Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Jailbreaks were likely tolerated because developers were hungry to try things and Apple knew the libraries on iOS weren't that great at the time.

> As you point out with the history of jailbreaks on iOS, you're saying Apple's permissiveness then suggests they don't have that security concern and they want to lock it down for other reasons (correct me if I'm wrong in characterizing your argument).

No: you completely misunderstand. I am not saying Apple let jailbreaking happen; I am saying Apple's device was so poorly secured (in an absolute, not relative, sense), that in practice you can model the device as being "open to anyone who wants to make their own device open". It was more open than Android for long periods of time as the jailbreaks were more consistent in their ability to give you full control of the device (Android jailbreaks tend to be "hit or miss", really).

The argument then becomes simple: if iOS is a platform you consider secure ("iOS is de facto the most secure consumer OS out there"), in practice this is a device which anyone who wanted to could get complete control over their own device, and so we know that property is unrelated to security.

The only thing it really does is make the device look better from a DRM perspective (particularly the AppleTV). I run into tons of developers constantly who are obsessed about piracy well past the point where it makes sense, and most of them have this weird mental model of Apple's security features that make them think weird stuff like "if I embed a key in my compiled binary no one can read it".

Regardless, I am just going to say it, as me having this information and trying to avoid saying it is probably just causing more problems than it benefits anyone: I have been challenged multiple times by people working at Apple (years ago, and I don't even think these people still work there, which makes me feel at least slightly more comfortable saying this) that if I want them to have a more open device in the ways that I want, I need to tell them how to do it without opening the flood door for piracy.



The argument to me reads as "if the security isn't perfect, it means they are not even trying, which makes it obvious that security is not the goal." but the not-perfect->not-trying jump doesn't seem to be fair.


I don't think goals or intents matter. Apple's goal might be to prevent the Ancient God Mulk'nar from returning to our dimension to begin the second stage of The Reckoning, and commenters might point out "Mulk'nar hasn't showed up yet, so this must be working"; but if either Apple or the commenters seriously think that having a closed device is what is preventing Mulk'nar from returning, they are clearly deceiving themselves as in practice the device has been de facto open (by ludicrous means that should not be required) for many years. The argument here is essentially "you are asking Apple to give up the only thing preventing Mulk'nar from returning" and I am showing how that makes no sense given the reality of history. People are saying the iPhone is very secure. The iPhone is, factually, a device which for many years was one of the more open platforms for people to tinker with their own device, due to the jailbreak scene. So the idea that allowing even all people, much less just security researchers, to tinker with their own device somehow would undo the security of the system doesn't make sense.


I think it's important to remember that Apple has a history of leaning to the decision which is most financially beneficial to Apple, wrt opening up the flood door to piracy. See iTunes/iPods policy changes over it's lifetime.

Interesting paper: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2244111


The article I read said Apple had iPhones that are easy to hack ? Can you explain what it means ? Quote “for special iPhones that don't have certain restrictions so it's easier to hack them, according to multiple people who attended the meeting.”




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: