Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

61–70 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#61

[flagged]

You can enable Advanced Data Protection to address that issue with iMessages. Giving users an option between both paths is usually best. Most users care a lot more that they can’t restore a usable backup of their messages than they do that their messages are unreadable by the company storing them. I used to work at a company where our products were built around encryption. Users here on HN are not the norm. You can’t…

> Apple can still read any message you exchange with practically anyone through their iCloud backups, since they are overwhelmingly likely to have backups enabled and overwhelmingly unlikely to have proactively enabled the non-default "Advanced Data Protection" feature.

> They could have implemented iMessage to not backup messages from people who enabled ADP, but they didn't. They won't even inform you when your conversation partner has uploaded your messages to Apple's servers in a form that Apple can read.

> Android's equivalent cloud backup service has been properly end-to-end encrypted by default for many years. Meaning that you don't need to convince the whole world to turn on an optional feature before your backups can be fully protected.

> Apple's stated reason for not enabling end-to-end encryption on iCloud backups by default is that it would cause data loss when users lose their devices. But Google's implementation avoids this problem. Furthermore, Apple does do end-to-end encryption by default on other critical information that would be painful to lose, such as your account passwords stored in Keychain. So that excuse doesn't seem to hold water.

Re: Apple Platform Security (Jan 2026) [pdf]

#62
post #33

Earlier quoted context omitted.

That people fall for this corporate BS while Tim Cook is giving gold bars to Trump and dining and dancing with him When people are being murdered on the streets by ice is just amazing to me.

Well that’s what Americans voted for. So I don’t think anyone cares that every CEO (definitely not just Tim Cook) is schmoozing with Trump.

Funny that you think that people have free will under this zombie social media mind controlled Internet world we’re living in.

Besides Trump‘s approval ratings are worse than ever so I don’t think people really got what they wanted, they got who they voted for not what they voted for.

Re: Apple Platform Security (Jan 2026) [pdf]

#63

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

I claim bs at this whole apple privacy thing, nothing but propaganda.

Two years ago I was locked out of my MacBook pro.

Then I just booted in some recovery mode and just..reset the password!?

Sure macos logged me off from (most) apps and website, but every single file was there unencrypted!

I swear people that keep boasting that whole apple privacy thing have absolutely no clue what they are talking about, nothing short of tech illiterate charlatans. But God the propaganda works.

And don't start me on iMessage.

Re: Apple Platform Security (Jan 2026) [pdf]

#64

[flagged]

What is "Google Messages"? I can't count the number of articles people have written over time about how many first-party messaging apps Google themselves have put out (and then put down), not to mention what messaging apps get shoveled on by third-party android integrators. > the main reason a message wouldn't be properly end-to-end encrypted in Google's Messages app is when communicating with an iPhone user, because…

HSMs are designed to protect encryption keys from everyone including the manufacturer. Signal trusts them for their encryption features. It's the best security possible for E2EE backups with passcode recovery, and Apple does it too for the subset of data that they do real E2EE backups on, like Keychain passwords. Characterizing using an HSM to implement E2EE securely as "not any better than" just giving up on E2EE for messages backups is ridiculous.

Re: Apple Platform Security (Jan 2026) [pdf]

#65
It sucks that Apple decided to monitize iPhone the way they have, by controlling the owners ability to install software of their choosing. Ignoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound, but it's hard to take them serious regarding privacy arguments.

Our choices are either (A) an OS monitized by tracking user interaction and activity, or (B) monitized by owning the basic act of installing software on the device, both of these options suck and I struggle to give up the more open option for one that might be more secure.

Re: Apple Platform Security (Jan 2026) [pdf]

#66

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

I claim bs at this whole apple privacy thing, nothing but propaganda. Two years ago I was locked out of my MacBook pro. Then I just booted in some recovery mode and just..reset the password!? Sure macos logged me off from (most) apps and website, but every single file was there unencrypted! I swear people that keep boasting that whole apple privacy thing have absolutely no clue what they are talking about, nothing sh…

You chose not to enable FileVault during setup. Probably because you were worried about being locked out and wanted an easy way to reset the password.

Would you prefer that Apple did not give you the option to disable the security feature you disabled during setup?

Re: Apple Platform Security (Jan 2026) [pdf]

#67
post #62

Earlier quoted context omitted.

Well that’s what Americans voted for. So I don’t think anyone cares that every CEO (definitely not just Tim Cook) is schmoozing with Trump.

Funny that you think that people have free will under this zombie social media mind controlled Internet world we’re living in. Besides Trump‘s approval ratings are worse than ever so I don’t think people really got what they wanted, they got who they voted for not what they voted for.

The Twinkie defense is alive and well, I see.

Re: Apple Platform Security (Jan 2026) [pdf]

#68

It sucks that Apple decided to monitize iPhone the way they have, by controlling the owners ability to install software of their choosing. Ignoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound, but it's hard to take them serious regarding pr…

Ignoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound,

I wouldn't say they are sound. First, macOS provides the freedom to install your own applications (ok, they need to be signed and notarized if the quarantine attribute is set) and it's not the case that the Mac has mass malware infestations. Second, the App Store is full of scams, so App Store - safe, external - unsafe is a false dichotomy.

Apple uses these arguments, but of course the real reason is that they want to continue to keep 30% of every transaction made on an iPhone or iPad. This is why they have responded to the DMA with a lot of malicious compliance that makes it nearly impossible to run an alt-store financially.

(Despite my qualms about not being able to install apps outside the app store, I do think they are doing a lot of good work of making the platform more secure.)

Re: Apple Platform Security (Jan 2026) [pdf]

#69
post #58

Earlier quoted context omitted.

Apple is an ad company now though

Apple sells some ads yes. But it’s a tiny fraction of their revenue. Would Google or Meta go bankrupt if they stopped selling ads? Yes. Apple wouldn’t.

What does whether they’d go bankrupt or not have to do with whether they’re an ad company?

They sell third party ads: companies unaffiliated with Apple pay Apple to advertise on Apple platforms.

They’re an ad company. Just because it’s currently a small slice of their total revenue doesn’t make it untrue.

Re: Apple Platform Security (Jan 2026) [pdf]

#70

Earlier quoted context omitted.

Well that’s what Americans voted for. So I don’t think anyone cares that every CEO (definitely not just Tim Cook) is schmoozing with Trump.

> Well that’s what Americans voted for. Americans are not one person. > So I don’t think anyone cares Clearly they do. > every CEO (definitely not just Tim Cook) is schmoozing with Trump. Tim Cook was (supposedly) principled. I guess it's hard to pretend that you care about privacy or human rights while eating dinner next to bin Salman.

> Tim Cook was (supposedly) principled. I guess it's hard to pretend that you care about privacy or human rights while eating dinner next to bin Salman.

I guess if you thought he had principles then yeah that could be disappointing. Personally I've never tried to moralize corporations though, I just assume the only principle that every company and CEO operates by is whatever increases the stock price.

Post reply on HN