary already has physical access. It's much more likely a brand protection scheme to ensure there are fewer items out there with sub-par hardware.

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#59
post #7

Interesting bit (translated) : > A practice contrary to the principle of the anti-waste law > In France, serialization is theoretically prohibited, according to Alexandre Isaac. Since the entry into force of the anti-waste law in November 2021, the consumer code mentions that "any technique, including software, by which a marketer aims to make it impossible to repair or recondition a device or to limit the restoratio…

Huh, I wonder if a lawyer could win the argument that printer companies who restrict 3rd-party cartridges violate this law... Next on eBay: "Buy French ink for HP printers, use VPN to download the French drivers!". "PC CHARGER LA LETTRE?! WTF does that mean?"

There has already been a class action against HP[0] ending with a settlement and reimbursement of some customers, but that's not very conclusive.

It seems clear to me though that they violate this law, we just lack enforcement.

[0]https://www.bleepingcomputer.com/news/hardware/hp-will-pay-c...

Re: Planned obsolescence: Apple attacked for the “serialization” of its spare parts

#60
post #56

Earlier quoted context omitted.

There are simple ways to allow hardware changes without losing security. One straightforward idea: Once the phone is unlocked (e.g. by pin code) allow the user to authorize the new hardware. This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe…

I don't think this is quite that simple, because one user's authority could potential trump everyone else's in a company or group, once a vulnerable device infiltrates the system. Having trusted authorities works well when everyone has to rely on the security of the device. Once you can bypass that authority you effectively have a cheap MITM attack.

this is still no excuse. You could just disable 3rd party replacement parts by group-wise policy, maybe even enabled as default.
Post reply on HN