They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…
Apple Platform Security (Jan 2026) [pdf]
91–100 of 205 posts
Re: Apple Platform Security (Jan 2026) [pdf]
#92It sucks that Apple decided to monitize iPhone the way they have, by controlling the owners ability to install software of their choosing. Ignoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound, but it's hard to take them serious regarding pr…
The OP is about security and you specifically ignore security when bringing up a common flamewar topic for which much discussion has already been had on this site. Perhaps such discussion could at least be limited to articles where it is less tenuously related.
Security, privacy, and ownership aren't equally separated in my mind.
Re: Apple Platform Security (Jan 2026) [pdf]
#93Earlier quoted context omitted.
This is your blog post, so I'll ask you a question. What are you trying to state in Belief #1? The message is unclear to me with how it's worded: > In this table, in the "iCloud Backup (including device and Messages backup)" row, under "Standard data protection", > the "Encryption" column reads "In transit & on server". Yes, this means that Apple can read all of your messages > out of your iCloud backups. In addition…
Or Apple can also push an update, which you can't refuse, that upon first message to iCloud just uploads your private key. It's a bit foolish to count on encryption implemented by the adversary you're trying to hide from. Of course, this will most likely only affect individuals targeted by state-level actors.
Re: Apple Platform Security (Jan 2026) [pdf]
#94They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…
They made a dialect of C with bounds safety, see:
Re: Apple Platform Security (Jan 2026) [pdf]
#95Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.
It's all tempered by them ultimately controlling what you can put on your phone though. As was demonstrated in LA, it's starting to have significant civil rights consequences.
Re: Apple Platform Security (Jan 2026) [pdf]
#96Earlier quoted context omitted.
modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…
ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences. How does Google manage this, such every normie on earth isn’t freaking out?
They get deleted and people shrug.
Re: Apple Platform Security (Jan 2026) [pdf]
#97They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…
>They made C memory safe? They made a dialect of C with bounds safety, see: https://clang.llvm.org/docs/BoundsSafety.html#overview
Re: Apple Platform Security (Jan 2026) [pdf]
#98Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.
Apple is an ad company now though
https://www.apple.com/newsroom/pdfs/fy2024-q4/FY24_Q4_Consol...
https://www.macrumors.com/2025/10/30/apple-4q-2025-earnings/
Re: Apple Platform Security (Jan 2026) [pdf]
#99Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.
I claim bs at this whole apple privacy thing, nothing but propaganda. Two years ago I was locked out of my MacBook pro. Then I just booted in some recovery mode and just..reset the password!? Sure macos logged me off from (most) apps and website, but every single file was there unencrypted! I swear people that keep boasting that whole apple privacy thing have absolutely no clue what they are talking about, nothing sh…
Re: Apple Platform Security (Jan 2026) [pdf]
#100Earlier quoted context omitted.
ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences. How does Google manage this, such every normie on earth isn’t freaking out?
Nobody expects their text messages to be backed up. They get deleted and people shrug.