https://techcrunch.com/2015/02/11/apples-activation-lock-lea...
https://techcrunch.com/2015/02/11/apples-activation-lock-lea...
That to me is worth the whole phone bricking thing. And it's also not like I've gone through a bunch of them, I got a 6S on release and a 12 pro when I felt it couldn't play video games anymore.
...and if I'm too lazy to do that, I can still sell it for parts online since less lazy people who know how to do that will buy it for the same reason.
Could they still do it for Apple official parts without locking out 3rd parties? i.e. if an official screen that was previously registered to a different phone, then lock it out. If it's never been registered, then allow it?
To date, no HN discussion of this crypto-pairing of the phone to its parts has revealed an alternative solution that would be effective at Apple’s scale for preventing phones from being hacked by a parts swap while also allowing any part to be swapped in — not to mention while providing the anti-theft benefits described upthread. I’d love to see a viable alternative solution described, if anyone has one.
Random-ass repair shops are not going to expend the effort of putting in fake parts to hack you to.. hack a couple of thousand dollars off of your account and then get caught due to it easily being traceable to the repair shop?
The only people who need protection from hardware-swap hacks are people like journalists. And if you are one, you shouldn’t be giving people physical access to your device regardless.
Here is a simple solution: give the normal user (after a passcode unlock) a pop-up: ‘your X has been replaced. Do you wish to authorize this new part for use with your iPhone?’.
Make it so that if your phone is set to the new Lockdown mode, you cannot authorize any new parts.
These protections apply to considerably more of one country’s populace than would benefit from off-market parts being usable at third-party repair shops. I appreciate Apple’s choice to prioritize in this regard, but I’d still like to see if tech can overcome this barrier without sacrificing that safety.
Assuming you are a normal person, you already are. Rapidly click the lock button 5 times and they cannot extract any data with normal means. If you are someone worthy of nation-state attention, why are you crossing the border without a wiped device, as has been the adviced standard practice for years?
Again: these draconian repair protections should be tied to Lockdown mode. There is no reason to destroy repairability to protect a tiny group that isn’t giving their device out for repairs anyway if they’re following opsec.
No state will burn extremely expensive tools like Pegasus on a garden-variety criminal.
I’m very conscious of my privacy and device security myself, but I’m also aware that I do not warrant high-cost surveillance. Most people are in that boat. You can model your threats accordingly.
I think you might also be failing to account for situations where you aren't in possession of your phone for an hour or two. Imagine if police in a foreign country take your phone for a couple of hours and then give it back to you. Or you leave your phone in a hotel room to charge for a few hours. Or your phone gets "misplaced" for an hour after going through the airport x-ray machine.
There are many targets other than journalists too, such as people in the USA who develop export controlled technologies, certain tech company employees, defense contractor employees, other government employees, etc. I don't think you can expect every potential target to constantly set their iphone to lockdown mode.
If this is the case, they can add their own fingerprint or face (alternate look feature) to your iPhone. You’re thoroughly pwned at that point, no hardware swaps necessary.
> I think you might also be failing to account for situations where you aren't in possession of your phone for an hour or two
If I came back to my unattended phone after 2 hours and it was giving me a pop-up about a swapped part, I would never trust that phone again.
> I don't think you can expect every potential target to constantly set their iphone to lockdown mode.
If they are that much of an attractive target, their organizations would be stupid not to enforce it. I know that Lockheed used to give personnel that was China-bound a throwaway laptop and would shred it the moment they returned to the USA.
Exactly. It boggles my mind the amount of mental gymnastics Apple apologetics will go through to try to justify Apple's anti-consumer anti-repair practices of software locking replacement parts.
Do you live in an area where phone theft is rampant? Ok, then leave SW lock enabled on your phone's parts.
Do you want to legitimately transplant parts off your old phone to your new phone? Then let the user disable the SW lock after entering their PIN or Face-ID or whatever.
It's not like this is some super-complex problem Apple couldn't solve with a few line of code to have the best of bot worlds if they really wanted to.