|
|
|
|
|
by Nextgrid
635 days ago
|
|
It is sad to see such a misinformed take on a technical forum. You can already do everything you want. It will take some reverse-engineering work, but it's possible. Similar things were said about iMessage interoperability with Android, until Beeper proved them wrong. They managed to reverse-engineer it, build a compatible client and clearly proved Apple's claims were BS (and no, this didn't lead to a mass-scale compromise of iMessage, contradicting fanboys' claims). If the feature allows to pull up the iPhone's screen without any user consent, then it is vulnerable to begin with - the reverse-engineering requirement would become an insignificant hurdle compared to the value of such a vulnerability. Presumably however, there will be a consent step, either on the spot or prior (maybe it can reuse the cryptographic pairing mechanism that happens when the phone asks you to "trust this computer?" the first time), and no third-party (whether using an approved API or reverse-engineered) would be able to bypass it without the user intentionally consenting. |
|
The idea that breaking device attestation that is secured through Secure Enclave hardware i.e. not accessible from user code is an insignificant hurdle is hilariously ridiculous. It is borderline impossible for any ordinary developer.
And people that bring up the "just ask the user" argument clearly don't remember how poorly that has worked in the past e.g. Microsoft Vista. Users will blindly approve any dialog which is why Apple has been so careful to limit them to targeted actions which a "do you approve this app to record everything on your iPhone" is not.