8 ms·
completely insecure if you are not the only one with the key
by zaxbeast 5y ago
completely insecure if you are not the only one with the key
- sys_64738 5y agoWhich key?
- zaxbeast 5y agoThe secret key that Apple holds?
- diontron 5y agowhich is literally the case for any security system lol
- zaxbeast 5y agoYet companies still try to convince you otherwise...
- BoorishBears 5y agoShow me where Apple says they protect against attackers who already have your passcode.
- zaxbeast 5y agoThat's not what I was talking about... secure boot and locked boot loaders are "protected" with keys held by manufacturers...
- BoorishBears 5y agoThen your comment doesn't make sense? You wrote: > completely insecure if you are not the only one with the key What key is shared between you and the manufacturer here? There's signing keys and there's passcodes, which ones are you "not the only one with"?
- zaxbeast 5y ago> BoorishBears - What key is shared between you and the manufacturer here? There's signing keys and there's passcodes, which ones are you "not the only one with"? because you don't even have the key? not sure where passcodes came from
- BoorishBears 5y agosigh > completely insecure if you are not the only one with the key This implies you are referring to a key that the user has. What key does the user have? A passcode? Password?
- HunterWare 5y agoHow do you secure something when other's know the secret? There has to be some "secret" (aka key) that some definition of "you" only knows, that the system then tests against (hopefully via some kind of asymmetric system or hash).
- rovr138 5y agoPublic/private keys? In this case, since others already know it, signing something is sufficient.
- HunterWare 5y agoYep. The signing is done with public/private (aka asymmetric) keys and some kind of hashing mechanism.
- KerrAvon 5y agoThe private key held by Apple and used to sign code from Apple? Yes, this is how modern crypto works. Some useful background reading: https://www.schneier.com/books/applied-cryptography/ https://www.schneier.com/books/applied-cryptography/ .
- lovelyviking 5y agoThe OP statement was about insecurity that comes with signing code with anyone other than the owner. It doesn't matter how secure communication between Apple and Apple device because even if it's perfect the owner is not secured from the Apple itself and those who Apple would love to communicate with. For instance oppressive governments. (here the result of such communication: blocked app that oppresive government didn't like https://apps.apple.com/us/app/%D0%BD%D0%B0%D0%B2%D0%B0%D0%BB%D1%8C%D0%BD%D1%8B%D0%B9/id918148289 https://apps.apple.com/us/app/%D0%BD%D0%B0%D0%B2%D0%B0%D0%BB...)
- xoa 5y agoFor the record, I'm in favor of legal mandate that hardware owners have the buy-time option to enable adding their own keys to any root trust stores on their devices. However, that'd be in addition to Apple's keys and wouldn't be about the security of Apple's keys, because Apple is part of the fundamental trust foundation if you buy a Mac or iDevice. Period. The devices are massively vertically integrated, right down to the core silicon which is completely custom. Apple has absolutely unfettered ultimate low level access opportunity up and down the stack. If you completely don't trust Apple, then you absolutely should not use their hardware at all. So some level "trust Apple" is simply a security axiom on this platform. And they've shown that to be not unreasonable at least when it comes something like root private keys. Fact is they've been operating for a long time now and like the rest of the big players that hasn't been a leak issue. It's not that big a deal for a big player to physically secure such things to a high enough degree that it's unlikely to be a limiting factor. Dedicated rooms, full offline, hardware backed Shamir's secret sharing for m-of-n key signing ritual requirements etc etc.
- lovelyviking 5y ago>If you completely don't trust Apple, then you absolutely should not use their hardware at all. So some level "trust Apple" is simply a security axiom on this platform. It is not about trusting Apple or any other company for that matter. It is about tendency and attempt to make it a norm/legalize to sell personal computers without respecting right of the owner to have a full control over their own computer. If owner cannot fully control own computer this computer cannot be called 'personal' anymore. This practice needs a push back as it completely unacceptable. It should be made illegal to sell such devices if that is not already the case because you can be left without working computer just because link to the company isn't available for some reason. Company goes away and you are left without a working computer. Internet isn't available and you have brick instead of your computer. This is crazy and even more crazy that there are bunch of people brainwashed enough to the level that they do not even perceive it as a problem. Probably because they can't think 3 steps forward.
- GeekyBear 5y ago> It is about tendency and attempt to make it a norm/legalize to sell personal computers without respecting right of the owner to have a full control over their own computer. If owner cannot fully control own computer this computer cannot be called 'personal' anymore. I have bad news about Intel CPUs. >[Intel] processors are running a closed-source variation of the open-source MINIX 3. We don't know exactly what version or how it's been modified since we don't have the source code. We do know that with it there Neither Linux nor any other operating system have final control of the x86 platform. https://www.zdnet.com/article/minix-intels-hidden-in-chip-operating-system/ https://www.zdnet.com/article/minix-intels-hidden-in-chip-op...
- jeff_vader 5y agoIt really depends on the threat you are planing against. If for some reason I'm target of US government - I'm screwed anyway. If my concern is trusting the laptop after I left it in train station and got it back from some random dude - it's good enough.
- microtonal 5y agoAdditionally, many of these security measures are put in place to prevent that rootkits/malware can compromise the firmware, boot loader, or operating system.
- lovelyviking 5y ago>It really depends on the threat you are planing against. What about oppressive let's say Russian government while you travel let's say in Ukraine and then occupation occurs. Not a fantastic scenario by the way ... It really doesn't depend on the threat at all. It's about the model of the society you wish to have and what values you promote. It's about who you wish to be responsible : the 'big company' caring about your safety and taking your freedom on the way or you caring yourself about own safety and preserving freedom on the way. I do not really think there is a choice here because the first option will always be abused at some point. Freedom does matter and it comes with responsibility. THIS is the main issue here. THIS is what separates society with responsible citizens from the society with 'irresponsible people' who wish to trade their freedom for 'safety' resulting in loosing both (and democracy itself after some time).
- hraedon 5y agoAll sentiments like this one and those similar to it elide the facts that 1) we’ve tried relying on “user responsibility” before, and excusing the comically bad outcomes through victim blaming doesn’t change them; and 2) we didn’t get together and vote Apple the only manufacturer of computers. If you don’t like their model, choose someone else. Why should average users who would otherwise be served perfectly well by Apple’s solution be required to be “responsible” for some subset of personal security you think denotes a “responsible” citizen from an “irresponsible” one?
- kmeisthax 5y agoWell, if you want to distrust Apple software you probably shouldn't be trusting their hardware, either. That being said, I actually think this is a reasonable way to do secure boot. The default OS the device ships with can be validated, but there's still a proper owner override so you can boot into Linux or whatever. They even use the SEP to validate that the owner override has been tripped by the owner. The first user account you make gets handed a key generated by the SEP that can be used to sign kernels, so only that account can actually use the owner override. This is a good way to stop evil-maid attacks in their tracks while still not locking the user out of their property. My only real complaint is that Apple's gone to great lengths to ensure the iOS side of their business is completely unaffected by owner overrides: - If you boot into an owner-signed OS volume, macOS disables it's iOS support - iPad-fused M1s won't generate or respect owner keys This is silly. If individual iOS applications are sensitive to owner overrides, then they already have devicecheck APIs to get a cryptographic attestation that they haven't been tampered with. The SEP could flag those attestations as coming from an owner-signed kernel and picky banking apps[0] could check for that. [0] And Pokemon GO, because it's easier to blacklist jailbroken users than to enforce a rate limit on GPS jumps