8 ms·
Apple Platform Security (Jan 2026) [pdf]
- OGEnthusiast 8mo agoGlad there's still at least one tech company that cares about personal security / opsec.
- buildbot 8mo ago262 pages!!! Pretty interesting to see how the different SoCs have evolved security wise over time.
- varispeed 8mo agoNo mention of Pegasus and other software of such sort. Can latest iOS still be infected? There is no point creating such document if elephant in the room is not addressed.
- wat10000 8mo agoPegasus isn't magic. It exploits security vulnerabilities just like everything else. Mitigating and fixing those vulnerabilities is a major part of this document.
- gjsman-1000 8mo agoWhy? The obvious conclusion is that Apple is doing everything in its power to make the answer “no.” You might as well enumerate all the viruses ever made on Windows, point to them, and then ask why Microsoft isn’t proving they’ve shut them all down yet in their documents.
- varispeed 8mo agoThat analogy misses the asymmetry in claims and power. Microsoft does not sell Windows as a sealed, uncompromisable appliance. It assumes a hostile environment, acknowledges malware exists, and provides users and third parties with inspection, detection, and remediation tools. Compromise is part of the model. Apple’s model is the opposite. iOS is explicitly marketed as secure because it forbids inspection, sideloading, and user control. The promise is not “we reduce risk”, it’s “this class of risk is structurally eliminated”. That makes omissions meaningful. So when a document titled Apple Platform Security avoids acknowledging Pegasus-class attacks at all, it isn’t comparable to Microsoft not listing every Windows virus. These are not hypothetical threats. They are documented, deployed, and explicitly designed to bypass the very mechanisms Apple presents as definitive. If Apple believes this class of attack is no longer viable, that’s worth stating. If it remains viable, that also matters, because users have no independent way to assess compromise. A vague notification that Apple “suspects” something, with no tooling or verification path, is not equivalent to a transparent security model. The issue is not that Apple failed to enumerate exploits. It’s that the platform’s credibility rests on an absolute security narrative, while quietly excluding the one threat model that contradicts it. In other words Apple's model is good old security by obscurity.
- gjsman-1000 8mo ago[flagged]
- wat10000 8mo agoIt’s not “a weakness.” It’s many weaknesses chained together to make an exploit. Apple patches these as they are found. NSO then tries to find new ones to make new exploits. Apple lists the security fixes in every update they release, so if you want to know what they’ve fixed, just read those. Known weaknesses get fixed. Software like Pegasus operates either by using known vulnerabilities on unpatched OSes, or using secret ones on up to date OSes. When those secret ones get discovered, they’re fixed.
- jesseendahl 8mo agoI am not sure if you missed my earlier comment, but it's directly applicable to this point you've repeatedly made: >If Apple believes this class of attack is no longer viable, that’s worth stating. To say it more directly this time: they do explicitly speak to this class of attack in the keynote that I linked you to in my previous comment. It's a very interesting talk and I encourage you to watch it: https://www.youtube.com/watch?v=Du8BbJg2Pj4 https://www.youtube.com/watch?v=Du8BbJg2Pj4
- varispeed 8mo agoOn some random YouTube video that is mostly consisting of waffle and meaningless information like "95% of issues are architecturally prevented by SPTM". It's a quite neat and round number. Come on dude.
- Retr0id 8mo agodon't worry, they set the allow_pegasus boolean to false
- goalieca 8mo agoApple did create a boolean for that. They call it lockdown mode. > Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats. Most people are never targeted by attacks of this nature. When Lockdown Mode is enabled, your device won’t function like it typically does. To reduce the attack surface that potentially could be exploited by highly targeted mercenary spyware, certain apps, websites, and features are strictly limited for security and some experiences might not be available at all.
- varispeed 8mo agoIf Pegasus can break the iOS security model, there’s no reason to think it politely respects Lockdown Mode. It’s basically an admission the model failed, with features turned off so users feel like they’re doing something about it.
- jkubicek 8mo agoLockdown mode works by reducing the surface area of possible exploits. I don't think there's any failures here. Apple puts a lot of effort into resolving web-based exploits, but they can also prevent entire classes of exploits by just blocking you from opening any URL in iMessage. It's safer, but most users wouldn't accept that trade-off.
