16 ms·
I think the part of the discussion that is ignored here is the security aspect. Apple has hardened their hardware against attackers replacing components of the
by lykr0n 5y ago
I think the part of the discussion that is ignored here is the security aspect.
Apple has hardened their hardware against attackers replacing components of the phone with compromised versions. Sure, at the same time it prevents 3rd party repairs, but I don't think Apple's only motivation for doing this was to screw over 3rd party repair shops.
When the NSA leaks came out, there was some sections that showed how shipments of electronics could be intercepted and backdoored. I would 100% believe there are groups out there that have or are working on chip level attacks for iPhones and other mobile products. Swap Apple's Face unlock chip with a custom one that includes other embedded profiles that can unlock the phone without the owner's knowledge does not seem far fetched.
A lot of the changes to the MacBooks seem to also have been done with device hardening in mind.
I cannot tell you how much damage my iPhone 12 Pro has taken without the screen cracking, which makes me personally think the reasons these changes have been made are not just related to 3rd party repairs.
- ClumsyPilot 5y ago"Sure, at the same time it prevents 3rd party repairs, but I don't think Apple's only motivation for doing this was to screw over 3rd party repair shops." Is that why they don't let you replace the microphone jack on a macbook and prevent their suppliers from selling me a replacement battery, keyboard or display?
- MichaelZuo 5y agoYou can’t buy a replacement battery through their official channels? Which country are you in?
- mrunkel 5y agoHe wants to buy the battery from Apple’s suppliers. Not from Apple or an authorized reseller.
- sudosysgen 5y agoYou cannot buy the battery from Apple or an authorized reseller. You can pay for them to replace it themselves, but they won't sell you the part.
- ClumsyPilot 5y agoYou can pay for battery replacement, but you cannot buy a battery and replace it yourself. They literally refuse to sell you any parts
- dpkonofa 5y agoYes. If you can replace the microphone jack, or any of the other hardware you mention without verifying its integrity, you can add surveillance hardware to the device. I could replace your microphone with one that records everything and sends it to me and you'd be none the wiser.
- ClumsyPilot 5y ago"I could replace your microphone with one that records everything and sends it to me and you'd be none the wiser." How is this miracle microphone going to send you anything exactly, telepathically?
- dpkonofa 5y agoYes, because we definitely don't have the capability to connect hardware to some kind of wireless, global communications network... You people are ridiculous.
- sudosysgen 5y agoAnd if it could, you could just glue it to the computer or other personal belongings anyways
- dpkonofa 5y agoYou don't think that would be more noticeable than something that's inside the computer?
- dmz73 5y agoI think you got it backwards. The main reason is to exclude 3rd party repairs and extra security is a side effect that can be used as justification. Follow the money.
- hyperbovine 5y agoIMO there is way more money, like orders of magnitude more, to be made from successfully branding the iPhone as the most secure and private smartphone, compared to the repairs market.
- coldtea 5y agoThey can already do that without harming repairs. As if replacing the hardware with physical access and giving the phone back to you to tap you is an attack people are actually afraid of... (and if they were, e.g. targeted by state actors or whatever, they could just get a specialized phone, not a mass market one). They already have non-E2E-encrypted iCloud backups where they give access to the Feds and others.
- threeseed 5y agoThe same argument could be made for any security hardening. Why bother with MFA, biometrics etc when the chances of being compromised are statistically very low. The reason is that it does happen and on a scale that's hard to quantify. We have examples in Australia of ordinary citizens being targeted by China for promoting Hong Kong or showing support for Uyghur Muslims. And evidence has come to light that their phones and cloud accounts were hacked and friends/families targeted. So for me personally I will take security hardening any day over saving a few bucks to go to a cheap screen repairer.
- coldtea 5y ago>The same argument could be made for any security hardening. Why bother with MFA, biometrics etc when the chances of being compromised are statistically very low. No, the chances there are statistically very big. Because a thief might get your phone, and then can exploit access to it without MFA, biometrics, etc, and stole your bank account, data, etc. But the chances of people (a) getting your phone, (b) replacing the camera module and compromising the OS, (c) giving your phone back without you noticing, to get your data, are statistically tiny. And we've somehow managed for 15 years of smartphones without those mitigations... >And evidence has come to light that their phones and cloud accounts were hacked and friends/families targeted. Where they hacked in the way we're talking about here? If not, how is this relevant?
- echelon 5y agoIt's easy to view every move Apple makes through the lens of money. Their platform is locked down so that nobody can carve out their own turf. No custom browsers with modern web features. No runtimes. Apple's rules and taxes, or you're banned. I've never been afraid of batteries compromising my system. Or new screens. Apple wants the extremely lucrative device repair market, and this is how they get it. Screens are the most common and expensive part to replace. I am, however, afraid of my device reporting files that the government doesn't like. The Russian FSB is salivating at Apple's new device spying "CSAM" capabilities. Apple built this system to satisfy totalitarian regimes so they could still sell their devices. It turns their entire platform into a dragnet so that intelligence knows exactly who to target. The FBI probably put pressure on the DOJ for these same capabilities too. Apple is deathly afraid of antitrust breaking up their gravy train and would bow to pressure. This is about money. Apple wants it all. They need extreme growth to justify their stock price and future outlook. Everything is about money to Apple.
- Bud 5y agoIt's easy to view a lot of things in facile, inaccurate ways. Not very informative, but, certainly easy!
- zepto 5y agoAccusing a business of being motivated only by money is completely trivial and in informative. For example iFixit clearly cares absolutely nothing for user security and is only motivated by money. They simply don’t care if devices are secure as long as they can sell repair kits. Also it is clearly in ifixit’s interest to have unreliable devices that break often and need more repairs. This is true of the entire repair business - all they care about is money.
- commoner 5y agoiFixit's business incentives are more aligned with the interests of consumers than the incentives of manufacturers like Apple who obstruct the repair of the devices they sell. The negligible security difference that Apple is using as an excuse to enforce high repair charges plays a minimal role in an informed user's decision to use a third-party part.
- zamadatix 5y agoI'm not against blocking government level physical security attacks on personal devices but I am against the idea such a thing warrants or truly requires every user to be blocked from all but first party repairs. If whatever infallible repair process and repair techs Apple is using internally can truly not be open to 3rd parties without compromising against such nation level attacks then at the very least protections against such attacks should be an option you enable which tells the security processor to never accept new hardware, not a forced default for all consumers which just happen to need repairs over time and are given only one place to get them.
- hdjjhhvvhga 5y agoThis is the most ridiculous thing I read this year - and I've read a lot of mad stuff. Let's assume your justification is true and Apple cares so much about the privacy that they implemented this feature just to protect them and that they don't care about the money from repairs. So, in your scenario, someone would have to steal my phone, disassemble it, and replace the face unlock recognition chip with a custom version. Let's assume this is easy technically, i.e. you could actually do it in the iPhone 12 and the phone would happily accept the modified version (not a small feat if you ask me). Now, while I don't think it's absolutely impossible, the means to accomplish this are usually available to nation-state actors, and in cases like this one the xkcd 538 comes to mind.
- saagarjha 5y agoI mean, yes, this change makes them more money. But Apple is weird, because they are actually able to convince themselves that they're doing this for a good reason, and if you follow them closely you can almost see their central argument: when it comes to security, they trust nobody but themselves, not even the user they sell the device to. It's kind of a strange mindset, but if you look at it under that lens a lot of the concerns about sideloading and repairs make sense from their perspective ("we don't trust the user to do the right thing for their devices"). How does this look like from the outside? I think there are genuinely a lot of people who actually agree with this. Actually, I think almost everyone agrees with this to some extent: people only have a limited amount of effort they can spend managing different parts of their life. The conflict occurs for the parts where people do feel like they can make better decisions than Apple, but they can't because Apple won't let them. For most people, going to an Apple Store or AASP to get a repair is generally fine and saves them hassle. But for the people who are willing to save money to go elsewhere, or do their own repairs, it really sucks.
- someguydave 5y agoit would be easier to stomach “apple owns the device not the loser customer” if there was a single major oem who was focused only on producing customer-owned devices
- fsflover 5y agohttps://puri.sm/products https://puri.sm/products
- someguydave 5y agoyeah man do they have data sheets and programming guides for every chip? are they gonna get interoperability with US cell providers?
- fsflover 5y agohttps://source.puri.sm/Librem5/community-wiki/-/wikis/Frequently-Asked-Questions#19-is-the-librem-5-freeopen-hardware https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque... https://source.puri.sm/Librem5/community-wiki/-/wikis/Cellular-Providers https://source.puri.sm/Librem5/community-wiki/-/wikis/Cellul...
- concinds 5y agoIf Apple Stores have the ability to pair a new FaceID module after an "official" repair, then why wouldn't the NSA have that same ability? Only third-party repair shops don't have that ability.
