22 ms·
A Message about iOS Security
- saagarjha 7y ago> First, the sophisticated attack was narrowly focused, not a broad-based exploit of iPhones “en masse” as described. The attack affected fewer than a dozen websites that focus on content related to the Uighur community. Of course, being 0-days, this is speculation on Apple's part. > When Google approached us, we were already in the process of fixing the exploited bugs. This is an interesting twist: Apple apparently knew about these bugs prior to Google Project Zero's involvement? The media overhyped the vulnerabilities (as they normally do), but this statement seems like it's blaming Google for making a big deal of something that Apple supposedly didn't need help on. Not a good look for Apple to be throwing shade in a public statement :/
- deleted 7y ago[deleted]
- ajconway 7y ago> The media overhyped the vulnerabilities No, the media underhyped it. It's a remote code execution vulnerability that's triggered by visiting a website.
- 693471 7y agoWhich to me is a big yawn because as long as we have javascript engines in our browsers this will probably be possible. Browsing websites is basically an RCE anyway.
- saagarjha 7y agoThe point of a browser's security model is to make it so that "remote code execution" does not mean "arbitrary remote code execution with elevated privileges".
- 693471 7y agoIf we really cared we'd only ship data and not code
- saagarjha 7y agoThat's assuming that parsers don't have bugs in them.
- lonelappde 7y agoCode is data. There is no technical difference, only human interpretative models.
- jcranberry 7y agoHe's obviously talking about shipping only non-executable data.
- minty_phoenix 7y agoI remember having been able to jailbreak my iPhone 3GS for a period of time entirely through visiting a website and letting it exploit such vulnerabilities enough to perform the task. Searching for a related article, appears to have been possible on iOS 4.0/4.0.1: https://www.cultofmac.com/53323/jailbreakme-2-0-jailbreaks-iphone-4-3gs-and-3g-on-ios-4-4-0-1-and-ipad-on-ios-3-2-1/ https://www.cultofmac.com/53323/jailbreakme-2-0-jailbreaks-i... Edit: I use ‘letting’ above loosely meaning that the specific website mentioned allowed the visitor to control whether the exploit was actually executed or not.
- saagarjha 7y agoI'm not denying that they're serious vulnerabilities–made especially concerning because it looks like they're the work of a nation state against an ethnic minority–but headlines of "1 billion iPhones hacked" do not convey the issue accurately.
- Someone1234 7y ago> headlines of "1 billion iPhones hacked" That wasn't an actual headline though. You can find: "Google Warns 1 Billion Apple Users They May Have Been Attacked." Which is quite different and doesn't conform to your complaint as well.
- saagarjha 7y agoThat was a generic headline I condensed from the results of a quick search. Here's one that was the top result for me in DuckDuckGo: https://www.pymnts.com/apple/2019/google-says-billion-apple-users-risk-hack-attacks/ https://www.pymnts.com/apple/2019/google-says-billion-apple-...
- Someone1234 7y agoSo you created it, and then used its wording as the focus of your complaint. And your link has the same headline I referenced above, which is quite different in tone and implication.
- saagarjha 7y agoI just read the article I linked a bit more closely, and it's worse than I thought: pretty much everything in it is wrong. > The details of the exploits are being kept a secret They are not. > Four out of the six bugs can trigger a malicious code on an iOS device, and a user doesn’t even need to do anything. Simply sending the message to the phone will execute the code once a person opens and looks at the message. No. The article also fails to mention that the the bugs targeted previous versions of iOS and have been fixed by Apple. And finally, the title makes it clear that "1B Apple users could be hacked", which is categorically false and much closer in meaning to my headline than yours.
- deleted 7y ago[deleted]
- Despegar 7y ago"iOS security is unmatched because we take end-to-end responsibility for the security of our hardware and software." Good stuff
- kerng 7y agoDefinelty highlighting their approach vs Google's.
- mkozlows 7y agoProject Zero's whole brief is "end to end security" even outside of Google's corporate borders.
- kerng 7y agoAs long as it's not involving Google itself I would add....
- SquareWheel 7y agoThen you'd be mistaken, because Project Zero has covered both Android and Chrome vulnerabilities.
- panpanna 7y agoAnd lots of windows exploited. Google engineers basically fuzzed all vulnerabilities out of Microsoft's font rendering system for free
- cheeze 7y ago> The attack affected fewer than a dozen websites that focus on content related to the Uighur community Expect a bunch of green accounts to come in and argue on China's behalf.
- dang 7y agoThis comment breaks the site guidelines. Please review https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here. We've had to ask you this before.
- bjornedstrom 7y agoWhat is Apple trying to gain by publishing this article? The tone is accusatory and defensive in a combination that does not make me sympathetic towards Apple. When Google posted the Project Zero articles, that did not impact my view of Apple in any way. However this press piece affects my view of Apple negatively, so from my perspective this press article has turned a more or less neutral event into one that is negative.
- _bxg1 7y agoThe general population of iPhone owners don't have the technical knowledge to understand the nuance of the actual vulnerability and exploit, so for many of them it probably wasn't a "neutral event". The subject of the article does come off as a bit defensive - though much less so than it could've - but I understand why they felt the need to tell their side of the story.
- 3JPLW 7y agoI mean, it is by definition defensive. They're pushing back against some of P0's claims. Project Zero (whether it's housed at Google or not) has a vested interest in making their detections as newsworthy as possible. Apple has a vested interest in downplaying those claims as much as possible.
- _bxg1 7y agoEdit: This article points out that some of Apple's wording wasn't as good-faith as it may've seemed: https://www.theverge.com/2019/9/6/20853393/apple-iphone-ios-exploits-statement-security-google-false-impressions https://www.theverge.com/2019/9/6/20853393/apple-iphone-ios-...
- dpkonofa 7y agoWhile I do admit that I agree with a few of those points, the Verge isn't exactly reporting in good-faith either, IMO. They are very biased against Apple, for whatever reason.
- elicash 7y ago
- saagarjha 7y agoHonestly, I really dislike Apple's recent policy of publishing "statements" for everything that ends up in the press. They did it for the Bloomberg article, and that was fine, but the one against Spotify and this one sound whiny and more importantly they fail to address the actual issues being brought up. It's just a bad look.
- mehrdada 7y agoIs this a recent policy? "Thoughts on Flash" was undersigned by Steve Jobs himself.
- saagarjha 7y agoThat's the only one that I can think of that compares. Apple wasn't publishing those three times a year, though.
- deleted 7y ago[deleted]
- phillco 7y agoThose one was more "here's why this technology sucks and we're not going to use it", less "Company XYZ made us look bad, here's OUR side of the story."
- mehrdada 7y agoThe trigger was Adobe was whining to the press and badmouthing Apple regarding Flash
- scarface74 7y agoAnd before that “Thoughts on Music” in 2007.
- themagician 7y agoI'm the opposite. I really like it, and I don't even really like Apple. Companies like Spotify piss me off immensely in the way they lie and whine publicly pretending like they are some cool startup who cares about users or artists or some other causes. Google does the same thing, hiding behind their phono "do no evil" motto. It's something about how two faced tech companies have become. Apple is arrogant. They always have been. This is just them being who they are, instead of pretending like they are something they aren't. I actually find it refreshing. I wish Spotify would be that honest.
- trolololooo 7y agoBy now, many of us have experienced an oddly targeted ad delivered to them after having a conversation. Facebook and Instagram deny it very publicly. Coincidentally there's an exploit that allows audio access to iOS devices after someone hits an infected webpage. I can imagine an ad company trying to use this kind of exploit. But Apple PR says it's all okay. It must be true so don't even think about it. Those Google security researchers are probably just jealous.
- hacker_newz 7y ago> When Google approached us, we were already in the process of fixing the exploited bugs. If Apple already knew about the flaw, then why did they never notify those affected?
- AceJohnny2 7y agoWho was affected? The flaw was distributed through a website. They can infer from the contents of the website who was the likely target audience, but they don't know who visited the website and got hacked.
- jedberg 7y agoUnless they had a way to test if a phone had been hacked and distributed that along with the patch. It's quite possible that they had pretty good telemetry on the extent of the exploit. I agree that they should have told those who were affected, but perhaps they did?
- AceJohnny2 7y ago> It's quite possible that they had pretty good telemetry on the extent of the exploit. Why would they? This is Apple, one of their selling points is how they don't have fingers in your phone
- jedberg 7y agoThere are a ton of places in iOs that report back to Apple. When you first set up the phone it asks if you want to "share your usage". You also agree to let them have stats on how long you use each app as part of the app store agreement. Apple's selling point is that they don't make money selling your private data (or transitive access to it) to third parties, but they don't make any claims about not doing it themselves. I don't see anything that would preclude them from installing some telemetry for this specific attack. And I think it would be perfectly justified in the name of security too.
- jedberg 7y ago> The attack affected fewer than a dozen websites that focus on content related to the Uighur community Is this new information or did we already know this? If it's new, this is very interesting. It's well known that China is doing everything it can to harm the Uighur community, which would imply a state sponsored attack. Making a slight logical leap, it makes me think that China took some iPhones that were in various states of construction so they could discover these exploits. Given that the iPhones are made in China, it is not much of a leap to assume they have effectively unfettered access to the same things that the factories do. I wonder, is there iOs source code access from the Chinese factories? Does this mean the Chinese government has access to "test" iPhones? Lots of interesting questions here.
- saagarjha 7y agoYou can buy a development iPhone by DM'ing the right guy on Twitter and paying him a couple grand. I don't think the Chinese government needs any additional access to factories to be able to exploit them.
- jedberg 7y agoThey may not need the access, but they have the access, so perhaps they used it. Definitely safer for them to just go into a factory and get a test phone than "DMing a guy on Twitter".
- FakeComments 7y agoIs it? Seems much more deniable — and unlikely to be followed up on — to have an associate of an agent DM the guy on Twitter and buy one for you: - None of your people inside Apple get exposed. - If Apple notices the theft, it looks like typical petty crime, and won’t get the same response. - If Twitter guy comes forward, the Chinese govt disappears him as a thief from Apple.
- Despegar 7y ago>Is this new information or did we already know this? It's confirming this report by Techcrunch that the Uyghurs were targeted. https://techcrunch.com/2019/08/31/china-google-iphone-uyghur/ https://techcrunch.com/2019/08/31/china-google-iphone-uyghur...
- rkagerer 7y agoGot a link to the original post and/or a good summary?
- saagarjha 7y agoOriginal post: https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d.... TL;DR: five web-based 0-days that Google saw being used in the wild for versions of iOS ranging from 10 to 12.
- dev_dull 7y ago> The attack affected fewer than a dozen websites that focus on content related to the Uighur community. When we refuse to work on defense technology (E.g., weapons), let’s remember who our rivals are, because they are surely investing their best technology and minds into weapons of war at full speed. What do you think they'll do once we finally and willingly lose our technological edge? Whatever they want.
- onemoresoop 7y ago> What do you think they'll do once we finally and willingly lose our technological edge? Whatever we did. What goes around comes around...
- jrockway 7y agoDiplomacy seems to be working better than weaponry.
- dev_dull 7y agoLeverage brings people to the table.
- godelski 7y agoEdit: I don't want a fight.
- acqq 7y ago> The 11 million people China is placing in concentration camps There are certainly no 11 million people in concentration camps there. Also nobody cites any sensible proof of the estimates pushed by the US-supported organizations and the US directly. For example, here Zenz, who claims that 1.5 million are detained, quotes that: "Zenz found abundant local county budgets and procurement bids indicating that large police or security guard units were hired for the camps. In one example, a county’s 2019 budget stated that its “training centers” employ 212 teaching staff, but more than twice as many security guards." 400 security guards can't guard 1.5 million. https://www.inkstonenews.com/politics/china-calls-xinjiang-camps-training-centres-governments-own-documents-say-otherwise-researcher-finds/article/3016918 https://www.inkstonenews.com/politics/china-calls-xinjiang-c... The whole "China oppresses Muslim Uighurs in millions" is supported in the UN by 22 countries (1), while 37 specifically deny that: https://www.businessinsider.com/china-joint-letter-condemn-muslim-oppression-no-islamic-signatories-2019-7?r=US&IR=T https://www.businessinsider.com/china-joint-letter-condemn-m... Those 22 signatories of a "joint letter condemning oppression" are: Australia, Austria, Belgium, Canada, Denmark, Estonia, Finland, France, Germany, Iceland, Ireland, Japan, Latvia, Lithuania, Luxembourg, the Netherlands, New Zealand, Norway, Spain, Sweden, Switzerland, and the UK. https://www.businessinsider.de/syria-saudi-nk-support-china-uighur-prison-camps-xinjiang-2019-7 https://www.businessinsider.de/syria-saudi-nk-support-china-... Note that there are 47 Muslim countries in the UN and not a one is in the above list. Whereas among those who apparently support China's treatment are Pakistan, Saudi Arabia, Egypt, Algeria, United Arab Emirates and Qatar, all Muslim countries: http://www.xinhuanet.com/english/2019-07/13/c_138222183.htm http://www.xinhuanet.com/english/2019-07/13/c_138222183.htm
- godelski 7y agoI'm saying there are 11 million Uighurs. I'm not claiming they are all in "training center". I imagine only a small portion of them are.