- varispeed 8mo agoClaiming reduced attack surface without showing which exploit classes are actually eliminated is faith, not security. And Lockdown Mode is usually enabled _after_ user suspects targeting.
- deleted 8mo ago[deleted]
- jesseendahl 8mo agoApple's head of SEAR (Security Engineering & Architecture) just gave the keynote at HEXACON, a conference attended by the companies who make Pegasus such as NSO Group. That doesn't seem like avoiding the elephant in the room to me. It seems like very much acknowledging the issue and speaking on it head-on. https://www.youtube.com/watch?v=Du8BbJg2Pj4 https://www.youtube.com/watch?v=Du8BbJg2Pj4
- random_duck 8mo agoWow, this is hardcore (pun intended).
- easton 8mo agoWeb version: https://support.apple.com/guide/security/welcome/web https://support.apple.com/guide/security/welcome/web
- modeless 8mo ago[flagged]
- runjake 8mo agoThis is your blog post, so I'll ask you a question. What are you trying to state in Belief #1? The message is unclear to me with how it's worded: > In this table, in the "iCloud Backup (including device and Messages backup)" row, under "Standard data protection", > the "Encryption" column reads "In transit & on server". Yes, this means that Apple can read all of your messages > out of your iCloud backups. In addition to the things you mentioned, there's certainly a possibility of Apple attaching a virtual "shadow" device to someone's Apple ID with something like a hide_from_customer type flag, so it would be invisible to the customer. This shadow device would have it's own keys to read messages sent to your iCloud account. To my knowledge, there's nothing in the security model to prevent this.
- shawnz 8mo agoThe table has two categorizations: "In transit & on server" and "End-to-end". The former, which covers iCloud backups in the default configuration, is explicitly NOT end-to-end, meaning there are moments in time during processing where the data is not encrypted. However, iCloud backups actually are listed as "End-to-end" if you turn on the new Advanced Data Protection feature.
- deleted 8mo ago[deleted]
- digiown 8mo agoOr Apple can also push an update, which you can't refuse, that upon first message to iCloud just uploads your private key. It's a bit foolish to count on encryption implemented by the adversary you're trying to hide from. Of course, this will most likely only affect individuals targeted by state-level actors.
- shawnz 8mo agoIIRC Apple has attempted to implement some defences against this, for example by requiring the passcode to be inputted before an update can be installed to prevent another San Bernardino scenario. A cursory search indicates that they also have some kind of transparency log system for updates, but it seems to only apply to their cloud systems and not iOS updates.
- whitepoplar 8mo agoGiven that A19 + M5 processors with MIE (EMTE) were only recently introduced, I wonder how extensively MacOS/iOS make use of the hardware features. Is it something that's going to take several years to see the benefit, or does MIE provide thorough protection today?
- bri3d 8mo agoI think all of the kernel allocators and most (?) system processes in iOS 26 have MIE enabled, as does libpas (the WebKit allocator), so it’s already doing quite a lot.
- armadyl 8mo agoI was just watching a video on this yesterday: https://www.youtube.com/watch?v=5McB6-2r-ds https://www.youtube.com/watch?v=5McB6-2r-ds Apple’s implementation of MTE is relatively limited in scope compared to GrapheneOS (and even stock Android with advanced security enabled) as it’s hardware intensive and degrades performance. I imagine once things get fast enough we could see synchronous MTE enabled everywhere. It is curious at the moment though that enabling something like Lockdown Mode doesn’t force MTE everywhere, which imo it should. I think the people who are willing to accept the compromises of enabling that would likely also be willing to tolerate the app crashes, worse performance etc that would come with globally enabled MTE.
- drnick1 8mo agoBut all the software is closed source, and there is little to no opportunity to verify all these security claims. You don't have the encryption keys, so effectively the data is not under your control. If you want to see security done well (or at least better), see the GrapheneOS project.
