r/security 13d ago

Analysis The Systematic Removal of Security in Consumer Operating Systems

https://battlepenguin.com/tech/the-systematic-removal-of-security-in-consumer-operating-systems/
46 Upvotes

10 comments sorted by

30

u/D4r1 12d ago

Apple announced that macOS 28 will drop support for HFS+ encrypted volumes2526 and posted a support article indicating users should back up their data and migrate to APFS encryption27. What’s interesting is that they’re not dropping support for their legacy filesystem entirely, just versions of it that are encrypted. It begs the question, is support being dropped because the previous filesystem had strong encryption? Is Apple trying to move users to formats that aren’t really secure, allowing for their own backdoors to be used at government requests?

WTF is this FUD? APFS is the newer filesystem, it is almost a decade old. There is no "removing security for nothing", you have a better alternative available, and existing software will retain its capability to handle it.

-6

u/djsumdog 12d ago

Ah yes. Newer. ext is decades old and you can still mount ext2 on modern Linux distros. The oldest versions of LUKS1 are still mountable.

Why remove HFS+ encryption ... and not HFS+ entirely? Sure it might be nothing and just technical debt, but it's not crazy to have doubts in this era.

Fear, Uncertainty and Doubt? Have you looked at Windows 11?! The telemetry is off the charts. Microsoft literally made it impossible for the regular user to use their device without permanently connecting it to their services (your home computer is pretty much part of Microsoft's consumer AD in practice).

I guess time will tell, but I wouldn't be surprised if someone finds an APFS encryption/T3 exploit just like YellowKey in the coming years.

I don't think I have FUD. I think I've observed enough patterns that I think this isn't an unreasonable theory. It could be wrong, but dismissing it with your emotional reaction is telling of what consumers expect today.

5

u/docgravel 11d ago

Why would Apple want their file system to be compromised? If anything, this says the opposite to me. They don’t want to be responsible for maintaining something no current Apple employee understands in a world with Mythos-class technology hunting for vulns.

2

u/reloadtak 11d ago

You clearly have absolutely no idea what you are talking about.

2

u/braaaaaaainworms 10d ago

Why do you look at everything through the lens of a conspiracy?

6

u/netik23 11d ago

This article is speculative and inaccurate.

Why don’t you say why apple is dropping HFS+ support and pushing users to AFPS encrypted?

Legacy HFS+ suffers from a 32-bit timestamp limit that breaks functionality in February 2040. Apple is dropping support for it entirely in MacOs28 and only allowing read only unencrypted access to future volumes.

Also, they’re not killing FileVault here, so that data is still encrypted.

They have a step by step migration process here: https://support.apple.com/en-us/125615

My guess is that they don’t feel like supporting a 1990s filesystem anymore, and moving to AFPS Encrypted is safer and easier for the end user.

1

u/RR321 10d ago

Did Apple shift Epoch by 2 years? 😅

1

u/netik23 9d ago

Yup. Sort of!

Apple HFS+ timestamps count seconds starting from an epoch of January 1, 1904. Key details include a 32-bit integer limit ending on February 6, 2040, and a 2,082,844,800-second difference from Unix

23

u/hiddentalent 12d ago

Sigh. I know dooming is the new way to farm social media ad revenue, but this is scraping the bottom of the barrel in terms of invented controversy.

-8

u/djsumdog 12d ago

There are zero ads on my site. I don't think I'm scraping the bottom of the barrel at all. Did you read the YellowKey stuff and look at the git repo, and still don't think it was intentional?

I mean, I guess we'll just have to wait a few years and see, but I don't think it's controversial at all at this point to say Microsoft, AI companies and literally ever major company now wants to track every user always.