TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

About Lockdown Mode

374 pointsby hjuutilainenover 2 years ago

36 comments

ievansover 2 years ago
Notable highlights for me:<p>&gt; Lockdown Mode is available in iOS 16 and coming soon in iPadOS 16 and macOS Ventura.<p>&gt; Web browsing - Certain complex web technologies are blocked, which might cause some websites to load more slowly or not operate correctly. In addition, web fonts might not be displayed, and images might be replaced with a missing image icon.<p>The first sentence I believe is referring to disabling JIT (just in time compilation of Javascript), which is dangerous as it allocates W+X pages which are often used by the final stage of an exploit. Apple did an amazing job already of hardening iOS by severely restricting which applications can use JIT (and this is their justification for why non-Safari browser engines are not allowed on iOS) and even enabling per-thread memory page permissions. Many more details are in this fantastic post from Google&#x27;s project Zero: <a href="https:&#x2F;&#x2F;googleprojectzero.blogspot.com&#x2F;2020&#x2F;09&#x2F;jitsploitation-three.html" rel="nofollow">https:&#x2F;&#x2F;googleprojectzero.blogspot.com&#x2F;2020&#x2F;09&#x2F;jitsploitatio...</a><p>Overall it&#x27;s very interesting to see Apple invest so significantly in something that will benefit relatively few users -- not that I&#x27;m complaining!
评论 #32843144 未加载
评论 #32843098 未加载
评论 #32843544 未加载
评论 #32843397 未加载
评论 #32844182 未加载
评论 #32844747 未加载
评论 #32843087 未加载
评论 #32844909 未加载
评论 #32843331 未加载
评论 #32846532 未加载
评论 #32847144 未加载
评论 #32843063 未加载
teerayover 2 years ago
&gt; Lockdown Mode is not a configurable option for Mobile Device Management by system administrators<p>This is the best news. Otherwise, you can bet your IT department would be throwing that switch on for everyone.
评论 #32843846 未加载
评论 #32843273 未加载
评论 #32843721 未加载
评论 #32843282 未加载
milesover 2 years ago
Still waiting for Apple to allow restricting network access (both cellular and WiFi) for specific apps on all devices, not just those sold in China: <a href="https:&#x2F;&#x2F;apple.stackexchange.com&#x2F;a&#x2F;312430&#x2F;51806" rel="nofollow">https:&#x2F;&#x2F;apple.stackexchange.com&#x2F;a&#x2F;312430&#x2F;51806</a> .
评论 #32849422 未加载
评论 #32845681 未加载
评论 #32845390 未加载
HL33tibCe7over 2 years ago
This further cements my opinion that Apple is just leaps ahead of anyone else wrt security and privacy these days. They should be applauded for this.<p>I look forward to when this comes to iPad. An iPad with a Bluetooth keyboard is an excellent option over a traditional laptop for a high-risk target, and this’ll make it even better.
评论 #32845477 未加载
评论 #32844163 未加载
评论 #32844320 未加载
评论 #32846565 未加载
评论 #32849249 未加载
评论 #32850897 未加载
yositoover 2 years ago
I wonder why all of these settings are grouped together into a &quot;mode&quot; rather than giving users control over each of them individually.<p>What if I want to block USB devices, but I want to be able to use shared photo albums?
评论 #32843319 未加载
评论 #32843488 未加载
评论 #32843353 未加载
评论 #32843261 未加载
评论 #32843426 未加载
geoffegover 2 years ago
I find it interesting that Lockdown Mode doesn&#x27;t (yet) enable multiple lock screen authentication methods. Requiring Face ID AND a pass code could be useful. (There are rumors that Apple will add Touch ID back to their phones in the future. I&#x27;m not sure they&#x27;d keep Face ID on a phone with Touch ID but combining those two methods AND requiring a pass code would seem to be the most secure.)<p>I&#x27;d also like to see some method for quickly wiping the phone or severely disabling it. A friend mentioned that a new scheme for thieves is to ask you for your unlocked phone at gunpoint and then use a cash app to transfer money to one of their accounts. Some way to very quickly (and covertly) wipe your phone would help defend against that attack. (Related: <a href="https:&#x2F;&#x2F;www.startribune.com&#x2F;warrant-grifters-targeting-cash-apps-suspected-in-over-100-cell-phones-thefts-downtown-minneapolis&#x2F;600202085&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.startribune.com&#x2F;warrant-grifters-targeting-cash-...</a>)
评论 #32844291 未加载
评论 #32844312 未加载
larsnystromover 2 years ago
My only worry with this is that Lockdown Mode will be a reason to let the “default” mode be less secure. I understand some security features can cause major inconveniences, and so Apple needs to weigh security against convenience as part of their design process. I just hope they keep striking a good balance there, and won’t use Lockdown Mode as an easy way out of those design questions.