- thothamon 7y agoApple has done its best to secure customer privacy not only from bad actors and the government, but even from Apple itself, something that is certainly not true of Google. Apple went to the mat to protect its customers from the FBI. That earns ️<3 from me. Do I think Google would look out for me like that? Hahah, no, I do not think so. Does this mean these vulnerabilities were not real and serious? Not at all. But Apple took them seriously and reacted quickly. Nobody's perfect, but they deserve a lot of credit for their hard work on security.
- shazow 7y ago> Do I think Google would look out for me like that? Hahah, no, I do not think so. This article is literally about things that Google's Project Zero did which were for your benefit.
- throwaway2048 7y agoProject Zero is no charity.
- thothamon 7y agoI appreciate the good things Google does for me; they are many. But I don't think protecting my privacy, much less securing my data even from themselves, is their priority.
- mda 7y agoFunnily, I don't think there is any other company that protects users private data better than Google. Not military, not Apple, none of them come closer to it.
- TazeTSchnitzel 7y agoGoogle are good at preventing people hacking their servers, but they also broadcast your private data to thousands of third parties every time you open a webpage. Facebook and Google's approach to data security is lock it down so only they and their partners can access it. It does nothing for your privacy.
- ianferrel 7y ago> The attack affected fewer than a dozen websites that focus on content related to the Uighur community. Nice use of the passive voice there. "The attack" did it.
- musicale 7y agoNot exactly passive voice, but I agree: this does dance around who the likely attackers were and why the specific victims were targeted.
- duckqlz 7y agoHaving read all of the posts on the related blog from google I don’t think customers fears are unwarranted. I think apple spent a large amount of money “fighting” the fbi publicly on one case, built an image of a security focused phone company and is terrified of losing that image and going back to being seen as the Orwellian overload we saw painted by the Snowden dump. Not that google is any better though
- CodeSheikh 7y agoIs Uighur community the one that Chinese government is partaking in ethnic cleansing? Is it fair to deduce from this information that hackers were pro-Chinese govt?
- Rafuino 7y agoMore likely part of the gov't of PRC
- blackflame7000 7y agoI do detect just a bit of snark in that press release although to be fair, no one likes to be called out on their mistakes.
- fpgaminer 7y agoI didn't follow this story beyond reading Google's deep dive on the bugs. So I'm curious about a few things. (Deep Dive: https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...) The deep dive actively avoided mentioning information on who the targetted group(s) were. Was it later revealed who the targeted demographic was? Or did Apple just now reveal that information in this statement? It's a rather big piece of the puzzle. This attack being orchestrated by a nation-state was a strong possibility. Knowing that it was a targeted attack against the Uighur makes that case significantly stronger, and adds even darker tones to the story. And then there's this bit from Apple's statement: > all evidence indicates that these website attacks were only operational for a brief period, roughly two months, not “two years” as Google implies Interesting. So I re-checked Google's post and: > This indicated a group making a sustained effort to hack the users of iPhones in certain communities over a period of at least two years. A week ago, I read that to mean that these exploits were being actively used for two years. Reading it today ... it still reads the same to me. I guess what it is actually supposed to say is that the exploits were developed over the course of two years; not that they were actively used for two years. So that's definitely poor wording on Google's part. I wouldn't say it's nefariously worded, though. I think the author of the blog post was just trying to drive home the sophistication of the malicious group. But I know that I certainly came away from Google's article thinking that the exploits were _active_ for two years, which is significantly more frightening. So it makes sense that Apple would want to rebut that point.
