6 ms·
iOS, the Future of MacOS, Freedom, Security and Privacy
- karimdag 8y agoI am no connaisseur, just a guy who cares about privacy (in general and his in particular) who also happens to own an iPhone and wants to buy a Mac. This seems pretty troubling, as I as well as many I suppose, trust Apple and think that they're one of the good guys. I know it's cliché but I think this is the part where "[..] live long enough to see yourself become the villain." applies. The more important question, imho, then is: what can we do about it ? If nothing, what should be done ?
- unstatusthequo 8y agoWhat do you do? Windows world is worse. So is Android generally. Use Linux? How do you trust that? QubesOS? Pen and paper? If you walk outside, you’re on camera. Living off grid with no phone or computer seals the deal, but not very practical. I’m all about security and privacy, but everything is on balance with practically. If a three digit govt agency wants to find you, they have so many other ways than Apple.
- nixpulvis 8y agoWhy not trust Linux? No activation, full control over all the processes. Seems like a good solution for people who "care".
- Rjevski 8y agoUser experience and usability.
- nixpulvis 8y agoSure, but that has nothing to do with the notion of trust we're talking about here.
- irq 8y agoPerhaps, but if poor UX prevents a user from using an ostensibly more secure platform, then security of said platform doesn’t enter into the consideration at all.
- nixpulvis 8y agoYes, we're all well aware. That's NOT what I'm talking about though. I'm responding to "Use Linux? How do you trust that?". Please think about things before aimlessly countering someone's question.
- boudin 8y agoThat has nothing to do with trust and is highly subjective.
- andromeduck 8y agoIt's good in theory but in practice you'd need to spend a lot of time and money doing deep audits yourself, both hardware and software. That just really isn't a worthwhile investment for the vast, vast, majority of people. At the end of the day it all still boils down to trust based on reputation, incentives and oversight. Openness is important but no panacea.
- nixpulvis 8y agoWell at least the surface area of the audit is a LOT smaller than on macOS, Windows, etc.
- andromeduck 8y agoI really doubt that's the case if you use more than a few small apps which is the case for the vast majority of users.
- nixpulvis 8y agoMust I link a running process list of my Linux laptop vs my macOS laptop?
- davewritescode 8y agoHow do you know the process list is accurate for certain? The point is, there’s potentially back doors in everything, including the C compiler that built your Linux kernel.
- nixpulvis 8y agoWe've all read reflections on trusting trust... still my point stands, it's hard to argue that Linux is not lighter than the mainstream OSes.
- userbinator 8y ago
- r00fus 8y agoIt's not that you shouldn't trust it, it's that you could from security perspective easily shoot yourself in the foot. Does anyone know of a distro that focuses on usability and privacy"? Subgraph is still in alpha...
- nixpulvis 8y agoEither trust yourself, or trust someone else. (of course it's generally impossible to avoid some amount of trust in others.)
- gsnedders 8y agoHow many distros are shipping with ASLR now? Last I knew there were still major distros that weren't. Heck, do the common DEs sandbox their search indexing processes yet, given there's been various vulnerabilities there previously? Yes, okay, you have control, but when nobody implements relatively basic defence-in-depth mitigations that have been available on Windows (especially) and macOS for over a decade it's just sad and undermines the argument that its security is better.
- karimdag 8y ago> I’m all about security and privacy, but everything is on balance with practically. If a three digit govt agency wants to find you, they have so many other ways than Apple. Can't argue with that.
- userbinator 8y agoWindows before Vista/XP is quite good in terms of privacy in the "phones home" sense --- no activation and a fresh default install will remain absolutely quiet on the network. Activation started with XP (but easily cracked), and then Microsoft began increasing the noise and phoning-home crap shortly after that. I find it ironic that one of the features removed starting with Win7 was the network activity indicator in the system tray. Of course, recent Apple hardware and software has no indicators either. The opaqueness is unsettling.
- michaelmrose 8y agoThis is a false dilemma. If you walk outside and must necessarily put up with shopkeepers rights to record their premises we don't in turn invite people to publicly accessible webcams in our bedrooms/bathrooms. I'd say you use as much privacy respecting hardware/software as is feasible given your present use case and circumstances and progressively look to improve this situation funneling your money towards people and projects that respect you and your privacy in order to encourage people to build the things you need. If you already have expensive hardware that doesn't work with open source software I don't think it terribly reasonable to suppose you throw it in the trash for example. Just buy something better next go round.
- stuartd 8y agoHow old is this? the state and details of disk encryption on both OSes is slightly unclear, but hopefully will become clearer when iOS 10.3 is released. 10.3 was released 9 months ago. And I find it hard to take seriously any article where every other sentence is bolded.
- stuartd 8y agoAnswering my own question - the original gist was posted in March 2017.
- dang 8y agoOK thanks, we'll add that.
- seltzered_ 8y agoHaven't RTFA, but my judging that the link is Andrew Desantis's fork I'd guess there's interest by the submitter in gauging interest in his Deos project which leverages the darwin kernel. I feel like one may have to understand his preferences towards bitcoin, libertarianism, etc. though to truly get the deos vision to discern whether it's actually a better solution or a sleight of hand. I don't follow desantis or the bitcoin community closely enough to know.
- saagarjha 8y ago> macOS devices to date lack any form of verified boot process Before iMac Pro, I’d guess.
- 8y ago
- LeoPanthera 8y agoWhen the iPhone was new, Apple wasn't fighting surveillance society. They were mainly fighting carriers forcing you to buy shitty locked-down phones preloaded with as many monetization tools as they can fit in them. So a lot of the basic security of iPhone OS, as it was originally called, was supposed to stop your carrier from fucking it up. That legacy continues today, even though Apple is pivoting to a "privacy is the product" model. I suspect a lot of these criticisms are a byproduct of that legacy, and not necessarily a sign of trouble in the future. I still trust Apple - but Apple will have to continue to work hard to maintain that trust.
- dcow 8y agoDoes anyone have a pastebin copy or something? I don't log into gh on my phone and gists are behind a reg-wall now...
- gruez 8y agohttps://gist.githubusercontent.com/desantis/5728d5536b6dfe37e781c0a4a0f32e54/raw/985c2b476d5b0baa4ce8e9fc5fcc4ff433652b69/iOS,%2520The%2520Future%2520Of%2520macOS,%2520Freedom,%2520Security%2520And%2520Privacy%2520In%2520An%2520Increasingly%2520Hostile%2520Global%2520Environment.md https://gist.githubusercontent.com/desantis/5728d5536b6dfe37...
- acdha 8y agoIt loads on mobile Safari without a login. Do you have any browser extensions which might be causing that?
- saagarjha 8y ago> gists are behind a reg-wall now I've never encountered this behavior. I can load this fine when logged out in Safari.
- eridius 8y agoYou can't create gists without an account anymore, but there's no account requirement to simply view them.
- saagarjha 8y agoWow, this was a long article, so let me try to unpack it: > iOS devices (even non-cellular devices) on first boot and, occasionally for unclear reasons after OS upgrades, will require “Activation” and an internet connection to contact an array of Apple servers. The linked patent says that this is for carrier locking. It's possible that the code is used even on non-cellular devices because they just found it more convenient to not remove it? There might be more to this; maybe it allows for something like Activation Lock to work or allow Apple to track stolen inventory. > Apple links the credit card used at purchase, the purchaser's name and email, and of course, the serial number and all components required to generate a UUID Of course they do; these are all components of an Apple ID, so it would be impossible for them to keep them apart. > This means, for example, that if you were to use a certain app for a social network under a pseudonym on an iOS device (not that I would recommend installing any social networking site’s apps on your device) and that service sends information via APNS, Apple (and possibly the social networking service) can most likely link the pseudonym account to your real identity. I'm not very familiar with APNS, but doesn't it work something like "social media server sends Apple message, and Apple forwards it to the right device"? How would device-specific information get to third parties? > if you enter contacts into the address book, contacts’ details are hashed and automatically sent to Apple, supposedly to check for presence in Apple’s iMessage database to determine whether to show iMessage as an option on that contact’s page I agree that this is a stupid decision. This is a reasonably large loss of privacy for a very small benefit. > ust try to remove your Mac’s WiFi card and rebooting - all Mac App Store apps will likely fail to open Wait, what? I've been able to open Mac App Store apps without a network connection. You can try to validate with the App Store over the network, but that's an option, not a requirement: https://developer.apple.com/library/content/releasenotes/General/ValidateAppStoreReceipt/Introduction.html https://developer.apple.com/library/content/releasenotes/Gen... > Apple