Apple previews Lockdown Mode
apple.com
apple.com
This is a huge step forward for iPhone users. Look, I get it. From the typical HN perspective, this potentially looks like a lot of hype. But many of you aren't looking at from a high level.
In the world we are now living in; even what's happening in the United States right now, being able to protect yourself from well-funded, determined attackers for the average person couldn't come at a better time.
There's a huge gap between Fortune 500 executives, government officials, etc. and regular people in terms of the resources available to them to prevent state-sponsored attackers. It doesn't take much these days to go from a nobody to being on somebody's radar.
If you're a woman seeking an abortion in a state where it's illegal or severely restricted, you could be the target of malware from your local or state government or law enforcement. In Texas, you can sue anyone who aids and abets a woman who attempts to get an abortion for $10,000, which is enough to get someone to trick someone into installing malware on a phone.
No, it's not China or Russia coming for you but it doesn't take much to ruin someone's life.
I don't think this is virtue signaling or marketing hype by Apple; if anything, this is right in alignment with the stance they've had on privacy for years. Even for a company the size of Apple, putting up $10 million to fund organizations that investigate, expose, and prevent highly targeted cyberattacks isn't pocket change.
At the end of the day, this is all good news for user privacy and security going forward. I also suspect if I lockdown my iPhone, my other compatible devices using the same Apple ID will also lockdown. No IT department required.
Much of the low interaction malware is only persistent in memory, so a reboot will clear it until they get their claws back into you. Depending on what the attack path is, that may take some while - and using those attacks is still somewhat risky. "Having to re-pwn a phone every 6 hours" is a lot more risky to an attacker than "someone who never reboots their phone and never updates it."
What this seems to be focused on are the "remote zero-click/one-click" vulnerabilities we've seen, in which either a message is delivered that never shows up but installs a backdoor hook, or a website can deliver a malware package to a particular user and install the backdoor hook without notifications.
It sounds like it does improve some of the physical security features, which should help reduce attack surface, but I wouldn't trust any bit of consumer electronics against a sustained physical attack by a sufficiently motivated adversary.
Even with this, there's not very much you can do against a state level actor who had physical control of your device and you, and a $5 wrench. Even without having you and being prepared to use violence, a sufficiently motivated state actor will probably get into your device anyway - Apple didn't6 cave to a judge when the FBI wanted them to break every iPhone user's security to get into the San Bernadino shooter's phone, but they didn't get to set a precedent there because someone else broke into that phone for the FBI anyway and they dropped that case...
This really is a mode designed for those who really desperately need it, and it really is implemented in a strong enough way to be useful (hardware root of trust, no-drive by changes since it requires a reboot with a wiped key bag cache so you must reauthenticate in order to change it). But all of that for consumer-attainable pricing. It doesn't have to be perfect and I'm sure in due time there will be jailbreak-esque attacks. But until then, this is effectively a very high barrier for an attacker that lacks the resources of a nation state (or a smart but bored teenager in a basement these days).
No protection is perfect, and this kind of things are always another layer in a defence-in-depth approach. Just like car locks, the idea is that it becomes enough of a hurdle that someone on a fishing expedition will go look elsewhere. Of course it won't be enough for a determined state actor.
Got any info/links explaining that? Having only read Apple's webpage, it sounds to me like the major problem is slowed down javascript execution? I certainly didn't;t get the impression it's going to shut down all social media apps/websites?
For more of my take on the topic, see:
> Even for a company the size of Apple, putting up $10 million to fund organizations that investigate, expose, and prevent highly targeted cyberattacks isn't pocket change.
is kind of funny, as it’s about 1/20000 of their total cash reserves. With 20000 in my savings account, it’d be equivalent to giving 1 dollar to charity. In other words, pocket change :)
Zero-day buyers are going to have a hard time topping that.
You could easily get more for selling a zero-day likely this than reporting it to Apple. If you combined the risk this is being turned on is reported back to Apple or remotely detectable, combined with a zero day, it would be a goldmine; cover this and other issues in my comments on the topic:
Specifically the 2022 Q2 financial statement(it's a PDF). under "Cash and Cash equivalents" on the 2nd page, you will see: 28,098
That's in millions of dollars(see top of that page for source), so they have 28 Billion USD just laying around.
10M/28098M = 0.0004 so it's 0.04% of their cash.
You know what people do when they're targeted by state actors? They don't use computers. And if they have to, they air gap.
A great example of this might be visiting a country like China while on business. Straight up going "off the grid" isn't really an option in that scenario.
They may compel all kinds of things, such as unlocking it or more.
KISS.
That's not always practical.
Most corporations who know what they are doing (and some who don’t) send their execs with burner devices when traveling to certain countries on business trips.
It's not going to be a flip phone, it's going to be a iOS or Android device specially provisioned by the company's IT department for use in environments like these.
You can't get anything done on a flip phone, you can barely operate in China without WeChat/AliPay.
It wouldn't be very difficult to provision an iOS device with limited connectivity to proprietary information while still maintaining necessary operational communication and productivity. The idea here isn't to just flip Lockdown Mode on and pray that all the secret stuff on your phone doesn't get hacked, the idea is to use it as one tool of many to reduce your blast radius.
It’s irrelevant what it runs, the point is it doesn’t have the individual’s personal data and most importantly access to company data.
That's like saying "men who don't have easy access to condoms just stay abstinent instead". This is what we wish would happen. But empirically, they just shrug and do the insecure thing.
(There was an article posted on HN a few years ago that was from a journalist pointing out this exact thing, from his personal experience. I can't find it though.)
You know the state is after you.
So you ignore this, turn off your phone instead, and… what? Now you’re even more alone, can’t get help from friends/family.
This seems like a very reasonable option in some situations.
*maybe he has a team that audit comms for malicious activity and payloads, but not everybody is as well resourced so the point still stands
Anecdata for people who think this is unlikely: my wife had an issue getting unclaimed property back from the state of Texas and hired someone who advertise the ability to help. She turned out to be a bulldog with a ton of knowledge of the necessary bureaucracy. She put hours per week into it on our behalf for months, through many rounds of filing paperwork and then hounding bureaucrats on the phone by telling them exactly how and why we could sue if they ignored it. She did all that for a cut that was a fraction of the $10k abortion bounty. The $10k might seem like a symbolic gesture, but it will spawn a cottage industry of bounty hunters. No doubt most of them will be ideologically excited wannabes who quickly give it up, but some will be dogged and effective and will cultivate an expanding repertoire of skills. It's a terrifying prospect.
There will be many, many people who never previously entertained the idea of getting involved in serious criminality who now need protection from the prying eyes of the state and their fellow citizens. To look at it from a cold and opportunistic viewpoint, this could change the public perception of digital privacy from being just for dangerous creepy people to something that everybody should value.
This functionality makes a lot of sense in such a case.
Presumably someone could use malware on someone's phone to know who to target with an abortion-related lawsuit, and then use legal forms of investigation to find evidence to prove that they got an abortion.
This needs to be the case of course, unless you support law enforcement agencies doing unlawful actions to get convictions.
Isn't this even more complicated to prove in the case of private bounty hunters, instead of the police?
Even if the method used was illegal, and found to be illegal in court, the evidence is still admissible iirc?
Parallel construction often means they hide how they got the original information from the court and from the defense.
For example, you use illegally gained access to messages to find out about a meeting at a particular time. Then when the meeting to exchange contraband is happening, “a concerned anonymous citizen” calls in a tip of suspicious behavior and a patrol cop stumbled onto a bust.
It's really disgusting that we allow this.
It’s like saying that it’s disgusting we allow cops to steal seized property. We don’t, but it happens.
While there is a problem with US police acting unlawfully, it mostly happens in specific situations. At the federal level, they are much better behaved. And the incentive structure just doesn’t make it worthwhile to break the law
Find out from the phone, that they have an appointment at a particular time and place? It's easy to just be there and photograph them, "as part of occasional surveilance" or whatever.
this is when evidence is collected in nefarious and often illegal ways. it is then given to the organization which will weaponize the information. this organization then launders how they acquired the evidence, obscuring the shady way it was originally obtained.
there is no shortage of instances where different groups (including local police) have laundered how evidence was obtained to get around legality requirements for obtaining evidence.. [various links below]
as the above commenter highlights, it’s about to get even more terrifying as incredibly well funded, incredibly authoritarian groups jump into the fray using religion as their excuse.
https://www.eff.org/deeplinks/2013/08/dea-and-nsa-team-intel...
https://www.jurist.org/news/2018/01/hrw-us-authorities-conce...
https://reason.com/2018/01/09/federal-agencies-may-be-regula...
https://www.aclu.org/blog/privacy-technology/surveillance-te...
https://www.techdirt.com/2014/02/03/parallel-construction-re...
https://www.hrw.org/report/2018/01/09/dark-side/secret-origi...
https://www.scmagazine.com/news/security-news/fbi-stingray-n...
https://www.wired.com/story/stingray-secret-surveillance-pro...
Fairly sure this is wrong. The point was to create a mechanism to sue various people "in orbit" around an abortion without involving state officials. This was supposed to "immunize" the process from any Roe v. Wade-related block.
With Roe v. Wade now struck down, Texas can basically do whatever "it" wants w.r.t abortion, and the federal government cannot intervene. SB8 at this point is possibly (just possibly) a way to reduce state spending on abortion legal cases, but not much more beyond that.
It's directly (and I believe explicitly) modelled on the Americans with Disabilities Act. The ADA creates a model in which private citizens can and do bring lawsuits against all types of organisations for any type of harm they can define.
This has spun out a cottage industry of disabled people who's full time occupation is visiting everything from websites to restaurants, being harmed and bringing lawsuits. While that may sound like a bad thing, it is in fact a very very cost effective way of enforcing the law quite effectively without bureaucratic bloat. Strangely, it's been quite successful. The history of why this decision was made is very interesting.
For all your devs, this is why large American companies care so much about accessibility on their websites - because it creates an almost unlimited liability on their end if you do it badly. Companies now scan websites for accessibility as soon as they're launched, then others will buy the set of companies which 'fail', then visit those sites in order to be harmed. It's an interesting little cottage industry which keeps legitimate disability rights enforced quite nicely without too big a government.
My impression is that it fits the pattern of trying to disrupt society and government and create a vigilante citizenry, similar to encouraging people to arm themselves and use their firearms to prevent crimes.
As a private plaintiff, you can typically sue a state official that is charged with enforcing a law in federal court on constitutional grounds. SB8 is written in such a way that state officials are barred from enforcing the law. Thus, it is effectively impossible to challenge in federal court because there is no state official that enforces the law, only private citizens, and thus there is no proper defendant.
In the discussion about privacy we use tik tok to get our data, aren’t we?
Great communist china welcome you. Heard of the leaky story of the firm lately and the FCC case.
The US right now is a fucking shitshow. It’s one bad election away from being yet another gunslinging theocracy hating women and gay people. They’d probably switch sides and bomb Ukraine, without necessarily looking at a map.
With this, steep decline in US power projection is inevitable, I mean you can't lose half a billion big rich western population almost 100% aligned with your values.
I feel that if given another Trump win, the rest of the west will be forced to remain in another holding pattern for four years and suffer whatever consequences occur hoping that four years later things improve.
>The EU would probably try to find closer relations to countries with semi big military, totally guessing here India, South Korea, Japan, Australia, New Zealand, Turkey.
This is assuming they have the capability to project forces anywhere in the world which given these countries you listed, feels unlikely either now or in the distant future.
When you don't have regulations, strong federal oversight, high taxes, or invest in social programs, then you can have a fucking excellent party nearly all of the time.
Until the economy tanks or the American Taliban decides their party involves telling you what you can do with your body.
It's a very immature/libertarian way to run a society. Wonderful when things are good. Horrific when things are bad.
The stakes are higher than individual hedonism now, though. American Prosperity is boiling our atmosphere and by the end of the century, excess American contributions to carbon emissions will have killed more people in the 3rd world than Hitler and Stalin put together. This is not an exaggeration. Hundreds of millions will die in Bangladesh and India from rising seas and heatwaves because Americans wanted the freedom of the house, the picket fence, the 2 F150s, and the 2 hour commute, and Next Day Shipping From Amazon for All The Things.
One of the quirks, and ongoing debates, of the US is the strong deference to states’ rights. Don’t confuse US law with Texas law. The majority of the population of the United States actually lives in states with abortion laws that are more liberal than what you’d find in the EU, for example.
The state versus federal distinction can be very confusing to people who view US politics through the lens of the worst news stories that come out of every state. The entire US has a land mass and population on the same order as that of the entire EU, and many states have populations similar to that of individual EU countries. We have a single state (California) that has an economy larger than all of the UK combined and almost as large as India.
The United States is big and diverse. We’re going through a phase where federal power is being reduced due to politics and some of the states are doing weird stuff. If you only view the US through news stories and imagine the US as a conglomeration of all of the worst and weirdest news stories from individual states, you’re going to have a very negative view of the US in general.
For the 4.5 million of us in Louisiana, the current laws are a pretty huge deal. But according to him we apparently don’t matter when having a national dialogue.
Yes, but the idea that those laws are being imposed on an unwilling population by an extremist minority is wrong. Half of Louisiana residents believe abortion should be illegal in most or all cases (https://www.theadvocate.com/baton_rouge/news/article_4973b4e...), and many in the other half likely support restrictions that weren't allowed under Roe/Casey. This is what democracy looks like, and an example of how democracy isn't always a good thing.
The GOP controls this state in a wildly disproportionate way. They passed it because of that, not because of a possible slim majority. We’d have legalized weed if that’s all it took.
We also have fifty governors, 100 senators, 435 house reps, nine supreme court justices, and countless state legislators. We do not live in a dictatorship. Yet.
Of these, it's the court that has changed most wildly over the past 8 years.
> soon it will be much less diverse than you can imagine right now.
I think it's possible to say "overturning Roe v. Wade didn't make abortion illegal in California, as your worst case presumption might assume" and still believe that GOP gerrymandering, Supreme Court appointments, and attempted coups are an existential threat to majority rule.
That is, per Popper, tolerating people who will physically harm you as part of the discussion means a discussion cannot be meaningfully held at all.
But people really like to stretch this to whatever edge-case meaning of "intolerant" would be convenient to them at the time...
The freedom for individual states rights you espouse has always been used for almost exclusively civil right violations.
If you don't do something about that, you are complicit. Now you might say there is nothing you CAN do about it.
But that is the problem. That is WHY the rest of the free world looks at you and says "You are not a democracy."
Because you couldn't change this even if you wanted to.
The last time you tried you came close. You had to fight a war over it but you almost got there. Then you fucked it up during the Reconstruction.
It's also a question of whether you want that. Anyone can take anti-phishing training, it just takes a lot of time. Want to download a mod for a game? You better have a separate gaming machine with no important data on it and, to be sure, in a separate network. Want to buy a phone? Better drive to a random store, ordering is to dangerous.
Sure, it's easy to get on the radar, but avoiding a state-sponsored hack is also a lot of effort. Fortune 500 executives need to put that effort in and they do have the money to make it happen, but for most people, the problem is not the cost.
10 Million = 0.0027% of Apple's sales in 2021.
Equivalent to an Apple developer who made 300K in 2021 donating 8 dollars.
If this doesn't classify as pocket change, it's quite close.
If you went with net income, it would be 0.0105% of Apple's 2021 net income.
Or $31.80 of $300k instead of $8.
- You have people whose security depend on you
- You say this is a top priority and of ultimate importance (people's lives depend on it)
- You make $300K gross income over a year
- And you dedicate $50'ish for an entire year to contribute into solving the issue
It does look like pocket change to me.
To stave off tedium, it's still $800 at a 1/3rd tax rate. These numbers aren't pocket change any way you slice it.
At $30000 income where someone else is making the money to pay for expenses, it’s like $10. That’s pocket change.
Or the profit someone has after paying for rent (isn’t this equivalent to paying rent for their own stores and office buildings?), and other things that companies write off before they calculate profit or net income, a $300K income, might have equivalent profit be $90K. That’s under $50. Change it to someone making $75K income and you’re at $1.
Neither of my comparisons are properly analogus but neither is yours. Comparing a company that is doing billions and billions in profits with the income of an average upper middle class person is as incorrect as comparing what is considered negligible money between $300K income and full time minimum wage. The latter person likely has no money left over, maybe goes into a bit of debt each year.
Let's not get in above our heads, here: if the US government wants to know what's on your iPhone, they still have the faculties to retrieve that information. Setting your iPhone in a lockdown mode isn't going to let you escape the purview of government surveillance, and if it did then Apple wouldn't be announcing it today. We're all targets of government malware, and the way they ensure we all keep it installed is simple: they just make Apple and Google write it for them. This pervasive idea that Apple is somehow escaping the jurisdiction of PRISM is pretty hysterical, and it makes me excited for the first Senators to get caught paying for prostitution services with Apple Pay inside Lockdown Mode. The only enemy of "good" in a threat model is the unknown, and Apple makes sure there's plenty of unknown factors in your iPhone.
Edit: For all HN loves to rant about the Halloween Documents, you lot seem awfully unfamiliar with the Snowden leaks...
Lockdown Mode basically cripples the phone, feature-wise. It's not quite to the point where I'd (even hyperbolically) say "why don't you just get an old dumb phone instead", but still...
The right thing to do would be to redesign the system from the bottom up to actually be secure in the face of vulnerabilities in any of these features that get disabled because they can be dangerous for people. (And maybe Apple is working on this behind the scenes, which will take them years to complete.)
But, agreed: let's not let perfect be the enemy of the good. It's better to have this option than to not have it, even though it likely creates a super restricted user experience that probably isn't particularly pleasant to use.
The problem is that phones (of the "dumb"/"feature" variety) are running OSes that don't have nearly the security attention or hardware features related to them as iOS devices.
I carry a KaiOS feature phone as my personal phone (when I remember it). Apple pissed me off enough with the CSAM stuff that I wanted to experiment with alternatives, and I've done so. However, I don't pretend KaiOS is particular "hard" against attackers - it's almost certainly not. But neither does it have much of an attack surface. It doesn't even try to render emoji, they're just black rectangles. And neither does it try to, say, render weird old Xerox image formats.
I would trust an iOS device with "most of the complex attack surfaces turned off" far more than I'd trust a KaiOS or stripped Android device. You get all the hardware protections, regular OS updates, a bug bounty program focused on this mode, and the smaller attack surface window of Lockdown.
I'm incredibly excited by it, because it turns off all the stuff I don't want in a phone anyway.
Unfortunately, "crickets on CSAM" is a problem too. If they say they're not going to ship that ill conceived feature, I might move back to iOS. If not, well... I'll probably play with Lockdown mode for a week or two and then go back to the Flip.
Again, the CSAM "scandal" was actually an improvement of what the other online photo services do (constantly scan your entire library of photos with no controls in place). Just the improvement involved on-device scanning that folks seem allergic to. But you can opt-out, so still better than KaiOS.
If I store content on your server, yes, absolutely, you can use your resources to check the stuff I've stored for what you define as badness.
But Apple's system is using my device to scan for their definition of badness. If they'd then said, "And this allows us to do iCloud E2EE," well, OK, this is a discussion to have. Except they didn't and haven't. It is, as designed, "I use my device to scan stuff for you, and then you can still scan it."
And as a direct result, the EU is now pushing for "badness scanning" in all sorts of E2EE channels, to include searching for "grooming" in text chats. "But Apple said they could do it! Why can't you do the same thing?" is a valid argument from a politician's point of view.
KaiOS doesn't have anything in the way of photo uploading in the first place.
Disabling the JIT compiler makes the browser a bit slower. It does not cripple it.
Disabling profiles, debugging and MDM? These are not useful unless you’re in ‘enterprise’ or a developer.
Can’t send documents or links through iMessage? Use another service or copy and paste the links you actually want to open.
Really a tiny price to pay for the added security.
I consider myself "recreationally paranoid", I enjoy locking my stuff down for fun, not because I ever think anyone's gonna burn an NSO zero day to get into my stuff.
Microsoft did some tests for Edgium's "Super Duper Secure Mode" and found that disabling JIT improves real world performance more often than it makes it worse (and usually makes no difference):
https://microsoftedge.github.io/edgevr/posts/Super-Duper-Sec...
Diabling JIT makes it possible to enable some additional exploit mitigation methods. A follow up article mentioned that few people who tried it noticed a difference:
https://microsoftedge.github.io/edgevr/posts/Introducing-Enh...
"It is worth mentioning that when we originally had this idea, we doubted our Microsoft Edge peers would even consider it. We quietly made changes to our browser without explicitly telling them the specifics and then asked them weeks later to see if they noticed the change. They would always say no, and only then would we inform them that we disabled the JIT. After surprising multiple developers in Microsoft Edge, we got the support needed to try this experiment. One can’t help but wonder what other well established assumptions about users and the web we should reconsider."
I'm not really going to argue this but, just in case it is interesting for you and others to learn:
I use profiles/configurator on my kids' iphones ...
i understand the impulse to immediately question if this might solve security, but it just won’t. there are some classes of known vulnerabilities which it may mitigate, but at best it would be a temporary security solution.
security is hard.
we also need to remember that we would, with almost 100% certainty reintroduce long forgotten about mitigations that someone silently did years ago but they didn’t make a big deal over. or even mitigations which were made a big deal of, but they were a decade ago therefor long forgotten about.
we have a tendency to think those who built complex systems before us were unenlightened, or lazy, or primitive. this often really isn’t the case.
anyone who has worked on large projects will inevitably learn the hard way that scale adds incredible fractal depths of complexities that we can’t dream of until it slaps us in the face. so we put out that fire, do not-nearly-enough-documenting on why or what caused it so future people might avoid the same mistake, and then we continue running up the hill.
security is hard.
and of course sometimes a from-scratch-rebuild might make sense but we’d be looking at years and years of relearning mistakes which were previously learned and corrected for.
security is hard.
It is frankly ridiculous that anybody should believe Apple when they claim to provide even minimal resistance to well-funded determined attackers. Protecting against well-funded determined attackers has been the holy grail of software security since forever and everybody in software security at least claims to be working toward that. Despite that, the prevailing state of “best-in-class” “best-practices” commercial software security is objectively terrible including Apple circa 1 year ago.
Are we supposed to believe that Apple, despite abject failure over the last few decades until as recently as the last time they announced security updates to the iPhone, has finally this time, for sure, pinky swear its true, jumped from terrible to the holy grail, or even good, because they said so?
No, this is absolute, utter, unequivocal garbage. Their claims are completely unsupported and they should be excoriated for spewing unsubstantiated bullshit that muddies the waters of the actual state of software security and misleads people into believing they are getting a meaningful degree of protection or software security.
If they want to make such claims, they should put their money where there mouth is and, instead of certifying iOS to EAL1+ and AVA_VAN.1 as they currently do, they should certify it in “Lockdown Mode” to EAL6-7 and AVA_VAN.5 which actually does certify protection against “high attack potential” attackers such as large organized crime and state-sponsored attackers. At the very least they could certify it to EAL5 and AVA_VAN.4 which certifies protection against “moderate attack potential” attackers. Until they do that, their claims to protect against state-sponsored attackers are complete unverifiable bullshit.
For that matter, it is not like they could not provide such evidence even though it came out today. It has presumably been in development for some time, so if they did actually provide verifiable protection against state sponsored attackers they could just release their formal proofs of security to that effect and be done with it or at least preliminary certification evidence demonstrating protection against high attack potential attackers as outlined in the international Common Criteria standard via AVA_VAN.5.
iOS is already certified according to Common Criteria as their only advertised security certification, just at the lowest possible level, and it already has a certification for high attack potential attackers, so doing this would be consistent with their existing certification regime and provide clear evidence supporting their claims.
Absent that, I see no independent verifiable evidence of any of their claims, endless precedent to dispute their claims, and not even a token effort to provide even a sliver of objective backing for their claims.
So why should I or anybody else reject the standard wisdom of “you are screwed if state sponsored attackers are interested in you and there is no product that can help you” and instead believe Apple’s marketing that they can?
What was announced today is the first version of a feature in a beta version of an operating system that won’t be released for at least 2 months from now. Chill.
I’m sure there will be the requisite white paper, statements from security experts, verification from industry groups, presentations at security conferences, etc.
In the meanwhile, from what little we know now, it seems to be heading in the right direction.
I will start by pointing out such a standard, the Common Criteria, which can reliably reject systems that can not protect against state-sponsored attackers as systems such as Windows have never been able to achieve even protection against moderately skilled attackers, which is a fair assessment. Under that standard, which iOS and all other Apple products are already certified to, Apple has never once been able to achieve protection against moderately skilled attackers let alone highly skilled attackers. In fact, that very same standard declares from empirical evidence gathered over decades that it is infeasible to retrofit a system that can not protect against moderately skilled attackers to ever become able to protect against moderately skilled attackers or above.
For reference, one way of demonstrating protection against highly skilled attackers according to the Common Criteria is to subject the systems to a penetration test by the NSA with full access to source code with successful penetration constituting a failure. That is a reference point for what protecting against a state-sponsored actor looks like according to the standard.
Everything is always insecure. Like in toxicology, it's a matter of degree.
If you're really facing state-sponsored actors, you shouldn't be using an iPhone. You probably shouldn't be using a mobile phone. But that isn't a tradeoff most people are willing to make.
Lockdown Mode existing is unequivocally better than it not. Those who would have air gapped aren't going to be tricked into using Lockdown Mode instead. Instead, those who would have reluctantly used their iPhones in normal mode and e.g. turned off location tracking will now be better protected.
Lockdown Mode is being advertised as protecting against state-sponsored actors: “Lockdown Mode offers an extreme, optional level of security for the very few users who, because of who they are or what they do, may be personally targeted by some of the most sophisticated digital threats, such as those from NSO Group”. They are attempting to convince people who would otherwise air gap to avoid being killed that their systems are perfectly adequate. Their systems are on the order of 100x worse than what it necessary to protect against state-sponsored actors. It is not acceptable to attempt to conflate the two just because everything is a shade of gray; one is off-white and the other is off-black, they are not even remotely similar.
Apple’s advertising of Lockdown Mode is unequivocally worse for the stated use case than not having it at all since then at the very least people at risk would not be mislead into thinking Apple can protect them. If they want to change their advertising to clearly indicate that it should not be used if you are at risk of state-sponsored attacks and that there is no independent verification for any of their claims, then I would agree with you, but they are not doing that. Until they do, they should be censured for making such irresponsible and reckless claims that mislead at-risk individuals from taking proper precautions.
If your threat model includes any level of the US government, and that includes women seeking abortions in states where it is illegal, you cannot rely on US-based company's tech to protect you from the law.
If you're in a developing country and you engage in activism against some questionable project by the state owned mining company, you're probably not going to get the full force of the NSA directed against you. But your country's domestic intelligence agency may be interested, and they probably only have off the shelf spyware to work with.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
I haven't heard of any changes to this to-date.
https://support.apple.com/en-us/HT202303
That seems pretty clear to me, but maybe it’s misleading?
Did not look good for Apple. For a company of their means, they had to do something.
When you use the hack and it's discovered, it'll get patched and you'll need a new one. These cost 6 figures to acquire in the least.
We expect so little of our phones with respect to our desktops when we know full well there's no legitimate reason to do so. Particularly now, if you're imagining that one needs security against state level actors.. then the notion that a single vendor is required to simplify the ecosystem and broaden adoption is directly in conflict with this future you have declared we are now in. It's literally the weakest possible model of defense available.
This isn't the perfect being the enemy of the good.. this is Apple monopolizing yet another aspect of the platform for themselves at the cost of true innovation.
I’m okay with this; I’ve always felt that dealing with the security issues of 3rd party rendering engines and JavaScript implementations is a valid reason to not allow them on iOS.
Since Apple is the platform vendor, at the end of the day, if there’s a vulnerability, it’s their responsibility, even if (in a hypothetical future) it’s Google’s or Mozilla’s JIT that allowed the the malware to be installed on a user's device.
Of course, since all browsers on iOS use WebKit and JavaScript Core, they all get Lockdown protection for free.
What is the alternative, though? That each user figures out for themselves how what their security risks are, cobble together various security-focused apps, stays up to date with new developments, etc.?
Otherwise are you suggesting it would actually be impossible for any other company than Apple to do the best job here?
If that isn't the case, and absent that market, then is there any reason to believe Apple is itself currently doing the best job?
The average person has no meaningful way to distinguish between any those. They all claim to be great, auditing is expensive and difficult, and most people are going to get recommendations from people they incorrectly think are experts (shoutout to the websites I had to migrate/secure after someone’s “tech guy” picked GoDaddy for the bikini pictures). Even enterprise security software tends to be long on snake oil despite theoretically more knowledgeable buyers & budgets for auditing.
I think there is a solid argument that this space is not a naturally well-functioning market and is probably better with a few regulated players, similar to how we decided that the patent medicine market wasn’t good (and, yes, the regulatory failures are an important cautionary point!). People are literally staking their lives on something which has to be better than some SEO-d rathole.
You're describing an unregulated market where the FTC and DOJ didn't seem particularly interested in policing. I would suggest that's a bigger reason for the state of the market then thinking it's a natural phenomenon endemic to this particular case.
And finally.. the giant disconnect here is that "you should worry about state level actors" but "you're too unsophisticated to do anything other than beg Apple for help." Mostly, I was trying to point out the absurdity of this position while at the same time taking a dig at Apple for their "cute friendly monopoly" tactics.
> Mostly, I was trying to point out the absurdity of this position while at the same time taking a dig at Apple for their "cute friendly monopoly" tactics.
Yes, and you let the desire for a quick jibe lead to oversimplification. The level of access which is needed to implement things like this also allows very powerful attacks. It’s not unsophisticated but realistic to recognize that allowing that level of access would have some benefits but would also reliably produce a large number of victims who trusted the wrong vendor. Reducing the number of parties who have to get it right to keep you secure has a significant benefit, especially if you’re familiar with the long history of companies which were acting in bad faith or compromised.
I think that there's a practical reason. For all your examples, the companies operating the solutions can be held to US laws and regulations. But purchasing (or downloading for free!) software from anywhere in the world cannot be regulated effectively (at all?).
So as a consumer, there is base level trust I have in companies providing me home & property security, financial security, and medical records security because they can be constrained by US laws & regulations, such as minimum standards. Not so for random software that I download for free or buy from some overseas (or basement somewhere in the US) location.
People have done far worse for far less.
Can we stop spreading these lies?
What can i say ? Good luck then with your "privacy and security going forward". And remember later, when they knock at your door, that it was for your's and (mostly) their security.
are these US companies not legally obligated through some clandestine patriot act style laws to enable backdoors - and to deny the existence of these at any cost.
You could wake up one morning, and every billboard in Washington, every newspaper will have ads for this issue. Every representative would be followed around by lobbyists. And Apple could pay it from their coffee money.
Now, I get why we don't crack down harder on selling exploits. First, intelligence agencies love NOBUS (No one but us) exploits and believe something like this exists. Second, it is convenient because sometimes foreign intelligence agencies are used to spy where domesitc agencies are not allowed to; and third the US could probably do little (officially) against companies, say, in Israel.
But this is totally the kind of issue that you could escalate into a bipartisan national security thing. And it would be an incredible marketing, and security win if Apple could push any stricter legislation in that direction.
I would be strongly, strongly opposed to this.
It is a clear-cut free speech / first amendment issue.
If you don't believe me, just imagine yourself describing the pseudocode of an exploit to someone over the phone - or sketching out the details of a vulnerability in a short note.
I believe we won't get to this place because we have the first amendment but I would really love to not waste ten years fighting about it ...
Now imagine you figure out how to do the hack, do all the preparation, and sell it ready to use to somebody. And they are open about the fact that they are selling it to foreign powers. This should definitely be illegal, too. In the physical world, you also probably shouldn't be able to go around and sell instructions how to break into cars or houses.
> If you don't believe me, just imagine yourself describing the pseudocode of an exploit to someone over the phone - or sketching out the details of a vulnerability in a short note.
I don't see how any of this would be effected. You could still do hacking, security research, you could get bug bounties, report bugs to the vendor, the government, or even disclose them to the public. You just shouldn't be allowed to sell that kind of information to a third party.
There are many laws like that right now. In the case of insider trading, you are not allowed to share certain nonpublic information against some benefit with others.
Now imagine you notify the vendor that they have a grave security flaw in their product. They could totally turn you in to the police and the PoC is sufficient to consider you guilty. You won't be able to prove yourself innocent without a long, expensive and life-destroying legal battle.
It would have a massive chilling effect on everything else instead of what you originally intended.
Should that be illegal?
When it comes down to money, or protecting the freedom or privacy of users, they will choose money. In this case the money is in good PR to help them secure more government contracts. They are playing all sides.
I do not feel anyone that needs high freedom, security, and privacy is well served by proprietary walled gardens. Particularly those that only grant holes in the walls to corrupt state actors.
https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
However the Australian government attacking you specifically isn't the only problem this solves.
The dream I have is someone making a phone that is purpose-built to be secure against state actors. Unfortunately, this makes very little economic sense, and probably won't happen (maybe if some rich person started a foundation or something?). The phone would need to have pretty restricted functionality and would not be generally appealing to mass market consumers.
As it stands, securing a mass market modern smartphone, even from just remote attacks, is just intractable. We should not bury our heads in the sand and wishfully think that if they just spend a little more money, close a few more bugs, and make the sandboxing a little better, somehow iOS 16 or Android 13 will finally be completely secure against state actors. The set of features being shipped will grow fast enough that security mitigations will not someday 'catch up'.
This is the next best thing! The more we can give users the freedom to lock down their devices, the more the vision of an actual solution comes into view. This is the first step towards perhaps our only hope of solving this someday - applying formal methods and lots of public scrutiny to a small 'trusted code base', and finally telling NSO group to fuck off.
Even this dream may not pan out, but at least we can have hope.
A lot of people really don’t understand much at all about anything that they don’t constantly see and touch their whole lives. A lot of people truly just live in the moment constantly and use their higher order thinking for social navigation and sex.
You don't need a special phone or hardened OS to defend against that, and users vulnerable to this will remain just as vulnerable regardless of how much hardening there is.
I have a much harder time thinking about how giving states access to my information has been harmful for me. I can think of potential harms, if the state started doing religious or ethnic persecution(not trying to diminish the chance of this, but not a problem today) so I'm aware of potential threats. But other than that... What exactly should I be worried about?
I am concerned about any actor, as well, but take into account that a state has a huge amount of resources and if they are motivated enough can make your life worse than almost any private actor. It has happened in history, this is not something fictional.
The reach at which a private actor can harm you is much more limited in the general case IMHO.
https://nymag.com/intelligencer/2021/06/fbi-snooped-on-crimi...
Sure, and they have been open about what information they give. If you're talking about being forced to introduce compromised code, well I'm not aware of the US government being able to force a company to do that. Signal has said before they'll shut down and then move if this is a requirement and on top of that[1], the code is open sourced and constantly scrutinized by the security community. So sounds like a pretty difficult thing to pull off.
I don't think handing your phone number to Signal is as big of a security issue as you're making it out to be.
[0] https://signal.org/bigbrother/
[1] https://www.wired.com/story/signal-earn-it-ransomware-securi...
(1) It's the network of phone numbers - who knows who, when they added, that starts to draw a picture.
(2) If they have any infrastructure at all - update checks, contact additions, whatever, that is going to phone home or be polled or contacted whatsoever, particularly that which can facilitate a network response (generate network traffic when an ID is added) then the app effectively acts as an element that can be used for identity verification even if all traffic is encrypted. This is not a small issue.
These issues are not unique to Signal, but they should not be swept under the rug. FWIW I do not claim to have read or audited their code, I just feel the use of PSTN IDs (== highly available link to personal identification) is a total farce which introduces huge risk for nearly no benefit to users and is fundamentally incompatible with their nominal public stated goals (again haven't read the official text) of end user security if that security is supposed to be best-effort.
You can add contacts through Signal that aren't synced with Google. I've just understood this process as a way to initiate the social graph. You can just not give Signal access and start from scratch, but I don't think that accomplishes much.
Also, as far as I'm aware, Signal doesn't actually know your phone number.
To this day they're violating their own privacy policy because after they started storing user data in the cloud they never bothered to update the policy.
Currently it states: "Signal is designed to never collect or store any sensitive information." while in practice they store your name, your photo, your phone number, and a list of everyone you're in contact with which is pretty damn sensitive, especially if you're an activist or a whistleblower.
I've stopped using/recommending it. To this day I run into posts where people think Signal isn't collecting any user data. I hope every user who has to learn what signal is really collecting from some random internet comment thinks long and hard about what that says about how transparent and trustworthy signal is.
> they're now storing exactly the same data that they've bragged about not being able to turn over
Can you provide me a source on this? This is the first time I've heard of this.
Doesn't surprise me. You're my new example of folks still unaware.
My old one was here (none of the answers this guy got tell the truth of the situation): https://old.reddit.com/r/signal/comments/q5tlg1/what_info_do...
Here's an early discussion on the user forum: https://community.signalusers.org/t/proper-secure-value-secu...
It was a total mess with tons of posts there and on the subreddit too. Here's an example: https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...
Anyone not following all the drama at the time wouldn't have a clue, and a bunch of people who did still came away with incorrect information anyway because Signal didn't make it clear at all what they were doing and they've gone out of their way to avoid answering direct questions in a clear way ever since, instead keeping the myth that they don't collect user data alive.
There's no reason they couldn't have provided a simple opt out for the data collection and avoided the issue entirely and the fact that they wouldn't do that was red flag enough, but the mess of confusion their communications caused and their refusal to update their privacy policy should be all the evidence we need that they're not to be trusted. To be fair to the folks at Signal, they may actually be trying to communicate that very message to their users as loudly as they're legally able to.
Additional links you might not enjoy:
https://community.signalusers.org/t/dont-want-pin-dont-want-...
https://community.signalusers.org/t/can-signal-please-update...
https://community.signalusers.org/t/wiki-faq-signal-pin-svr-...
https://community.signalusers.org/t/sgx-cacheout-sgaxe-attac...
It doesn't require creating an account and giving up your phone number.
They use the same signal protocol with different trade off in terms of security and privacy[0]
My only concern is they are based in Australia.
0] https://getsession.org/session-protocol-technical-informatio...
Matrix fixes this, but only in the sense that they replace the whole protocol without reverse compatibility.
The same need for modern communications (phones) exists.
I think it has about zero chance of withstanding physical attacks, which is important to me in a phone, but it's a nice effort.
I just don't see how anyone could build such a thing. State level actors have the tools necessary to force you or your company to build in any backdoor they want, and prevent you from ever talking about it to anyone. US certainly does, and could just force apple to add a backdoor to this lockdown mode and apple could never even hint at its existence under legal threat.
Why anyone allows their devices to be manufactured overseas is beyond me.
$$$$
The former is assembled in China, the latter in the US.
I don't know one has been issued. But Apple still sells devices in Australia, so I'm assuming it has complied when it was asked.
See https://www.techtarget.com/searchsecurity/definition/Austral... for an overview.
There are enough issues with the spying bills introduced in the last few years without creating ones that don't exist.
If I was really concerned about targeted cyber attacks against me, I think that I would exclusively use computers that I would buy from random people on Craigslist, take the hard drives out and only boot with live CDs using ram disks, and only connect via random public Wi-Fi locations.
Excellent precautions if you live and work in average middle-class suburbia and never go anywhere or do anything dangerous, controversial, or politically unpopular.
Lockdown Mode is not for you. It's for other people with different lives.
How exactly does this method stop working in cities? You could have provided some content instead of a weirdly vitriolic dismissal.
Your mitigation is not a mitigation against being singly targeted. There are so many attack vectors in a computer outside of the boot disk. The computers sold on Craigslist should not be considered secure, since there is no level of trust in the supply chain or the state of the hardware.
For ex: If you are being directly targeted, a nation-state can purchase the computers from your local Craigslist, rewrite their bios, and list them for you to purchase. Then flood Craigslist with 100 other compromised machines.
All of that certainly sounds much more involved than sending a zero-day zero-click iMessage to the well known phone number of a dissident.
And I think you may be overestimating even the resources and capabilities of nations.
Let's say you lived in Philadelphia. You could drive down to Baltimore or up to NYC in 90 minutes. Within that range, there are literally over 10,000 individuals selling 1 or more laptops on craigslist and other sites that I did a cursory search over. And that's not even counting all of the small mom and pop shops that are selling laptops, as well as the big box stores.
How should the adversary state figure out which of those people you're going to purchase from? Should they purchase literally every laptop in the region? Okay then...what about when people start selling more laptops they had in storage because the market is red hot?
What do they even do when they have the laptops? Do they have exploits for every BIOS for every type of laptop for the past 15 years? How do they sell the laptop to me? Do they have their agents sell them? Do they have hundreds of agents who are deep undercover in America, who could lure me in?
I just don't see "buy every laptop in a region, exploit it, and resell it, hope your target picks one up" as a viable strategy, even for the wealthiest of nations, assuming you need to do it discreetly.
What means of communication are available to you via a phone but not via an internet connected computer?
There isn't even anything intrinsically wrong with a cell phone, other than the fact that it encourages you to carry it everywhere and merge all communications with everyone onto a single device that is default connected to the internet.
It's designed to be secure even though it communicates via insecure wifi, for instance via tethering or at home. The CPU and most peripherals are in an FPGA with an auditable bitstream to program the device to ensure there are no back doors. Hardware and software are all open source. It has anti-tamper capability.
It looks well-thought-out.
A microcontroller on 130nm? Different story probably. Still crazy hard
Adding one undocumented latch is enough to undermine an ASIC CPU. To do that to an FPGA, you'd have to know where the layout engine is putting the circuit you intend to pwn, and good luck with that staying still under any revision.
If this did become a problem, a technique analogous to memory randomization could be employed to make any given kernel unique from the hardware's perspective.
The manufacturer/adversary knows nothing about your core design or where you'll place logic. Synthesis tools literally randomize routing and placement on each run as a natural consequence of routing being strongly NP. Further, once you add in the fact that FPGAs are often fairly high volume goods since the same chip is sold to thousands of different companies, it makes even less sense since now you have to have a backdoor that activates only on specific random designs but not any other design in regular industry use since an activation would lead to incorrect circuit behavior there. You'd also need this behavior to not show up under automated verification (you're running a verification suite against your chips, right??) which is nearing on science fiction. While, I guess you could do something like this, it'd be wildly impractical in every sense of the word.
DEFINE:
State Actors: [0]
As one who is acting on "behalf" of a government.........
What if said government was actually an arm of the corporate entities as the state ACTING at their behest?
Crazy, I know.
It will be interesting to see what third-party researchers discover about these new protections. Might remember something about Apple rewriting format parsers for iMessage in memory-safe language with sandboxing as Blastdoor and it was discovered there was still plenty of attack-surface in the unprotected parsers.
You can also say "Hey Siri, whose phone is this?" and your phone will lock down the same way as described above.
Of course, this doesn't protect from the $5 wrench attack, but plausible deniability only goes so far as well in a targeted attack. At least, depending on your local laws, law enforcement may not be able to compel you to provide your passphrase, but they can easily force you to use your biometric data, so this protects against that.
First thing is to remove a lot of the economic power and legislative power states have and hardening security in devices is also good news. But the problem is also that they have so much money and power that they can misspend money to target people and violate their rights because yes.
Here you go: https://puri.sm/products/librem-5.
FAQ: https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque....
It's the first such flag-raise I've seen. Security researchers talk about protections from state actors all the time, and there are tools which support that... but this is the first public announcement, and tool, from a corporation with more spare, unrestricted capital than many countries. It comes at a time when multiple nation states are competing for energy and food security; and Apple are throwing up a flag for a security-security fight (or maybe data-security). This is not just handy tech, it's full-on cultural zeitgeist stuff. Amazing.
The relationship between state and private industry has never been binary and has always had features like this. I don't think this is a "Jennifer Government" type scenario.
on the other hand, this is how democracy dies. what structures (systems) exist to prevent apple (and other comparable corporations) from being an oppresive force against human persons? moreover, what incentives do they have?
I only found out about this bank because the former president of the mexican central bank -- Mr. Carstens, left the central banking gig to go to that bank.
Source: friend used to work in the BIS and I've also been involved in banking off and on for a long time, including dealing with various international banking regulators.
Some fun BIS facts:
1) They process payments via regular SWIFT[2] messages. So the $100m in aid comes as a message just the same as if you transfer $5 from one bank account to another. It has an IBAN number with a regular bank account, so if you changed that to your own account details and the message was processed suddenly $100m would appear in your checking account instead of going fund an aid programme for some government in Africa or whatnot.
2) The number of payments they process is very low (>100 per day max and usually in the low tens of messages) so every payment message is checked by hand by several independent people as well as having automated checks. Partly to avoid the risk of funds getting sent to the wrong places etc.
3) My friend worked there in the 90s and said that even back then they had extremely strong security with multifactor biometrics on every entry to the premises. You got in via an entrance where you had to step into a cylander which would only unlock after it had taken multiple photos including an iris scan
[2] https://www.swift.com/about-us/discover-swift/messaging-and-...
Also, few know this, but many African slaves who were victims of the slave trade became slaves due to debt-slavery (though this didn't involve formal banks). I've seen estimates of up to 25% of slaves back then having been debt-slaves.
I hadn't realized that about African slaves; debt for what?
https://www.un.int/orderofmalta/about#:~:text=in%20your%20br....
Apple doesn't have a military or police force with jurisdiction over me. They don't have the legal power to arrest me or throw me into prisons, which they also don't have. I don't have to pay taxes to Apple. I don't have to do business with them or interact with them in any way if I don't want to. I don't need Apple's permission to do anything unrelated to their product lines.
Same is true for any megacorporation. It's a big stretch to say they are even remotely as powerful as nation-states, let alone more powerful.
Many nation states don't have control over interest rates (because their central banks are run independently of the government) or even the ability to print money, if they have adopted another currency.[0]
> Mandatory taxes
States typically tax transactions which happen on their territory (e.g. wages and sales), and in the case of Apple, their devices are their territory, like feudally controlled tracts of land in cyberspace. Taking a cut of all app sales and in-app purchases seems very much like a tax under this analogy.
And many others do. The State can abdicate such power and it usually does in stable economies where markets can self regulate. Given a big enough crisis, however, and the State will usually take that power back.
>or even the ability to print money, if they have adopted another currency.
Usually in cases of near total State bankruptcy
>Taking a cut of all app sales and in-app purchases seems very much like a tax under this analogy.
That's an interesting take.
Nope. You can avoid buying an iphone, but you cannot escape Google. I'm often forced to "do business" with google. I've seen several government websites that require code hosted on Google's servers. I need Google's permission to do all kinds of things unrelated to their service (reCAPTCHA) and google will track everywhere you go online even if you never use any of their services. Facebook also doesn't give you any option. They'll create a profile for you and start collecting data on you even if you've never created an account. You could argue that you pay these companies taxes in the form of your data rather than money, or that the fees they charge developers drive up consumer prices (acting as a tax on the purchases), and I suspect that should Apple/Google pay become more commonplace they will start charging a fee (tax) for that as well. Nothing stops them from doing it.
Some corporations even have their own literal armies (Blackwater/Xe/Academi), but others don't bother because they have the ability to command the police and military wherever they are. The RIAA have their own "swat" team. They participate directly in raids breaking down doors and handling evidence.
Companies like Apple and Google are far more invasive than police watching everything you do, listening to everything you say, recording every person you're in contact with. They censor and ban with impunity. If they really wanted to, they could plant data on your devices that would get you arrested and thrown in prison in any country around the globe.
corporations might not yet be as powerful as a nation state, but they're a lot closer than you give them credit for, and they likely have more direct influence on your day to day life and what happens to you.
Captchas are definitely worthy of criticism, but they are not remotely on the same level as forcefully controlling the land under someone's feet.
That is, they're turning features off for security. Something every IT department has been doing for decades. Windows supports this. Mac OS supports this. In fact, iOS was kind of notable in being so unconfigurable. The settings available in their MDM implementation were pitiful and didn't let admins disable many of these features.
Apple's profits are bigger than my country's (Slovenia) whole GDP. You bet your butt they're a state level actor in the digital world. They have more resources than many countries.
If Apple was a country, their $365bn in revenue would make them the 43rd richest country in the world right after Hong Kong.
https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(nomi...
GDP per capita for Slovenia is $25,179 in comparison. 100x less.
For Hong kong, which makes a bit more GDP than Apple does revenue, the per capita number is $46,323. 50x less than Apple.
But your iMessage data...well there, your ass is hanging out in the breeze. In fact, I'm not sure it's possible to log into an iPhone with your Apple ID and not have an iCloud backup immediately fire off, which means your private encryption keys hit iCloud and stay there until it is purged according to their data retention policies. And we have no idea what those policies actually are; those keys made end up stored forever.
The US Government pressured them to drop a plan for fully encrypted cloud backups.
>Apple dropped plan for encrypting backups after the FBI complained
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
If you want a fully encrypted backup of your device, you have to make it to your local Mac or Windows computer.
Yes, it absolutely is possible. I have never turned on iCloud backup so I have no cloud backups of any of my phones or other devices.
You are correct there’s a bit of dark pattern going on here, but it is possible (to the extent the code does what it says of course). To be extra sure I have a custom lockdown MDM profile to disallow iCloud backups, as well as a number of other nefarious things like analytics, and whenever I get a new device, I first DFU restore it to the latest iOS image to ensure software (post bootrom) isn’t tampered with, then activate and install the MDM profile via a Mac and only then I interact with the device and go through setup.
Almost all users can't handle this; to support people, you need to be able to recover their account when they've lost every single password and proof of identity they possibly can. It's not a backup if you can't restore it.
The only persistent connection Apple has that I can think of to implement such a concept is for push notifications. Which would be a massive security hole if a HTTP response to that daemon was capable of bypassing the lock screen, secure enclave etc.
And the logical question is if they had such a system why would they bother triggering an iCloud Backup when they could ask the device to specifically hand over certain information e.g. Messages. Which at least could be done quietly over Cellular.
I mean, Apple has killswitches for every iPhone they ship. I wouldn't be the least bit surprised if that suite of tools also included settings management (MacOS has such a thing built-in, fwiw).
https://www.cpomagazine.com/data-privacy/icloud-data-turned-...
IMHO it should still be an option but only as part of Lockdown Mode, with the explicit caveat that turning it on risks losing data.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Also, there are many users who would benefit from e2ee iCloud backups who are not targets of NSO Group-type attacks, so I don't think it makes sense to make it only available in "Lockdown Mode".
Reuters makes two claims:
1) The FBI talked to Apple (duh) 2) An unannounced plan to implement fully E2EE backups was no longer discussed with the FBI at their next meeting
Both of those things might be true! Reuters isn't known for just making stuff like this up, like, say Bloomberg, but the article specifically says:
"When Apple spoke privately to the FBI about its work on phone security the following year, the end-to-end encryption plan had been dropped, according to the six sources. Reuters could not determine why exactly Apple dropped the plan."
So we've got an unannounced product, which the FBI didn't like, which Apple stopped talking to the FBI about (according to some leakers at the FBI).
This does not add up to "Apple dropped plans due to pressure from [the] FBI/DOJ". It adds up to "secretive company discusses plans with secretive agency, and some stuff about that conversation leaked".
This is likely the real reason E2E hasn't been done yet. I would wager Apple deals with orders of magnitude more people who are locked out of their phones than the number impacted by the lack of E2E backups. Trusted recovery contact added in the last iOS version is a step in a direction of providing some way to implement E2E, and still give people a way to recover.
https://www.reuters.com/article/us-china-apple-icloud-insigh...
https://www.forbes.com/sites/roslynlayton/2022/06/08/silicon...
https://www.theinformation.com/articles/facing-hostile-chine...
Microsoft handed over control of Azure in China to a Chinese company years ago.
"You" only means you if you're a Chinese citizen.
I wish we were more willing to cite our own government(s) as the bad actors here, rather than pretending that we have to reach for China/Russia/North Korea to find the kind of behavior Apple is attempting to protect its users against here.
The CLOUD Act expressly brings data stored by US-based companies anywhere in the world under the purview of US warrants and subpoenas.
Who wins? The USA, the EU, no one, everyone?
https://nextcloud.com/blog/the-new-transatlantic-data-privac...
Most companies affected are currently awaiting the results of these processes, because following the current precedent to it's logical conclusion, it appears unlawful to transfer any personal data of an EU resident to a US-based company (even if that data remains physically in the EU or another adequate country). That would obviously have catastrophic consequences for the current status quo, so it's hard to believe that a compromise won't be found to avoid it.
However, it's also hard to see a compromise unless the United States exempts EU data subjects from the CLOUD Act, which seem unlikely. Hard to know where it'll go.
Bureaucrats are capable of breathtaking sophistry when it makes their jobs easier. If red was illegal but convenient they’d make a policy that red was actually green and argue it was until they were blue in the face.
You unfortunately need something like this because otherwise people will just hide documents, money, stolen property, etc. in foreign countries out of reach of US courts, even if they are US persons and corporations.
It isn't just pro-government. Imagine you are a criminal defendant and there is evidence proving your innocence in a foreign server controlled by an American person or company. This rule makes sure you can legally compel that entity to go get the data, the laws of that other country be damned, so you can present your defense.
Such a blunt rule was considered a little too harsh, and a potential source of international problems, so Congress passed a law softening the rule and allowing judges more discretion in considering the burdens of complying with the order. The law had the effect of making the Supreme Court case moot.
Sorry that the truth is more nuanced than you’d like it to be.
It is unambiguously an expansion of Government powers. You're the first and only person I've ever come across who has argued the opposite. It's such a ridiculous thing to write that I am wondering if you're trolling me?
What part of this do you think is incompatible with the fact that almost everyone expected Microsoft to lose the case?
And in fact, Microsoft, Apple, and Google lobbied for the CLOUD Act.
So maybe instead of accusing people of bad faith, you should have a little humility and open-mindedness to improving your understanding of the world. Believe it or not, techie discussion forums and Wired are not reliable sources of legal information, so that would explain why you're so misinformed.
If this is trolling, I applaud your creativity. If not, I'm in awe of the irony.
I think it's maths preventing e2e backup.
E2E supports sending messages to known devices.
Backups need to support unknown devices in order to restore to your new device when all your existing devices are lost or broken.
Maths and common sense. If you back up encrypted data and don’t back up the keys it’s not much of a backup.
iMessage offers excellent privacy of message content, but no 'pen register' protection.
Phone device security is very strong, but it's made largely moot if you turn on iCloud backups (which is the default behavior if you provide an Apple ID. I'm not sure there's even a way to stop the initial backup from happening?)
Apple reportedly doesn't offer e2ee on iCloud, or even encrypted device backups, out of compromise with the federal government...specifically the FBI, CIA, and NSA.
Why might people care about this? Criminalizing abortion and miscarriages...and what looks like at the very least a re-recognizing, and possibly criminalization, of LGBTQ relationships.
Apple should offer other sorts of backups, and offline iCloud systems.
You can backup to a Mac or PC. And it's offline and encrypted.
Not anything against LGBTQ or the like, though.
https://www.microsoft.com/en-us/corporate-responsibility/dem...
Furthermore this isn't the first of its kind; Google has been alerting high-risk Gmail users about state-sponsored hacking for about a decade now. Microsoft probably does something similar. Apple is comparatively late to the party on this. On the offensive side you have the zero-day vendors that broker exploits between hackers and the government.
A better explanation is that Apple isn't supplanting the US government. It's supplanting Halliburton. As more and more people and things go online, hacking and doxxing them is becoming more militarily valuable than just arresting someone or firing a missile. After all, physical attacks risk counterattacks and escalation, but Internet attacks are relatively cheap, not really treated as an attack by many sovereign states, and, most importantly, difficult to attribute.
[0] Call me when Apple black-bags Louis Rossman for illegally repairing MacBooks, or threatens literal nuclear war - like, with uranium bombs and radioactive fallout - on the EU for breaking the App Store business model.
That money is significant from the perspective of a particular employee (i.e. if they personally would get the money) or for a specialized consulting company, but it's a drop in the ocean for the large companies actually making the products. So we should expect some backdoors intentionally placed by rogue employees (either for financial motivation or at the behest of some government) but not knowingly placed by the organizations - unless in cooperation with their host government, not for financial reasons.
I do suspect the number of 0days which were deliberately added by plants from Five Eyes or elsewhere is not zero.
It’s great that Google alerted Gmail users, but then what?
“We believe you may be a target of a state-sponsored attacker; have a nice day.”
Beyond just telling you, Apple is providing some tools to do something about it.
The threat models are different because the companies provide different services (spear phishing defenses from the web services company, hardware defences from the hardware provider), but still.
Not to sound flippant, but defense attorneys do this, too. I don't think it's as big a zeitgeist as you think
I think Apple's announcement (and as I've learned from this thread MS's and Google's similar programmes) represent a significant step-change. A single defense attorney performs this action on a case-by-case basis, and they earn "single human" levels of income from it. They (to some degree) use that money to make themselves comfortable and perhaps share it with charities and make investments. All the defense attorney's in the world combined still, probably, have access to a fraction of Apple's budget, and a fraction of Apple's audience. Defence attorneys don't always win all their cases.
Apple have the kind of money that makes 1000s of attorneys envious. Apple use that money to make infrastructure and client devices and then sell/share that technology with billions of people. Most of Apple customers buy their phones on loan agreements over some contract time-frame. It's "cheap", and the protections are automated.
I'm tired and getting rambly about this now, but I intuitively feel like the combination of state-level power (albeit exercised with a very narrow focus), and the way so many people live their (digital) lives interacting with a "noosphere" that crosses international borders are facets of a complex phenomenon we have not witnessed before, and which will merge with other related facets and then emerge as something really different. I accept I'm getting very fuzzy in my thinking here. I'm leaning into my inner sci-fi author (who's not come out for 30years and wasn't too talented when it did).
I don’t think it has sunk in for most HN readers that every iPhone since iPhone 8, released in 2017, can upgrade to iOS 16 and get Lockdown Mode.
Apple is providing some protection against state-level actors at scale--hundreds of million devices. That is a step change!
Maybe. But these security “features” feel like things that should have been there from the beginning. Windows 11 has already had a much wider and deeper array of security options. Sure, it’s not mobile, but many of those security options would be unlikely to be needed against unsophisticated attacks.
Flag-raise or marketing gimmick? You be the judge I guess.
Making mountains out of molehills.
I'm pretty sure they are saying that they will "offer specialized additional protection to users who may be at risk of highly targeted cyberattacks from private companies developing state-sponsored mercenary spyware".
There is a looooong list of things which nation states can do which Apple cannot, some examples of that are in other comments in this thread.
>but this is the first public announcement, and tool, from a corporation with more spare, unrestricted capital than many countries.
Google & Microsoft have both had fairly long-standing tools and procedures (which were publicly announced) to both alert users and aid users against nation state attacks.
[1]: “About Apple threat notifications and protecting against state-sponsored attacks” https://support.apple.com/en-us/HT212960
After the Snowden leaks that showed even in-country citizen-to-citizen communication was being scooped up by the NSA without a warrant through fiber taps (if I remember that right) when Google replicated the data to out-of-country data centers, Google announced encryption of those links:
Google encrypts data amid backlash against NSA spying
https://www.washingtonpost.com/business/technology/google-en...You haven't been paying attention. Many tech companies have been protecting accounts from state attackers for many years, and explicitly calling out state sponsored attacks. Google introduced state-sponsored attack warnings in 2012 [1] and the Advanced Protection program explicitly protects from state sponsored attacks [2].
[1] https://security.googleblog.com/2012/06/security-warnings-fo...
[2] https://blog.google/threat-analysis-group/protecting-users-g...
How many people have Microsoft and Google actually helped?
Incase you didn’t notice, Apple is in the process of giving a few hundred million iPhone owners--every iPhone since the 2017 iPhone 8--protection from state-level actors, for free, in the next operating system update due this fall.
It totally dwarfs anything that any other company has done in this area. So there’s that.
> Apple is in the process of giving a few hundred million iPhone owners
Um, no? Lockdown mode is explicitly for "very few users". There's no way a hundred million iPhone users would benefit. Google's Advanced Protection offers protection from state-level actors to anyone with a Google account, so if you want to count by the number of people offered optional protection, Google wins by a landslide.
> for free
Haha, no, you have to buy an iPhone from Apple first. Google offers protection to anyone actually for free. All you need is a free Google account and a security key which doesn't have to be purchased from Google.
The point is the several hundreds of millions of existing Apple customers who own an iPhone 8 or newer are going to get Lockdown Mode in the next version of iOS for those "who may be at risk of highly targeted cyberattacks from private companies developing state-sponsored mercenary spyware" at no cost.
While it's true that very few iPhone users should ever need to activate this feature for the described use case, Apple has already indicated there will be more features added in the future where this could change.
There are likely additional use cases where an iPhone user may want to activate Lockdown Mode, such as traveling to an authoritarian country.
This article makes the argument that Lockdown Mode could benefit iPhone users who never activate it. [1]
[1]: "iPhone Lockdown Mode could benefit those of us who will never use it"—https://9to5mac.com/2022/07/07/iphone-lockdown-mode/
Assessing Russia’s War in Ukraine
To be fair has anyone made it work safely ?
Throw together a basic set of options that should have been available long ago, now apple is protecting you, don't strip apple of the ability to protect you, etc.
I must that on one hand it’s anti-democratic, on the other hand western democracies have a rather poor track record on safeguarding this kind of info.
In some way it reminds me (with all the differences!) of how things like cryptocurrencies could remove the state from a monopoly.
Good news for me this announcement!
Apple are basically saying that they're going to do their best in terms of security measures to thwart even state actors, which is only as much of a nation-state level thing as "military grade encryption" is a thing only applicable to militaries.
Zuckerberg, 5 years ago: https://www.youtube.com/watch?v=mFPAe8Tc2NE
“Flag-raise” seems a bit hyperbolic but at any rate I think the BSA asserted such reach and power, long ago. Both have to act within the oversight of actual nation states.
Beyond that, a secure phone is necessary but not sufficient to defend oneself against a nation state.
I don't think the aim here is to block at state actors but to basically continue to close all security holes that can be exploited by any other company and continually proving to users that Apple cares about privacy.
The things is I really like Apple even more now since they have realize that my privacy interests can be tightly aligned with their own economic interests. I never trust companies to be good or look out for my interest even when I pay them to, but when my privacy ultimately means they gain a very strong competitive edge the I'm much more trusting.
Apple has realized they can become to privacy what Google has been to ubiquitous search, and doing so can reap even larger and more secure rewards.
They started with a walled garden and now extending it to fortress surrounding the garden.
not to be glib, but 'citation please?'
Other than running ads inside the App Store, do you have any knowledge or evidence of Apple collecting personal information for advertising or any other use?
Tell me it's a Hacker News comment without telling me it's a Hacker News comment.
... than most countries. There are only 7 countries with a higher GDP than Apple's market cap.
