HN user

thejsa

46 karma
Posts0
Comments35
View on HN
No posts found.

In case it’s helpful- apparently you can just use a secondary Apple ID (even one made just for this use) with AltStore and it works just as well without risking one’s main ID. (Though for 365 day signing, that’d also need to be added to its own, or a non-individual, dev team.)

The article covers this:

So how does a prison laptop end up on eBay?

The laptop that Zhang bought came from a state whose corrections department contracts with a Milwaukee-based nonprofit to dispose of its old laptops. But instead of recycling the devices, the organization resold them, selling out of 100 Securebooks after Zhang’s post went viral.

I don’t remember where I read it, admittedly, but apparently the iPad didn’t cross the market share thresholds or something like that; would be happy to be wrong.

Suppose we’ll see in due course whether the European Commission takes them to task on it…

Yes, given the size constraints of the deep-level Tube tunnels, which are much smaller than those for mainline trains; apparently developments in small air con systems have helped a fair bit here, fifteen odd years ago apparently it just wasn’t feasible.

Even listening is in a grey area in the UK; it’s a separate offence to “use wireless telegraphy apparatus with intent to obtain information as to the contents, sender or addressee of any message” where you aren’t an intended recipient. But the intent bit is probably hard to prove in practice.

Re: the gifted trojan device scenario, I think the primary line of defense would be to display a prominent boot time warning in the bootloader where a non-Apple root of trust has been used, just as many Android devices do already -- perhaps similar to the recovery screen, but with more warning signs and an open lock symbol or something.

Why would android even allow such restrictions to be enabled in the first place?

To enforce DRM in streaming apps, mostly; though other apps have ended up bodging that for their own purposes.

I suppose at least in the context of secure messaging or banking apps (which also do this) it makes you think twice before snapping something, but even so I think there should be a variant of whatever API which lets the user override it / disable it globally.

Only genuine security concern I can think of that it addresses is that of screen recording malware / stalkerware (assuming said malware doesn't already have root access on your device to circumvent it...), and perhaps the risk of accidentally screenshotting/capturing something sensitive like bank details while screen sharing.

My understanding is that the permissions popup is used for the registration flow (generating & enrolling a key into the Secure Enclave), and after that if there are existing credentials, it's just 'Touch ID to login'.

Not so much with WSL 2, which Microsoft are focusing on at the moment; WSL 2 runs a real Linux kernel in a lightweight Hyper-V VM with lots of jazzy integration services.

Have you tried clicking the ‘End Task’ button twice? It’s arguably rather unintuitive, but in my experience the first click seems to send a ‘politely quit’ signal and the second results in the merciless massacre which hasn’t failed me yet.

Their copy protection schemes do largely stem from the basic ‘signed personalised tickets’ thing they’ve had going on since the iQue Player and then the Wii, but insofar it seems to have held up to attacks and no fatal fundamental flaws have been found yet. Short of software exploits, until 2048-bit RSA is broken it’s not a concern really