iPhone 15 teardown reveals software lockdown
ifixit.com
ifixit.com
I can also understand parts pairing for Face ID for security, and maybe even the battery. I've had aftermarket battery repairs swell up, which is a safety risk.
But what Apple is doing is using this as a pretense to lock down repairs.
There are APIs available for verifying whether FindMy is disabled for the device in question, that might be a better proof that the device is honestly sold to a repair shop for parts.
For devices broken enough that they don't turn on there needs to be a way to remove them from FindMy without using the device though... is removing them from the list available at https://appleid.apple.com enough?
I think there is an argument to be made that these protections preserve the used Apple market because people can actually trust it for the most part (we certainly see that reflected in the prices). I imagine the lifespan of an iPhone is much longer than a comparable (by footprint) android device.
I’m my mind right to repair trumps all these upsides but it isn’t as clean as it always seems imo.
The larger issue seems to be where there is calibration info that needs to be set up but only Apple has the software and tools for it.
You're assuming a technical, informed and assertive user here. There are lots of people who don't even try to turn off and on the phone when buying. Or fall for bullshit like 'it's normal, just ignore that message'. And what do you do when some repairman used a knockoff battery and is threatening with calling the police if you don't accept and pay for the 'repaired' phone?
Apple could put in as many oem checks as they want, hell, even throw a persistent warning in the settings menu or something to inform and even dissuade but they should absolutely allow it at the end of the day.
Yes please. Check every item for authenticity. That’s why I’m an Apple customer. I’d buy android if it weren’t the case.
> "If we had met five years ago, you wouldn't have found a more staunch defender of the newspaper industry than me ... And then I wrote some stories that made me realize how sadly misplaced my bliss had been. The reason I'd enjoyed such smooth sailing for so long hadn't been, as I'd assumed, because I was careful and diligent and good at my job ... The truth was that, in all those years, I hadn't written anything important enough to suppress."
[..]
> Webb's ex-wife, Susan Bell, told reporters that she believed Webb had died by suicide. "The way he was acting it would be hard for me to believe it was anything but suicide," she said. According to Bell, Webb had been unhappy for some time over his inability to get a job at another major newspaper. He had sold his house the week before his death because he was unable to afford the mortgage.
So he was killed indirectly; not a distinction I personally care about. Unless you are investigating state crimes yourself, I wouldn't throw popcorn from the cheap seats.
In cases like this we have to weigh the likelihood and risk regardless, and proactively protect ourselves.
https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...
If instead of VIN-locking they just notified you a differenr part was swapped out, you could go get some part from a trustworthy third party and replace that potentially back-doored part yourself.
It's way more likely that the NSA would say "hey apple, install this backdoor in your software but don't tell anyone about it"
Protects your integrity of the hardware but gives you the choice to repair.
Can someone elaborate on why parts pairing is needed for biometrics?
In my understanding the biometrics module can simply send raw "image" data to the CPU which then performs validation/authentication. Hardware authentication seems to be only necessary if one plans to send some precomputed data.
But I don't understand the very reason behind that. To save power you don't want to run biometrics recognition all the time anyway. If the recognition task is so computationally taxing that even the very powerful CPU present in smartphone cannot provide required hard real time guarantees and therefore an ASIC/FPGA/DSP is needed, well... Apple makes custom hardware anyway, so there is no apparent penalty in embedding biometrics accelerator right into the CPU anyway.
When you do this, the parts must be securely linked otherwise you can swap the biometric system with one that is already unlocked.
And, they want to ensure the Face ID dot projection and image captures come from a real camera and projector system, not some device that spoofs them. And in reverse, to prevent intercepting and capturing biometric data.
But why? What's the algorithm/architecture here? I am genuinely curios here.
I guess we can generalize finger/face readers as multichannel cameras. What do you gain by computing a "hash" of the data (and the associated machinery to send that hash securely) versus simply sending raw data for evaluation at CPU level? In the end the CPU has to trust the data sent by peripheral anyway.
I understand the use of separate compute unit when extraction of secrets must be protected, but in this case it is the CPU that protects those secrets anyway.
But isn't the data on the device actually encrypted with the bio key?
So swapping out new bio data => new key => can't decrypt original data.
Or do you mean it just means you get a working device (but all stored data is lost)?
Parts pairing seems like a good solution if theft for components is a major issue.
I've had the original, built-in-from-factory battery of a Google Pixel phone swell up. Assuming that this only happens with third-party batteries is something laptop and smartphone manufacturers try to brainwash us into thinking. Buy your third-party battery from a reputable company (not a random seller on Alibaba) and the risk will be the same as buying one from the original device manufacturer.
My friends at support had to deal with dozens of original Apple batteries that swelled up. And, contrary to what people may think, Apple doesn't consider a swollen battery a safety issue.[0] But, for certain models, they would replace it at no fee (although such support programs have ended IIRC).
[0] See e.g. here: https://discussions.apple.com/thread/251466658
"Unfortunately, software is the anchor around an otherwise exceptionally designed phone. But without the ability to swap components, repairability suffers dramatically. We don’t purchase products for our team that score below a five, so iFixit will not be purchasing the iPhone 15 for internal use."
LiDAR not sure what’s happening.
Having a module which could be removed and replaced just say Yes or No would seem to be a very poor design. Also in that case, Apple could presumably authorise a new module, meaning they would retain the capability to break into any phone (which I understood they did not want)
They’re also is the case of “Steal two phones, swap a few parts, reset the phones, and sell them second-hand”. Both phones will have 100% genuine parts.
The thief wouldn't have been able to reset Face ID, would they? Also it would make sense to warn a second time when you go to set up Face ID again.
If they reset the entire phone, uh, they could have handed you a different phone entirely. I don't see how part swapping is the problem here.
> They’re also is the case of “Steal two phones, swap a few parts, reset the phones, and sell them second-hand”. Both phones will have 100% genuine parts.
What role does the part swap have in this scenario? What stops me from simplifying it to "Steal two phones, reset the phones, and sell them second-hand."? Because if that simplification is valid, then this scenario has nothing to do with repairability.
https://support.apple.com/guide/security/secure-enclave-sec5...
https://support.apple.com/guide/security/face-id-and-touch-i...
I think some very highly paid engineer at Apple could figure out this simple solution. "If the FaceId, Fingerprint Reader is compromised you fallback to the password, there should always be a password/PIN for special cases".
Just in case those engineers could not coem up with such ideas , Apple(and others) you can use my idea for free, I will donate it to you for the environment sake.
Overcharging: Apple tends to replace whole assemblies rather than individual parts, and don't do board-level repairs or anything. Apple staff are generally just following a procedure and aren't allowed to/aren't trained to solve problems in the best way. Here's an example of them charging for a whole motherboard replacement when the issue was a bent pin: https://www.youtube.com/watch?v=o2_SZ4tfLns
Some people might be OK with this, but not everyone; competition is important!
About the self/independent repair program: The self repair program allows you to order one part at a time and you have to have the device to do it. Realistically, almost no one will do it themselves, and will use a repair shop. The program is impractical for repair shops, because they can't stock parts in advance. The other option is the independent repair program, which effectively turns you into a shipping centre for Apple; it bars you from doing anything but the most basic repairs without sending it to sending things off to Apple and they will do random inspections on your store and fine you if you're actually offering good service like board level repair or using cheaper aftermarket parts. So it's likely that both are mostly just PR stunts to get ahead of regulation while also not making a significant change to their business
as parts/ports are ever-increasingly multi-functional (and more advanced), there needs to be regulations in place to ensure no lockdowns, or preferential treatment. Of course we need hardened security and privacy, but I think Software should be used to detect & notify of atypical/dubious device parts so the User can chose/decide - akin to an AntiVirus.
If certain level of security/safety is required (say gov device, Chief Execs, VIPs etc) then create an Industry Standard and let the OS report on device's Compliance. This way, the market (users) brock low-quality/nefarious tech, not a corporate.
Nobody is forced to be in the Apple ecosystem, and, since when did we all need a supercomputer in our pocket?
Next we will be complaining about tyre prices on Bugattis. People can just buy a Ford.
https://news.ycombinator.com/item?id=37615238 https://news.ycombinator.com/item?id=37614279
iPhones are the same. There's a whole phishing industry to get people to unlock stolen iphones just so they can be wiped and resold.
This isnt even than usefull, a friend of mine had an iPhone stolen, and then he was contacted by the guy who 'found it' and wanted a reward. Basically extortion.
Anyone with a half-functioning brain knew USB-C was coming to the iPhone well before the EU decision. It's so annoying to see so many people parrot this line. Apple was one of the first to go all-in on USB-C and has been slowly expanding it to whole line. It only makes sense that the iPhone was the last to get the change.
And they said the lightning connector would be the iPhone connector for the next ten years when it launched in 2012.
IMO USB-C is just now in the last year or so truly ubiquitous and has the ecosystem to back it.
That said, it probably would’ve been accelerated if Apple made the move on the iPhone shortly after the Mac. Of course, it would’ve pissed people like my best friend off, who complained for like two years about the last iPhone connector change.
Yes, limitations of self-repair should be clearly pointed out and discussed critically. But on the other side, if the phone becomes easier to repair for Apple-certified shops and Apple shops themselves, this is very important. Because repairs do get cheaper for the customer and repairing phones is good for the environment. Progress there should not be conflated with the DRM issue. They should rather introduce a second score, if they want to score on that.