8 ms·
Apple hires one of the developers behind Signal
- HappyTypist 11y agoI think this move shows that Apple is serious about security. They previously assessed the risk of a government ordered backdoor low and the potential for bugs in the Secure Enclave higher, and hence made the trade off the allow signed updates.
- ianamartin 11y agoI can understand how people want to put puzzle pieces together, but this is completely idiotic. Whatever remaining security holes there are with secure enclave, they have nothing to do with a software chat app. This is entirely coincidental and has nothing to do with anything. TechCrunch should be ashamed of itself (again) for being such a douchebag. Edit: I'm not saying Apple hiring the guy is stupid. I'm responding to the hattery from the article itself. As a hire, it makes sense. But trying to decide that it means "Apple is now serious about security" is just a bunch of horseshit on both ends.
- imron 11y agoNo, but this is very likely to be them tightening up other parts of their software stack.
- ianamartin 11y agoOh right. All the other insecure parts of their software stack. You know, all that other insecure stuff that's notoriously insecure. That one guy who wrote a chat app is going to tighten up. Come on. Don't pretend this is anything more than it is. A really hard-working guy worked hard and built a thing that worth while. Apple said, "hmmm, it would be easier to buy this person than to hire him." So they did. There is no one-person fix to secure enclave or any of Apple's other problems. You are being delusional. Apple's problems, such as they are, are systemic and cultural. Apple cannot buy its way into better cloud services or better Siri, or better security, and certainly not with the purchase of a such a small company.
- ontoillogical 11y ago> "hmmm, it would be easier to buy this person than to hire him." In what way did they buy him? Apple didn't buy Whisper Systems. They hired Frederic Jacobs.
- studentrob 11y ago> Apple said, "hmmm, it would be easier to buy this person than to hire him." Those two things sound the same to me. The guy was hired. What are you saying here? > There is no one-person fix to secure enclave or any of Apple's other problems Nobody said he's going to work on that. > Apple's problems, such as they are, are systemic and cultural. Apple cannot buy its way into better cloud services or better Siri, or better security, and certainly not with the purchase of a such a small company. You seem to know a lot about Apple's culture. Do you have some evidence to support your claims?
- imron 11y ago> All the other insecure parts of their software stack I didn't say all the other parts, or that he's going to do it singlehandedly. Maybe they want to improve end-to-end encryption for iMessage or similar and figure he's got relevant experience. > Apple's problems, such as they are, are systemic and cultural. Possibly, but even then, I would argue that this current situation is a culturally defining moment for post-Jobs Apple, maybe even strong enough to override other parts of their culture. One thing for sure, it's being driven from the very top down and Tim Cook is making clear, unequivocal comments about where the line in the sand is.
- dotch 11y agoThere are probably not many tech companies who would turn down an internship applicant with this guy's résumé. So, yes, no puzzle to be pieced together here.
- studentrob 11y agoIt's not idiotic, it's interesting news given the climate. They didn't say what his role or project will be. What's wrong with reporting on Apple hiring a developer of one of the most popular secure messaging tools?
- ianamartin 11y agoAre you blind to the difference between reporting an event and interpreting the event badly?
- studentrob 11y agoPlease quote the article where you feel it interpreted events poorly. And be civil.
- ianamartin 11y agoI don't really take orders from students, rob. Especially ones who don't read the article and are named studentrob. :)
- studentrob 11y agoI read it, Ian. I didn't see them call him a messiah anywhere. Is the word transparent like your comments are now? Also, I'm no longer a student in the traditional sense. That's sort of a life mantra of mine, to be perpetually learning. You can think of it as the opposite of your world, in which you think you know everything.
- teamhappy 11y agoHow about the first paragraph? > Apple hires plenty of interns all year round, but one particular addition > revealed this week caught the eye given the company’s current position > opposing a controversial order to enable the FBI to access the iPhone used > by one of the San Bernardino shooters. // Of course it's worth writing about, but it certainly would have been higher quality reporting if they didn't immediately link it to the FBI story.
- vonklaus 11y agoIs it idiotic to assume a company embroiled in a debate about privacy and security for a communication device-- the biggest driver of revenue for the company, hired someone in the secure communications space to work on communications products? Also, Apple has a PR problem and can't operate without secure systems. Article title notwithstanding, it is a pretty big deal that while an intelligence agency is coming at them hard they hired a developer, in a very public manner, that's application is used by the very person who made the evidence of surveillance known. This could be a signal to the market that they not only passively oppose this, but they are actively locking down their systems and they won't cooperate. Seems like a very sharp developer and as a bonus he did secure system messaging so it is not idiotic. edit: I ammended post to reflect that he is likely not working on iPhone directly.
