3 ms·
A jailbreak is not something Apple (or whoever) allows, it's a (serious) security vulnerability being exploited to gain root level permissions on the device and
by error503 3y ago
A jailbreak is not something Apple (or whoever) allows, it's a (serious) security vulnerability being exploited to gain root level permissions on the device and then circumvent whatever checks are in place. These are things that should be fixed. It's also a cat and mouse game that is always changing.
> Does Apple have something like a "key" that would allow you to just run arbitrary software on the device? Is it something they would have to build, support, and maintain? I'm guessing this isn't a problem on Android and you can run whatever you want.
Not sure about the specifics of Apple's architecture (as it's also undocumented), but most modern secure boot systems have a hardware public key store (TPM) that any boot binaries must be signed with. Apple would closely guard those keys, and without them (and without security flaws), it is impossible to boot other code. Once you get a bit further along into the boot process, the architecture gets much more complicated as far as actually running apps, but it's all predicated on that secure boot key. Such a key store is probably possible to change, but Apple doesn't give any access to it from the userland, so users are unable to do so. It's also possible to make such a verification completely unchangeable in hardware; not sure if Apple may do it this way.
An open system would look something like UEFI secure boot, where the owner of the system can manage the keys in that hardware key store, to the extent of removing the manufacturer's keys entirely (which I think is also an important ability - what if I don't want Apple to be trusted on my device?). From there you can patch the OS to allow other code to run, though preferably this is something that would also be opened up explicitly.
Yes, it will require intentionally designing those capabilities into the products, but most likely it's not a significant architectural change, just a matter of giving users access to change the keys in the hardware they own.
- ericmay 3y agoYou said it didn't need to be easy to run arbitrary code. Why would security not fall under that purview? You can jailbreak your phone and run arbitrary software on it. If there are security problems that's kind of your problem that you introduced by running your arbitrary software. How would Apple/Google be able to monitor malware here? How do we know that the secure boot key for example isn't part of the security architecture and by giving it out you basically enable those root level permissions? Are we really trusting users to not lose or compromise secure boot keys that they manage on their own? If grandpa gets scammed out of his life savings are taxpayers footing that bill? I'm not necessarily looking for answers to those questions, but it really just seems like there's a lot of open items here that have to be addressed for not a lot of benefit and instead it seems like people just want an effectively jailbroken iPhone that's somehow secured by Apple/Google more easily.
- error503 3y agoI'm not sure what you mean? The only reason jailbreaking is possible is because it's a security flaw. A secure device can't be jailbroken, and we should all have secure devices. Regardless, this is far from a sure thing, opens you to 'voids your warranty' bs from the manufacturer or even bogus DMCA paper terrorism. I'm saying it should be a legally enshrined right with no ambiguity. Security is about trust. If you trust Apple or Google, and don't care about their 30% tax, then you should be able to choose that. Make it the default, even. But if you don't trust them, and don't want them to control what runs, that should be your choice too. It's your device for fucks sake! "Security" is a weak argument for unconditionally giving up all control over your own device. Especially when that control is very obviously being used against us by those very same that are claiming to protect us. The situation is reminiscent of countless dystopian novels. If we're going to accept that anyway, I think it needs to come with much stronger protections for the common good in other ways than vague and pretty bogus "security" arguments. If they want lock in, I think they should have to operate the platform on a cost basis, and with strong antitrust protection in exchange for that privilege. Most Windows PCs allow users to enroll keys in their secure boot system. Do you hear about grandpa getting his life savings stolen by this mechanism often? I certainly haven't. Much more likely he lost it to social engineering, where no technological measure is going to help you.