6 ms·
>Why would governments push back, when this hole which has already been used will _always_ be available? I'm not aware of a time when Apple pushed a software u
by dxf 4y ago
>Why would governments push back, when this hole which has already been used will _always_ be available?
I'm not aware of a time when Apple pushed a software update (silently or otherwise) to defeat security for a user (or users). Can you provide a reference?
- szundi 4y agoUS can always pass a bill or have one that enables them to covertly force apple to comply otherwise Tim goes to jail. Easy
- acdha 4y agoYou make this sound easy but look at how that worked for NSLs. They got a ton of pushback for that and there’s no way to keep that a secret for very long – especially since things either end up in court or involve foreign governments who won’t share the desire to keep things secret.
- tinus_hn 4y agoLast time they tried that Apple caused a lot of hoopla and made the case go away. Not easy.
- supertrope 4y agoAre you referring to the Pensacola encryption bypass demand or PRISM?
- acchow 4y agoIn the US, this is not easy.
- bee_rider 4y agoWhat do you mean, “can pass a bill?” On some level the US could also pass a law that says every iPhone user will be summarily executed. That’s how sovereignty works. Is it a realistic concern? Probably not.
- bboygravity 4y agoThe entire precondition for being able to do that is that you're not aware of it. Ever.
- jodrellblank 4y agoThe parent comment said “hole which has already been used”, that’s a claim that Apple has actually done it, not only a speculation that they could. They are being asked to back up that claim.
- Melatonic 4y agoThe thing that people always miss is that the damn SIM card is running its own little processor already. If the government really wants to read your shit they can probably just do some behind the scenes work with your mobile ISP and find a way to access your phones screen output or microphone data or something.
- gumby 4y agoThe baseband module has a processor too, and you don't have access to it per FCC regulation.
- lilyball 4y agoiPhone 14 doesn't even have a SIM card anymore, it's strictly eSIM (and previous models could optionally use eSIM).
- astrange 4y agoeSIM isn't any different here, it still runs the same applets. What makes it secure is the IOMMU preventing it from accessing main memory.
- madars 4y agoIf I really wanted a physical SIM and imported a European SKU which does have it (only North American variant is eSIM-only), would I expect seamless support in the US? E.g. would AppleCare just work?
- amelius 4y agoIt doesn't matter. You are missing the entire point about E2EE.
- parineum 4y agoThat's not the point. The point is that Apple hasn't closed the government out of Apple user's phones. The point of E2EE is to remove the power of the middleman to read the data but that middleman also has complete control over the device and the software running on it with remote root access. Apple's ecosystem is, by default, design and necessity, insecure to Apple. Keys stored on an Apple device are insecure. One can easily make a similar argument for Android/Google, however, a security conscious user could still take control over their device and install a more secure OS.
- smoldesu 4y agoWhen they migrated Chinese iCloud data to domestic servers.
- ghostpepper 4y agoYou're saying there was a silent update pushed to Chinese iphones? Can you provide more details or a source on that?
- smoldesu 4y agoIt certainly wasn't silent, but that wasn't a condition for the parent's question. It was a well-documented (and much derided) decision though: https://mashable.com/article/china-government-apple-icloud-data https://mashable.com/article/china-government-apple-icloud-d...
- astrange 4y agoYou want them to break Chinese laws? Don't think they have popular support for that.
- sbuk 4y agoSeeing as context is conspicuously missing, all cloud services offered by foreign business in China a required to be hosted and controlled by state owned providers. For instance, China has a separate Microsoft 365/Azure region hosted and controlled by 21Vianet. Apple still controls the encryption keys and there is no evidence that they have handed them over to the CCP, but it is largely assumed. Federighi has said that Apple will offer EE2E in China.
- shuckles 4y agoWhy is data residency law cool and progressive when the EU does it and Big Tech complies, but Bad and Dystopian when China does the same? Tim Cook has said on the record that iCloud is the same regardless of data center.
- 4y ago