← Back to context

Comment by foltik

2 hours ago

Being able to run “custom” code is the default state of computers, and doesn’t require additional effort on the part of the manufacturer. How do you think they got their own code on there? Apple has just not spent effort in the opposite direction to lock it down in this case. That’s not something to celebrate, we should demand it as the bare minimum, ideally via the law.

It literally takes effort to reach Apple's level of platform security while simultaneously having escape hatches designed to allow custom code without compromising the trust in the first-party code. Even simple, arbitrary decisions like having the secure boot state be per-operating-system rather than platform-wide take effort. Keep in mind Apple designed everything from the ground up including the silicon, so they did not just pull a part off the shelf that already can execute any code and then lock it down, they took their already very locked-down iPhone/iPad SoCs and specifically re-engineered the chain of trust to have these escape hatches while preserving the trust in macOS. Very careful engineering and not the "default state" of anything.

There are a lot of shortcuts they could have taken to leave us with less freedom and they did not take those shortcuts. For that, I am grateful.