5 ms·
Of course, just as America likes to spy on everyone as well. But let's not completely pardon Apple, they can always do something more to strengthen their system
by selmnoo 12y ago
Of course, just as America likes to spy on everyone as well. But let's not completely pardon Apple, they can always do something more to strengthen their systems to be more and more resilient to these attacks. It might well be a cat and mouse game, but they should at least try and play rather than just give up. They're sitting on hundreds of billions of dollars, they get hundreds from many of us, the least they can do is look out for us a little more.
- preek 12y agoI'm not saying security is not an important issue. Inherently it is. The problem is that Apple is using the industry standard for encryption here (SSL). China cracks that security by giving their folks a browser that allows them to easily swap the certificate out and send all the data to them before sending it to Apple. This is called a MITM (Man In The Middle Attack). Personally, I'm a big fan of privacy - also I'm the CTO of a web-company, so I'm concerned with security for webapps, too. When users are ignore warnings of their browsers (what Firefox would do in such an event) or even install a "trojan browser" by a mean government - well, then there is little you can do as a company. Just wanted to give a short TL;DR on the article to prevent an icloud shitstorm on HN, because the article is really on how mean China is. Not saying or implying at all that other governments are better. Also not saying that Apple is perfect in terms of security. Btw, as developer and sysadmin I'm using Debian stable - my Mac is for convenience and productivity. Just saying that to disqualify myself as the regular fanboy(;
- foobarfizzbuzz 12y agoYour arguments are relatively helpful and good, but no one cares that you are a CTO. Your post would've been just as relevant have you said you're an engineer/developer/work in tech or not even mentioned your position. I hope you don't take offense to this, but it just seems `cocky` when people act like that.
- preek 12y agoThank you for your feedback. I apologise, because I came over as cocky. I did make that statement to emphasise that the content has some base; I explicitly didn't mention which company or any other credentials on my behalf. I could have written that I'm a developer, but it wouldn't have been true, because most of my time is spend in other areas. I neither wanted to insult or boast, so my sincere apologies since it came off that way.
- ximeng 12y agoSaying you're a CTO of a company just came across as useful background information to me, but I guess different people have different interpretations.
- Jare 12y ago"I'm a CTO and that's why what I'm saying is correct" <- cocky "I'm a CTO and that's why this is important to me" <- absolutely relevant I think you are 100% in the clear, but you win extra points for humility (sp?).
- mattdeboard 12y agoAct like what? Why should he conceal his position? This comment makes absolutely no sense. If anything, with this comment, you're projecting your own feelings onto preek's comment and trying to hold him accountable for that. Being a CTO isn't a bad thing and there's no reason to insist he conceal it because it makes you feel bad.
- owenmarshall 12y agoWhat do you expect Apple to do in this case? What action can they take against a government-performed MITM? Seriously "they've gotta do something" sounds good but I'm not sure what options they actually have. If the user clicks through a clear SSL warning, that's Apple's fault?
- selmnoo 12y agoHalf our industry is built on fooling users. Exploiting their cognitive biases. Seriously, we understand where they fall, and if we really wanted to, we absolutely could look out for them -- at least, certainly better than we're doing right now. Your response is like saying when Facebook was privacy zuckering (http://darkpatterns.org/library/privacy_zuckering/ http://darkpatterns.org/library/privacy_zuckering/), the user clicks right through the settings that should have sounded an alarm. What can Apple do? They could make a better browser (I like how Chrome and Firefox do things - you have to go out of your way to reach a page with bad SSL -- compare Safari's rather passive and enabling error message: http://blog.serverdensity.com/wp-content/uploads/2009/05/ssl-error.png http://blog.serverdensity.com/wp-content/uploads/2009/05/ssl... vs. chrome's: http://i.imgur.com/ttmmDJ8.png http://i.imgur.com/ttmmDJ8.png -- you have to REALLY see and think how to access the site despite the warning, it's that good). They could be more vigilant in alerting users of where and how this can happen. If we were talking about any other young startup, your apology might fly -- not so with Apple, they're sitting on billions, they have the resources to think of a solution and implement it.
- owenmarshall 12y agoI'll buy the argument that the industry has a duty to protect users, and also that Safari could be designed to better warn about SSL. > Your response is like saying when Facebook was privacy zuckering, the user clicks right through the settings that should have sounded an alarm. This is a bit odd, though. On one hand we have a company directly attempting to trick users; on the other, we have a company whose product is being attacked by a hostile government. Drawing an equivalence between the two is a bit ridiculous, no?
- 12y ago