Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

81–90 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#81

Given that A19 + M5 processors with MIE (EMTE) were only recently introduced, I wonder how extensively MacOS/iOS make use of the hardware features. Is it something that's going to take several years to see the benefit, or does MIE provide thorough protection today?

I was just watching a video on this yesterday: https://www.youtube.com/watch?v=5McB6-2r-ds

Apple’s implementation of MTE is relatively limited in scope compared to GrapheneOS (and even stock Android with advanced security enabled) as it’s hardware intensive and degrades performance. I imagine once things get fast enough we could see synchronous MTE enabled everywhere.

It is curious at the moment though that enabling something like Lockdown Mode doesn’t force MTE everywhere, which imo it should. I think the people who are willing to accept the compromises of enabling that would likely also be willing to tolerate the app crashes, worse performance etc that would come with globally enabled MTE.

Re: Apple Platform Security (Jan 2026) [pdf]

#82

Earlier quoted context omitted.

If Pegasus can break the iOS security model, there’s no reason to think it politely respects Lockdown Mode. It’s basically an admission the model failed, with features turned off so users feel like they’re doing something about it.

Lockdown mode works by reducing the surface area of possible exploits. I don't think there's any failures here. Apple puts a lot of effort into resolving web-based exploits, but they can also prevent entire classes of exploits by just blocking you from opening any URL in iMessage. It's safer, but most users wouldn't accept that trade-off.

Claiming reduced attack surface without showing which exploit classes are actually eliminated is faith, not security.

And Lockdown Mode is usually enabled _after_ user suspects targeting.

Re: Apple Platform Security (Jan 2026) [pdf]

#83
post #69
post #58

Earlier quoted context omitted.

Apple sells some ads yes. But it’s a tiny fraction of their revenue. Would Google or Meta go bankrupt if they stopped selling ads? Yes. Apple wouldn’t.

What does whether they’d go bankrupt or not have to do with whether they’re an ad company? They sell third party ads: companies unaffiliated with Apple pay Apple to advertise on Apple platforms. They’re an ad company. Just because it’s currently a small slice of their total revenue doesn’t make it untrue.

I guess it’s also a financial company, since they have a branded credit card?

Re: Apple Platform Security (Jan 2026) [pdf]

#84
post #66

Earlier quoted context omitted.

I claim bs at this whole apple privacy thing, nothing but propaganda. Two years ago I was locked out of my MacBook pro. Then I just booted in some recovery mode and just..reset the password!? Sure macos logged me off from (most) apps and website, but every single file was there unencrypted! I swear people that keep boasting that whole apple privacy thing have absolutely no clue what they are talking about, nothing sh…

You chose not to enable FileVault during setup. Probably because you were worried about being locked out and wanted an easy way to reset the password. Would you prefer that Apple did not give you the option to disable the security feature you disabled during setup?

Ain't nobody paying attention, in any case it's still propaganda.

Re: Apple Platform Security (Jan 2026) [pdf]

#85
post #58

Earlier quoted context omitted.

Apple sells some ads yes. But it’s a tiny fraction of their revenue. Would Google or Meta go bankrupt if they stopped selling ads? Yes. Apple wouldn’t.

Apple would go bankrupt without US protectionist policy propping up their service revenue. That's pretty bad. Maybe not "reliant on ad monopoly" bad, but pretty close.

Elaborate? Financial results say otherwise.

Re: Apple Platform Security (Jan 2026) [pdf]

#86

It sucks that Apple decided to monitize iPhone the way they have, by controlling the owners ability to install software of their choosing. Ignoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound, but it's hard to take them serious regarding pr…

The OP is about security and you specifically ignore security when bringing up a common flamewar topic for which much discussion has already been had on this site. Perhaps such discussion could at least be limited to articles where it is less tenuously related.

Re: Apple Platform Security (Jan 2026) [pdf]

#87

Earlier quoted context omitted.

Lockdown mode works by reducing the surface area of possible exploits. I don't think there's any failures here. Apple puts a lot of effort into resolving web-based exploits, but they can also prevent entire classes of exploits by just blocking you from opening any URL in iMessage. It's safer, but most users wouldn't accept that trade-off.

Claiming reduced attack surface without showing which exploit classes are actually eliminated is faith, not security. And Lockdown Mode is usually enabled _after_ user suspects targeting.

If you did RTFA for this story, you’ll see on page 67 what I pasted with a link to the support article describing to end users exactly what’s blocked. It does greatly reduce the attack surface.

Re: Apple Platform Security (Jan 2026) [pdf]

#88
post #76
post #22

Sometime I wonder how much overhead all these security features take in terms of performance. I would really like to see a benchmark with and without security measures.

The ones I remember most affecting performance were zeroing allocated memory and the Spectre/Meltdown fix. Also, the first launch of a new app is slow in order to check the signature. Whole disk encryption is pretty fast today, but probably is a bit slower than unencrypted. The original FileVault using disk images was even slower.

> Whole disk encryption is pretty fast today, but probably is a bit slower than unencrypted.

Isn’t whole disk encryption nowadays done in hardware on the storage controller?

Re: Apple Platform Security (Jan 2026) [pdf]

#89
post #41

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences.

How does Google manage this, such every normie on earth isn’t freaking out?

Re: Apple Platform Security (Jan 2026) [pdf]

#90

Earlier quoted context omitted.

Why? The obvious conclusion is that Apple is doing everything in its power to make the answer “no.” You might as well enumerate all the viruses ever made on Windows, point to them, and then ask why Microsoft isn’t proving they’ve shut them all down yet in their documents.

That analogy misses the asymmetry in claims and power. Microsoft does not sell Windows as a sealed, uncompromisable appliance. It assumes a hostile environment, acknowledges malware exists, and provides users and third parties with inspection, detection, and remediation tools. Compromise is part of the model. Apple’s model is the opposite. iOS is explicitly marketed as secure because it forbids inspection, sideloadin…

[flagged]
Post reply on HN