zlacker

[parent] [thread] 9 comments
1. fc417f+(OP)[view] [source] 2025-06-12 07:50:14
If it was really about security (in the sense of that which benefits the end user) they'd just stick it behind a toggle and be done with it. I just think it's important to call out the misalignment - security can refer to the interests of the end user, or alternatively to the vendor. The ambiguity is convenient for PR statements.
replies(1): >>misnom+T2
2. misnom+T2[view] [source] 2025-06-12 08:24:37
>>fc417f+(OP)
We’ve decades of examples of simple toggles not working. Bad actors will just explain to the target the necessity of switching it on.
replies(4): >>jampek+d5 >>Teever+p5 >>znpy+c8 >>fc417f+Ah
◧◩
3. jampek+d5[view] [source] [discussion] 2025-06-12 08:48:43
>>misnom+T2
Put it in the bootloader then.

The pretence that Apple makes these things for security reasons and there's absolutely no way in the world to make it possible is a bit ridiculous.

replies(1): >>transp+D6
◧◩
4. Teever+p5[view] [source] [discussion] 2025-06-12 08:50:01
>>misnom+T2
But we have another example to look at. Why isn't this a big problem on Apple laptops?
replies(1): >>jaoane+C5
◧◩◪
5. jaoane+C5[view] [source] [discussion] 2025-06-12 08:53:09
>>Teever+p5
Laptops have always been able to virtualise, the same they can download stuff off the internet without going through the App Store. Changing that wouldn’t fly.
◧◩◪
6. transp+D6[view] [source] [discussion] 2025-06-12 09:06:25
>>jampek+d5
Apple shipped hypervisor support back in iOS 16, then removed it!

https://taoofmac.com/space/blog/2024/07/25/0900

replies(1): >>kokada+Ka
◧◩
7. znpy+c8[view] [source] [discussion] 2025-06-12 09:23:03
>>misnom+T2
You can load your own root CA on iOS devices (i did it to enable certificates issued by my own private CA). That bypasses a LOT of security issues, and yet it’s still feasible.
◧◩◪◨
8. kokada+Ka[view] [source] [discussion] 2025-06-12 09:51:54
>>transp+D6
This is a nice post of things that bothers me in the Apple ecosystem: arbitrary limitation after arbitrary limitation.

I didn't know about the Apple Watch couldn't pair with an iPad, and I don't think even an Apple fanboy could make an excuse for that one.

replies(1): >>jampek+vS
◧◩
9. fc417f+Ah[view] [source] [discussion] 2025-06-12 11:01:17
>>misnom+T2
By that logic the bad actor will just explain that he needs you to log into your online bank account so could you please do that and wire some money. Such scams certainly exist but it isn't a relevant attack vector for the sort of end user security that we're talking about here.
◧◩◪◨⬒
10. jampek+vS[view] [source] [discussion] 2025-06-12 14:49:32
>>kokada+Ka
> I don't think even an Apple fanboy could make an excuse for that one.

You're underestimating the strength of the reality distortion field.

[go to top]