I have been concerned for some time about these mega corporations being as powerful if not more powerful than governments. They wield tremendous economic and political power. Corporations have very little allegiance to countries and have little to check them. It is a major concern of mine. Democracy in the U.S. is already being sold to the highest bidders.
These corporations are feudal lords but much, much more powerful because there is not a single person who can be brought down. Corporations are a collective who are treated as people when it's convenient and as something else when it's not.
It's bothersome to me, because these corporations are tax sinks. They get absolutely massive tax breaks on everything they do and pay as little as possible income taxes, comparatively speaking, all the while keeping billions offshore.
Billionaires and mega-corporations are national security threats to the countries that house them.
It means in the best case shady agencies, foreign services, small governments, and in the likelier case just unhinged people with some access to state facilities (tax employees, unofficial police investigations, lawyers...)
I was dripping with disdain and sarcasm as I clicked "reply" but I actually want to engage you and have you seriously consider the history of oil and gas exploration and extraction.
This may, in fact, be a first for a US tech company ... but not in any way whatsoever a first for a business interest or corporation, etc.
This is also a very tame, roundabout and implied flag-raise - as opposed to "... summary execution, crimes against humanity, torture, inhumane treatment and arbitrary arrest and detention ...":
https://en.wikipedia.org/wiki/Ken_Saro-Wiwa#Family_lawsuits_...
This feeds into the point I was aiming at. The tech megacorps now have tooling to protect a narrow aspect of their customers lives from state incursion, regardless of which country that customer live in. I’ve not read the link you shared yet, so I don’t know the angle it takes or the angle you want to dig into my ideas from.
Thanks for sparing me the satcasm.
IMHO, whatever the reason why they are doing it, it's a good addition to their value proposition; but I don't think it's the same as what appears to be your understanding ("they will protect users from state actors"), at all.
By offering users a more locked down option with clear tradeoffs, (a) users can make a choice between security and convenience, and (b) given user agency, negative press around hacks of not locked-down devices loses potency.
Meanwhile, the choice seems straightforward on most of these...
Lockdown Mode includes the following protections:
- Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
GREAT!
- Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
GREAT!
- Apple services: Incoming invitations and service requests, including FaceTime calls, are blocked if the user has not previously sent the initiator a call or request.
GREAT!
- Wired connections with a computer or accessory are blocked when iPhone is locked.
GREAT! (Used to have to do this yourself with Configurator if you wanted to be hostile border-crossing proof.)
- Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on.
HMM ... there are hardening settings only available through Configurator or MDM profiles. Will those be defaulted on as well?
> HMM ... there are hardening settings only available through Configurator or MDM profiles. Will those be defaulted on as well?
Reading between the lines here - on lockdown mode, you can't install a profile, or enroll in MDM. What it doesn't say, is that you can't enable lockdown mode with a profile installed, or if enrolled in MDM.
I take this to mean, with lockdown turned on, I can't install profiles or enroll in MDM (but presumably could uninstall profiles or unenroll from MDM).
>HMM ... there are hardening settings only available through Configurator or MDM profiles. Will those be defaulted on as well?
Yes, that one leapt out at me as well as kind of an awkward one with more compromises, painting with a very broad brush. It's obvious that some of the very powerful config profiles/MDM capabilities could be used for a lot of mischief, but some of them are also exactly what I'd want to be running myself if I was at a lot of risk, and some are both. Ie., continuing to have one's own offline based CA with proper Name Constraints could be handy for a group of people who want to try to better secure and keep private their own internal network services from anything short of a government physical assault, but if an attacker can slip on a profile with an unlimited CA your goose is cooked.
Perhaps Apple simply doesn't have the capability for fine grained control of those capabilities yet, which wouldn't be surprising given their path up until now. I'll be interested to see if over time Apple leaves this mostly untouched or invests in seriously improving it. Like it'd be interesting if you could boot into a special mode ala DFU though requiring password and with graphics up and have a bunch of toggles for various capabilities that would then be enforced in normal usage. Analogous to the Recovery Mode on Macs.
I have to believe they’re working on exposing some of this via MDM. Certain organizations may never want the JIT turned on, for example or allow attachments in iMessage.
I expect we’ll hear more about more capabilities this summer and fall.
In general, no.
For specific website or web apps, yes.
Still a really good feature for those that qualify, though.
As long as the MDM profile is installed before using Lockdown Mode, they’ll be fine. They just can’t install an MDM profile once the phone is locked down, which makes sense.
Maybe this is the blank check :)
Quoting what’s in the first release:
> At launch, Lockdown Mode includes the following protections:
> Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
> Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode.
> Apple services: Incoming invitations and service requests, including FaceTime calls, are blocked if the user has not previously sent the initiator a call or request.
> Wired connections with a computer or accessory are blocked when iPhone is locked.
> Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on.
I’m not a target (I think, and hopefully don’t get to be one), but nevertheless I’d feel safer with this turned on (I very rarely use FaceTime, so not accepting it is not a big deal).
I’d also love more protections. Not allowing specific apps to connect to any network (WiFi included), Apple handling issue reports on apps with urgency (right now they seem to be ignored even when policy violations which are against the user’s interests are reported), etc.
Why? The iOS 15.x update history.
https://en.wikipedia.org/wiki/IOS_15
Lots and lots of privacy stuff in the point releases. (And accessibility stuff, they’ve been on a tear there.) They’re still in a monolithic mindset when it comes to the “big” apps, but they’re iterating faster on these sorts of things as the release cycle goes along.
[1]: https://techcrunch.com/2022/06/07/apple-introduces-real-time...
That…is seemingly a thing they should have done a long time ago…but it’s still smart, and I’m glad they’re doing it. Now they don’t have to rush the QA of a point release to vanquish yet another PDF parsing security threat.
Good. We need people with nothing to hide to turn Lockdown Mode on, so that Lockdown Mode isn't a telltale signal that you have something to hide.
For example, say I would like to install a photo editing application. It would need access to my photos. That is fine, so long as it is not allowed to connect to the Internet (or any other network). There is currently no way to ensure this.
It's under Settings > Privacy > App Privacy Report.
Does iOS not expose such functionality? Surely there's some kind of VPN API?
The Android app you link to seems to have the functionality I think should exist as a built-in. It needs to be built-in so that non-geeks can use it.
Just as users are asked the first time an application attempts to use the microphone and are able to prevent it before it starts, they should be able to limit network access and revoke it at any time.
(I don’t think users should be necessarily be forced to approve Internet access for every app install. Just make it possible to revoke in the global Settings widget and encourage users to think about personal data and Internet access being mutually exclusive.)
I tend to use that, and use Netguard as a fallback because the latter has an off by default config incase I forget to disable it for new apps.
Netguard on its own is insufficient because sometimes you'd need to use an actual VPN (which turns off Netguard)
I've also seen the toggles placed in the data usage graph, the other, older data usage graph you can sometimes find via a workaround, and in a separate app that pretends to be one of those system storage optimizers.
I'm sure Android supports it at the system level but how you get to those settings is anyone's guess, really.
I worked on AOSP for longer than I care to admit. This is mostly an illusion. System apps (like Google Play) can pretty much do whatever the heck it is that they want to. NetGuard, sure, "firewalls" it... but it wouldn't even know if a system app bypassed its tunnel. For installed apps, NetGuard is golden (as long as NetGuard itself doesn't leak).
disclosure: I co-develop a FOSS NetGuard alternative (and yes, this alternative has similar limitations).
I'm using my VPN as a Pihole tunnel and I don't notice any extra logs or requests when I turn off the VPN, but I may just be lucky. I did purge a lot of preinstalled Facebook crap…
For installed apps, there's no such respite, iff one enables 'Block connections without VPN' (the VPN lockdown mode) on Android 10+ (but NetGuard doesn't support it). This means in the times when NetGuard crashes or restarts (which it does on network changes, for example, or even on screen-off/screen-on, from what I recall), there's a chance the traffic flows through underlying interfaces rather than the tunnel (because the tunnel simply doesn't exist in the interim).
Datura (ebpf based) on CalyxOS and AfWall+ on any rooted Android can block out everything it pleases, though.
I don't mean to downplay NetGuard, because the codebase has evolved in response to years of addressing flaky networks, flawed apps, buggy Android forks. Marcel, the lead developer, has put his life's work into it and gave it away for free. The app I co-develop is, in fact, inspired from his efforts.
I absolutely love Netguard even though I don't really use a firewall in practice (I was sort of hoping a permanent VPN with some "real" traffic meddling would be enough to block most violations of my privacy). It's the one rootless firewall that actually just works on practically any device you can think of, among a sea of broken/scammy firewalls that fail all kinds of edge cases.
You should try the one I am building (: Promise, no scams in that one: https://f-droid.org/packages/com.celzero.bravedns/
Encrypted memory isn't part of arm yet, I was holding out hope with armv9 "realms" but not so.
This is not in any way intended for most use-cases, it's very clearly intended for a single, specific, uncommon use-case. The press release says as much more than once.
In other words: there's no "instead" here, any more than there's an "instead" between e.g. UI work and backend server work. Different people, different competencies, concurrent capacity.
Regardless, I was just lamenting that we don't (yet) have a feature that should be table stakes at this point.
That said, I think this is pretty unrelated to protecting yourself from nation state actors. Mercenary spyware (like NSO) doesn't use a legitimate app store app as their initial infection point. I can think of many reasons for this: difficulty getting target to install it, app store approvals, leaking their 0days, leaving more of a paper trail, and avoiding scrutiny in general, etc. I'd of course love this feature for my own data privacy of course.
Yeah, I would not want to have to approve every app. What I would like is a machine readable description of the app's capabilities to include Internet access, just as is required for access to the microphone or photos. This would encourage app developers to advertise to users that they don't need such capability and encourage users to realize that privacy and Internet access are mutually exclusive.
There are many small apps I simply will not buy/install (e.g., apps for editing photos or contacts or calendars) because they cannot be trusted. Even if you trust the developer, the developers are often embedding third party analytics libraries that cannot be trusted.
The Charles proxy iOS app doesn’t have the ui to support this, it’s clumsy to whitelist domains, but it does provide some visibility into what domains are being accessed.
Highly interesting, that Apple is doing this. This is a thing. MS and Google are also taking steps to harden Chromium security against JIT compiler issues with JavaScript. https://www.zdnet.com/article/securing-microsoft-edge-switch...
I seen some cool simulation, small apps, small games that I can just test online and not have to install them on my machine. Apple would love that we all got scared and only use installed apps from their store but the web is a decent deliver platform.
If we could have a modern subset of html and css for news websited and blogs , and the rest of js for web apps then you can have the option to turn off teh advanced settings or we could have different browsers that could focus on different things, like a website reader browser that does not care about super fast JITed JS it would not support webgl,camera or microphone acccess, it would just focus on text layout and simple forms,
and a web app browser that focuses on extreme optimizing for JS , canvas and webgl operations, camera and microphone access.
What OP wishes for is rather an experience that decidedly doesn't use JS, similar to Google's AMP or Gemini. A subset of HTML that makes publishing possible, without moving parts.
It's still very niche, but it's growing and the protocol is so simple that I'm writing software for it, specifically a multi platform browser (more like a viewer?)
More seriously, I guess they might want a way of avoiding sites that don't have a good no-script experience. Perhaps if there were a trustworthy way to vote on that (or detect it automatically), someone could offer an extension which puts scary red boxes around hyperlinks which point to such sites.
Instead, they (Google Play Store) removed our ability to see what “app privileges” that an app would required BEFORE we do the installation step from the Google Play Store. What we got instead was an obfuscated “Data Security” section that is pretty much always “blank”.
My flashlight app should not require GAZILLION app privilegeS nor hide that fact before I can determine whether I can safely install it, much like Apple App Store can do by doing the CRUCIAL pre-reveal of any needed app privilege(s) … for our leisure perusual and applying any applicable but personalize privacy requirement BEFORE we do the app install.
Obviously, this isn't perfect, especially since Google removed the internet permission and allowed all apps to access it. Allowing advanced users like us to toggle off internet access in the "App info" permission page would be a good compromise, and I hope and Android team does so to match Apple on their security efforts.
Google Play Store being proactive in protecting these end-users from their own form of stupidity (or “permission blindness”, as you have eloquently pointed out) is just opening themselves to potential liability ramifications instead of deferring to end-user’s responsibility of maintaining their own privacy.
I think that the term “permission blindess” is better referred to as an app having zero privilege.
And “App Privileges” should have referred to runtime permissions and should have been displayed in the first place at the Google Play Store instead of install-time privileges.
Apps would force you to consent to eg contact permissions "in case you want to share something to a contact" and then harvest all your contacts. Apps can no longer use that pretense.
Perhaps we can call what it is now as “trust me first, then we will let you verify”.
When it should be “trust but verify first”.
I find it frustrating when I install a simple app and it asks me for every permission possible. Waste of time.