- sircastor 5y agoPresumably it would be some sort of signing solution, which would be a level of cryptography that not even the NSA with their infinite resources can defeat. Their only hope is to find bugs in the system that can be exploited. In this case such a “bug” would be replacing a module that doesn’t have any hardware integrity checking.
- donmcronald 5y agoWhat? Apple will just give them a signing key or, more likely, build a portal for law enforcement to use. If they can provide those tools to authorized repair centers they’ll have to give them to the government when compelled.
- dillondoyle 5y agoOr if an employee of a store can do this, just pay or get an employee hired. I haven't heard of this seems concerning to me. I use a long passcode only on both phone and laptop.
- Bilal_io 5y agoOr the NSA could open a fake repair shop become an authorized shop through Apple.
- easton 5y ago> they’ll have to give them to the government when compelled. Says who? The whole bruhaha in the San Bernardino case was that Apple would not create a custom version of iOS that would bypass the passcode system. If what you say is true, the FBI could've just compelled them to hand over the root CA for signing iOS builds, built a custom iOS iPSW that's pre-jailbroken (as was a thing in the years before the bootrom became more locked down), and been done.
- pizza234 5y ago> When the NSA leaks came out, there was some sections that showed how shipments of electronics could be intercepted and backdoored. I would 100% believe there are groups out there that have or are working on chip level attacks for iPhones and other mobile products. Swap Apple's Face unlock chip with a custom one that includes other embedded profiles that can unlock the phone without the owner's knowledge does not seem far fetched. Which class of attackers are those hardenings supposed to deter? For three letter agencies, or groups with the resources to produce chip level attacks, this is child's play.
- jefftk 5y agoSince you can bypass it with a microscope and soldering, moving a chip from the old screen to the new screen, this doesn't seem like much added difficulty for someone who is already implementing a hardware-based attack?
- owlbite 5y agoI'd guess the aim is to be secure on all components (most of these things have their own processor(s)). If you can compromise one component you can move from there to compromise another one, until you get to something worthwhile. I don't think my main concern would be three letter agencies (they're going to find a way in to your average consumer one way or another). Probably more likely some organized crime gang backdooring cheap replacement screens and using that to perform an attack on financial data or similar. Attacker doesn't have physical access to the device, just manipulated the supply chain.
- deleted 5y ago[deleted]
- TaylorAlexander 5y agoWe don’t really have to assume that Apple is intentionally harming 3rd party repair, but even if we believe they are operating in good faith they seem to be ignoring third party repair. Which means they don’t really care about saving their customers time and money or reducing waste.
- emerongi 5y agoShow a warning to the user then? Would be a much better way to handle this.
- donmcronald 5y agoYeah. This should be what regulations enforce. I’m fine with parts serialization to help identify genuine, certified parts, but as the user I should be able to bypass it if I want to use compatible parts.
- dann0 5y agoI don’t want that. It would have to be a persistent warning of the person that compromised my phone could dismiss the warning. But most of these anti-Apple comments can be overcome by buying a different device. They have different trade offs.
- donmcronald 5y agoWould it be that bad if it were a persistent check that happened on boot? All you'd need to do to validate the hardware in your phone is reboot it and it would barely have any impact during normal operation.
- dann0 5y agoWhen was the last time you rebooted your phone?
- donmcronald 5y agoI don't know. Maybe a few weeks ago. The point of doing it on boot is that if you're so important that your threat model includes avoiding non-certified parts, you have an on-demand check to validate the entire chain of hardware in your device. So if you take your phone in for a repair, reboot it afterwards to make sure the parts are all certified. After that you don't need to do it again unless you leave your phone unattended or have a reason to suspect someone swapped parts on you. There could even be an option to toggle on super persistent warnings if needed. The point is, you don't need persistent warnings to give a normal user the tools they need to check if they have all genuine parts. Reboot your phone after a repair to ensure you received genuine parts is a pretty simple concept to teach people.
- donmcronald 5y agoSo they have all these restriction for security and privacy, but they’re all worthless if Apple decides they’re going to provide surveillance for the government, right? IMO this is a win win for Apple. They get to pretend the anti-repair shenanigans are for your protection, but they also have the option of turning around and selling access to you and your device to whoever they want. The NSA spying isn’t comparable either. That was mass surveillance. Swapping a piece of hardware, which requires hands on the device, doesn’t scale to the point of being a threat like that IMO. For me, the negatives of non-repairability outweigh the pros of the security provided. I’m not worried about the government swapping my screen to gain access to my device.
- secondaryacct 5y agoOr you know, we could click a radio button on the shop website and be able to choose: reparable vs secure. But they didnt think about that one...
- zepto 5y agoThey did, and they have written about that kind of choice. It’s a false choice. If you give it to people, they will be manipulated into choosing ‘repairable’.
- commoner 5y agoUsers who choose to repair the products they own with the parts they want at the price they're willing to pay are not being "manipulated" into anything.
- zepto 5y agoThey are if it is at the expense of security.
- donmcronald 5y agoDo you mean they did and people overwhelmingly chose repairable, so they invented a narrative to support the answer they wanted? I don't know anyone that would forgo having a repairable phone for the tiny bit of extra security it gets them.
- noasaservice 5y agoOh please. Scary high-end governmental supply chain backdooring with chips the size of a grain of rice are for fiction rags like Bloomberg: https://www.bloomberg.com/news/features/2018-10-04/the-big-hack-how-china-used-a-tiny-chip-to-infiltrate-america-s-top-companies https://www.bloomberg.com/news/features/2018-10-04/the-big-h... Techniques like this; tying hardware together and not allowing legitimate owners pair them to work is purely anti-competitive garbage. We've seen this with coffee pods, automated cat litterbox cleaners, dish washers, inkjet printers, and more. Apple finally wanted the market for themselves. And since they control the hardware, well, yeah.
- aurizon 5y agoYou are wrong. With a state actor in the room, it is quite possible to place a complex die with static ram on a thin substrate inside a multilayer board, using the +5 and ground and a number of traces that lead to I/O ports etc, https://hackaday.com/2019/01/18/oreo-construction-hiding-your-components-inside-the-pcb/ https://hackaday.com/2019/01/18/oreo-construction-hiding-you... Remember these are all from 15 down to 10 nanometer parts and at that size circuit complexity takes little space and since they live beneath other chips, they are hard to find with x-rays if there is a +5 and ground plane that hides them. Remember are 16 billion gates in an Apple M1 CPU, https://www.macrumors.com/guide/m1/#:~:text=M1%20Macs%20max%20out%20at,unparalleled%20CPU%20performance%20per%20watt https://www.macrumors.com/guide/m1/#:~:text=M1%20Macs%20max%.... A million gate parts is as small as a poppy seed and would need to have a fan out - perhaps they could have an optical I/O and live within the corporate data stream, only waking up when special complex command sequences occur and they read their RAM and do their job - back to waiting...
- dpkonofa 5y agoWhat a straw man! Coffee pods, automated litterboxes, dish washers, and all the rest don't carry an individual's entire digital life on them. You're literally comparing devices that really don't need any kind of security (other than, at worst, network security) to devices that demand privacy and security. This is either a disingenuous attempt to downplay the important of hardware security or an extremely ignorant analysis of the situation being described.
- 908B64B197 5y ago> Apple has hardened their hardware against attackers replacing components of the phone with compromised versions. It also hurts phone thieves. Once the device is locked up remotely it's impossible to sell, and you can't even sell the thing for parts since they won't work.
- MichaelZuo 5y agoThis. Every iPhone owner gains some tangible value from every disappointed thief. And this will rise as more and more of the userbase converts to totally locked down phones. Cumulatively over every user, that seems to be a huge value add.
- userbinator 5y agoIf you look back at the history of Apple you'll find they've always been authoritarian control-freaks, ever since the original Macintosh. This is merely another step in the same direction. The article even says that the repair shops have already found ways around it, so whatever element of "security" it provides is clearly extremely low. It only exists as a (low) bar against third-party repair, with "security" as an excuse. As the saying goes "those who give up freedom for security..." etc.
- posnet 5y agoExcept that the 'work around' does maintain security since it preserves the original FaceID chip assembly. "The most sophisticated repair shops have found a workaround, but it’s not a quick, clever hack—it’s physically moving a soldered chip from the original screen onto the replacement. "
- username190 5y agoI'm not convinced by this - if you look at an iPhone 13's screen, it's entirely separate from the face ID hardware. https://i.imgur.com/D63HrIT.png https://i.imgur.com/D63HrIT.png (screenshot from [0]) On iPhones X through 12, if you kept the Face ID hardware and only changed the display, Face ID would continue to work. On the iPhone 13 series, if you keep the Face ID hardware and change the display, Face ID stops working. The chip which people are removing seems to serve only to identify the display - nothing to do with the Face ID system. Apple has been using this chip for years to disable "true tone" display functionality when the screen was swapped (unless it was programmed by a proprietary tool, only available to first-party repair shops) - they're now also tying it disable Face ID. [0] https://youtu.be/8s7NmMl_-yg?t=253 https://youtu.be/8s7NmMl_-yg?t=253
- varenc 5y agoThe workaround requires physically moving the original chip to new phone screen. Assuming that chip is where the important Face ID stuff happens, this ensures the important component hasn’t been tampered with and would thwart the NSA hardware intercept attacks op mentioned. Can anyone confirm this chip is also where the Face ID profiles are stored/enforced? That said, I’m still doubtful this is entirely for security. What’s frustrating with Apple is that their moves to secure their hardware at every level also have the effect of tightening their stranglehold on the ecosystem. Unclear what the core motivation is.
