frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Apple Platform Security (Jan 2026) [pdf]

https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf
51•pieterr•1h ago

Comments

OGEnthusiast•44m ago
Glad there's still at least one tech company that cares about personal security / opsec.
varispeed•37m ago
No mention of Pegasus and other software of such sort. Can latest iOS still be infected?

There is no point creating such document if elephant in the room is not addressed.

gjsman-1000•32m ago
Why? The obvious conclusion is that Apple is doing everything in its power to make the answer “no.”

You might as well enumerate all the viruses ever made on Windows, point to them, and then ask why Microsoft isn’t proving they’ve shut them all down yet in their documents.

varispeed•17m ago
That analogy misses the asymmetry in claims and power.

Microsoft does not sell Windows as a sealed, uncompromisable appliance. It assumes a hostile environment, acknowledges malware exists, and provides users and third parties with inspection, detection, and remediation tools. Compromise is part of the model.

Apple’s model is the opposite. iOS is explicitly marketed as secure because it forbids inspection, sideloading, and user control. The promise is not “we reduce risk”, it’s “this class of risk is structurally eliminated”. That makes omissions meaningful.

So when a document titled Apple Platform Security avoids acknowledging Pegasus-class attacks at all, it isn’t comparable to Microsoft not listing every Windows virus. These are not hypothetical threats. They are documented, deployed, and explicitly designed to bypass the very mechanisms Apple presents as definitive.

If Apple believes this class of attack is no longer viable, that’s worth stating. If it remains viable, that also matters, because users have no independent way to assess compromise. A vague notification that Apple “suspects” something, with no tooling or verification path, is not equivalent to a transparent security model.

The issue is not that Apple failed to enumerate exploits. It’s that the platform’s credibility rests on an absolute security narrative, while quietly excluding the one threat model that contradicts it. In other words Apple's model is good old security by obscurity.

Retr0id•32m ago
don't worry, they set the allow_pegasus boolean to false
goalieca•21m ago
Apple did create a boolean for that. They call it lockdown mode.

> Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats. Most people are never targeted by attacks of this nature. When Lockdown Mode is enabled, your device won’t function like it typically does. To reduce the attack surface that potentially could be exploited by highly targeted mercenary spyware, certain apps, websites, and features are strictly limited for security and some experiences might not be available at all.

varispeed•5m ago
If Pegasus can break the iOS security model, there’s no reason to think it politely respects Lockdown Mode. It’s basically an admission the model failed, with features turned off so users feel like they’re doing something about it.
wat10000•20m ago
Pegasus isn't magic. It exploits security vulnerabilities just like everything else. Mitigating and fixing those vulnerabilities is a major part of this document.
random_duck•30m ago
Wow, this is hardcore (pun intended).
buildbot•21m ago
262 pages!!! Pretty interesting to see how the different SoCs have evolved security wise over time.
easton•19m ago
Web version: https://support.apple.com/guide/security/welcome/web
modeless•19m ago
Then they turn around and upload your iMessages to their own servers in a form that they can read, breaking their own E2EE. Google Messages fixed this issue a long time ago. Why hasn't Apple? https://james.darpinian.com/blog/apple-imessage-encryption
runjake•11m ago
This is your blog post, so I'll ask you a question. What are you trying to state in Belief #1? The message is unclear to me with how it's worded:

  > In this table, in the "iCloud Backup (including device and Messages backup)" row, under "Standard data protection", 
  > the "Encryption" column reads "In transit & on server". Yes, this means that Apple can read all of your messages 
  > out of your iCloud backups.
In addition to the things you mentioned, there's certainly a possibility of Apple attaching a virtual "shadow" device to someone's Apple ID with something like a hide_from_customer type flag, so it would be invisible to the customer.

This shadow device would have it's own keys to read messages sent to your iCloud account. To my knowledge, there's nothing in the security model to prevent this.

shawnz•5m ago
The page has two categorizations: "In transit & on server" and "End-to-end". The former is explicitly NOT end-to-end, meaning there are moments in time during processing where the data is not encrypted.
whitepoplar•5m ago
Given that A19 + M5 processors with MIE (EMTE) were only recently introduced, I wonder how extensively MacOS/iOS make use of the hardware features. Is it something that's going to take several years to see the benefit, or does MIE provide thorough protection today?