- makomk 7y agoThe press found out that it was targetting Uighur Muslims in China a few days ago. I think the story about that got flagged off the front page of HN so you might have missed it.
- garaetjjte 7y ago>Was it later revealed who the targeted demographic was? It is speculation based on list of targeted apps (listed in implant teardown post) >I guess what it is actually supposed to say is that the exploits were developed over the course of two years; not that they were actively used for two years. I don't know what evidence Apple has, but Google definitely meant that it was exploited for two years: (from exploit chain 1 post) >This exploit provides evidence that these exploit chains were likely written contemporaneously with their supported iOS versions; that is, the exploit techniques which were used suggest that this exploit was written around the time of iOS 10. This suggests that this group had a capability against a fully patched iPhone for at least two years.
- hmx48 7y ago"Dont worry people, it just affected Uyghurs, who cares?"
- dymk 7y agoNot at all the content nor tone of the article
- acoye 7y ago> targetting the Uighur community I read between the lines "A state actor was actively tracking a group based on religion"
- musicale 7y agoYeah, it is too bad that Google or Apple didn't say more about that. For example, they could say that this example shows exactly why security and privacy matter: smartphones, computers, and the internet should not be used as tools for governments to track citizens based on their religion, culture, or political views.
- m0zg 7y ago>> focus on content related to the Uighur community Yeah, Tim, perhaps making your $1K phones in a Chinese sweatshop to save a few bucks wasn't such a brilliant idea.
- droithomme 7y ago> The attack affected fewer than a dozen websites that focus on content related to the Uighur community. Ah, so the exploit was written and placed by the Chinese government.
- scarface74 7y agoLet’s see. If Google finds a vulnerability in IOS, Apple patches the vulnerability and it’s patched for at least all iOS users on the current OS, as of right now, that’s all phones dating back to 2013. But Apple has also within the past three months released an update for phones back to the iPhone 4s released in 2011. If Google finds a vulnerability in Android, what percentage of the phones would actually receive the patch?
- berkes 7y ago> If Google finds a vulnerability in Android, what percentage of the phones would actually receive the patch? 100% of the vendors that have solid update in their pipeline. That means: all Google flagship phones and tablets. A lot of phones from companies that take updates serious. But also: hardly any planned-obsolence phones. And also hardly any phones that ship with a FUBAR Android "theme/skin/variant". The latter is, by definition of Open Source, out of Google's control.
- scarface74 7y agoThat means: all Google flagship phones and tablets. A lot of phones from companies that take updates serious. It’s estimated that Google sells at most 2.5 million phones a year and has 0.2% market share of the Android market. Where are all these other companies that “take updates seriously”? How many Android phones still get updated after 2 years? 3 years? 4 years? Think that’s too much to ask for? I bought an iPhone 6s in 2015 and my son is still using it, it’s running the latest OS, and according to many benchmarks it was faster in single core performance than high end phones released last year. It’s still faster than most midrange phones. The latter is, by definition of Open Source, out of Google's control. Google has plenty of control over any Android phone that runs Google Play Services. In fact, it has so much control that it had to pay a fine and is under a consent decree with the EU about forcing anti competitive conditions on Android manufacturers.
- wilde 7y agoSo, none of the vendors except Google and Nokia: https://www.theverge.com/2019/9/4/20847758/google-android-update-problem-pie-q-treble-mainline https://www.theverge.com/2019/9/4/20847758/google-android-up...
- marcosscriven 7y agoWhy don’t they write a blog post thanking Project Zero!
- sigzero 7y agoWhy would they? Their post points out that Project Zero was incorrect in a few assumptions.
- lern_too_spel 7y agoFor reporting actively exploited vulnerabilities?
- mavhc 7y agoHow does the sandboxing of applications compare on iOS and Android? Reading that iOS had trouble blocking applications from calling OS functions they weren't supposed to, plus they're running native code, not Java, seems to imply a security bug in an application is more severe on iOS than Android. See the Whatsapp root exploit for an example. Or are there additional protections in iOS, comparable to Android?
