Live data from Hacker News

iOS 10 Security White Paper [pdf]

apple.com

81–90 of 99 posts

Re: iOS 10 Security White Paper [pdf]

#81
post #28

Earlier quoted context omitted.

If you go with the Pixel, which is basically the iPhone of Android, you'll get a similar to iOS update experience.

You are mistaken. The pixel has the same 2 year support length of the Nexus series. iPhones are typically supported for 4 years.

I think you get something like 3 years, not as good as iOS, but by the 4th year, you only get a very crippled version of the newest iOS anyways.

Re: iOS 10 Security White Paper [pdf]

#82
post #30

Earlier quoted context omitted.

How so? You mean from user access and usability standpoint? I know I certainly wish there was a Keychain access app like on macOS available for iOS rather than only being able to access passwords via Safari settings.

Probably referring to the key distribution process, where to enable iCloud Keychain you have to approve from another device. It's a sound design in theory - the keys are only stored locally, so even Apple can't access them - but I've personally experienced issues several times where the approval notification wouldn't show up on my other devices, or the UI was in an inconsistent state, etc.

Thanks for saying what I should have said. I have devices that refuse to apparently sync the keychain. One device has the right key for something but the other does not, and there is no indication of why.

Re: iOS 10 Security White Paper [pdf]

#83
post #72

Earlier quoted context omitted.

Signal won't run without access to your contacts (at least on iOS). Whether that's considered "unreasonable" is being actively argued on Twitter at the moment...

I dont often join in, but the fact this doesn't work without contacts seems alarming. Any guess as to why?

https://www.jwz.org/blog/2017/03/signal-leaks-your-phone-num...

Re: iOS 10 Security White Paper [pdf]

#84

Earlier quoted context omitted.

You picked a bad example, as Uber car ordering does work with location services disabled. Any better examples come to mind of apps that refuse to run unless hey have an unreasonable feature granted?

Perhaps this has changed recently, but the last time I tried to use Uber without "allow location access even when not using the app," I was unable to call a ride. Instead, I was given instructions on how to enable that setting.

I've used it constantly without location services since the day they first requested the feature. When I open it, the splash screen has 2 options - Enable Location Services and Enter Pickup Address. Perhaps you missed the second option?

Re: iOS 10 Security White Paper [pdf]

#85
post #68

Earlier quoted context omitted.

You picked a bad example, as Uber car ordering does work with location services disabled. Any better examples come to mind of apps that refuse to run unless hey have an unreasonable feature granted?

On Android, GM's Maven car-sharing app (similar to ZipCar) does not run unless all permissions are granted, which include the ability to manage phone calls. The Chinese WeChat messenger also refuses to run unless location access is granted, even though messaging apps do not depend on location to work. This type of behavior makes fine-grained permissions systems not very useful. It should be prohibited by the Apple Ap…

Agreed - I don't think this type of thing should be allowed. I'd be very happy if Apple required all apps that use locations services to offer the 'when app is running' option - seems perfectly reasonable to me.

Re: iOS 10 Security White Paper [pdf]

#86
post #13

Earlier quoted context omitted.

Mmm? Secure enclave is present on most Android devices and is mandatory since Android 6.0. (It's just called something else.) Historically Android has been lagging behind a bit from iOS devices when it comes to security, but Pixels and their software have a very similar security model and design (with some exceptions - less granularity with file-based encryption and some other mostly minor details). Non Google device…

My OnePlus 3T uses dm-verity as well, sadly. Displaying an "unlocked" badge during boot is acceptable. Actually pausing boot for 10 seconds every time is not by a long shot.

That's good to know when recommending devices.

Re: iOS 10 Security White Paper [pdf]

#87
post #61

Earlier quoted context omitted.

What purpose do you want to access raw NAND? If you are okay with just a basic low speed connection to read the NAND, there is a fairly standardized async protocol which you could achieve with a dozen GPIO pins. You could also use a FPGA or and NAND flash programmer (like of like the old EPROM programmers) However beyond this, you need to know a bit more information to interpret this raw data. This includes any data…

I just want it to show up in the OS as MTD so e.g. I could use it with JFFS2 like OpenWrt does on routers. But on a desktop PC.

In that case, I'm not familiar of any practical way to to interface to the NAND flash except that which comes with some embedded controllers boards. But let me add that even if you interface to the NAND, you still need to solve some of the things I mentioned above if the NAND is any technology node below 20nm or so. If you don't do it right, even with decent error correction you will get a high bit error rate.

Re: iOS 10 Security White Paper [pdf]

#88

Earlier quoted context omitted.

I dont often join in, but the fact this doesn't work without contacts seems alarming. Any guess as to why?

https://www.jwz.org/blog/2017/03/signal-leaks-your-phone-num...

Be careful about jwz links on HN. He detects the referrer and redirects to a prank image.
Post reply on HN