Why Apple sends spyware victims to this nonprofit security lab
techcrunch.com
techcrunch.com
The norm in high-end platform security practices at companies is to keep cards as close to the vest as possible, revealing information largely in the form of feature-style announcements of security improvements. The norm Apple is setting here is better.
My guess is that if Apple did this themselves, it would be firewalled from most of Apple, so like AccessNow, so hopefully they help fund AccessNow.
Based on that, it seems smart for each of the tech players to support the 3rd party solutions
> All the experts TechCrunch spoke with strongly recommend turning on Lockdown Mode if you think you may be a target, especially if you are a journalist, human rights defender, or dissident.
What does Lockdown Mode do?
> When someone enables Lockdown Mode, some Apple apps and services work differently. For example, most attachments and link previews are blocked on iMessage, FaceTime calls from unknown contacts are filtered, location information is removed from shared pictures and certain fonts on websites are prevented from loading.
https://techcrunch.com/2023/12/07/apple-says-it-is-not-aware...
After reading the whole thing it still looks like that. After doing all that work to identify who’s been targeted with mercenary spyware why would you want to go to someone else to have them try their best at finding who it was?
My guess is expertise and scale; if Apple finds five such users a day, that doesn’t support a staff of 100 forensic experts. But if Apple, Facebook, Google, etc, etc, find 500 users a day, that might.
But who knows? The article sure doesn’t.
Note that I don't think the 2024 table is complete yet. Compared to 2023 there's hardly anything on it. In 2023 you can see that Meta was specifically funding the helpline. Lots of other major tech companies show up too.
Though mostly the charity seems to run on European taxpayer money (~60% of its funding).
If you're really targeted, "they" will also go for your non Apple devices like your "smart" TV. So you could probably use support to harden all your tech stuff.
Apple’s game is deep vertical integration. That’s all fine and dandy for selling products, but helps not one bit for customers who aren’t all-in on Apple’s ecosystem. A third party who only does this sort of work, in a platform agnostic way, is the sane way to handle things.
Thus is a great question and Apple's actions here seem to undermine many of the privacy arguments they've made against Right To Repair.
If someone breaks into your house do you call the builder for help?
if the builder of my house also charged me on a regular basis cloud storage fees, and made a cut of the fees when I used my credit card, and routed all my messages through the builder's server and contacted me and said "we've detected people trying to break into your house from your messages, but we aren't going to help you any more than this" I would sure wish I had some power to change my relationship with the builder.
If they constructed and installed the locks, and a weakness in the locks appears to have been the entry point for the break in, then yeah maybe?
Apparently quantum computing is around a decade away, when that happens I’ve been told you can say goodbye to all privacy at that point.
Not the builder, but calling the lock maker for sure.
I feel like the notification already does exactly that, no? “Hey, your phone looks busted, go call the <people who investigate sophisticated cyber surveillance targeting for a living>.”
And from the angle of “yeah you guys installed the locks wrong and they just opened the door, you should fix that”- does anyone reject the idea that the vuln would get reported to Apple, and that they’d be on it like crazy?