Apple's desensitisation of people to fundamental security practices
troyhunt.com
troyhunt.com
The analogy that a commenter made here about a plumber entering your home is spot on. Like the locks on a door, the security mechanisms Apple has designed are constructed to thwart breaches on a large-scale (governments) and also on a small scale (your snooping family members).
Protecting it from people who need to service is it does not seem to fit any of these categories; if you cannot trust the Apple Genius in the store, seems silly that this same person would nonetheless trust the probably dozens of people who handled the device before it was finally placed in its box. And, like the plumber, if you somehow want him in your house and you want him to provide expert advice on how to fix your problem yet you fear that he may do something nefarious in the process, Apple does one better than "keepin' ya eye on him" -- it essentially allows you to strip the house of all of your belongings so the plumber has nothing to look at but the sink. And then it lets you put all your things back in. Seems pretty good to me.
A better analogy from the physical world would be a locksmith who tells you to just leave your keys under the door mat for him so that he can come in and do the work when you aren't home.
> but Apple can not enter into your phone without your help
Of course Apple can - that is why the FBI asked them to do just that. Apple won't as a matter of principle, not due to any technological limitation.
If they can, it's broken. Do not buy those devices.
It's more akin to leaving the car keys with the manufacturer when you are getting your car serviced.
You are supposed to know that beforehand, and they are even discorauging you to consider that there are some issues with handing over an unlocked phone, which means 95% of their userbase are not aware that there are security implications.
An anecdote from a long time Nexus owner: last year my Nexus lost the ability to charge via its USB port. After a short while on the phone with Google (who, contrary to other anecdotes I've read here, does have good customer service in my experience), they overnighted me a brand new phone at no charge. They too provided me instructions on wiping my phone before sending it back, but they also provided me a brand new device without ever having to hand over my old one for evaluation first. It was easy enough to setup the new phone, since my old one had plenty of charge when the new phone arrived the next day.
Does Apple do this? Is it a requirement to bring your phone into an Apple store or ship it to get replacement equipment? If they provide similar service as Google gave me, this seems more like a complaint about Apple Stores or their employees, and not Apple.
Is Apple support bonded and insured, so the risk to the customer is limited? Do they follow a code of ethics[1] that creates requirements to, for example:
...act as a trustworthy and fiduciary agent
for each employer or client, shall seek
no favors and shall not profit or misuse
confidential client or employer information.
[1] https://www.aspe.org/codeofethicsTech guy: "This process is obviously broken. Any cop could spy on me with this!"
Lawmaker: "Oh, don't worry. There's a law forbidding that."
I'm under the impression that some lawmakers actually think that a law forbidding snooping will keep snoops out.
You have two options: either you give me you unlocked iPhone and I, and any of my colleagues, could steal any information from your device, or you backup and wipe the phone before giving it to us.
That is, Apple should make very clear what it means giving an unlocked phone to an untrusted third-party - even when that party happens to work for Apple.
Let's not forget that, by definition, Apple the company is also an untrusted third-party (not only the Apple employees).
Maybe in theory. In practice, the devices trust all software updates signed by Apple's certificates. Who knows what other trusted diagnostic hardware exists 'at the back' referred to in the article.
Ultimately, it is an issue of trust; and I argue that the relationship of trust with Apple started the moment you decided to buy an iPhone, and continues to apply when you ask Apple for support.
Does Apple provide any insurance to protect/reimburse the customer if a Genius misuses their access to the customer's device?
Yes people do give service professionals access to there homes, but unless they are hopelessly naive they don't leave credit cards, money, jewellery and guns around.
If you read the fine print in the agreements you make to have such items you explicitly agree not to allow other people access to them.
The scary thing is that responses here don't seem to be playing the devils advocate and actually seem to be believing this is OK.
Trust is not binary or one-dimensional. You have no choice[1] but to place some hope in them working in alignment with your interests when the build the product, but it doesn't mean you should be careless about retaining some control in the process when doing business with their retail staff. Their staff is human and heterogenous, and you know there are more levels of QA in the phone production process than in the customer service, and customer service employees have much lower risks of getting caught & much less to lose career-wise than iOS engineers if they violate your privacy.
People complain about Facebook and Windows 10 too. "You're implicitly trusting Facebook/Microsoft anyway" is not really true there either, you're just tolerating their privacy behaviour in exchange for value, and hoping to escpe harm.
[1] If you want a smartphone, that is (the competition is worse)
The hyperbole is shady. I like some of troy's work, but this post just further exacerbates the "Chicken Little" stereotype of Security Advocates.
The users Apple is 'targeting' (an odd choice of words; most would use 'customers' here) mostly don't do anything so sensitive with their phones that they need to worry about bad actors within the company which sold them their phone in the first place. In the rare instance where some Apple tech starts stealing nude photos or credit cards, they will be fired, probably prosecuted, and the customer will recover. Big whoop.
>The Australian privacy commissioner will call on technology giant Apple to explain reports of staff stealing, sharing and ranking of customers' explicit photos.
