5 ms·
Why is it on Apple to defend everyone against hackers sponsored by another country to begin with? The governments should be providing any resources necessary to
by andersa 3y ago
Why is it on Apple to defend everyone against hackers sponsored by another country to begin with? The governments should be providing any resources necessary to defend here...
- zozbot234 3y agoBecause Apple makes the phones, silly. The iPhone is a 100% proprietary device, we know zilch about what code is running on it. Why should anyone be responsible besides the manufacturer? Maybe the government should care about the Obamaphone, but not anything beyond that.
- kube-system 3y agoClose to 100% but not quite. It has some open source components.
- saagarjha 3y agoNSO Group seems to know quite a bit about what code is running on it.
- austhrow743 3y agoIf an Israeli hit squad kills someone in a McDonalds, we dont get on McDonalds case for not providing a safe and secure place for their customers. Not putting up a sign when the floor is wet is on them. Assassins is on the government. It's not clear to me why things being different in the software world is so obvious that not seeing why is silly. Regarding Obamaphone, in the US there is a government agency responsible for such things. The NSA. It's tasked with securing US information infrastructure on top of its more known role of signals intelligence. It just happens to favour the latter over the former so its not about to share its stockpile of iPhone zero days with Apple.
- ameister14 3y agoIf McDonald's advertised their hamburgers as especially safe from outside influence and you are assassinated by someone poisoning your McDonald's hamburger, people will probably be upset at McDonald's.
- insanitybit 3y agoApple is welcome to seek aid from the US Government, I imagine they would be happy to assist.
- Dah00n 3y agoThe US government have already "assisted" plenty. Every assist is a setback. IE. Snowden's revelations, encryption standard weaknesses, backdoored devices, etc.
- insanitybit 3y agoObviously not what I'm talking about.
- jacquesm 3y agoNo, but that is exactly why Apple might be a little bit reluctant to go for assistance. It's a bit like going to the neighborhood burglar to ask him how to secure your house. "I'll be right over to take a good look at your property" is not the answer you think it is.
- insanitybit 3y agoThat's an absurdly narrow view of the USG security positioning. USG pours billions of dollars into defensive infrastructure through a number of methods.
- jacquesm 3y agoPouring money into it is something else than asking them to look into your secret kitchen.
- jonathanstrange 3y agoThat's the question, though. The NSA is known to have strongly conflicting objectives. On the one hand, they're supposed to secure US government devices and sometimes assist US companies in securing devices. On the other hand, they're supposed to surveil foreign citizens using such devices and the devices of US citizens who communicate with foreign citizens, as well as assisting other US agencies in doing that. In a nutshell, whether they will increase or subvert your security depends on factors outside of your control. But unless they have found ways of surveilling foreigners without compromising the security of any Apple device, it's almost certain that they won't disclose their own 0-day exploits to Apple.
- Veserv 3y agoBecause that is what they advertised they would do [1]. “Apple makes the most secure mobile devices on the market. Lockdown Mode is a groundbreaking capability that reflects our unwavering commitment to protecting users from even the rarest, most sophisticated attacks,” said Ivan Krstić, Apple’s head of Security Engineering and Architecture. I mean, we know nobody on their team actually believes Lockdown mode can protect against state funded actors with even a tiny $10M budget since their Lockdown mode total bypass bug bounty is only $2M. But they did say it in their marketing, so they should be held to it even if we know for a fact that they are totally incapable of doing so. This is not a question of money, it is a question of ability, and we know they do not have that. [1] https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/ https://www.apple.com/newsroom/2022/07/apple-expands-commitm...
- zozbot234 3y ago> Apple makes the most secure mobile devices on the market. Well, they're not wrong on that one point. As it turns out, "most secure" is a pretty low bar. We'll see how Purism's Freedom Phone fares once it reaches genuine daily-driver status and it too becomes a target for this class of attacks.
- kube-system 3y agoBeing open source doesn't mean immune to vulnerabilities. (and Purism's stuff will likely never be 100% open source due to regulatory complications with basebands) Niche software often fares very poorly in terms of security because few people are trying to exploit it.
- charcircuit 3y agoPureOS is decades behind in security compared to Android or iOS.
- anthk 3y agoPureOS with Flatpak, Wayland and such make it close.