really wanted the DRM aspect I'm not even sure what the purpose behind Apple's "DRM" is. It's trivially bypassed on jailbroken devices, and I think on macOS as well. > On macOS you can separately download an update/upgrade DMG, which will be signed by Apple, and then simply install it without a network connection. On macOS you can also downgrade your OS to whatever you like. iOS requires a firmware to be signed before it will install, which obviously means that it will have to reach out to Apple somehow. > if a user feels like removing/modifying certain Apple system binaries they are uncomfortable with What if a user removes AMFI or the Sandbox? > The fact that there is no way of monitoring or intercepting file system events, network connections and other system calls on said device and that you are giving apps many, many more privileges than you realise It takes work, but this is possible. What you need to do is sign every app you download with your own entitlements that allow for debugging. Despite the author's hesitations, I'm still pretty convinced that macOS/iOS are probably some of the most secure operating systems you can buy today; the amount of time Apple has put into this clearly shows. Plus, it's obvious to see that Apple's incentives don't really align along data collection, even when taking a cynical viewpoint. Not collecting user information allows them to resist government requests for data and increases public goodwill; unlike other companies they have a clear source of revenue that's not tied to data collection, and it's highly unlikely that they'd burn that money to go after data collection for AI or whatever given that's not an area they have a whole lot of experience in. That being said, there are many good points brought up in the article, namely the centralized control that Apple has over devices. We've already seen occasions where this has caused Apple to acquiesce to third-party requests: for example, the removal of network extension apps from China's App Store. Apple is playing a delicate balancing game of trying to maintain some control over the hardware they vend while trying to keep it secure, and this is a difficult thing to do, especially when they need to cater to the needs of users for whom features are important and privacy is invisible.
- deleted 8y ago[deleted]
- GlenTheMachine 8y ago“On iOS, there is no full-disk or full-volume encryption, only varying levels of file-based encryption...” I don't understand this claim. iOS had full disk encryption starting with iOS 3.0, in 2010. Or at least Apple (and other security experts) says it does: https://darthnull.org/security/2014/10/06/ios-encryption/ https://darthnull.org/security/2014/10/06/ios-encryption/ Am I missing something here?
- lilyball 8y agoYou're not missing something. The author doesn't seem to understand how iOS's disk encryption works. It's not "full disk encryption" in that the full disk is not encrypted with one key. However, every single file on the disk is encrypted, with separate keys, and the various levels of security (e.g. "accessible always", "accessible when unlocked", etc) are managed by storing these keys in different key bags whose own keys are evicted from memory at the appropriate times. Which is to say, it's not classic FDE, but if you were to take the storage out of an iPhone and inspect it, you'd find that everything in the filesystem is in fact encrypted.
- drodgers 8y agoYep. And this layered encryption is great because it allows — for example — your phone to boot up before you enter a passphrase. Making this technology more convenient is just as important for making people secure as the algorithms themselves, because otherwise, almost no one will use them (PGP-encrypted email being the classic example).
- tinus_hn 8y agoThe full disk is not very useful though because the disk is automatically unlocked at boot. Anything you can see after starting the phone without entering your passcode is effectively not encrypted.
- trisimix 8y agoHaving to choose between sanely developing and cuatomizing your phone, and privacy on your phone, sshouldnt be the case.
- deleted 8y ago[deleted]
- userbinator 8y agoThis post by a security researcher who prefers to remain anonymous If iOS is to really be considered a secure OS, and if vanilla macOS is to become more secure, independent end-user control must be considered. Increased low-level design security at the cost of control, and the ability to prevent leaking data, cannot be considered a real improvement in security. Whoever you are, thank you greatly for not being another one of those authoritarian cargo-cult "users are stupid so we should remove all control from them" people which the greater security community seems to be full of.
- feelin_googley 8y agoIts encouraging to be reminded that still not everyone who uses Apple hardware runs MacOS exclusively. https://sivers.org/openbsd https://sivers.org/openbsd http://www.sacrideo.us/openbsd-on-macbook/ http://www.sacrideo.us/openbsd-on-macbook/ However I have not heard any reports of anyone running an alternative OS on iPhone or iPad hardware. With every passing year I continue to think it would be interesting to observe how users would choose if Apple hardware and Apple software were sold separately. Would all users choose Apple software? Expecting to take a little karma subtraction from the thought police for daring to entertain such a nonpermissible idea. Par for the course here and well worth it.
- mercer 8y agoI'm almost certain that your comment wouldn't be greyed out if you hadn't added that last paragraph.
- deleted 8y ago[deleted]
- feelin_googley 8y agoComments from me that are skeptical of Apple are always downvoted. Complaining is acceptable but doubting is not. I have tested this over the years and it is remarkably consistent. Its both amusing and sad. The clicks can sometimes take a while to come, sometimes days, but they always come. Whether I add something silly acknowedging this phenomenon makes no difference. They come either way. Its just a small price to pay for being irreverent I guess. I have plenty of karma to spare. Well worth it.
- feelin_googley 8y agoWell, I tried posting the comment with the last paragraph removed to test your theory. As expected, within 24hrs, someone downvoted it. I agree with author of the gist on many points. With iOS, autonomy has been removed. He failed to mention the user is not even permitted to use her own time servers. Apple is the sole permissible timekeeper.
- 8y ago
- tedunangst 8y ago> Apple Activation servers are accessed via Akamai, which means sensitive data may be cached by Akamai and its’ peering partners' which includes many global ISPs and IXPs Wouldn't this be devastating to about 10000 other businesses as well?
- drodgers 8y ago> Especially since iOS10, and the “differential privacy” (dprivacyd) concept, which Apple pushed, and which this author feels essentially boils down to “let’s collect even more data without giving a real reason and spin it as a privacy improvement because we remove certain metadata, after all none of our users understand or care anyway” This is too misleading and dismissive. Differential privacy collection requires that the device will send back data which doesn't contain enough information to tell anything significant about the individual, but does allow for population-level statistics to be computed from many samples (eg. the old private-survey trick of flip a coin and answer truthfully if it's heads or randomly if it's tails). If they're collecting more data with this system, then it's supposed to mean that they don't know more about you. Almost all tech companies collect extensive usage data; Apple seems to have made a genuine and rare attempt to improve the privacy of their users (admittedly without damaging their ability to make informed product decisions). Given the popularity of AI tech and the huge amounts of data it requires, systems like this are probably the only plausible way to improve user privacy without getting left-behind in the AI and product-development race.
- feelin_googley 8y agoIts encouraging to be reminded that still not everyone who uses Apple hardware runs MacOS exclusively. https://sivers.org/openbsd https://sivers.org/openbsd http://www.sacrideo.us/openbsd-on-macbook/ http://www.sacrideo.us/openbsd-on-macbook/ However I have not heard any reports of anyone running an alternative OS on iPhone or iPad hardware. With every passing year I continue to think it would be interesting to observe how users would choose if Apple hardware and Apple software were sold separately. Would all users choose Apple software?
- dang 8y agoDuplicate comments are not ok here. For a long time now—and an astonishing number of posts—you've been using HN basically to post agitprop. The trouble isn't your opinions—whatever they are, I'm sure plenty of other users agree with them, all of whom manage to use HN just fine. The trouble is that you've crossed into being a single-purpose account, which is not cool. HN threads are for conversations, not agendas. One can't have a conversation with a megaphone. Since we already asked you once to stop and you don't seem interested in changing, I'm going to ban this account. If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future.
- feelin_googley 8y agoIts not a duplicate. @mercer suggested the last paragraph should be removed, so thats what I did. Alas, the edit period had expired. Edit: Notice that youve toned down your original reply, which had statements like "No one cares about your opinions about Google, Apple or Facebook." It seems I have agitated you. I apologise.
- dang 8y agoI didn't say "no one cares". Originally I wrote "We really don't care about your opinions of Apple or Facebook or Google". That is true, in the sense that if you flipped the high bit on all your opinions to turn them into the opposite opinions, we'd have the same moderation response. But I've learned it's better not to word things that way. I can't easily stop myself from typing the first version of a comment more strongly than I know is helpful, so my solution is to sand off the sharp edges by editing, which I do a lot of.