The "User-Generated Content" Ruse

https://www.newcartographies.com/p/the-user-generated-content-ruse
1•razorburn•39s ago•0 comments

Users report Firefox's new update deletes bookmarks and more

https://old.reddit.com/r/firefox/comments/1qrnrga/firefox_just_randomly_nuked_itself/
1•lazylion2•1m ago•1 comments

Russia's Oil Revenue, the Lifeblood of Its War Machine, Is Plummeting

https://www.nytimes.com/2026/01/31/world/europe/russia-economy-oil.html
1•doener•3m ago•0 comments

Pydantic Monty: A minimal, secure Python interpreter (in Rust) for use by AI

https://github.com/pydantic/monty
1•patrick91•5m ago•0 comments

General relativity explains why binary star systems rarely host planets

https://phys.org/news/2026-01-tatooine-planets-rare-general-binary.html
1•bikenaga•5m ago•0 comments

Autonomous Agent Marketplace

https://50c14l.com
1•rgbrgb•5m ago•0 comments

Withnail and AI – We've Gone on Holiday to the Future by Mistake

https://www.sebs.website/blog/withnail-and-ai
1•Incerto•6m ago•0 comments

A lot of the Moltbook stuff is fake

https://twitter.com/HumanHarlan/status/2017424292548673830
3•kumarm•7m ago•0 comments

U.S. Military Tells Key Middle East Ally to Prepare for Attack on Iran

https://www.dropsitenews.com/p/united-states-iran-imminent-attack-strikes-trump-israel
1•spzx•9m ago•0 comments

China's genius plan to win the AI race is paying off

https://www.ft.com/content/68f60392-88bf-419c-96c7-c3d580ec9d97
2•alecco•10m ago•1 comments

So, why *should* GNOME support server side decorations?

https://blister.zip/posts/gnome-ssd/
2•PaulHoule•11m ago•0 comments

Long-lost shipwreck resurfaces on Jersey Shore

https://www.foxnews.com/travel/long-lost-shipwreck-resurfaces-along-jersey-shore-officials-warn-a...
1•newsoftheday•11m ago•1 comments

Remembering Christa: 40 Years After the Challenger

https://www.nhpr.org/remembering-christa-40-years-after-the-challenger
1•indigodaddy•12m ago•0 comments

A self-hostable media stack that configures itself on Kubernetes

https://charmarr.tv/en/latest/
1•ivdi•13m ago•0 comments

Single Entry Point Layer Is Underrated

https://medium.com/@HobokenDays/single-entry-point-layer-is-underrated-e116eab03b53
2•HideInNews•13m ago•0 comments

Demystifying Evals for AI Agents

https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents
1•i7l•14m ago•0 comments

Exposing a 'mental trap': The hidden bias behind chronic indecision

https://medicalxpress.com/news/2026-01-exposing-mental-hidden-bias-chronic.html
1•bikenaga•14m ago•1 comments

Show HN: ArtCraft AI crafting engine, written in Rust

https://github.com/storytold/artcraft
1•echelon•14m ago•0 comments

GNU Guile

https://www.gnu.org/software/guile/
1•tosh•14m ago•0 comments

Will AI Replace Builders?

2•skshadan•16m ago•1 comments

Ask HN: What are the best things to do for high schoolers in summer?

2•artostash•18m ago•1 comments

If you had unlimited tokens for one month, what would you use them for?

1•hmokiguess•20m ago•0 comments

Ask HN

1•artostash•21m ago•0 comments

All-in-One project management tool for organizations with sensitive data

https://www.stackfield.com/
1•doener•22m ago•0 comments

Amazon Layoffs Hit 1,400 in Seattle as Local Tech Jobs Wither

https://www.bloomberg.com/news/articles/2026-01-30/amazon-layoffs-hit-1-400-in-seattle-700-in-bel...
1•1vuio0pswjnm7•26m ago•0 comments

Bitcoin Looks Set for Longest Monthly Losing Streak Since 2018

https://www.bloomberg.com/news/articles/2026-01-30/bitcoin-btc-slides-toward-longest-monthly-losi...
7•1vuio0pswjnm7•29m ago•0 comments

Faster package builds using Icecream and a Mac

https://iovec.net/2026-01-26
1•pratham_IN•30m ago•0 comments

US Has Investigated Claims WhatsApp Chats Aren't Private

https://www.bloomberg.com/news/articles/2026-01-29/us-has-investigated-claims-that-whatsapp-chats...
1•1vuio0pswjnm7•30m ago•0 comments

AI, data centre companies will have to compete for electricity in B.C

https://www.cbc.ca/news/canada/british-columbia/ai-data-centres-competitive-bid-process-bc-9.7069103
1•barbazoo•31m ago•1 comments

Writing an optimizing tensor compiler from scratch

https://michaelmoroz.github.io/WritingAnOptimizingTensorCompilerFromScratch/
1•t-3•32m ago•0 comments