3 ms·
Apple continues to push the industry forward in terms of what privacy and security options they offer their consumers. Their implementation of TouchID, disk enc
by timcederman 11y ago
Apple continues to push the industry forward in terms of what privacy and security options they offer their consumers. Their implementation of TouchID, disk encryption, and application security is better than anything else out there. The CIA and FBI have gone on record as saying as how frustrated they are with Apple's security. Do you really think iPhones can be used as spying devices?
- ris 11y ago"TouchID" Largely meaningless from a security standpoint (easily bypassable), and it enables someone to build a large database of fingerprint hashes. (Don't give me any of that "it doesn't upload the actual fingerprints" - uploading hashes is just as useful to security services) "disk encryption" You trust Apple way, way too much. "The CIA and FBI have gone on record as saying as how frustrated they are with Apple's security." Which is exactly what they would say, wouldn't they? "Do you really think iPhones can be used as spying devices?" Yes. In fact I have little doubt.
- stephenr 11y ago> In fact I have little doubt. And yet you present no evidence. The only thing you're close with is about whether a mobile device (including an iPhone) can be used for spying - baseband software in the cellular modem is a known area of concern for any mobile device. The rest you're making claims that either directly contradict what is known or have no basis, without any evidence.
- ris 11y ago"And yet you present no evidence." Funny thing, this sort of information doesn't tend to be put into the public domain. Anybody who knows anything about the relationships massive companies tend to have with the government can see that the situation being exactly as Apple paints it is highly unlikely.
- matwood 11y agoAre the things you mentioned perfect security? No, but Apple is operating in the land of midgets and is one of the taller players right now. You're also making a lot of conjectures without any evidence backing them up. The iPhone is one of the most examined pieces of hardware/software out there. If hashes are being uploaded to some master database there would be article after article screaming about it.
- Osmium 11y ago> [Touch ID] enables someone to build a large database of fingerprint hashes. (Don't give me any of that "it doesn't upload the actual fingerprints" - uploading hashes is just as useful to security services) This is speaking from a position of ignorance. Apple has been leading the way with responsible fingerprint management, in contrast to nearly every other fingerprint-capable device manufacturer out there (e.g. see HTC's recent debacle). Presupposing good faith on their part, the stated design of Touch ID is to prevent even the fingerprint hash from being accessible to the OS itself, let alone leave the device. All the fingerprint logic and stored hashes runs on a logically distinct "secure enclave" and it checks your fingerprints and just returns "match" or "no match" back to the OS (as I understand it). Technical details here https://www.quora.com/What-is-Apple’s-new-Secure-Enclave-and-why-is-it-important?share=1 https://www.quora.com/What-is-Apple’s-new-Secure-Enclave-and... but there's a white paper out there somewhere too. If anything, this kind of set-up is what gives me some faith that Apple might do self-driving cars correctly, rather than other manufacturers who think it's somehow okay that the entertainment system runs on the same device that can change driving parameters. Apple clearly needs to up their game too, but it's clear that the possibility of hacking cars is a Bad Thing, and as cars get more networked and more smart it seems clear that some car manufacturers do not seem to have the in-house expertise capable of doing it responsibly, so I wouldn't be surprised if a tech company actually ends up doing a better job (whether that's Apple or Google or whoever).
- ris 11y agofaith All that you've said rests on this single word - pretty much everything you've described is just taking Apple's word for it. I don't know where you get this faith from. Yes, they say they don't have any way into this "Secure Enclave" from the OS. We're living in a world where instructions passing through a processor can be sniffed over GSM frequencies from metres away. You're telling me that not a single engineer at Apple, who knows the entire system inside out, can think of any possible way to get data from a device it is physically, electronically connected to and communicates directly with? Not a single obscure "debugging" mode was left in for convenience? You have nothing but blind faith.
- 11y ago