Hacker News new | ask | show | jobs
by zyxley 3773 days ago
Signing a modified copy of iOS that will only ever load on a specific phone is technically feasible, but isn't practical as precedent.

This is because said signing generally takes a whole complicated physical process of assembling physically secure separately kept modules that hold different parts of the signing key, and likely takes the sign-off and personal involvement of multiple senior engineers at the company.

This is absolutely necessary, because the security of literally every iPhone depends on there being absolutely no chance that the signing key ever gets into unauthorized hands.

Now think about what happens to the company when more and more judges start issuing writs that require that this complicated process happens, and when a judge unhappy with the increasingly long processing time for every "software created for a specific device" instance instead issues a writ that demands an insecure version of iOS that can be installed on any iPhone.