iPhone3gs Guide

  • Increase font size
  • Default font size
  • Decrease font size
Home Security With iPhone, 'Security' Is Code for 'Control'



Please check our new website

iPhoneHall.com

With iPhone, 'Security' Is Code for 'Control'

E-mail Print PDF

Security' Is Code for 'ControlBuying an iPhone isn't the same as buying a car or a toaster. Your iPhone comes with a complicated list of rules about what you can and can't do with it.

You can't install unapproved third-party applications on it. You can't unlock it and use it with the cellphone carrier of your choice. And Apple is serious about these rules: A software update released in September 2007 erased unauthorized software and -- in some cases -- rendered unlocked phones unusable.

"Bricked" is the term, and Apple isn't the lea

Computer companies wants bit apologetic about it.

more control over the products they sell you, and they're resorting to increasingly draconian security measures to get that control. The reasons are economic.

Control allows a company to limit competition for ancillary products. With Mac computers, anyone can sell software that does anything. But Apple gets to decide who can sell what on the iPhone. It can foster competition when it wants, and reserve itself a monopoly position when it wants. And it can dictate terms to any company that wants to sell iPhone software and accessories.

This increases Apple's bottom line. But the primary benefit of all this control for Apple is that it increases lock-in. "Lock-in" is an economic term for the difficulty of switching to a competing product. For some products -- cola, for example -- there's no lock-in. I can drink a Coke today and a Pepsi tomorrow: no big deal. But for other products, it's harder.

Switching word processors, for example, requires installing a new application, learning a new interface and a new set of commands, converting all the files (which may not convert cleanly) and custom software (which will certainly require rewriting), and possibly even buying new hardware. If Coke stops satisfying me for even a moment, I'll switch: something Coke learned the hard way in 1985 when it changed the formula and started marketing New Coke. But my word processor has to really piss me off for a good long time before I'll even consider going through all that work and expense.

Lock-in isn't new. It's why all gaming-console manufacturers make sure that their game cartridges don't work on any other console, and how they can price the consoles at a loss and make the profit up by selling games. It's why Microsoft never wants to open up its file formats so other applications can read them. It's why music purchased from Apple for your iPod won't work on other brands of music players. It's why every U.S. cellphone company fought against phone number portability. It's why Facebook sues any company that tries to scrape its data and put it on a competing website. It explains airline frequent flyer programs, supermarket affinity cards and the new My Coke Rewards program.

With enough lock-in, a company can protect its market share even as it reduces customer service, raises prices, refuses to innovate and otherwise abuses its customer base. It should be no surprise that this sounds like pretty much every experience you've had with IT companies: Once the industry discovered lock-in, everyone started figuring out how to get as much of it as they can.

Economists Carl Shapiro and Hal Varian even proved that the value of a software company is the total lock-in. Here's the logic: Assume, for example, that you have 100 people in a company using MS Office at a cost of $500 each. If it cost the company less than $50,000 to switch to Open Office, they would. If it cost the company more than $50,000, Microsoft would increase its prices.

Mostly, companies increase their lock-in through security mechanisms. Sometimes patents preserve lock-in, but more often it's copy protection, digital rights management (DRM), code signing or other security mechanisms. These security features aren't what we normally think of as security: They don't protect us from some outside threat, they protect the companies from us.

Microsoft has been planning this sort of control-based security mechanism for years. First called Palladium and now NGSCB (Next-Generation Secure Computing Base), the idea is to build a control-based security system into the computing hardware. The details are complicated, but the results range from only allowing a computer to boot from an authorized copy of the OS to prohibiting the user from accessing "unauthorized" files or running unauthorized software. The competitive benefits to Microsoft are enormous (.pdf).

Of course, that's not how Microsoft advertises NGSCB. The company has positioned it as a security measure, protecting users from worms, Trojans and other malware. But control does not equal security; and this sort of control-based security is very difficult to get right, and sometimes makes us more vulnerable to other threats. Perhaps this is why Microsoft is quietly killing NGSCB -- we've gotten BitLocker, and we might get some other security features down the line -- despite the huge investment hardware manufacturers made when incorporating special security hardware into their motherboards.

In my last column, I talked about the security-versus-privacy debate, and how it's actually a debate about liberty versus control. Here we see the same dynamic, but in a commercial setting. By confusing control and security, companies are able to force control measures that work against our interests by convincing us they are doing it for our own safety.