I have no idea why people think this is a crazy hypothetical. Of course some techs will look at your nude photos. And in this case, copy them, post them online, and rate them.
Troy has done some excellent work on security and I for one applaud his attitude.
The fact that tech guys cannot easily get into a locked iPhone actually gives me better peace of mind.
At the end of the day, as others have said - It's like handing over the house key to a tradesman, or your car key to a mechanic (I do both on a routine basis, once I have vetted the other party). End of the day, it is about making their job as easy as possible, and some semblance of trust is required if humanity is to keep moving forward.
I wonder what the author would say if he went to his employer or a client site to diagnose a network issue and they refused to give him any admin passwords. Sure you can diagnose a DNS or firewall issue without the domain admin password, but having it surely makes the job a LOT easier and quicker.
A dangerous suggestion.
A better policy might be for Apple to require it's users to backup all their data, wipe the phone clean and hand over an unlocked device. After getting back the device, you could sell it on ebay, like OP suggested, or wipe the device clean in case you suspect malware was installed and continue using it.
Of course I don't know of a better alternative so... who knows.
The OP said that he had the option to instant wipe his device and restore it back home. But he choose to buy a new iPhone for "convenience" because the process take time.
Last time I got my phone serviced (and ultimately replaced so I had to wipe). The Apple employee even let me backup to iCloud from the store wifi so I would'nt loose the last data of the day.
PS: It's totally the locksmith case, except that (in theory) even if they wanted to apple can't get into you phone without consent while the locksmith can lockpick.
I volunteer with an engineering education camp over some summers and kids are totally unable to do anything with a normal computer. We try to start teaching them programming through writing minecraft mods and we require that kids have a little bit of experience with minecraft, but half the kids that come in have NEVER used a computer that wasn't an iPad. In their lives. We have to show kids how a keyboard works, and they're point of refrence is the virtual one from a touchscreen.
I don't live in a tech-y area either, and the kids come from a lot of diverse backgrounds. It's just that kids first introductions to computing is always an iPad. Makes the job of educators a lot harder :/
Interesting. I wonder if any parents nowadays teach their kids to use dvorak, colemak or other alternative layouts?
The question is whether or not speech (or even thought) recognition will be good enough to properly replace 99% of what a keyboard empowers you to do -- probably easy for most messaging/writing, perhaps a bit harder for coders as you wouldn't be efficient spelling out every symbol.
Then we'll really have entire generations who never used a keyboard and don't really need to. Except coders, maybe, which rarely account for more that 2-5% of the population. And it seems all too natural that we'd create "natural speech coding languages" that properly fill in the blanks to convey the programmer's logic (e.g. just saying "if i=0 given i++ while i<10 then do this else do that"). This could probably be enough for most of the code out there. Soon enough, you'd actually just spell the logic in plain english and the interpreter would code it for you.
It's basically the idea of moving ever closer to Star Trek's computers, naturally human interfaces.
Your comment is both frightening looking at today (and yesterday) and at the same time a probable clear indication of the shape of things to come.
Settings > General > Accessibility > Guided Access
With the above option turned on you can enable triple tap home key in caller app to only be used for dialing calls, can't view prior calls or anything else in phone until passcode is entered.
EDIT: I use this all the time, just make sure you draw the 'no go area' around the buttons at bottom of dialer app and you can also disable physical buttons as needed this way too.
I just wish the guided access had more fine-grain controls on touch areas - some apps you have to block out both orientations and/or lock the rotation. I mainly use guided access for my kids.
[1] https://9to5mac.com/2016/03/18/how-to-reduce-iphone-screen-b...
Apple could do a much better job in this department.
I could have wiped it there and then, handed it over and later restored from last night's iCloud backup,
but I don't like not having a fully working outgoing device before doing a restore to a new one.
I also don't like the lag time due to poor Australian internet and
whilst I could have driven home and done a local backup to iTunes,
there's still the need to reconfigure a bunch of things that don't cleanly restoreThe entire point of this article was that Apple shouldn't be requiring bad practices that require either teaching bad lessons or preexisting technical knowledge about the existence of and need for a workaround.
A good example of a similar principle are the modern rules for gun safety[1]. One rule is to never put your finger anywhere near the trigger area until just before you intend to fire. Nobody should be judging if a gun is safe, because accidents happen when someone makes an incorrect assumption or mistake. Instead, anybody handling firearms should be in the habit of following basic safety rules. Safety - aka "security" - happens by minimizing risk, and the way to get the average person to minimize risk is either by making failure modes impossible, or by teaching and encouraging good habits.
[1] https://en.wikipedia.org/wiki/Gun_safety#Rules_and_mindset
It's a hardware problem. Can't Apple as the hardware manufacturer create a sandboxed service area on your phone where they and their genii can do diagnostics? Does it really take every person with a hardware issue to either hand-over their entire device unencrypted or wipe the device before giving it to the manufacturer for maintenance?
