TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Apple Platform Security February 2021

56 pointsby Duckiover 4 years ago

11 comments

naturalpbover 4 years ago
Still waiting for Apple to provide end-to-end encryption on iCloud Backup for devices. Their documentation on this has always seemed intentionally vague.<p><a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT202303" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT202303</a><p>End-to-end encrypted data -&gt; - Apple Card transactions (requires iOS 12.4 or later) - Home data - Health data (requires iOS 12 or later) - iCloud Keychain (includes all of your saved accounts and passwords) - Maps Favorites, Collections and search history (requires iOS 13 or later) - Memoji (requires iOS 12.1 or later) - Payment information - QuickType Keyboard learned vocabulary (requires iOS 11 or later) - Safari History and iCloud Tabs (requires iOS 13 or later) - Screen Time - Siri information - Wi-Fi passwords - W1 and H1 Bluetooth keys (requires iOS 13 or later)
评论 #26186268 未加载
评论 #26186238 未加载
评论 #26186850 未加载
评论 #26188010 未加载
saagarjhaover 4 years ago
Lots of interesting stuff this time. Short list that I’ll update as I go:<p>Some sort of “checked C” in iBoot: <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;memory-safe-iboot-implementation-sec30d8d9ec1&#x2F;web" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;memory-safe-iboot-i...</a><p>Data is encrypted with your security policy, so if that changes (e.g. you disable SIP) it doesn’t expose it: <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;sealed-key-protection-skp-secdc7c6c88e&#x2F;web" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;sealed-key-protecti...</a><p>Details on what the SRD is and how it works: <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;apple-security-research-device-seca7ff718d2&#x2F;web" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;apple-security-rese...</a>
Ennisover 4 years ago
&quot;For certain sensitive information, Apple uses end-to-end encryption&quot; - there&#x27;s a lot of important user generated data from Apple apps that is not end-to-end encrypted.<p>Frankly, I&#x27;d like to see them go even further and put in place a policy that all user-created-and-consumable content can only leave the device in end-to-end encrypted format and have those keys managed by my AppleID so not even Apple can decrypt.<p>They can introduce it at an API level without having to dictate storage providers. If a web-version of an app needs show my photos they can let the end-user browser decrypt it. This works for private data, 1:1 and 1:Many shared data.<p>I should have a choice with who hosts my encrypted data, who manages my keys&#x2F;identity and who provides a service that uses that data. Let&#x27;s get back to providing value through services and away from leaching value through hoarding data and controlling protocols.<p>Yes - this will force companies to change their business models if they rely on access to my data. Will it make for better software - Yes hands down. More companies can compete and we&#x27;ll start to see more creative solutions.
judge2020over 4 years ago
I don&#x27;t see anything about the &quot;Unlock your iPhone with your Watch&quot; feature that 14.5 is going to have[0] - i&#x27;d be interested in reading the in-depth security considerations they had. It&#x27;s also currently a mystery if this feature does a partial Face ID scan in addition to requiring an unlocked Watch.<p>0: <a href="https:&#x2F;&#x2F;www.macrumors.com&#x2F;2021&#x2F;02&#x2F;01&#x2F;iphone-apple-watch-unlocking-ios-14-5&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.macrumors.com&#x2F;2021&#x2F;02&#x2F;01&#x2F;iphone-apple-watch-unlo...</a>
评论 #26186753 未加载
评论 #26188902 未加载
eastonover 4 years ago
It&#x27;s nice to see that the Apple Security Research Device (i.e. the iPhone with root access) hasn&#x27;t been forgotten about[0]. They even describe the additional security protections they had to do to ensure an attacker didn&#x27;t give this device to someone that thought it was a regular iPhone (for example, the phone won&#x27;t cold boot without being plugged into a charger, and if you plug it in, it shows the words &quot;Security Research Device&quot; before booting XNU in verbose mode)<p>0: <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;apple-security-research-device-seca7ff718d2&#x2F;1&#x2F;web&#x2F;1" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;apple-security-rese...</a>
Duckiover 4 years ago
PDF version: <a href="https:&#x2F;&#x2F;manuals.info.apple.com&#x2F;MANUALS&#x2F;1000&#x2F;MA1902&#x2F;en_US&#x2F;apple-platform-security-guide.pdf" rel="nofollow">https:&#x2F;&#x2F;manuals.info.apple.com&#x2F;MANUALS&#x2F;1000&#x2F;MA1902&#x2F;en_US&#x2F;app...</a>
someonehereover 4 years ago
I’m bummed as an admin that the new M1s remove a function as an admin I always loved with remote management.<p>From what a sales&#x2F;dev person for a Saas MDM app for macOs told me, the M1s do not have a lock device feature. You can only wipe the device.<p>If an employee was terminated, we could remote send a lock command with a numeric code. The only way to remove the lock is to get the code from us or have Apple reset it in person. The in person visit you have to prove you’re the owner or have authorization from the company to have Apple unlock it.<p>My only option now is to wipe it. So now I have to find a cloud backup provider to back these devices up in case I need an important file from an employee who decides to go rogue.
johnwayne666over 4 years ago
I’d like to know how I’m still logged in in Twitch even after deleting and installing the app. Or how Spotify offered me to link it to an Alexia device I was setting up after I installed the Alexa app.
评论 #26185991 未加载
评论 #26185876 未加载
评论 #26185875 未加载
评论 #26185959 未加载
coldcodeover 4 years ago
Currently I have no non-apple kext running, not sure this is a big problem any more other than old legacy hardware or mostly esoteric usage.
评论 #26186000 未加载
评论 #26194939 未加载
qrbLPHiKpiuxover 4 years ago
Is there a separate Law enforcement guide?
tumultover 4 years ago
Any news about the T2 chip ending up being a way to silently implant malware in all Intel-based Macs that have it? Refunds? Replacements? Anything? Bueller? <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2020&#x2F;10&#x2F;apples-t2-security-chip-has-an-unfixable-flaw&#x2F;?comments=1" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2020&#x2F;10&#x2F;apple...</a><p>I don&#x27;t really know why anyone would take Apple&#x27;s hardware security claims at face value after this.<p>edit: more links, though they&#x27;re all pretty similar.<p><a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;apple-t2-chip-unfixable-flaw-jailbreak-mac&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;apple-t2-chip-unfixable-flaw-jai...</a><p><a href="https:&#x2F;&#x2F;appleinsider.com&#x2F;articles&#x2F;20&#x2F;10&#x2F;05&#x2F;apples-mac-t2-chip-has-an-unfixable-vulnerability-that-could-allow-root-access" rel="nofollow">https:&#x2F;&#x2F;appleinsider.com&#x2F;articles&#x2F;20&#x2F;10&#x2F;05&#x2F;apples-mac-t2-chi...</a><p><a href="https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;hackers-claim-they-can-now-jailbreak-apples-t2-security-chip&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;hackers-claim-they-can-now-jai...</a><p><a href="https:&#x2F;&#x2F;www.theregister.com&#x2F;2020&#x2F;10&#x2F;08&#x2F;apple_t2_security_chip&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.theregister.com&#x2F;2020&#x2F;10&#x2F;08&#x2F;apple_t2_security_chi...</a><p>edit 2:<p>If this is wrong, I&#x27;d like to know the truth! Really! Was it a hoax? Is there a patch? What happened?
评论 #26186036 未加载
评论 #26186164 未加载
评论 #26185614 未加载