- digiown 8mo agoGrapheneOS also doesn't give you the encryption keys. If you run the official version, there is no way for you to extract the data from your device at all beyond what app developers will let you access. This means that you do not own the data on your device. The backups are even less effective than Apple's, although they say they will work on it. The developers also appear to believe that the apps have a right to inspect the trustworthiness of the user's device, by offering to support apps that would trust their keys [1], locking out users who maintain their freedom by building their own forks. It's disheartening that a lot of security-minded people seem to be fixated on the "AOSP security model", without realizing or ignoring the fact that a lot of that security is aimed at protecting the apps from the users, not the other way around. App sandboxing is great, but I should still be able to see the app data, even if via an inconvenient method such as the adb shell. 1. https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu...
- zb3 8mo agoFor some reason they don't release userdebug versions which was a dealbreaker for me.. (the device should be secure, but not against me) But if you wish to build it from source, it could probably be a good option.
- digiown 8mo agoYou can re-sign it using https://github.com/chenxiaolong/avbroot https://github.com/chenxiaolong/avbroot I don't currently have any root on the phone, but I reserve the right to add it or run the userdebug build at a later date
- rrgok 8mo agoSometime I wonder how much overhead all these security features take in terms of performance. I would really like to see a benchmark with and without security measures.
- Retr0id 8mo agoIt's not really possible to make a direct comparison, given that a big chunk of the features are baked into the silicon, or are architecture-level choices.
- TheNewsIsHere 8mo agoIt’s technically possible, but it would be difficult and likely require breaching an NDA. A bit pedantic, perhaps, but it’s out there. Apple makes available on a highly controlled basis iPhones which permit the user to disable “virtually all” of the security features. They’re available only to vetted security researchers who apply for one, often under some kind of sponsorship, and they’re designed to obviously announce what they are. For example they are engraved on the sides with “Confidential and Proprietary. Property of Apple”. They’re loaned, not sold or given, remain Apple’s property, and are provided on a 12-month (optionally renewable) basis. You have to apply and be selected by Apple to receive one, and you have to agree to some (understandable but) onerous requirements laid out in an legal agreement. I expect that if you were to interrogate these iPhones they would report that the CPU fuse state isn’t “Production” like the models that are sold. They refer to these iPhones as Security Research Devices, or SRDs.
- Retr0id 8mo agoThese devices still have all the security features.
- relium 8mo agoThe ones I remember most affecting performance were zeroing allocated memory and the Spectre/Meltdown fix. Also, the first launch of a new app is slow in order to check the signature. Whole disk encryption is pretty fast today, but probably is a bit slower than unencrypted. The original FileVault using disk images was even slower.
- zb3 8mo agoProtects the device well... against the owner of the device using it as they wish :)
- wcfrobert 8mo agoApple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.
- bigyabai 8mo agoYou know what's even cooler? Apple's commitment to hiding US federally-mandated backdoors for dragnet surveillance: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-secretly-giving-governments-push-notification-data/ https://arstechnica.com/tech-policy/2023/12/apple-admits-to-... Apple has since confirmed in a statement provided to Ars that the US federal government “prohibited” the company “from sharing any information,” but now that Wyden has outed the feds, Apple has updated its transparency reporting and will “detail these kinds of requests” in a separate section on push notifications in its next report.
- Noaidi 8mo agoThat people fall for this corporate BS while Tim Cook is giving gold bars to Trump and dining and dancing with him When people are being murdered on the streets by ice is just amazing to me.
- OGEnthusiast 8mo agoWell that’s what Americans voted for. So I don’t think anyone cares that every CEO (definitely not just Tim Cook) is schmoozing with Trump.
- bigyabai 8mo ago> Well that’s what Americans voted for. Americans are not one person. > So I don’t think anyone cares Clearly they do. > every CEO (definitely not just Tim Cook) is schmoozing with Trump. Tim Cook was (supposedly) principled. I guess it's hard to pretend that you care about privacy or human rights while eating dinner next to bin Salman.
- willturman 8mo agoYou can request a downloadable a copy of any/all of the data that Apple has associated with your account at https://privacy.apple.com https://privacy.apple.com. This apparently includes retrieving all photos from iCloud in chunks of specified size, which seems an infinitely better option than attempting to download them through the iCloud web interface which caps downloads to 1000 photos at a time at less than impressive download speeds.
- gumby271 8mo agoIt sucks that Apple decided to monitize iPhone the way they have, by controlling the owners ability to install software of their choosing. Ignoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound, but it's hard to take them serious regarding privacy arguments. Our choices are either (A) an OS monitized by tracking user interaction and activity, or (B) monitized by owning the basic act of installing software on the device, both of these options suck and I struggle to give up the more open option for one that might be more secure.
- microtonal 8mo agoIgnoring the arguments one could make about this making it "more secure" it's clearly disrespectful to the power user that doesn't want to beg Apple's permission to use their computer. I'll grant them their security claims are sound, I wouldn't say they are sound. First, macOS provides the freedom to install your own applications (ok, they need to be signed and notarized if the quarantine attribute is set) and it's not the case that the Mac has mass malware infestations. Second, the App Store is full of scams, so App Store - safe, external - unsafe is a false dichotomy. Apple uses these arguments, but of course the real reason is that they want to continue to keep 30% of every transaction made on an iPhone or iPad. This is why they have responded to the DMA with a lot of malicious compliance that makes it nearly impossible to run an alt-store financially. (Despite my qualms about not being able to install apps outside the app store, I do think they are doing a lot of good work of making the platform more secure.)
- dan-robertson 8mo agoThe OP is about security and you specifically ignore security when bringing up a common flamewar topic for which much discussion has already been had on this site. Perhaps such discussion could at least be limited to articles where it is less tenuously related.
- gumby271 8mo agoI guess I bring it up in the sense that no matter how good their security is, it still sucks that Apple products are so hostile to their owners. It's hard to be impressed by their security work with the platform being what it is. Security, privacy, and ownership aren't equally separated in my mind.
- promiseofbeans 8mo agoThey made C memory safe? This is a big thing to gloss over in a single paragraph. Does anyone have extra details on this? > On devices with iOS 14 and iPadOS 14 or later, Apple modified the C compiler toolchain used to build the iBoot bootloader to improve its security. The modified toolchain implements code designed to prevent memory- and type-safety issues that are typically encountered in C programs. For example, it helps prevent most vulnerabilities in the following classes: > • Buffer overflows, by ensuring that all pointers carry bounds information that’s verified when accessing memory > • Heap exploitation, by separating heap data from its metadata and accurately detecting error conditions such as double free errors > • Type confusion, by ensuring that all pointers carry runtime type information that’s verified during pointer cast operations > • Type confusion caused by use after free errors, by segregating all dynamic memory allocations by static type
- vsgherzi 8mo agoSort of. From my understanding they’ve been heavily using clang with fbounds checks to insert checks into functions. I think there was work done to try to insert them into existing code as well. They memory tagging in new processors help avoid overflow exploitation. Maybe someone can jump in and add more details
- bri3d 8mo agoMany years ago. It’s called Firebloom. I think it’s similar in theory and lineage to Fil-C. https://saaramar.github.io/iBoot_firebloom/ https://saaramar.github.io/iBoot_firebloom/
- 1over137 8mo ago>They made C memory safe? They made a dialect of C with bounds safety, see: https://clang.llvm.org/docs/BoundsSafety.html#overview https://clang.llvm.org/docs/BoundsSafety.html#overview
- deleted 8mo ago[deleted]
- pjmlp 8mo ago
- cyberax 8mo agoSomehow, they conveniently forgot to mention these "security" features: 1. Constant popups about "application requesting access" on macOS. That often happens without any user's activity. 2. If you leave the permission popup open for some time (because it's on a different screen), it auto-denies. And then you won't be able to find ANY mention of it in the UI. 3. macOS developers can't be assed to fix mis-features, like inability to bind low ports to localhost without having root access (you can open any listening port on 0.0.0.0 but you can't open 127.0.0.1:80).
- LoganDark 8mo ago> Since 2012, Mac computers have implemented numerous technologies to protect DMA, resulting in the best and most comprehensive set of DMA protections on any PC. Macs are PCs now? This coming directly from Apple is hilarious.