4 ms·
I think your worry is this: this capability means Apple can turn on and install arbitrary software whenever they want. Wood you be ok if this capability could
by MarkSweep 3y ago
I think your worry is this: this capability means Apple can turn on and install arbitrary software whenever they want.
Wood you be ok if this capability could only be activated at super-closer range (wireless charging range) and only worked on iPhones that have not been activated?
We don’t know if that is how this works, but I would be comfortable with this feature if that’s how it works.
- raverbashing 3y agoYes And that's obviously how it works. Maybe it will then enable wifi instead of sending data through wireless charging but that's it. And then it would turn itself off. Still what you can do is what Apple could do before putting it into the box. Again, obviously I fail to see how this is concerning (to put it politely)
- QuercusMax 3y agoThis seems really easy to implement , IMO. Here's a world where this basically already works: * When an iPhone comes from the factory, it's not really off-off, it's just in standby mode. Probably true to some extent in any case? * If battery is above 50%, try to connect to a special Apple Store wifi network with a known signature. (Wifi has to have this kind of feature, right?) * If you're connected, check for updates and apply any that apply. * Go back to sleep. Easy peasy. Bonus points if you can wirelessly charge them through the box, but honestly apple stores probably go through enough product it doesn't even matter.
- crazygringo 3y agoAFAIK it's off-off. Any kind of standby mode that was monitoring WiFi would drain the battery after some number of weeks, and Apple doesn't want consumers to open their box to a phone that won't turn on until it's charged. And phones can definitely sit around for many months, at the warehouse and the store.
- diffeomorphism 3y agoThat is how you would like it to work, but we have learned time and time again that "obvious" does not mean all these safeguards are actually implemented or bug free. So what you get is a mechanism that wirelessly, without any confirmation, modifies the software on your device and "only" requires proximity. That seems like a great angle of attack for malware, surveillance, cracking a stolen phone,... . You are free to believe that apple implemented this perfectly bug free, but I would not be surprised if we get a CVE related to this in a few years.
- raverbashing 3y agoYour worries are valid, but thankfully Apple security architecture is better than your average left-pad enjoyer. Sure, it is possible there will be security implications. > that wirelessly, without any confirmation, modifies the software on your device and "only" requires proximity Running an update is different than "modifying the software". It is possible that such an update just wipes everything on the phone as well
- MBCook 3y agoHow would it wipe everything on the phone anyway? There’s nothing on the phone. It’s brand new and in the box. Apple clearly take security very seriously. There’s no way this would be left enabled after someone sets up the iPhone.
- awesomeMilou 3y agoJust.. how it is.. with any other device and OEM service..? I don't get it? What do you think does Samsung do when you send over your device for repair? Ever got asked for a passcode by them?
- diffeomorphism 3y agoLuckily the post explicitly stated how it is different and you can even read it again.
- butlike 3y agoI walk into an Apple store with my device masquerading as the Apple update endpoint, and update the phones with some arbitrary payload to pwn your device before you even open the box? idk if it's possible, but seems plausible.
- BenjiWiebe 3y agoApple might not be willing to give you their private key to sign your updates with.