评论 #32845394 未加载
calo_starover 2 years ago
&gt; FaceTime - Incoming FaceTime calls are blocked unless you have previously called that person or contact. Apple Services - Incoming invitations for Apple Services, such as invitations to manage a home in the Home app, are blocked unless you have previously invited that person.<p>Well I would like to have these two enabled in regular situation.
评论 #32846286 未加载
_jalover 2 years ago
Unless I&#x27;m missing something, I think I plan to just run this all the time. I see very few downsides, personally.<p>&gt; web fonts might not be displayed<p>Great, I almost always prefer system default fonts.<p>&gt; Incoming FaceTime calls are blocked<p>Perfect, I don&#x27;t use it, it is always some scammer.<p>&gt; Incoming invitations for Apple Services<p>Perfect, I don&#x27;t care.<p>&gt; Shared albums are removed from the Photos app<p>I don&#x27;t use this stuff, I don&#x27;t care.<p>&gt; To connect your device to a USB accessory or another computer, the device needs to be unlocked.<p>This seems like it should have always been the default.<p>&gt; Configuration profiles can’t be installed<p>Perfect, nobody should be trying to manage my phone.
评论 #32843655 未加载
评论 #32845023 未加载
yuan43over 2 years ago
&gt; Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats. Most people are never targeted by attacks of this nature.<p>The list of restrictions doesn&#x27;t seem to inhibiting - for those who have used it, what are the points that stand out? Is this something designed for habitual use or under specific situations?
评论 #32843133 未加载
评论 #32843393 未加载
Tomteover 2 years ago
I think lockdown mode prevented me from copying text on my iPad and pasting it on the iPhone in WhatsApp, but let me paste it in Apple Notes.<p>I&#x27;m not sure though, it might have been a bug, it might have been a user error, but I wonder if inter-device copy and paste is limited, too. I haven&#x27;t read anything about it, though.<p>Otherwise I&#x27;ve noticed nothing, except a popup when starting apps for the first time after activating lockdown mode, that lockdown mode is active for the app.<p>To me, lockdown mode is a no-brainer. But I don&#x27;t use very JS-intensive web sites, and never use Apple messages.
评论 #32843473 未加载
评论 #32844742 未加载
mark_l_watsonover 2 years ago
I have been running Lockdown Mode for several weeks. It is very rare that my iPhone can not access a web page correctly, etc. iMessage behaves a little differently but I am used to it.
aborsyover 2 years ago
I try it and the experience is good. Barely noticeable. Maybe the sites load a bit slower, and occasionally fonts on some websites don’t render correctly. Otherwise it’s something that many people could just keep turned on.<p>Private relay and locked down mode are two of the recent good features in iPhone.<p>I am wondering how much is it effective against NSO-style spyware? Like, are they going to still come up with exploits and zero days hacking locked down iPhones, maybe adding 25% to their fees?<p>Is there a similar mode in desk and server Linux?
walterbellover 2 years ago
Any startup employees working directly on technology trade secrets or otherwise non-public intellectual property should enable iOS16 lockdown mode.<p>Thanks to years of invasive online targeting, bulk data breaches and mobile phone network structural insecurity, it has never been cheaper to screen for higher-than-average-value targets with digital assets that can be exfiltrated.<p>Since targeting costs have fallen, it is profitable to target employees below the C-suite, e.g. those in strategic or development roles who routinely need to access sensitive information and digital assets. This applies to enterprise, mobile and WFH environments, e.g. leveraging mobile phone foothold to reach other devices like a home router.
arecurrenceover 2 years ago
I was very happy to see this feature announced! I turned it on immediately and so far it has had little negative impact on my life.<p>Some apps like Gmail will warn you that Lockdown mode is activated and that it will impact your experience but I have not encountered any drawbacks beyond iMessage links not opening the browser. This is easily worked around by copying them.<p>I hope this also blocks incoming calendar invites. Apple has as a feature the automatic addition of calendar invites... spammers soon noticed this and send out calendar invites with their favorite links that can clutter it up.
评论 #32843564 未加载
MuffinFlavoredover 2 years ago
&quot;jeff bezos get caught cheating on his wife by saudi prince&quot; mode?
aborsyover 2 years ago
The audience for this is broader than journalists and human rights activists.<p>Executives, politicians, government figures, engineers and scientists with access to intellectual property, lawyers, … will all benefit from this mode.<p>Think of nations stealing trade secrets and technological know-how from each other. Or how much money you could make hacking iPhone of an employee or CEO of a company that might provide inside information.
smarterthanyou_over 2 years ago
I am not sure if Lockdown Mode is a lot of help if it can easily be detected by websites:<p><a href="https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;epzpb4&#x2F;websites-can-identify-if-youre-using-iphones-new-lockdown-mode" rel="nofollow">https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;epzpb4&#x2F;websites-can-identify...</a>
notart666over 2 years ago
I don&#x27;t really see why this matters when Apple also installs backdoors into their phones and grants nation states the exploits to attack dissidents for any person or group that would need a feature like this, apple is the last company I&#x27;d trust to protect me from an authoritarian regime.