- ianamartin 11y agoI will argue that this guy has none of the skills needed to up the ante on the current security model of the latest versions of iOS. What's not known is how security enclave works. But what is known is that it's firmware. Something very much outside what we know about the secure chat app. We also know that iMessage has never been known to have any fundamental security flaws. I tried to clarify above, and I'll do so here again. I don't think the hire was idiotic. I think TCs characterization of hiring a security messiah was idiotic. That is not anywhere close to reality.
- ascorbic 11y ago"I will argue that this guy has none of the skills needed to up the ante on the current security model of the latest versions of iOS." What are you basing that assertion on?
- vonklaus 11y agoIt is a strong signal to the market that they aren't cooperating and actually, actively hiring to get to market with something that is non-trivial to break into. I don't know about his engineering abilities but the interview I read and some of the news articles presented him as quite a talented person. Signal, if it is as secure as the EFF audit suggests, would be one way to shore up older iPhones. > I think TC's characterization of it was idiotic. I mean, if we grade it on the TC scale it wasn't. It is hard to say it is unrelated. Their communication device is very publicly being regulated into compliance and they want to hire all the good people they can get. This is good on 3 levels, solid engineer, strong communication to market and that commitment brings in other solid engineers.
- ascorbic 11y agoHe's not been hired to work on messaging though. He's been hired to work on the Core OS team, i.e. the low level parts of iOS and OS X.
- sbose78 11y agoIt does make sense to hire a guy who has had great success in Security. The chat app is just one of the use cases which he handled, and a good experience in designing secure software always helps.
- kriro 11y agoI disagree and think this is potentially big news. You push us to relax security...we push back by trying to make a play in the secure chat (for everyone not just iPhone users) market which would make your life a lot harder. The market is tough but it would be interesting if Apple would actually enter it. They have enough power to seed the network effect needed with a large enough user base. I think this entire saga has actually opened up a nice spot to push really hard for the positioning slot of "secure by default". It's been done by a lot of people including Apple before but I think we're at a point in time where the media echo might be good enough for a big company to make a true positioning play. It's also a great differentiation against Google/Facebook. Apple has voiced the "essentially our competitors are in the we make money off privacy violations business" (in other words) but they might want to hit that harder soon. A bit fickle since you need FB/Google in the "security now" alliance but still interesting. I'm still skeptical about closed source software for secure X but I guess it's better than nothing.
- izacus 11y agoThe worrying this is that Apple really has a terrible record of making their solutions available to other platforms. A secure communication software that will only work well on Apple platforms and have a half-broken solution for perhaps one more is not really the direction we want to move to :/
- dang 11y agoIt's arguably a poor, baity article, but please don't rant like this on HN. It lowers the quality of the discussion and usually sets off a degrading spiral (as below).
- ianamartin 11y agoI apologize for the rant. It was misplaced here. If you feel like it needs to be deleted, I'm okay with that.
- dang 11y agoNo, but thanks. We really appreciate your understanding.
- thecryof 11y agoThis news is another +1 for Apple in my view.
- Vivtek 11y agoI'm starting to think Apple has found its first viable post-Jobs narrative.
- saurik 11y agoI would say that this has been Tim Cook's narrative for a while, and along this path we've seen iOS integrate things like WiFi MAC randomization and website ad blocking.
- danieldk 11y agoI would say that this has been Tim Cook's narrative for a while, While part of it may be PR, I also believe that these are Tim Cook's values shining through. Having an orientation that gets you jailed or killed in some countries, makes you value individual freedom and privacy. It's great to see this new Apple.
- benevol 11y ago> While part of it may be PR It definitely is. The NSA has access to all this data anyways. They just need to get it nailed down legally now, as far as possible. Apple just can't be seen as collaborating.
- abalone 11y agoConjecture: Isn't Apple's private signing key already a "master key to turn 100 million locks"? I.e. the key they use to sign software updates. With that key, someone could create malware and sign it... Apple creating the malware just saves them a step. Ergo the "target on that piece" is already pretty high value, yet Apple is able to keep it secret / prepared for contingencies (like rotating the key..) Thoughts?
