Or is it just security theater ?
Or is it just security theater ?
Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0]
I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way.
[0]: https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...
The only things end to end encrypted are listed on this page: https://support.apple.com/en-us/HT202303
If you turn on iCloud syncing, basically you're falling back to simple "in transit" and "at rest" encryption.
A lot of iPhone cracks involve just attacking your iCloud account, and then reading all of your messages from backups. This is not possible on Pixel which encrypt your device backups with on-device hardware encryption.
Can you set up a new android phone from an old phone’s backup? If so, how could this work?
This is a standard way to set up a new iPhone: “restore” from a backup of your previous phone. Especially handy when your old phone is no longer available (lost/broken)
https://security.googleblog.com/2018/10/google-and-android-h...
Not that I fully understand how hard it is to circumvent.
Unless Apple is really bad and somehow collects my keys from keychain, or collects keys passed to CryptoKit, etc., straight out of RAM, and sends them to 3-letter agencies ... if I think that's happening, then I will look for new devices.
This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of-country servers.
This is not even remotely true, even if you define "major tech company" to mean "major US tech company".
Both AWS and Azure have actual cloud regions in China (delivered with a local JV partner just like Apple's cloud services are).
Even Google operates there in various ways - they have four offices there, they manufacture hardware there, and they sell tons of ads to Chinese companies via their local subsidiaries (for display outside of China obviously).
What Apple does in China is more than complying with local laws. They appear to be exceptionally proactive in staying in the regime‘s good graces.
Can you provide a reference for Apple's JV partners being government owned? Any company in China of course has to do as the Party tells them to, so I guess the difference is largely academic, but I haven't seen it mentioned before that Apple's China partners are government-owned.
https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...
There are conflicting reports and vague language around how exactly the keys are handled.
Edit: your linked article says nothing about icloud
In general less complexity is better, but it also constrains things. For example it took until recently for third party iOS to be able to do NFC. Android had it since ~2012.
I seriously wonder: what difference did it make? Was there any groundbreaking thing iOS users missed for 8 years?
Apple is just great in omitting things and keeping focus to deliver a great product and then expand on that basis.
Most famous example: First iPhones didn’t have MMS
Or cut and paste. ;-)
For example, I have set up a tag to automatically connect friends phones to my WiFi network. You can also stick tags on places to trigger specific actions/mode/app: office, meeting room, car, bedroom.
Also one thing that could have been great to share pictures/files/urls with your computer or other phones: Android beam [1]. Sadly Google is removing it.
https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...
4-digit passcode hasn't been the default passcode option in iOS for a long time.
>This is supported by a look at smartphone cracking company Cellebrite’s effectiveness at breaking into different phones. Cellebrite can easily open up any iPhone X or earlier iPhone, but the same software used on a Google Pixel 2 or Galaxy S9 extracts very little information, and nothing at all in the case of the Huawei P20 Pro.
>That’s not to say that these Android devices are unbreakable. It's just that it requires a different, more labor-intensive process to get the data requested.
>The sheer variety of Android hardware and customized software builds makes it hard for phone-crackers to build a universal tool to break into Android phones. Meanwhile, a "jailbreak" released late last year permanently bypasses the security functions of every iPhone model from the iPhone 4s to the iPhone X.
This perfectly squares with what I personally know from law enforcement friends but I'm just an internet stranger.
On the Android side, Google makes good software changes to Android, but ultimately the security is dependent on the handset maker (e.g. Samsung) and SoC maker (e.g. Qualcomm). Security will vary between Android phones. The bigger Android phone makers are more able to make security investments than the cheaper phone makers.
In any case, the biggest vulnerability in any system is the end user. No amount of idiot-proofing will stop people from being scammed on an iPhone, nor will it stop someone on Android. When these companies market their "Secure Enclave" or "Titan Security", they're really just dressing up otherwise expected or boring features. The T2 chip was basically a dedicated PRNG chip with basic encoding capabilities, yet Apple paraded it as a boon for device security and game-changer for the end user. In reality, it doesn't solve any practical issues with computer security.
I've tried about every OS on the planet, and I've used them on a decent handful of different devices. I won't tell you what to think or do, but Apple's devices are difficult to appraise and hurt my head when I try to consider their impact on my overall "security". I'd much rather just use a Linux system that's transparent about it's vulnerabilities. Much of that same reasoning is why I still use Android these days.
My ultimate point is that the biggest liability is the user, and those "security updates" don't really matter when the biggest attack vectors don't even consider these exploits in the first place.
This is an extremely misleading description of the scope of T2’s duties.
As you can see, the price is so low it hardly even matters if there is a difference. There are literally millions of people in the US alone who personally have the liquid net worth to purchase a remote wormable persistent compromise that you can use to mass infect any Android or iPhone. Essentially every business with more than maybe 10 employees has enough assets to purchase such a weapon on the market. Just today I read on HN that the US government inked a deal for $22B over 10 years for 120k AR headsets from Microsoft [5] which comes out to ~$183k/headset. So, a weapon you can use to fully compromise any phone you want is equal in cost to a mere 15(!) headsets. That contract alone would be enough to purchase 10,000(!) vulnerabilities at existing clearing prices and $22B is only ~1/200th of the yearly US government budget.
Frankly, the entire thing is like two people jumping and comparing who is closer to landing on the moon.
[1] https://www.google.com/about/appsecurity/android-rewards/
[2] https://developer.apple.com/security-bounty/
[3] https://zerodium.com/program.html See Mobiles payout.
[4] https://www.statista.com/statistics/276306/global-apple-ipho....
[5] https://techcrunch.com/2021/03/31/microsoft-wins-contract-wo...
Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.
They aren’t perfect but I don’t think it’s fair to say they don’t try.
If you have written a hardened, safe browser engine then you are free to share it to the world, otherwise I wouldn't downplay their efforts.
Not OP, but I'll stop complaining when Apple lets me use other browser engines.
Yes, IMO their business model is more accurately described as “gilded cages/jails” than just general “gilded/good-appearing stuff”. They deeply care about the strength of their DRM — including at the expense of end-user security, eg. you can’t access the internet through the Tor browser installed the normal macOS way without macOS broadcasting that you used Tor Project products to Apple’s DRM servers.¹
> They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well.
They definitely care about the appearance of trying to prevent that exfiltrating (they don’t publicly appear to help the FBI do it), but they don’t try hard enough to actually prevent it (including in situations were preventing exfiltration seems to have been proven possible, see nearby comment https://news.ycombinator.com/item?id=26667141).
¹Edit: ocsp.apple.com, enabling targeting of the people who need or want security the most.
To the people downvoting: I’m trying to make an evidence based refutation of the less supported speculation/assertions in the parent post. If you have counter-evidence or any reason to downvote other than fanboyism, please explain it so we or I can learn.
Your first point is intended to refute the effort put into stopping jailbreaking in iOS. The example you give is about privacy on Mac OS.
Last, accusing folks of being fanboys is a particularly weak argument. It says, if you don’t agree with me then your blind allegiance to a corporation renders you incapable of critical thought. Basically, if you don’t agree with me, you’re dumb. There is no practical engagement with that thesis.