4 ms·
One thing I'm curious about is the DOJ took specific aim at Apple Pay and how Apple was creating a monopoly by limiting third party apps from making payments. I
by bdzr 2y ago
One thing I'm curious about is the DOJ took specific aim at Apple Pay and how Apple was creating a monopoly by limiting third party apps from making payments. I'm personally a bit torn, because it seems like the preventing third party apps from accessing the secure enclave is a security feature.
- jonny_eh 2y agoCan't each app have it's own section of it?
- L-four 2y agoApple could of allowed payment providers build payment services/plugins within their walled garden to preserve control and security. But they want their 30% so now the government is gonna come in and haphazardly create rules to enforce competition.
- jszymborski 2y agoThere are no bike thieves in a police state, etc...
- redeeman 2y agoyou might want to look up bike theft statistics :)
- iansinnott 2y agoI don't see why granting access to an app would grant full access to the whole thing. I.e. similar to how apps don't get full filesystem access. I also know nothing about how it's implemented though.
- okanat 2y agoSecure enclave doesn't have to be single software locked thing. They don't have to give every app unconditional access to securely executing code either nor giving access to other apps' data. Users can choose just like they choose their camera permissions to access RFID / NFC and each wallet can get a prioritized access to those services.
- senorrib 2y agoAfaik, the security enclave is treated as if it was owned by the manufacturer, not the consumer. It's also used for DRM, which is arguably anti-consumer, and giving any app access to that would effectively reduce the strength of DRM.
- bloppe 2y agoThere is no "accessing the secure enclave". Not even the iOS kernel itself can access the secure enclave. That's the point. It's designed to keep your biometrics and private keys safe even when the entire OS is compromised. It's also not completely relevant to third party payment processors. They don't have to use the secure enclave at all. They could theoretically just ask for your credit card info every time. They're not allowed to do that currently for no other reason than Apple's bottom line. For convenience, they'd probably want to store it encrypted on your device, using a private key from the secure enclave to decrypt it when you pass the biometrics test. That's the normal level of "access" to the secure enclave that all apps should have. It's in no way concerning because private keys and biometrics never leave the enclave, but can still be used to decrypt data elsewhere on the device when the biometrics test is passed. It's the whole reason why the secure enclave exists in the first place.
- standardUser 2y agoSecurity features are security features. Blocking interoperability and calling it a security feature is a marketing technique.
- kjkjadksj 2y agoYet at the same time, I can go to the 7/11 and open my wallet and use whatever form of payment I want, secure enclave be damned, and the sky doesn't fall. I can go on the internet on my macbook and use any payment form I want on any service, secure enclave be damned, and the sky doesn't fall. I would think everyone on this website is tired by the nanny state that Apple has created on iOS. If the argument is security that's fine, just let us power users who know what we are doing toggle this off and actually use our hardware to do what we'd like with it, short of waiting with baited breath for a teenager in eastern europe to give us a jailbreak that lasts for a week before patching.
- merrywhether 2y agoI’d always thought “power users” toggled this type of stuff off by switching to Lineage or similar and having full control.
- kjkjadksj 2y agoYou can't install lineage OS on an iPhone. The answer to gaining control shouldn't be to buy different hardware when you have perfectly good hardware capable of also offering that control.
- Dah00n 2y agoYou can't install it on an iPhone and on Android it doesn't pass SafetyNet, IE. no more payments, no banking apps, no national ID apps, no drivers license app, etc.
- makeitdouble 2y agoIf security is the only talking point ever, Apple is also lowering it's OS security by constantly adding new APIs (= more attack surface) or accepting third party apps in the first place. It's a trade-off, and it can't be fine when it benefits Apple, but nonnegotiable when it benefits the others.
- veeti 2y agoGenerating and using keys held in SE is already a public API available to third party apps.