4 ms·
I made only a claim that there is no evidence that Apple provided encryption is secure, based on the absence of evidence for it. That's a negative claim. Pointi
by Veserv 5mo ago
I made only a claim that there is no evidence that Apple provided encryption is secure, based on the absence of evidence for it. That's a negative claim. Pointing out a standard argument is fallacious is a meaningful contribution.
You appear to have taken umbrage at me pointing out how your claims are unsupported and have already twice attempted to weaponize social norms to quash disagreement instead of presenting a argument.
> "If the only thing that will satisfy you is rolling your own encryption"
You have now made another fallacious argument by painting a strawman and then arguing that strawman is unreasonable and thus I am being unreasonable.
> "Nobody can demonstrably prove the security of Apple’s hardware platform."
You can, in fact, demonstrably prove the security of Apple's platform. I literally presented a uncontroversial criteria in my second response: "You need a competent, unbiased, third-party with demonstrated discriminatory power to support such a claim.". The key element here is demonstrated discriminatory power.
As you have implied that Apple provided encryption is secure against the NSA:
> "I don't see anything on the linked page that supports a conclusion that NSA has successfully broken the encryption at rest of an Apple device's storage since they introduced the secure element."
Please present a party who has previously ruled a system as secure against the NSA and was demonstrated to be correct. Hell, I will even accept it if you can present literally any technically competent executive in Apple who is even willing to claim their system is secure against the NSA, let alone actually proving it. If even Apple will not claim it, then there is no hope it is accidentally better than that as claimed by ignorant outsiders.
You will most likely then claim that the standard, which you yourself implied, is unreasonable as it has never been done. Which is, again, utterly false on multiple counts. First, standards drawn from objective criteria for success (e.g. secure against specific threats) are the gold standard of standards. Second, it has been done before, you are just ignorant of it.
The Common Criteria SKPP standard required NSA penetration tests until the NSA was satisfied that no defects would be discovered. The Common Criteria EAL7 standard requires a formal hardware specification with formal proofs of correctness, a standard generally believed to be "secure" and which I would accept if it covered the entirety of the hardware/software system. Absent that you need empirical demonstrations that specific security implementation choices consistently, empirically, and discriminatorily achieve the desired objective criteria for success.
Apple has done certifications, which they proudly present on their security page [1], to the absolute lowest levels of security you can even certify to. A level only fit for products where [2]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration attackers with a basic attack potential" [3]. A real vote of confidence in their implementations.
[1] https://support.apple.com/en-us/103027 https://support.apple.com/en-us/103027
[2] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf#page14 https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 14
[3] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf#page16 https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 16
- otterley 5mo ago> You appear to have taken umbrage at me pointing out how your claims are unsupported and have already twice attempted to weaponize social norms to quash disagreement. I was not trying to quash disagreement. I like healthy disagreement, provided it’s done so politely and respectfully. It is possible to make a valid point or offer a substantive correction and not be disrespectful or impolite about it. So I was trying to nudge you to disagree in such a way that conforms to the social norms of this site. You’ve read and accepted those norms, have you not? > I literally presented an uncontroversial criteria in my second response: "You need a competent, unbiased, third-party with demonstrated discriminatory power to support such a claim.” Lack of third-party vetting doesn’t mean it’s not secure. The food I grow in my backyard might well be healthy even though I didn’t have the agriculture department inspect it. You might feel better with validation, but that is a personal choice, not an objective requirement. On the flip side, third-party review doesn’t guarantee security, either. Consider how many third parties have blessed implementations of one thing or another over the course of history and how many times those opinions have turned out to be wrong later down the line. In any event, you’re still welcome to your skepticism. But it’s not an objective fact that the platform isn’t secure. It all comes down to an opinion and trust at the end of the day. I still trust Apple more than Microsoft to get this right, and so I’ll take my chances.