You describe the direction CalyxOS / DivestOS are going. And of course, there's the Pixel phones on GrapheneOS which arguably is more security-focused.
I just read their homepage, and they don't have Google Play support. The requirement to run Google Play Services to access and run apps represents a serious anti-trust concern to me (and to the DoJ under any administration, I would imagine). Perhaps more importantly, I see no mention of any facility for network monitoring.
>DivestOS
Hadn't heard of this LineageOS fork, thanks. TBH I can't really tell how it differs from either Calyx or Divest. None of these tools have the top-line features I mentioned.
CalyxOS intends to build a comprehensive netmon: https://gitlab.com/CalyxOS/calyxos/-/issues/349
Right now, they've got an ebpf-based firewall: https://calyxos.org/docs/tech/datura-details/
> TBH I can't really tell how it differs from either Calyx or Divest.
The lead developer is pretty active on github and fdroid forums: https://forum.f-droid.org/t/10105
Don't use Google Play Store, then. There are other APK repositories.
You can close the proverbially "front door" by enabling "Lockdown mode" but if that same government sends a subpoena to Apple, then they will just give them a copy of all your iCloud private data.
If you do not trust your communication partner to safeguard your messages, E2EE will not help you at all.
It leads to E2E being systemically weakened, since most of your iMessage conversations will get immediately scooped up by Apple and alpbabet agencies, dragnet-style.
https://support.apple.com/en-us/HT202303
Yes, that really does mean that Apple can decrypt your messages. In fact, Apple does it this way at the explicit request of the FBI, as reported by Reuters. https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
And look at all the other potentially sensitive data that is not end-to-end encrypted in the backups. Photos, notes, reminders, calendars, the list goes on.
I don’t think so:
Apple doesn’t log the contents of
messages or attachments, which are protected
by end-to-end encryption so no one but
the sender and receiver can access them.
Apple can’t decrypt the data.
When a user turns on iMessage on a device,
the device generates encryption and signing
pairs of keys for use with the service. For
encryption, there is an encryption RSA
1280-bit key as well as an encryption EC
256-bit key on the NIST P-256 curve. For
signatures, Elliptic Curve Digital Signature
Algorithm (ECDSA) 256-bit signing keys are
used. The private keys are saved in the
device’s keychain and only available after
first unlock. The public keys are sent to
Apple Identity Service (IDS), where they are
associated with the user’s phone number or
email address, along with the device’s APNs
address.
From iMessage Security Overview--https://support.apple.com/guide/security/imessage-security-o...https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
According to Reuters sources, Apple abandoned plans to offer iCloud backup encryption, out of fear of government retaliation or even spawning new anti-encryption legislation.
On the other hand, GP is responding to:
> Nobody who is at risk for this is doing iCloud backups. That's something you can already turn off.
And indeed, if you turn off iCloud backups, there is no "backdoor" into iMessage. You can also set up your phone to do encrypted backups locally to your laptop, if you want that instead.
Even if iCloud was encrypted they still run on third party cloud providers who nobody knows what relationship they have with governments. Many types of encryption are breakable if you have effectively unlimited resources.
It hasn't happened for a while but whenever there's an iOS update it's advisable to check your iCloud settings immediately afterwards and if they changed, you change them back and pray that your important data hasn't been sent to the cloud in the meantime.
Worth noting Apple previously refused an FBI order to do just that. https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute
Depends what you think of as ‘most’ really, things that don’t have end-to-end includes photos, icloud drive files, notes and backups.
[1] https://support.apple.com/en-gb/guide/security/sec1782bcab1/...
On a mobile device chances are your passphrase is rather weak because it's tedious to enter.
My password manager app might be bought out and exfiltrate all my credentials, or any of the linked libraries it uses.
This is less likely if you use Apple Keychain for your passwords. lock-in intensifies
That makes my phone useless to me.
Our only hope is a proper Linux phone with an Android emulation layer
These are all fixed by the DMA, but it will take a lot of time for things to mature, however other issues persist
- no way to put apps on the bottom of the screen - the FOSS scene on IOS basically doesn't exist, while on android there is a whole app store for it(https://f-droid.org) this is a big point for me. - no way to duplicate apps - no separate work profile - limited file mangament - no notification chat bubbles(a pretty good feature on android 11/10?+ - no advanced apps like local terminal emulators, virtual firewalls or virtual tracker blockers(partially because the FOSS community rightly doesn't care about iOS) - non encrypted iCloud backups(basically a backdoor into WhatsApp) or any important file medium - CSAM Scanning inbound
And many other issues, iOS is hardly making Android hard to choose, its still locked down prison, its just a bit nicer inside now.
Since I value my privacy and like FOSS iOS is even more useless for me.
Who wants to bet that this reflects minimum requirements dictated for user experience, rather than reflecting what Apple are actually securing today ?
The correct model here, the one that would actually defeat these adversaries, is to start with what you can actually secure and expand from there, prioritising customer needs. This delivers security improvements for all customers, but it makes the calculus simple for Lockdown customers, whatever Lockdown allows will be OK.
Suppose today Apple has a working safe BMP reader, and a working safe WAV reader, but they're still using their ratty JPEG and MP3 implementations. As described, this feature says you can receive a JPEG attachment (which takes over your phone and results in your cousin who remains in the country being identified as a contact and imprisoned) but you can't listen to the WAV file an informant sent you because that's "dangerous"...
Apple is over confident in it ability.
https://arstechnica.com/information-technology/2021/09/apple...
People who need this have already a dumb phone, using this Lockdown mode is an unnecessary gamble on they part.
My concern about enabling this would be that I'm unsure how much this puts barriers in place to prevent the owner of an account regaining access should it be stolen by a threat actor (i.e. could this backfire on the account owner?).
It's still unclear to me how much Apple really protects against (for example) sim swaps to take over an iCloud account - and the documentation around when they'll truly insist on having something like a Recovery Key if it's enabled is sparse. It almost reads as if the right amount of begging will socially engineer access to a locked iCloud account by a threat actor with the right personal information to hand, which if coupled with Lockdown mode, seems pretty dangerous to the true account holder.
With a bit of luck, this will cause site operators to reduce their usage of unnecessary JS, so maybe this has positive impacts :)
My sense is that the functionality to provide those experiences resulted in a decrease in user security and privacy when they were introduced -- and that those risks were widely-discussed and well-understood.
It's weird (although not unexpected) to see the reversal of them touted as a selling point.
https://www.wired.com/story/imessage-interactionless-hacks-g... https://www.cnet.com/news/privacy/researchers-attack-my-ipho...
apple is/was a part of prism (https://www.theguardian.com/world/2013/jun/06/us-tech-giants...)
"An Apple spokesman said it had "never heard" of Prism."
Hasn't this been happening for years (drug dealers, anonymous, etc..)?
Phone calls and sms are also completely unprotected as opposed to chat apps with e2e.
What if this isn’t a good news for 99% of Apple users?
That’s obviously an amazing measure for the 1% high targets out there.
But what about the other 99%? Does that create an incentive for Apple to strengthen Lockdown Mode security to the detriment of the regular mode (should we call it Unsafe Mode)?
I’m afraid that this architecture will make it harder to prioritize security features or fixes for the 99% users. Developers bandwidth is limited, they can’t fix all bugs. Hence if you have to choose between one bug impacting the 1% most important users (from a security standpoint) versus one bug impacting the 99% others, which would you choose?
Would such an architecture have led to the emergence of Blastdoor[1] - which attempts at mitigating iMessage attachement exploits, but is now useless in Lockdown mode?
My hope here is that by reducing attack surface, Lockdown mode will make exploits much easier to fix (as they’ll target a limited area), allowing to strengthen the system core while freeing bandwidth to implement longer term, Blastdoor like mitigations.
[1] https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...
I can't imagine the threats security researchers deal with every day. And their innovative solutions. Extracting live code from samples to inject in other malware. Wow, so cutting-edge. It's wonderful to talk about, no stress there, no drama. We don't want wear and tear on our machines.
Like the article states, we're spending millions and billions on these problems.
And lockdowns are an innovative approach. I've been thankful for device lockout in the field before. It's saved my bacon. Captures the favorite philosophy of strong regulatory control. Nice, has network effects for other political goals. Very cool.
Better than Kevorkianing or Bricking a machine in the field.
Oh God, Oh God, Oh God. Sorry for that narrative-scape shattering. Dementia is a serious issue. Ok, back to sanity.
Some really fucking smart people showed me a study on evolutionary computation and diversity in investigator-guided processes. Hand-edited synthetic organisms may be less evolutionary successful than purely evolved ones.
Like my storytelling, right? It's a fucking hot mess that isn't excersing my audiences mind as much as a more diverse author population.
Oh God, there I am breaking down story-wise. Back to stability. We have political goals like reduction of 99% of security threats. And the perfect is the enemy of the good, right?
I'm so sorry for my slips there, I know you lost time with loved ones and reading other comments talking about this in a more professional tone that captures the point.
In closing, I'd like to thank the sponsors who kept me fed for years.
Damn... if this was something that could be enabled by typing the pin in wrong, it would be the death of modern phone forensics. Actually, I would rather this be the default after a device is powered on... let me "restart in non-safe mode" when I need it.
That's very cool actually. You can keep JS enabled but choose to make it run more slowly in exchange for better sandboxing
Windows has all sorts of buzzwordy-sounding security features: Microsoft Defender Application Guard (Hyper-V for untrusted websites & Office files), kernel virtualization-based security (VBS), Code Integrity Guard, Arbitrary Code Guard, Control Flow Guard, and Hardware-enforced Stack Protection.
It's extremely hard to compare the two on a deep technical level (beyond "modern OS's are safe, install updates, you'll be fine") without having deep security experience. Any professional insights?
So, if you have nothing worth more than ~$1M and indefinite disruption of your systems is worth less than ~$1M, then there might be a meaningful difference. However, basically every business is beyond those levels, so quantifying the differences in a professional context is kind of like discussing whether a tshirt or a single piece of paper provides more protection against a gun.
This mode sounds excellent, because all they can do without a warrant is try and attack it with a Celebrite or Graykey device, so having the extra protection from physical connection and other attacks sounds awesome.
I expect to always enable this while I’m doing international travel anywhere.
This should be ON by default. It would force webdevs to write efficient websites.
Those are the kind of threats Lockdown Mode finally acknowledges — targets (well IMO everyone) would need it permanently enabled.
Otherwise the temporary protection before clicking a link can be had today in other ways, like disabling Settings > Safari > Advanced > JavaScript.
[1] Lack of persistence likely an attempt at making it harder to analyze: https://www.amnesty.org/en/latest/research/2021/07/forensic-...
i'm even suspicious that signal does it.
if you really want to design a secure messaging system it needs to handle text ONLY.
“Apple is also making a $10 million grant […] to the Dignity and Justice Fund established and advised by the Ford Foundation - a private foundation dedicated to advancing equity worldwide and designed to pool philanthropic resources to advance social justice globally.“
So Apple is releasing a great new hardened security mode in iOS, AND… they’re donating money to collectivist activism? What a bizarre combination. One step forward, two steps back.
I travel internationally a lot (or did before the pandemic) and my primary concern is when crossing borders. I always power off my devices to prevent warm-boot attacks, and take other precautions, this lockdown mode would be a big win in this case. Even with the other protections Graphene offers over regular AOSP, I am concerned that Android doesn't really provide meaningful ways to prevent attacks where the adversary has physical access.
However, will this comply with the new EU Digital Markets Act (DMA), which provides a general interoperability for messaging apps (for big players, with Apple and iMessage being certainly one of them)? Certainly, foreign services – or at least parts of their features and APIs – had to be disabled in lock-down mode. (Will it help to any degree that Apple is drastically limiting their own service?)
NSO Group's zero click exploit for iphones involved images. specifically using the PNG compression algorithm to use the logic gate sequence of the CPU to compile and execute a new process that allowed for escape
If that's the level of sophistication this is to guard against, then it seems like it should include a block of images
BTW bringing up the power off UI on iPhone (holding power and up buttons at the same time) disables FaceID/TouchID until a passcode is entered.
https://www.cbp.gov/sites/default/files/documents/inspection...
If you are not a US citizen, refusal to unlock a phone and allow inspection, inclusive of allowing access to social media and corporate apps, will probably result in denied entry. They also have the right to detain you until indefinitely until you unlock the phone if they have "reasonable suspicion", but requires a court order within 72 hours.
Most foreign counties have similar rules in place for residents and non-residents.
They also get to steal it and keep it if they want.
https://www.cbp.gov/sites/default/files/documents/inspection...
ArriveCAN (Canada), Mobile Passport Control (USA), WeChat (China), and other mandatory government apps would be perfect vectors to stage highly targeted attacks.
I can’t see many people submitting bounty reports if it’s too much of hassle or not worth the effort.