Imagine if you could let a plumber into your house, but they could only see the plumbing! They would have no access to all the goods in your house. Isn't that what we should be aiming for with technology? Don't try to put real world constraints where they shouldn't exist. I can already create a sandboxed 2nd user on my device, why can't apple do this themselves, just for them, with the correct hardware or whatever. Or why doesn't apple recommend people do this before handing over the phone.
Apple said they'd have to send it off to fix it. It'd be about three weeks before I'd get it back and, yes, they'd need my password -- to fix a purely cosmetic issue.
The next day, I took it to a local AASP and showed it to them. They said they'd order the part, get it the next morning, and I could pick it up the next afternoon. No, they didn't need my password.
When I went back to get it, they had fixed it and it was just like brand new. Oh, and they had ran some type of diagnostic tests on it, found that the DVD drive was failing, and went ahead and replaced that for me too -- without my password!
It was all covered under AppleCare and I didn't have to do the backup/wipe/restore dance.
>The Australian privacy commissioner will call on technology giant Apple to explain reports of staff stealing, sharing and ranking of customers' explicit photos.
I think this is important, because all the comments so far are about how this is a crazy hypothetical scenario that no one should be worried about. It's not.
He is not being alarmist; it may only take a few rotten apples to spoil the barrel, but boy did it get spoiled.
Slightly off topic, but it really bugs me when people ridicule these workers who are just doing what they've been instructed to do. Seems to happen all too often when discussing the Genius Bar.
A Microsoft MVP probably shouldn't be throwing shade at another company's marketing term.
https://www.reddit.com/r/AskNetsec/comments/2ehk06/why_does_...
Yeah, because they will be magically able to test it and fix it while locked...
/facepalm
In all cases that I can remember I've been told when making the appointment to back up the device prior to the appointment and every time the device has had to go into service the genius person has had me wipe and factory reset the device in the store before they take it off me.
Anecdotal for sure, but so is the original article.
Tell them you are okay with them not being able to run diagnostics on completing the repair; yes, you understand this may leave the device badly calibrated. Don't waste time arguing; escalate until you get someone who will accept your locked phone.
I go through this every time I use Apple's Genius bar. Only once did I have to wipe, and that was with a Mac.
You can back up to iCloud and reset the phone. When getting it back, log in and wait 30min, everything should be there.
You can't diagnose hardware problems without access to the software and any limited "service mode" is just a backdoor in waiting.
That would prevent anyone from modifying your phone without your permission. Such as flash the BIOS or something more malicious. Again provided authorization is required to perform those actions.
The author doesn't seem to get that if Apple could run arbitrary software on a locked phone, THAT MEANS IT IS NOT SECURE TO BEGIN WITH.
I too am wary of a diagnostic partition/back door as an answer to this conundrum as it seems like it just introduces another vector for attack. We can say "just make it secure" or "don't give it access to do malicious stuff, but the nature of jailbreaks on the iPhone rely on bugs in otherwise innocent functions. Jailbreaks are just exploiting the phone security.
The author seems to be of the opinion that there should be a hardware test that doesn't require actual access to the phone, which is probably true -- they likely could just swap the speaker in this case and call it a day. But many of the hardware components are integrated on the iPhone and I'm not sure there's value in a dedicated speaker test device or a limited hardware test device like that. Similarly, quality testing afterwards would best be done before handing it back to the customer; it's pretty lousy service to hand back a fixed device for it to just not work again, and at some point to ensure that you've solved the problem you need to get into the phone.
I don't know what the full answer is here since the core problem seems to be Troy doesn't trust Apple. As others have said, you give up your car keys when you get your car repaired. You let the plumber into the house. At some point trust has to be there and people need to be held accountable for violating that trust. Geeksquad violated that trust without real penalties multiple times, so it's a legit fear. But Troy seems really intent on distrusting Apple -- that's fine, but he needs to realize how that's in direct conflict with how support works. Does he insist the same security on his car? (Ie, no keys for the mechanic?).
As for a solution, maybe an iPhone onsite imaging tool, some small microboard attached to a raid box that quickly pulls an encrypted image and stores it temporarily on site. The tech can test it on a vanilla and then restore for the client. I don't know if this would violate the iPhone security though being able to restore the image...
"Microsoft MVP has problems with Apple's security policies"
The article is actually a good read. I think the message needs to reach everyone - although I am sure the irony is not lost on the people with slightly longish memories about Microsoft's security track record till very recently.
In any case, I am sure someone would come in and change the headline and ask me to cut down the hyperbole and focus on the message.
This exact response needs to be sent to bloggers who write these click-baity headlines. The fact that some of them are experts who do know what they are talking about actually makes it more cringe-inducing, not less.
Oh, and no, the developed countries do not make up the entire human race (even if people in insular Australia might sometimes think so - see what I did there?), and many many people in the rest of the world don't even have Apple devices.
Edit: You can add to insult that a MVP has a problem with a genius... Oh this is a nice story!