- salamandersauce 5y agoThe security aspect is commonly brought up for justification for moves like this. Would something like this even remotely stop an actor with the resources like the NSA? Does this even remotely benefit people that are not being targeted by intelligence services? I'd guess no. Security benefits for most people don't outweigh the downsides. If they are so security conscious why even have FaceID at all? It's already been shown to be not that secure why not instead require users to enter a 15 digit password and use 2FA to unlock their phone instead? Is it that they value convienence over security in that case but not where it potentially loses them money?
- KingMachiavelli 5y agoIf Apple actually cared about security & privacy they would make iCloud et al. E2E encrypted but they don't. A sophisticated hardware attack is probably going to be government sponsored anyway in which case that government can just request data from Apple directly.
- dpkonofa 5y agoYou can care about security and privacy and also still care of ease of use. For 99.99% of their customers, encryption is enforced by default and being able to recover their data is more important than E2E encryption.
- superdude12 5y agoSo make it an option.
- chongli 5y agoMaking it an option results in people taking that option without fully understanding the consequences. Then those users forget their password and when Apple tells them it is impossible to recover their data they run to the local news station and Apple gets a black eye. Regular people see it on the news and stop buying iPhones. On the other hand, by not making it an option, Apple annoys power users and others at the extreme tail of the distribution. These users write about it in the tech press and Apple gets a black eye there… But Apple has always been criticized in the tech press so it doesn’t really change anything.
- varenc 5y agoIt is an option! https://support.apple.com/en-us/HT205220 https://support.apple.com/en-us/HT205220 I make encrypted iOS backups to my computer. Happens automatically when I plug in my phone. Data never touches the cloud. Also Apple does use E2EE for some iCloud backup data like Health, and Keychain (passwords). If you lose access to all of your iDevices you can't recover that data. I totally agree that Apple should just make all iCloud backup data E2EE. Given that users already lose some types of data from their backup when they lose the key, that doesn't seem like that much of a barrier. Supposedly the reason they're not all E2EE is because of pressure from the FBI[0]. But people like me that care can still have encrypted backups. [0] https://www.reuters.com/article/us-apple-fbi-icloud-exclusive-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
- 2OEH8eoCRo0 5y agoSo, we worry so much that the NSA will conduct a supply chain attack against an adversary (domestic surveillance does not fall under the NSA) that we further lock down our own devices?
- xet7 5y agoApple makes fixing even harder for authorized repair shops, than unauthorized repair shops: https://www.youtube.com/watch?v=v6025_yK02U https://www.youtube.com/watch?v=v6025_yK02U If Apple laptops internal harddrive gets broken, currently they can not boot from external harddrive: https://news.ycombinator.com/item?id=29083633 https://news.ycombinator.com/item?id=29083633
- deleted 5y ago[deleted]
- dreamcompiler 5y agoEverything Apple does in the name of security or privacy is about enforcing Apple's control over what you do with their hardware after you buy it. They give not one thin damn about your privacy: They want to know everything you're doing with your Apple hardware. Put a sniffer on your Mac and count the daemons phoning home to Apple. Your jaw will drop. As to the supply chain issue, microsoldering is trivially easy for serious adversaries, as TFA suggests. Apple just wants that sweet revenue stream from people who drop their phones. That's what they're protecting.
- Ansil849 5y ago> Apple has hardened their hardware against attackers replacing components of the phone with compromised versions. What specifically is being guarded against by not allowing users to replace a screen, as in this case?
- fomine3 5y agoIt was fair when Apple banned 3rd party home button(TouchID) replacement because it's sensor itself so it's natural that they should make tamperproof. But this case is FaceID. I'll accept they ban to replace FaceID module, but why they integrate security chip onto display module (say, most fragile part) despite it wasn't? It looks they aren't legit for me.