Parts Pairing Kills Independent Repair
ifixit.com
ifixit.com
... but give me, the owner, a way to override it. It could be through a pairing code delivered with the device.
Another thing OEMs are trying to control from is slippage in their supply chain being used to steal components for “cheap” repairs or to subsidize other OEMs which is not a trivial problem and does happen regularly.
Things become problematic/stupid when non security sensitive parts are peered. Things like the battery - while there’s an argument for reporting possible tampering, it seems to me that it should be possible to dismiss this one with a “yeah I know” - from the article it least it isn’t aggressively bricking the device, but still
But then I think Apple should be forced to re-pair (ideally for free) if sb provides receipt of legit acquisition, and maybe after checking a ”stolen items” database.
Otherwise we just increase e-waste.
Because I can install modified hardware that performs more complicated attacks like sending the PIN for your phone or your iTunes password over the network? And since it’s a hardware modification, it’s persistent forever and nearly impossible to find. Malicious hardware is not part of the threat model that phone manufacturers design around and it’s cheaper/simpler to pair components to fight against that attack vector than to come up with protection mechanisms (eg restrict the memory that the component has access to and various Hw measures to make sure you can’t fuck around in the analog domain - it’s really really complex to get right and a flaw means your entire run is vulnerable until you fix it if you even can without doing major redesign work).
What i'm saying is that most of us are willing to give up a bit of security for repairability and saving the planet. Phones and laptops are expensive products in terms of resources used to create them. We're definitely not paying the full price for them. Imagine how much would it cost to extract every microgram of precious resources and capture all pollution and co2 emitted in the supply and distribution chain. Instead we're lining the pockets of megacorps that use every trick to enrich themselves while slowly destroying the environment, the same corps that gives access to your data to the government if need be. I'd say the chance of a sophisticated hardware hacker implanting a rogue chip in your phone is somewhat smaller than the chance of your phone's screen or battery dying in the next year.
The sort of enemies Apple designs for are the highest-level ones one can think of. They often kind of walk the walk with things like lockdown mode. I respect and like that.
... however the compromises they make in the name of security are often weirdly broad, UX-degrading and suspiciously align very well with their business interests.
I mean your argument is not wrong, it just doesn't really apply to parts pairing. Clearly, this means it isn't Apple's only concern to secure devices.
Again, if the intent is to protect against defective batteries this seems a very strange way to go about it. This specifically disallows replacement parts. Any replacement parts, no matter where they come from.