As for Apple and the iPhone, I don't know what they're going to do. On the one hand, there's this analyst report that claims there are over a million unlocked iPhones, costing Apple between $300 million and $400 million in revenue. On the other hand, Apple is planning to release a software development kit this month, reversing its earlier restriction and allowing third-party vendors to write iPhone applications. Apple will attempt to keep control through a secret application key that will be required by all "official" third-party applications, but of course it's already been leaked.

And the security arms race goes on ...

 



Please check our new website

iPhoneHall.com

Follow Us






Please check our new website

iPhoneHall.com

Featured

iPhone Hack Exposed: The Key Facts

As reported today, security experts Charlie Miller and Collin Mulliner been exposed to a virus of iPhone that could allow criminals to control your phone just by sending a single text message (SMS). His presentation at the Black Hat conference in Las Vegas, is making a lot of waves, but the details are scattered or too technical for most iPhone owners.   So we've done some research on the information that has emerged in this security vulnerability. The technical details involved in the... Read more...

An iPhone and a car seat on fire

Possibly a first in Europe, an iPhone 3G has caught fire, causing serious damage to a car.  Pieter from the Dutch city of Leiden left his car for a while and saw the interior filled with black smoke when he returned. His iPhone 3G, covered in a white Belkin hardcase and left unattended for the few minutes he was out of the car, was on fire, resulting in a completely destroyed passenger’s seat. The iPhone wasn’t connected to a charger and was in standby mode while in the car. Pieter... Read more...

How to protect your iPhone

Apple's irresistible iPhone is a prize for thieves, vandals, and hackers too. Follow these tips to protect your device and its data. As someone who's been around the block a few times with mobile technology, I get a kick out of lengthy treatises on the practices one should follow to keep the information on your iPhone secure. They follow a commonsense pattern: Use a PIN, set the device to auto-lock after a minimal delay, set it to blank itself after a limited number of invalid unlock... Read more...

Apple to fix iPhone security flaw Tomorrow

Apple is set to release a software patch to address a recently described security flaw in the iPhone, the UK network operator 02 has said.Experts revealed on Thursday that modified SMS messages could result in iPhones being disconnected from the network or hijacked altogether. Phones incorporating the Windows Mobile and Google Android operating systems are also vulnerable, they said.  An O2 spokesperson said the patch would be available Saturday through iTunes. "We will be communicating to... Read more...

Six Essential Apple iPhone Security Tips

If you're an Apple iPhone user and security's not on your mind, you're at risk; at risk of having a Web mail account hacked; at risk of having your online identity stolen; and at risk of losing valuable personal information, such as wireless service account data, that could result in financial losses, among other disasters. When it comes to mobile devices, security tops the list of IT security managers' concerns. And rightly so: According to a Computing Technology Industry Association (CompTIA)... Read more...

Best Buy to offer Apple's iPhone 3G S with insurance

Best Buy to offer Apple's iPhone 3G S with insurance Those who want added protection for their new iPhone 3G S units on launch day will have the option of queuing up at Best Buy to purchase both Apple's device as well as a rare accident insurance plan, albeit one which may cost almost as much as the phone itself. Best Buy stores nationwide next friday will begin selling the next-generation Apple handset on launch day, albeit at the big-box retailer's usual 10 a.m. opening... Read more...

Be careful what you write: iPhone OS 3.0 doesn’t fully delete e-mails (Video)

Maybe you're trying to delete any persistent virtual sweet Nothings an old romance, or perhaps you are trying to remove all signs of top-secret government work, whatever the case, you probably expect email eliminated remain eliminated. That's just not the case with the current iPhone OS.   A colleague with the name of Matt Janssen was looking for something in iPhone OS 3.0 through 's new search homescreen, when he noticed that some of the results should not be there. Sure, that were... Read more...

Keep iPhone within acceptable temperatures

Learn about the operating temperatures and temperature management of iPhone 3G and iPhone 3GS.   Operate iPhone 3G and iPhone 3GS in a place where the temperature is between 0º and 35º C (32º to 95º F). Low- or high-temperature conditions might temporarily shorten battery life or cause the device to temporarily stop working properly. Store iPhone 3G and iPhone 3GS in a place where the temperature is between -20º and 45º C (-4º to 113º F). Don’t leave the device in your car,... Read more...

Eight easy steps to iPhone security

As someone who's been around the block a few times with mobile technology, I get a kick out of lengthy treatises on the practices one should follow to keep the information on your iPhone secure. They follow a commonsense pattern: Use a PIN, set the device to auto-lock after a minimal delay, set it to blank itself after a limited number of invalid unlock attempts, block access to the App Store, use Safari's security defaults, and use WPA2 security for Wi-Fi. This is helpful, but it isn't... Read more...



What is your favorite Apple product?
 

Now online: