|
|
|
|
|
by throwaway290
1133 days ago
|
|
> They already have cryptographic authentication for parts What if a genuine part is modified. I am not sure it is a solvable problem? > First they are indeed not exclusive options, locking parts when the phone is locked is a possible option. If that is technically possible I am all for it (but if I had to choose between no integrity protection and integrity protection that makes it harder to repair, I don't know what I would choose). However if you are a phone, how would you distinguish between a legitimate repair and malicious swapping out of parts? Sounds like incompleteness theorem would say you can't |
|
Same problem as it is now, nothing changes.
> However if you are a phone, how would you distinguish between a legitimate repair and malicious swapping out of parts? Sounds like incompleteness theorem would say you can't
If your threat model is malicious swapping parts, an iPhone isn't for you anyway, you need a device more secure than that.
And I doubt that applies to more than an handful of individuals, even targeted attacks themselves usually don't go this far and prefer to just exfiltrate the data by software.