评论 #32845882 未加载
calsyover 2 years ago
Obviously these types of features are welcome, even though they are apply to an incredibly small group of people. I cant help but feel the &#x27;personal security&#x27; push from Apple and its marketing is rather self serving.<p>Apple is under more legal pressure than ever for its apparent &#x27;anti-competitive&#x27; practices. They have on many occasions pushed the line of user privacy and security to defend their business. Features like this benefit a small group of people, but help Apple enormously in defending itself from litigation.<p>Edit: Downvote? Why are companies given the benefit of the doubt as if they were human and caring when they are clearly not! Large listed tech companies like Apple will ALWAYS act in their own interest first. User privacy is the advantage Apple has over its competitors who rely on free services and advertising. It is in their OWN INTEREST to pursue this path which in turn impacts others ability to compete. Must we continue to be so grossly naive?
评论 #32845912 未加载
steve_johnover 2 years ago
Lockdown Mode is an optional, it is a extreme protection that&#x27;s designed for the very few individuals who, because of who they are or what they do, Lockdown might be personally targeted by some of the most sophisticated digital threats.
jbverschoorover 2 years ago
Lockdown Mode should be the default, and people should actively enable it. There&#x27;s nothing anyone would want, except maybe shared albums. Those are from people you trust not to upload any images that exploit something.
评论 #32849705 未加载
Nifty3929over 2 years ago
Why can’t I have the option to turn off my GPS? That seems so important and easy.<p>Question: If I turn off cell, like with airplane mode, is it truly, completely off, with no cell tower pings and such?
randyrandover 2 years ago
A big shortcoming - 3rd party apps.<p>Many hacks these days exploit Whatsapp incoming message processing, etc.<p>Every app with push notification support increases your attack surface.
评论 #32845013 未加载
int_19hover 2 years ago
The trend towards disabling JIT for the sake of security is interesting. I wonder what effect this will have on wasm adoption.
nr2xover 2 years ago
Does lockdown mode also disable iCloud backup?
评论 #32845877 未加载
perryizgr8over 2 years ago
Will lockdown mode stop your phone from scanning your photos and sending them to Apple&#x2F;FBI?<p><a href="https:&#x2F;&#x2F;www.apple.com&#x2F;child-safety&#x2F;pdf&#x2F;CSAM_Detection_Technical_Summary.pdf" rel="nofollow">https:&#x2F;&#x2F;www.apple.com&#x2F;child-safety&#x2F;pdf&#x2F;CSAM_Detection_Techni...</a>
MMS21over 2 years ago
Looks like they&#x27;re preparing for sideloading (LFG!)
评论 #32853145 未加载
mikotodomoover 2 years ago
Wow, with this and the iPhone 14&#x27;s camera, they are massively ahead of all other companies. It makes me happy that I bought their products and helped create this.
etaioinshrdluover 2 years ago
The funny thing is that someone notable (and likely rich and successful) gets a much worse-functioning device because of this mode.
jaimex2over 2 years ago
Basically, Windows Server mode.
评论 #32846451 未加载
maybelsyrupover 2 years ago
Does anyone think that Lockdown Mode was allowed to roll out without the American security state feeling comfortable that they&#x27;re able to defeat it by pressing a button?
评论 #32843817 未加载
ffhhjover 2 years ago
&gt; 3. Under Security, tap Lockdown Mode and tap Turn On Lockdown Mode.<p>&gt; 4. Tap Turn On Lockdown Mode.<p>Tap twice? ;)
评论 #32843699 未加载
评论 #32843742 未加载
Arrathover 2 years ago
The ability to exclude apps or websites from the lockdown seems at the face of it to reintroduce attack surface that lockdown mode is meant to prevent.<p>Countdown to some 0day no-click exploit that adds an app or service or site to the exclusion list and then proceeds with a further attack?
评论 #32843031 未加载
评论 #32843832 未加载
lizardactivistover 2 years ago
Important to understand is that &quot;provisioned access&quot; as given to the US government is not considered to be a cyber attack, and lockdown mode will not help you there.<p>Also, it appears you cannot use configuration profiles in lockdown mode, meaning you may not be able to use DNS over TLS or HTTPS.
评论 #32844006 未加载
ThinkBeatover 2 years ago
These things are godo and bad.<p>It is nice to make the effort, and it might be dome good. and allow a lot of people to feel l33t<p>It is bad if people at proper risk think they are safe once it is enabled. (and those, to me, appear to be the people this is marketed for)
评论 #32843506 未加载