Hacker News new | ask | show | jobs
by lrvick 803 days ago
Apple can remotely execute code on any internet connected device running an proprietary Apple operating system.

It is only a matter of time before courts realize this.

The CCP controls the Apple software signing HSMs in China for a reason.

1 comments

But if this is your threat model - that you have no trust of the operating system or the vendor - then all of this is pointless because at any time they can just backdoor themselves. Apple could just never ask or collect this, but still they're one update away from starting to collect it.

Of course that's always a threat with any computer, but you must place some amount of trust somewhere.

If Apple did not collect the data today, then a court order in the future will not allow them to collect data that was not stored today.

Personally I only use reproducibly built FOSS software and I isolate most of my hardware and workloads from each other with virtual machines via QubesOS.

Proprietary software is not at all required to be well integrated into modern society.

> from starting to collect it.

So even then they would have no data before that point!

  you must place some amount of trust somewhere.
Using something and trusting it are different things.