5 ms·
I agree with all the ideas in the article, but at a bare minimum, Apple should configure devices so that no firmware update can be installed unless the user ent
by thothamon 11y ago
I agree with all the ideas in the article, but at a bare minimum, Apple should configure devices so that no firmware update can be installed unless the user enters their PIN first. This would be an easy move that would make this whole debate moot. The problem is that Apple only partially protected users from Apple itself.
- teacup50 11y agoThere's a much bigger elephant in the room, though: Updates to the OS and applications are encrypted, completely opaque, signed by Apple instead of the original developer, can be granted additional entitlements for arbitrary permissions, and cannot be audited by anyone but Apple without a jailbreak. When coupled with push updates, Apple already has a targeted backdoor into every iPhone anywhere connected the network. This is a much more difficult problem to solve, as securing against that threat model requires an diverse ecosystem of 3rd-party audit/review, software, and tools. I don't see any way of solving that issue while also maintaining their stranglehold on the platform via DRM.
- ikeboy 11y agoDon't users need to confirm OTA updates?
- saurik 11y agoThis person is talking about for applications, to which many users have "automatic updates" turned on; this is one of the places where Android is fundamentally by design more secure than iOS (though by implementation has often been weaker :/ see the Master Key family of vulnerabilities).
- ikeboy 11y agoAh. Missed that point. What's the highest permission an app can have? Wouldn't that be the limit of the vulnerability here? Also, many permissions require manual granting, e.g. contacts, camera. Edit: also, that could be mitigated partly by requiring user approval of any updates adding permissions.
- saurik 11y agoThe kinds of permissions that can be granted to an application by way of entitlements is pretty brutal and go well beyond the permissions that people tend to think of applications as being able to have: there are entitlements for things like "can install other applications" and "can obliterate all data stored on the device". I'm not certain if some of these are blocked to applications of certain kinds, but I know that a lot of them are available if Apple chooses to deploy them.
- ajross 11y agoMoot?! Please. In 2018 Apple gets handed a national security letter with a demand to backdoor all deployed iOS devices, with which they comply. Users see a routine update (maybe even with some conveniently timed security fixes included too!), and... key in their PIN. Everyone is now backdoored. Not the specific situation you were thinking of? Welcome to the world of security design: holes are everywhere and plugging them piecewise doesn't work if the problem is fundamentally intractable. Your theory would protect the San Bernardino shooters, but not you or me or anyone else. Why do people (smart people, even!) continue to insist that this problem can be solved by technical measures? This problem cannot be solved technically. Stop it. Please. This misinformation is hurting all of us. If you want snoop-proof encryption then the user needs to manage the keys herself, which I believe was MJG's point in that blog post. (And even then you're trusting the hardware itself not to have a backdoor to pull off the pass phrase, etc...).
- nickik 11y agoI agree, the general problem can no be solved technically. However I do think its valuable if apple builds the system in a way that forces the state to adopt clunky tools blanked backdoors. At this point the techindusty should have drawn a line and fight for it. Maybe this is Apples strategy. The want to raise the conversation but know they are gone lose this perticular case, so that they have a better position in the next, more important case.