- runholm 11y agoWell, this is true for any form of authentication. If you have information you need to update, you need to have a form of authentication, and authentication data can get lost. You just need to have good routines limiting the access to this data. This is a problem for signing software, but also things like updating their webpage and content on the App Store. All these systems need to have authentication data exist, and if lost to people with malicious intent it could be lost.
- abalone 11y agoSo what does this say about Apple's claim that a "master key" is too dangerous to create? Don't they already have that.. something that hackers could use to unlock iPhones? Doesn't that danger already exist? (Again this is meant as thought-provoking conjecture.)
- SideburnsOfDoom 11y agoYes, Apple has never denied that it is possible for Apple to create a signed build of iOS with some of the security stripped out. They just point out, rightly that it is not a good idea. It follows that this is a pretty thin layer of security. And it seems that Apple's signing keys are well-protected high value targets. Has Apple been "able to keep it secret" ? As far as we know, yes. But we don't know everything.
- duskwuff 11y agoThe CoreOS (https://coreos.com/ https://coreos.com/) security team, or just the core OS security team? If the former, I'm curious what Apple's involvement with that project is.
- dotch 11y agoPresumably the Core OS layer (https://developer.apple.com/library/ios/documentation/Miscellaneous/Conceptual/iPhoneOSTechOverview/CoreOSLayer/CoreOSLayer.html https://developer.apple.com/library/ios/documentation/Miscel...).
- EwanToo 11y agoApple's internal OS development team is called the core OS team, totally unrelated to coreos.com
- studentrob 11y agoGood for Apple. Maybe he can help critique Apple's security methodology. It will be interesting to hear what he works on and how he finds Apple's security systems.
- izacus 11y agoHmm, so Apple just hired away the dev of pretty much only secure open and cross-platform iMessage alternative?
- uxp 11y agoFrederic Jacobs has been planning on moving away from Open Whisper Systems for a while. They didn't hire him away, he took another job.
- Aissen 11y agoCongrats on the new gig. I wonder if this is a sign of bad financial health of Open Whisper Systems ?
- uxp 11y agoFrederic Jacobs announced he was looking elsewhere some time ago. I don't have any insight into Open Whisper System's internals, but considering they've still been committing code and they're still posting new job openings, I doubt this has anything to do with Open Whisper Systems and more to do with Jacobs wanting a change of scenery.
- jakobegger 11y agoApple is not known for high salaries, so I wouldn't jump to that conclusion. There are lots of reasons beside money why people switch jobs...
- aluhut 11y agoI don't care about Apple but I hope this won't end bad for Signal.
- MichaelBurge 11y agoThis article seems more than a little silly. They blew up a single tweet into an article about Apple's corporate strategy in relation to the FBI. What next? Are they going to dig through Apple employees' trash, looking for variations in the number of credit card offers? "Apple Employees Load up on Credit" "Investigators have uncovered a 10% uptick in the number of accepted credit card offers from key Apple employees. Speculation about Apple's poor recent performance seems validated by their own employees obtaining as much cheap credit as they can get before the inevitable catastrophe approaches. Leading VCs interviewed had this to say: 'We always recommend to our partners that they obtain credit during times of prosperity, so that they don't need to unnecessarily dilute their shares by raising money in a downturn. If you're profitable but don't need the money, it's a great time to at least seek a line of credit from your bank.' Apple representatives declined to comment on this article, possibly wishing to delay the bad news until the next shareholder meeting. Next up: Microsoft reallocates its purchases of employee free soda to 20% Coke / 80% Pepsi. But what are the impacts on its cloud computing business?"
- trymas 11y ago+1. the deal was on it's way probably way before FBI scandal started.
- vostok 11y ago> Microsoft reallocates its purchases of employee free soda to 20% Coke / 80% Pepsi. You joke, but I bet you could get a leading indicator if you looked at companies reallocating from European fizzy drinks to Coke/Pepsi.
- deleted 11y ago[deleted]
- stygiansonic 11y agoI know you joke about looking at credit card info, but it reminded me of this story[1] where fraud researchers at a credit card company (ab)used their access to credit card transactions of their customers in order to mine the data and perform fundamental research about various companies' retail performance. They then used this information to trade on the companies just before earning release, and made a lot of money. They were eventually caught by the SEC because their trading was deemed suspicious, i.e. their options bets always seemed to work out. 1. http://www.bloombergview.com/articles/2015-01-23/capital-one-fraud-researchers-may-also-have-done-some-fraud http://www.bloombergview.com/articles/2015-01-23/capital-one...
- a_lifters_life 11y agoWhy is this about Edward Snowden?
- jayarcanum 11y agoDoes anybody see through these PR plays? They've unlocked many phones in the past for the government, they're protecting their technology and using the moral issue to look good at a time when they're still majorly losing their way. To me this looks like governmental appeasement. Shutting down Snowden and other's methods of private communications is a fantastic gift to the government who doesn't want more of that type of scrutiny and people talking about the NSA badly, there's already enough thinking they're a major problem. What perfect a guise to get it done under another companies name that also happens to be having a great PR week on the back of data they gave up or are going to give up anyway, they always knew that. I wish more people would think for themselves or at least consider why the script might not be reality. They hired him! What happened is a formerly non corporate secure, private form of communication is now... who knows what. Maybe the government just figured out how to deal with the next Lavabit and not deal with more backlash. Nobody trusts them right now, everybody seems to love this Apple letter PR play.
- hellbanner 11y agoYes. And I'll say it again. When Apple revised their privacy text (around 12 months ago), it looked to me that a warrant canary died. Replaced with text like "We care about your privacy." "We protect you with all legal means available." And then there's PR like http://www.dailytech.com/Feds+Cant+Crack+Apples+iMessage+Encryption+for+Investigation+Purposes/article30280.htm http://www.dailytech.com/Feds+Cant+Crack+Apples+iMessage+Enc... Maybe it's true. But are you really that trusting?
- carlosnunez 11y agoNot sure if I believe that Apple acqui-hiring this developer was a concession for the bad press they've been giving the government lately. It was his choice to work for Apple; I'm going to guess that they didn't coerce him into taking this deal.
- givinguflac 11y agoHow can you possibly be so cynical that you think this? Be an Apple hater all you want, but your comment is just silly. If Apple has "unlocked many phones for the government" before, why does the government have so many they want unlocked? A warrant canary can't "look to you" like it died. It did or it did not, and it most definitely did not. You're blowing this almost as far out of proportion as the article. Where is your proof for all these prior phones they unlocked??
- Sir_Cmpwn 11y ago>Apple Hires Developer Behind Signal, Edward Snowden’s Favorite Secure Chat App A "secure" chat app that depends on Google Play Services (spyware) and is only available through the Play Store (rather than F-Droid, an open source software repository for Android) and maintained by an author who refuses to integrate fixes to either of these problems upstream. For those wondering if Google Play Services really is spyware: one of the purposes is to backdoor your phone for Google so they can _silently_ update any of their apps on your phone. It has access to _every_ Android permission and can (and does) grant any permission to any app silently. It also monitors your location and reports it to Google, along with brief voice snippets for "OK Google", as well as a list of all apps installed on your phone, and more. It's definitely an awful thing to have on your phone if you're privacy conscious.
- r0muald 11y agoYou're welcome to inform yourself on the subject before posting crude FUD: https://github.com/WhisperSystems/Signal-iOS/blob/master/BUILDING.md https://github.com/WhisperSystems/Signal-iOS/blob/master/BUI...
- Sir_Cmpwn 11y agoI encourage you to do the same: https://github.com/WhisperSystems/Signal-Android/issues/127 https://github.com/WhisperSystems/Signal-Android/issues/127 Security should be available to all, not just those with the environment and know-how to compile apps from source. Doubly so on iOS where you have to pay x dollars for a developer license.
- AdmiralAsshat 11y agoOh, they hired a developer behind Signal. No offense to Mr. Jacobs, I'm sure he is an excellent developer. But I saw the headline and assumed they had grabbed Moxie.
- qntty 11y agoI assumed the same
- jpstory 11y agoEveryone who has ever known, or known of Moxie, thought the same :D I think we'd all love to see him be CCO (Chief Cryptography Officer) or something similar for Apple. Not to diminish his work at Whisper Systems, but talent like his should be reaching the 100 of millions of customers that Apple has reach to. Moxie, I know you hop on hacker news every so often - if you read this - would you go work for Apple? Or are they too closed source for your tastes?
- robert_foss 11y agoI for one hope that his efforts aren't wasted within one narrow ecosystem.
- kitd 11y agoExactly. Writing a user of Signal on Android, Apple is the last place I want him to be!
- fweespeech 11y agoI'd honestly prefer he remains independent of Apple. I have no desire to purchase Apple products and them picking him up would probably be a loss to Signal which I actually use.
- nxzero 11y agoAgree, Apple's security culture is not compatible in my opinion; unless Apple changes, which is unlikely.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]