I can also understand parts pairing for Face ID for security, and maybe even the battery. I've had aftermarket battery repairs swell up, which is a safety risk.
But what Apple is doing is using this as a pretense to lock down repairs.
I can also understand parts pairing for Face ID for security, and maybe even the battery. I've had aftermarket battery repairs swell up, which is a safety risk.
But what Apple is doing is using this as a pretense to lock down repairs.
I think there is an argument to be made that these protections preserve the used Apple market because people can actually trust it for the most part (we certainly see that reflected in the prices). I imagine the lifespan of an iPhone is much longer than a comparable (by footprint) android device.
I’m my mind right to repair trumps all these upsides but it isn’t as clean as it always seems imo.
The larger issue seems to be where there is calibration info that needs to be set up but only Apple has the software and tools for it.
You're assuming a technical, informed and assertive user here. There are lots of people who don't even try to turn off and on the phone when buying. Or fall for bullshit like 'it's normal, just ignore that message'. And what do you do when some repairman used a knockoff battery and is threatening with calling the police if you don't accept and pay for the 'repaired' phone?
Apple could put in as many oem checks as they want, hell, even throw a persistent warning in the settings menu or something to inform and even dissuade but they should absolutely allow it at the end of the day.
My friends at support had to deal with dozens of original Apple batteries that swelled up. And, contrary to what people may think, Apple doesn't consider a swollen battery a safety issue.[0] But, for certain models, they would replace it at no fee (although such support programs have ended IIRC).
[0] See e.g. here: https://discussions.apple.com/thread/251466658
Yes please. Check every item for authenticity. That’s why I’m an Apple customer. I’d buy android if it weren’t the case.
> "If we had met five years ago, you wouldn't have found a more staunch defender of the newspaper industry than me ... And then I wrote some stories that made me realize how sadly misplaced my bliss had been. The reason I'd enjoyed such smooth sailing for so long hadn't been, as I'd assumed, because I was careful and diligent and good at my job ... The truth was that, in all those years, I hadn't written anything important enough to suppress."
[..]
> Webb's ex-wife, Susan Bell, told reporters that she believed Webb had died by suicide. "The way he was acting it would be hard for me to believe it was anything but suicide," she said. According to Bell, Webb had been unhappy for some time over his inability to get a job at another major newspaper. He had sold his house the week before his death because he was unable to afford the mortgage.
So he was killed indirectly; not a distinction I personally care about. Unless you are investigating state crimes yourself, I wouldn't throw popcorn from the cheap seats.
In cases like this we have to weigh the likelihood and risk regardless, and proactively protect ourselves.
https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...
If instead of VIN-locking they just notified you a differenr part was swapped out, you could go get some part from a trustworthy third party and replace that potentially back-doored part yourself.
It's way more likely that the NSA would say "hey apple, install this backdoor in your software but don't tell anyone about it"
Protects your integrity of the hardware but gives you the choice to repair.
There are APIs available for verifying whether FindMy is disabled for the device in question, that might be a better proof that the device is honestly sold to a repair shop for parts.
For devices broken enough that they don't turn on there needs to be a way to remove them from FindMy without using the device though... is removing them from the list available at https://appleid.apple.com enough?
Can someone elaborate on why parts pairing is needed for biometrics?
In my understanding the biometrics module can simply send raw "image" data to the CPU which then performs validation/authentication. Hardware authentication seems to be only necessary if one plans to send some precomputed data.
But I don't understand the very reason behind that. To save power you don't want to run biometrics recognition all the time anyway. If the recognition task is so computationally taxing that even the very powerful CPU present in smartphone cannot provide required hard real time guarantees and therefore an ASIC/FPGA/DSP is needed, well... Apple makes custom hardware anyway, so there is no apparent penalty in embedding biometrics accelerator right into the CPU anyway.
When you do this, the parts must be securely linked otherwise you can swap the biometric system with one that is already unlocked.
And, they want to ensure the Face ID dot projection and image captures come from a real camera and projector system, not some device that spoofs them. And in reverse, to prevent intercepting and capturing biometric data.
But why? What's the algorithm/architecture here? I am genuinely curios here.
I guess we can generalize finger/face readers as multichannel cameras. What do you gain by computing a "hash" of the data (and the associated machinery to send that hash securely) versus simply sending raw data for evaluation at CPU level? In the end the CPU has to trust the data sent by peripheral anyway.
I understand the use of separate compute unit when extraction of secrets must be protected, but in this case it is the CPU that protects those secrets anyway.
But isn't the data on the device actually encrypted with the bio key?
So swapping out new bio data => new key => can't decrypt original data.
Or do you mean it just means you get a working device (but all stored data is lost)?
Parts pairing seems like a good solution if theft for components is a major issue.
I've had the original, built-in-from-factory battery of a Google Pixel phone swell up. Assuming that this only happens with third-party batteries is something laptop and smartphone manufacturers try to brainwash us into thinking. Buy your third-party battery from a reputable company (not a random seller on Alibaba) and the risk will be the same as buying one from the original device manufacturer.