- mavhc 7y agohttps://www.wired.com/story/ios-security-imessage-safari/ https://www.wired.com/story/ios-security-imessage-safari/
- mavhc 7y agoAlso turns out the Whatsapp exploit didn't get root, just lived in the sandbox, with access to your microphone, camera, contacts, call log because you give it those permissions
- matmann2001 7y ago"...we take end-to-end responsibility for the security of our hardware and software" Remember that Apple said this.
- musicale 7y agoPretty sure that's what they are trying to do? But I agree that they should probably try to make it harder for authoritarian governments to exploit iPhones for use against political dissidents and unpopular minorities.
- ummonk 7y ago> When Google approached us, we were already in the process of fixing the exploited bugs. Wait, so Apple had already discovered the bugs / exploits before Project Zero disclosed them to Apple?
- mda 7y agoI call bullshit, maybe they found some of the issues in parallel, but it is obvious they did not have all of it and the scope of the problem. I am utterly disgusted by their tone as well.
- TazeTSchnitzel 7y agoPerhaps Apple have crash telemetry.
- cromwellian 7y agoSecurity researchers have a culture of being both overly paranoid and sticking to just the facts and not actively trying to minimize. It seems Apple doesn't want them to say "here are the exploits we found, and we found them on X websites, and estimate a few thousand visits per week", they appear to want them to say: "Only the Uighurs really need to worry. And by the way, it wasn't just us! They were going after Uighurs on Windows and Android too!" Even if PZ added "context" they seem to want, "just the Uighurs!", or "other platforms were attacked too", in what way that that actually diminish the fact that multiple 0-days with remote code execute on multiple OS versions were in the wild? The fact that we have one case where a single geographic group was targeted does not mean that these exploits weren't being used elsewhere. Imagine there's Windows 0-day and your an IT admin, but the advisory says only Ukrainians were targeted by Russia. Does that mean you shouldn't go back and look at your logs and look to see if you've been exploited, rotate credentials, install new countermeasures, etc? Shouldn't iPhone users be encouraged to rotate passwords on non-2FA sites after a reboot for example? To me, Apple's response looks like damage control. And why doesn't Apple have their own Project Zero that publishes deep dives on iOS/OSX vulnerabilities and would allow the press to have more context and not fly off the handle? Wouldn't it help to engender their development community and security researchers to be more active, by educating them on how these vulnerabilities typically work and how they're discovered, so more people can learn to spot them? It would make the claim "we already knew about these and were fixing them before other people discovered them" look better.
- freewizard 7y agoVery bold move for a global company like Apple to point fingers almost explicitly to China’s Xinjiang policy, which is also supported by 37 countries[1] worldwide. [1] https://www.reuters.com/article/us-china-xinjiang-rights/china-says-almost-40-states-openly-back-its-xinjiang-policy-idUSKCN1U721X https://www.reuters.com/article/us-china-xinjiang-rights/chi...
- deleted 7y ago[deleted]
- rolltiide 7y agoThats very interesting, where can I read about that perspective of China's internal administration within its own country? The detention and re-education under poor conditions is elevated to me as just reminiscent of all communist regime tactics for dissenters, but it had been presented to me as fairly arbitrary. I was not familiar with another perspective of the prior extremist attacks in that region. The 37 countries signing a document says something, although it doesn't say much to me since people just want to maintain their relationship with China, but it does make me want to know what they perceive a bit further. It seems more complex than just "poor Uighars, nobody is going to stand up against China", now replaced with "poor Uighars, its good that China has the unilateral authority to address domestic extremism in ways that other countries are limited in by their constitution"
- thesquib 7y agoBad apples.
- cavisne 7y agoThe original blog says this is a failure case for China, what went wrong specifically? Would this attack normally not be indexed/scraped by google? Apple PR seems to be trying to muddle the 2 years that the attack was likely available, and the 2 months where these sites operated.
- xtat 7y agoFor some reason this reminds me of trump obsessively defending that hurricane tweet-- really a bad look for Apple.
- panpanna 7y ago> First, the sophisticated attack was narrowly focused, not a broad-based exploit of iPhones “en masse” as described. The Chinese government decided to limit the attack to a 1 million population. Nothing technically stopped them from targeting the entire planet, so I don't understand why some is trying to downplay this.