11 ms·
Apple's security strategy: make it invisible
- codyb 13y agoI would guess a lot of their security stems from their closed app store. Apparently the process is a total hassle, takes weeks, and each every revision is akin to releasing a brand new app. Perhaps they have application security testers breaking that code and ensuring it can not be broken into? Beyond their pruning of content they deem... not worthy of the Apple brand? I do not have an iPhone (or even a smart phone) so I am not exactly sure how downloads work. Can you download files to an iPhone from Safari or any other browser? If you can't then that certainly helps rule out a lot of malicious software possibilities.
- threeseed 13y agoYou're definitely wrong there. The process is not a hassle, it rarely takes weeks and yes every update has to go through the same approval process again (as you would expect). And yes you can download some files to your phone but they only exist within the app's sandbox. The reason iOS security is so strong is because (a) there is no side loading, (b) system updates are regular, simple and apply to almost every phone and (c) apps are heavily sandboxed. It's not magic. Apple simply chose security over openness and flexibility. Android vice versa.
- tluyben2 13y agoI notice that the process is speeding up, at least here (it seems country specific, which would make sense as an English-only speaker would not be able to check if a Dutch app contains illegal language etc). Two years ago (for me, in the Netherlands), it took minimally 2 weeks to submit an app; these days it takes days. And the feedback loop if anything is wrong is also small now.
- krrrh 13y agoExactly. It's been under a week for the last 6 months or so. http://reviewtimes.shinydevelopment.com/ios-annual-trend-graph.html http://reviewtimes.shinydevelopment.com/ios-annual-trend-gra...
- codyb 13y agoApparently at one point it took longer and now it is shorter. That's good. That was kind of my point that I was trying to make though. I definitely could have said it better but what I was going for was "It is a closed system." Android development seemed relatively sandboxed to me though from the distributed systems course I did work for in. But I can see what you mean when you say heavily as things on Safari don't open up the Wikipedia app like on Android (if you choose to have it that way.) iPhone's are literally only iPhones too which I imagine helps. The system updates are tailored to a specific piece of hardware. Impossible to accomplish on an Android update.
- kimlelly 13y agoThen again, there's the elephant in the room: Apple is one of the companies that work directly with the NSA. Should we accept "security solutions" from such a company?
- raganesh 13y agoJust curious. Which company would be apt to provide "security solutions", then?
- kimlelly 13y agoNone. That's the point. The only thing we can do to improve our situation is to migrate towards open-source operating systems (and software and encryption solutions).
- pi18n 13y agoThis is literally true and goes beyond security. I hope everyone who complained about Google Reader takes note of this; once you have the freedom to modify and rebuild you are trivially able to continue using your software long after the creators have shut it down.
- kimlelly 13y agoI'd even go further: Closed-source operating systems/software solutions are dying a slow (too slow) death.
- doe88 13y agoGiven the number of times everyday I'm asked to fill my iTunes account's password on iOS, I wouldn't call it invisible.
- ollysb 13y agoThe iTunes password prompt is absolutely maddening. If I make multiple purchases in iTunes it refuses to accept my password after the first purchase i.e. I can buy one film, but to buy another I have to restart. Never mind that I check the remember me box whenever I get the chance (which appears to be shown at random in the login box).
- Osmium 13y ago> The iTunes password prompt is absolutely maddening. Perhaps this is the reason for their supposed push to fingerprint scanners?
- k-mcgrady 13y agoAFAIK they actually made this worse due to the in-app purchase complaints (from parents who recklessly allowed their children access to their credit card). It used to appear for the first purchase and then not for the next 5 minutes (something like that anyway) but now it appears every time you try to purchase anything.
- panacea 13y agoComplaints? They lost a lawsuit and had to pay out because of in-app purchases. Incidentally, in-app purchases have practically spoiled their nascent status as the handheld gaming platform. In-app purchases make sense for certain things, but they've ruined the app store for gaming.
- k-mcgrady 13y agoI will never understand how they lost that lawsuit. If a parent gives a child access to their credit card they deserve what happens. I totally agree with your second point, IAP has spoiled gaming on iOS and that's the fault of the game devs for taking advantage of it. However if it didn't work they wouldn't do it and obviously plenty of people spend money via IAP. It's also their only choice. People are willing to spend more small amounts of money over time than paying a fair price up front for the game.
- esolyt 13y agoI have to say that I dislike the fanboyish tone of the article. "The theft of iDevices is rampant throughout the world. While we might blame Apple for producing such desirable products, the company clearly doesn’t want people to have to hide their devices in fake Blackberry cases to use them in public without fear." Thieves aren't stealing iProducts because they are desirable, they are stealing them because they are expensive. What the hell is a fake Blackberry case and why do I need it to be able to use my iPhone safely? What's the point of insulting Blackberry in an article about security? It's hard for me take this article or author seriously.
- myko 13y agoOn a site like macworld.com that tone is to be expected.
- windexh8er 13y ago"Then I realized that Apple was tackling a real-world security issue by trying to make that issue simply go away for the average user." -- While there are a few features that are generally good for users (activation lock seemingly the best one) the way iCloud keychain is ridiculously a bad idea. Since there is no concept of segregation of the ownership of the data and everything is very easily tied back to the owner the implications of using this aren't worth it IMHO. Do you really want Apple in control of your hardware, software and now access to your online identity (by access I don't mean that they can directly read your account information, but I'm not saying that is out of the question based on what we know about how our government operates within partners such as Apple)? Apple's (and Google's) limitless boundaries should be taking a majority by concern. Third party security tools are not a bad thing. Users should be interested in understanding and learning at a level that is parallel with the risks they are taking online. This is the part that is breaking down and Apple is "solving" this for those users by further locking them out-of third party software through feature bloat. I'm surprised at the complacency Rich avoids this topic, it truly feels like a paid for point of view post. I own Apple hardware but I find myself using it less and less in my support of transparent 3rd party tools that help, not hinder, me to control my data. I'm glad the open laptop post sits above this one. To me that's an indicator the masses here are on the same page.
- _djo_ 13y agoThose of us with the technical understanding to be concerned about security should already be using third-party tools like 1Password, LastPass, etc. I doubt there'll be a massive out flux of those who use those tools to iCloud keychain. What iCloud keychain does bring is much better security for the other 99%, encouraging them not to re-use the same password across all their sites and to choose good passwords by default. When I see how difficult it has been to get other members of my family to adopt 3rd party password management systems I can only see that as a good thing.
- windexh8er 13y agoI would concede that you're right, however Apple doesn't provide a construct for the 99% to "do it right". Yes, there will always be those that blindly trust, however when you start talking about a master umbrella for an indivdual's complete, and utter, online presence including physical ties to money, property and other assets it shouldn't be taken lightly. If Apple had provided a "just works" method of showcasing how they cannot ever, without a doubt, decrypt the data while it sits on their servers, or offer up a way for the end user to easily leverage another service (for seperation of duties) they wouldn't receive the flack they do from those who inherently know the risks. I have had no problems getting family members to adopt 3rd party password tools. An hour showing them along with explaining the rationale and the light bulb switches on. A simple document showcasing how to generate new passwords and add new sites or services goes a long way for the few times they do that particular task. The root problem is that the 99% seems to be ignorant, not because they want to be, but because someone hasn't talked them through it. I find that pointing family to pages or videos is far less effective than me, personally, explaining things. Not sure why - but it's far more effective (maybe because they know I've actually taken time to show them vs just point them). I still view iCloud as a bad idea and wouldn't recommend it to anyone I know.