Since the apple ecosystem is mostly proprietary, it’s hard to gauge as individuals if this just provides a false sense of security or not against “state actors”.
(Of course, they could make some new MDM policies to individually turn these features on. You can already block external devices with MDM, and you can completely disable FaceTime/iMessage/iCloud. It wouldn't be much of a jump to add the more granular protections this has.)
At least the remote attack surface does not seem to be that huge...
But apple doesn't allow this.
Apple - in a self-serving way - does not provide good permission for network access.
I think it should say "allow this app to access the internet?"
There is also deep linking, the ibeacon stuff, the find my, the wifi access point mapping, and more
Hey no, don't look at that, look over here instead. We're playing ratfuck with the abortion laws.
Magicians call that "misdirection".
This is a load of bullshit and marketing hype. They are letting you turn off features for security reasons, i.e. what basically every OS has let you do, and what every half-competent IT department has been doing, for decades. In fact, iOS was an outlier in how unconfigurable it was, and with the pitiful MDM options not letting you turn off many of these features that are constant sources of vulnerabilities and social engineering.
Nothing that novel here other than the framing and cybersecurity marketing bullshit about Nation State Actors and "mercenaries."
Why do you find it necessary to reframe the introduction of these features as a load of bullshit?
Are you arguing that these features are bad or not useful?
Or are you just saying that “it’s about time”? And if so, why not just focus on the part where Apple is doing a thing that needed to be done?
The undertones in your comment feel a bit unnecessary.
I personally don’t think the individual features are as interesting as the overall framing and the fact that Apple is publicly announcing their intentions. The feature set will doubtless change over time - such is the nature of any software endeavor - but starting that journey is the interesting part.
Getting stuck on “but it’s just xyz dumb feature…” or “but they should have done x long ago”, etc. just obscure the more interesting fact that they’re explicitly embarking on this path to begin with.
I hate most iMessage functionality and I will be happy to get rid of it for security. The rest also seems reasonable?
but i'd love to know the series of changes that goes into something like this if its not just hype, potentially unpicking a giant complex system from the bottom up to remove attack surface.. interesting challenge!
I've been wanting to disable link previews for YEARS!! Not for security, but to keep those corporate advertisements (aka previews) out of the conversations I have with my friends and family.
It feels super disingenuous when I type out an articulate, heartfelt, personal message to my loved one, character by character, anticipate their reaction reading it, and then hit send — only to find the URLs expanded 400 pixels into corporate advertisements designed by the bonehead SEO jerks who care about clickbaiting over content.
What actually happens: criminals activate Lockdown Mode to evade law enforcement.
I think their should.
From press release, “Bounties are doubled for qualifying findings in Lockdown Mode, up to a maximum of $2,000,000 — the highest maximum bounty payout in the industry.“
Appears Apple is not aware there was a $10 million bounty [1] paid out; unless when they say “by industry” they mean phones, not bug bounties.
If Apple really believed it was secure, then even a $100 million bounty shouldn’t be a concern; 2 million, while clearly high, is no longer enough to pull in the best bounty hunters, in my opinion.
///// Re: Naming
Name conflicts with existing terms both Apple and consumers use. Naming should be unique so it’s possible to Google the unique name for this feature and only get valid search results.
///// Re: iCloud
While iMessage features are limited, it is neither blocked, nor is iCloud — and both are known to being vulnerable to nation state demands on Apple due to iCloud not being end-to-end encrypted.
///// Re: iCloud end-to-end encrypt
If Apple was serious about the topic, they would have already rolled out end-to-end encrypt for iCloud years ago.
///// Re: Targeting
If Apple is logging if this feature is on and sending it back to Apple, it will result in targeting from nation states even if this feature is “invincible” - which I have no reason it is; basically, nation states demand list of users subject to its jurisdiction.
///// Re: Off vs Locked
“Wired connections with a computer or accessory are blocked when iPhone is locked.” — Why is this not the default with an opt-in? Further, at the point you’re turning on this features, when locking the phone it should explicitly tell the user of the risk of locking vs turning the phone off. Lastly, when you turn an iPhone off, it should really be off if set to this mode; if it is, and activity is detected, likely good sign something is going on.
_______
[1] https://medium.com/immunefi/wormhole-uninitialized-proxy-bug...
> Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
> Apple services: Incoming invitations and service requests, including FaceTime calls, are blocked if the user has not previously sent the initiator a call or request.
This is nonsense. Security breaches can be discovered and used by anyone with the right knowledge and skills. Geohot was not sponsored by the CIA or the FSB.
From my own experience and from the postmortems I have had access to, most of the time this a work of patience and skills.
In my opinion, this is a way of saying to the public that their devices is secure against everything but state actors, this is simply not true.
I can imagine many use cases where they would e.g.
journalist enabling this before working on an article that was critical of a foreign government. Or any government contractor, NGO, embassy worker etc.
That's often not enough.
You need a lot of resources and most importantly prosecutorial immunity.
But practically speaking your debit or credit card does a pretty good job keeping track of where you are if your phone isn’t transmitting
Seems like a lot less than the care Apple is taking on behalf of vulnerable people.
It certainly feels "cheap" by comparison, but admittedly this is a horrible and stupid way to assess anything.
Play store doesn't seem to give much care about privacy compared to iOS.
Android defaults to charging only.
Android asks every time for every device. There is no 1-hour grace period.
I know that I've had approximately zero spam on my German number (that I've had for ~2.5 years) - I'm sure why, whether I'm just lucky, or whether it's much more under control here. My UK number definitely had problems with spam, though. Maybe a couple of spam calls a week.
1) A full solution to this problem is going to depend on mobile carriers making changes. It isn't something which Apple can unilaterally fix.
2) This is completely irrelevant to the purpose of "Lockdown Mode". It's intended to protect high-risk users from certain sophisticated threats -- it isn't a feature which most users should use.
Apple has demonstrated no such evidence. In fact, the opposite is the case. Despite decades of assurances that their systems provide meaningful security, every single year we see their security torn apart by individuals and small teams with budgets that do not even constitute rounding errors to a Fortune 500 company. There is exactly no reason to believe they have meaningfully superior technical expertise with respect to security relative to the default standard of the industry.
However, this should be no surprise to anyone as the security certifications that Apple advertises for iOS [1][2] are only “applicable where some confidence in correct operation is required, but the threats to security are not viewed as serious.” [3][4]. I mean, look at [4], the process used to certify their security is that their evaluators typed search terms into the internet and verified that every vulnerability that turned up was patched, that’s it. There is no requirement to even do a independent analysis that it protects against attackers with a basic attack potential, that is done at the next higher level of security that they could have chosen to certify against, but did not.
To be fair, Apple has historically demonstrated the ability to certify against AVA_VAN.3 which demonstrates resistance to attackers with a enhanced-basic attack potential, but they have failed every time they have ever attempted to certify against AVA_VAN.4 which demonstrates resistance to attackers with a moderate attack potential. It should be no wonder that they can not protect against moderate attack potential threats such as individuals or small teams, let alone high attack potential threats such as large organized crime and nations.
If Apple wants their security claims to be taken seriously, they should start by demonstrating their ability to protect against moderate attack potential threats via the internationally recognized security certification process they already use and advertise. Until then, the only thing we should trust is what they certify they can do (protect against script kiddies), not what they have failed to ever achieve in a auditable manner (protect against moderately skilled attackers).
[1] https://support.apple.com/guide/sccc/security-certifications...
[2] https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11146
[3] https://www.niap-ccevs.org/MMO/Product/st_vid11146-aar.pdf#p...
[4] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3...
For the vast majority of users the most realistic threat is simply being ordered to unlock their phone under the threat of force (from a criminal, a cop, a CBP agent, etc). This is way, way more likely than being attacked through an unknown JIT compiler vulnerability.
What would be really helpful is Apple implementing a way to have multiple iPhone profiles with plausible deniability (a la VeraCrypt) or some sort of compartmentalization (a la 1Password travel mode).
Of course that would mean people can start sharing their phones instead of buying one per person from Apple, so I'm not holding my breath.
Some features are (understandably) almost impossible to make very safe. Take PDF viewing for example, the entire thing is so huge, that it's bound to be holes in any implementation, just like what the NSO proved some time ago with the iMessage exploit.
I take this effort as something similar to the "Hardened Linux" effort. Just that it exists doesn't mean that Linux is "unsecure", it just means that if you really need to, there is more steps you can take to make it even more secure. Just like what Apple is doing here.
Security is always a tradeoff and there is no single answer. A feature for one person is another person's hell.
An acquiantance just lost all their data because they had enabled "format on too many missed passcodes" and their kid was playing with their phone.. caused quite a few tears. On the other hand, that feature is invaluable to international travelers.
Security by reducing attack surface is a standard, and sensible response.
What you are asking for is that Apple (or any company) be able to produce absolutely 100% bug free code, no matter the complexity or requirements. This feature is an acknowledgement that what you're asking for is an unreasonable demand for any company.
So Apple has looked at the attack surface present by default, and then provided an option to that trades off removing presumably low use features in exchange for removing large attack surface. That is a trade off: for example any modern phone would be vastly more secure if all it could do is make phone calls, and everything - the browser, apps, etc - were disabled. But that end of the spectrum results in an impractically restricted device, in reality there's a middle ground, but for high profile targets the trade off is closer to "just a phone" than it is for normal users.
An example is the RW^X region required to support JITting JS - the OS simply supporting such memory region at all was a huge addition of attack surface to the platform - prior to that every single executable page was protected by code signing, afterwards there was a region that by definition the OS could not verify, and it has been used by every attack since then. But disabling that simply disables the JIT, the JS interpreter runs, so the impact is only that some web content runs slower, but the functionality itself is still there.
Similar for messages: receiving JPEGs is super common, receiving OpenEXR or whatever probably isn't, so removing everything other than JPEG by default again removes attack surface without realistically impacting the usability of messages.
Absolutely not true.
There’s a difference between being secure and having all of the features and being secure against a state-level attacker. The vast majority of users are quite secure while enjoying all of the features of their iPhones.
For those who are being targeted, potentially in a life or death situation, being able to send attachments in iMessage is trivial by comparison. Only a tiny percentage of iPhone users should ever have to enable this; it won’t impact the user experience of over 95% of iPhone users at all.
* If Safari and Messages is allowed then all other apps should be allowed and have complete access to the device even in the lockdown mode. * If apple gets access to any traffic from the device in the lockdown mode, then all other applications should have full access to advertising metrics and device data as well.
At that point it's probably not much of a lockdown, but Apple can't have all the fun can it?
We will never have this, because we are ever decreasing the quality of software development. Apple could do something about this, but that is a politically and financially expensive move for no extra financial gain.
As always people will eat this up, and business will continue unaffected as usual.
That's an interesting wording, because it claims to protect you against... nothing that matters. Notably, it doesn't protect you against:
- The police. Don't get me wrong, I am all for letting the police do its job fighting crime, even if it means hacking iPhones, but even if you got the police attention for a noble cause, Lockdown Mode won't save you, at least, it doesn't claim to.
- Foreign governments, as well as your own government. Notice how it mentions "private companies" specifically, as in, not public. And the cyberattacks themselves have to be performed by private companies, if the tools that these companies develop are used by government entities, it doesn't count.
- Cybercriminals, the kind who are after your money. They are not "private companies", and they are usually not state-sponsored.
- Terrorist organizations, mafias, drug cartels, etc... again, not "private companies", and while they may be backed by states, they typically work for themselves.
The technical aspects have value, and I think giving the user the choice of wearing a tinfoil hat is great, but the claim they are making is deceivingly weak if you read carefully.
And what about the SMS equivalent? https://www.firstpoint-mg.com/blog/step-by-step-silent-sms-a... Apparently the German authorities sent 440,000 "silent SMSs" for tracking purposes in 2010: https://www.heise.de/newsticker/meldung/Zoll-BKA-und-Verfass...
AFAIK, yes, because Lockdown Mode disables any non-audited plugin code from running in response to the receipt of an iMessage message (which is what "disable formats other than images, link previews" et al really means under the covers.)
This is kind of a silly comment.
Making a phone harder to hack will help with foreign (and domestic) governments that buy exploits to target individuals as well as hackers trying to make money off of similar exploits.
I then thought: isn't that something that terrorists and pedophiles will love? If it is really that effective, I expect that soon enough, we will stories about Apple helping very very bad people who are after your children, and I don't think Apple wants to be associated with crime, and I was wondering what would Apple strategy be.
And that's when I noticed that very specific claim "highly targeted cyberattacks from private companies developing state-sponsored mercenary spyware", what are the words "private" and "mercenary" doing here? They do nothing but reduce their claims?
I am not calling conspiracy here, and I really think what Apple did is great, but I suspect that specific wording is Apple being cautious, probably of potential association with crime.