logoalt Hacker News

theshrike79yesterday at 7:52 PM1 replyview on HN

If they're not "hand-selected", what would be the way to select the auditors?

Just have an open house for anyone interested to come poke the hardware and software?


Replies

bigyabaiyesterday at 9:04 PM

Have a set of clearly-defined requirements that doesn't randomly reject valid candidates? Nobody wants another opaque system like the App Store review process.

By the sound of it, Apple's offered audit doesn't include insight into the most dangerous parts of a system like this. This could easily lead to a situation where real security experts are denied access to promote influencer-adjacent Yes Men who rubberstamp the hashes matching without any question.

Hence my concern for "SSL added and removed here" - none of Google's famously backdoored infrastructure will be audited. For privacy purposes, Apple's promise is woefully incomplete.

show 2 replies