Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

91–100 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#91

They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…

Many years ago. It’s called Firebloom. I think it’s similar in theory and lineage to Fil-C.

https://saaramar.github.io/iBoot_firebloom/

Re: Apple Platform Security (Jan 2026) [pdf]

#92

It sucks that Apple decided to monitize iPhone the way they have, by controlling the owners ability to install software of their choosing. Ignoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound, but it's hard to take them serious regarding pr…

The OP is about security and you specifically ignore security when bringing up a common flamewar topic for which much discussion has already been had on this site. Perhaps such discussion could at least be limited to articles where it is less tenuously related.

I guess I bring it up in the sense that no matter how good their security is, it still sucks that Apple products are so hostile to their owners. It's hard to be impressed by their security work with the platform being what it is.

Security, privacy, and ownership aren't equally separated in my mind.

Re: Apple Platform Security (Jan 2026) [pdf]

#93
post #21
post #14

Earlier quoted context omitted.

This is your blog post, so I'll ask you a question. What are you trying to state in Belief #1? The message is unclear to me with how it's worded: > In this table, in the "iCloud Backup (including device and Messages backup)" row, under "Standard data protection", > the "Encryption" column reads "In transit & on server". Yes, this means that Apple can read all of your messages > out of your iCloud backups. In addition…

Or Apple can also push an update, which you can't refuse, that upon first message to iCloud just uploads your private key. It's a bit foolish to count on encryption implemented by the adversary you're trying to hide from. Of course, this will most likely only affect individuals targeted by state-level actors.

IIRC Apple has attempted to implement some defences against this, for example by requiring the passcode to be inputted before an update can be installed to prevent another San Bernardino scenario. A cursory search indicates that they also have some kind of transparency log system for updates, but it seems to only apply to their cloud systems and not iOS updates.

Re: Apple Platform Security (Jan 2026) [pdf]

#94

They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…

>They made C memory safe?

They made a dialect of C with bounds safety, see:

https://clang.llvm.org/docs/BoundsSafety.html#overview

Re: Apple Platform Security (Jan 2026) [pdf]

#95
post #49

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

It's all tempered by them ultimately controlling what you can put on your phone though. As was demonstrated in LA, it's starting to have significant civil rights consequences.

Security is pointless if platform allows 90% users to be social engineered into running code disabling that security

Re: Apple Platform Security (Jan 2026) [pdf]

#96
post #41

Earlier quoted context omitted.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences. How does Google manage this, such every normie on earth isn’t freaking out?

Nobody expects their text messages to be backed up.

They get deleted and people shrug.

Re: Apple Platform Security (Jan 2026) [pdf]

#97

They made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example,…

>They made C memory safe? They made a dialect of C with bounds safety, see: https://clang.llvm.org/docs/BoundsSafety.html#overview

[deleted]

Re: Apple Platform Security (Jan 2026) [pdf]

#98

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

Apple is an ad company now though

Apple's ad revenue was 1% of its total in 2024. It was estimated to be 2-3% in 2025.

https://www.apple.com/newsroom/pdfs/fy2024-q4/FY24_Q4_Consol...

https://www.macrumors.com/2025/10/30/apple-4q-2025-earnings/

Re: Apple Platform Security (Jan 2026) [pdf]

#99

Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.

I claim bs at this whole apple privacy thing, nothing but propaganda. Two years ago I was locked out of my MacBook pro. Then I just booted in some recovery mode and just..reset the password!? Sure macos logged me off from (most) apps and website, but every single file was there unencrypted! I swear people that keep boasting that whole apple privacy thing have absolutely no clue what they are talking about, nothing sh…

[deleted]

Re: Apple Platform Security (Jan 2026) [pdf]

#100

Earlier quoted context omitted.

ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences. How does Google manage this, such every normie on earth isn’t freaking out?

Nobody expects their text messages to be backed up. They get deleted and people shrug.

Or IOW, Googles solution affects only messages. Apple’s solution affects your whole digital life so the consequences are a lot more dire.
Post reply on HN