Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, but if an attacker has physical access and unlimited time, you've probably lost anyway.

What this seems to be focused on are the "remote zero-click/one-click" vulnerabilities we've seen, in which either a message is delivered that never shows up but installs a backdoor hook, or a website can deliver a malware package to a particular user and install the backdoor hook without notifications.

It sounds like it does improve some of the physical security features, which should help reduce attack surface, but I wouldn't trust any bit of consumer electronics against a sustained physical attack by a sufficiently motivated adversary.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: