Live data from Hacker News

New vuln in Apple M-series allowing secret keys extraction can't be patched

twitter.com

1–10 of 145 posts

Re: New vuln in Apple M-series allowing secret keys extraction can't be patched

#4

if this is confirmed I'm really interested into how exactly Apple will somehow deflect this and make it vanish like they somehow always manage to do with the myriad of issues they're facing over and over

It definitely supports my belief that centralizing identity, payment, and apps into a single device is a fundamentally flawed security model.

Re: New vuln in Apple M-series allowing secret keys extraction can't be patched

#5
post #4

if this is confirmed I'm really interested into how exactly Apple will somehow deflect this and make it vanish like they somehow always manage to do with the myriad of issues they're facing over and over

It definitely supports my belief that centralizing identity, payment, and apps into a single device is a fundamentally flawed security model.

Can you elaborate what you mean?

I may be misunderstanding what you intended but how do you use traditional means of payment (credit card) without an identity? How do you check your email without identity?

Re: New vuln in Apple M-series allowing secret keys extraction can't be patched

#6
post #4

if this is confirmed I'm really interested into how exactly Apple will somehow deflect this and make it vanish like they somehow always manage to do with the myriad of issues they're facing over and over

It definitely supports my belief that centralizing identity, payment, and apps into a single device is a fundamentally flawed security model.

As opposed to what else?

Please elaborate.

Re: New vuln in Apple M-series allowing secret keys extraction can't be patched

#7
post #4

Earlier quoted context omitted.

It definitely supports my belief that centralizing identity, payment, and apps into a single device is a fundamentally flawed security model.

Can you elaborate what you mean? I may be misunderstanding what you intended but how do you use traditional means of payment (credit card) without an identity? How do you check your email without identity?

Single point of failure?

If a single code gives access to everything, loosing that code to a malicious actors is really bad.

Re: New vuln in Apple M-series allowing secret keys extraction can't be patched

#9
post #6
post #4

Earlier quoted context omitted.

It definitely supports my belief that centralizing identity, payment, and apps into a single device is a fundamentally flawed security model.

As opposed to what else? Please elaborate.

Using multiple devices: Credit cards for payment, instead og apple pay. A camera for taking pictures, instead of a camera app, a notebook to write notes, instead of an app.

From my perspective the original comment is not rocket science?

Post reply on HN