[HN Gopher] Why does iPhone 13 screen replacement disable Face ID
       ___________________________________________________________________
        
       Why does iPhone 13 screen replacement disable Face ID
        
       Author : judge2020
       Score  : 49 points
       Date   : 2021-10-02 19:16 UTC (3 hours ago)
        
 (HTM) web link (icorrect.co.uk)
 (TXT) w3m dump (icorrect.co.uk)
        
       | whoknowswhat11 wrote:
       | Just realize - if we let folks writing click bait headlines
       | control us, the technically quality will (usually) go into the
       | toilet. Site guidelines suggest not criticizing websites tech -
       | but do click through on your iphone to experience the enlightened
       | nature of current web design.
       | 
       | I'm reminded of the anti-tracking articles on news sites LOADED
       | with like 15 DIFFERENT trackers :)
       | 
       | Separatly, isn't this an obvious security feature, especially
       | with I thought in display touch or face ID coming?
       | 
       | Though it's not clear why an apple authorized replacement would
       | need to be distrusted, I'd imagine mostly third party shops would
       | be on distrust list.
       | 
       | Apple does need to fix their imessage security disaster though
       | first.
        
         | vbezhenar wrote:
         | > Just realize - if we let folks writing click bait headlines
         | control us, the technically quality will (usually) go into the
         | toilet. Site guidelines suggest not criticizing websites tech -
         | but do click through on your iphone to experience the
         | enlightened nature of current web design.
         | 
         | Actually I like this scroll on desktop with mouse. Now I want
         | it in my browser as native, LoL.
         | 
         | I agree that it's horrible on phone and probably horrible on
         | macbook with touchpad scrolling.
        
           | DaiPlusPlus wrote:
           | Most browsers have a "Smooth scrolling" option. Have you
           | tried toggling that?
           | 
           | I use a desktop. With a very expensive and ergonomic mouse
           | with a notched wheel (as opposed to a free-spinning wheel).
           | One notch - Scroll 3 lines instantly. No delay. No lag. No
           | animation. The way it should be.
        
             | vbezhenar wrote:
             | I found that feature in chrome://flags and enabled it. It
             | did not make any effect. There are some extensions, but I
             | don't really trust extensions so probably I won't use
             | those.
             | 
             | Scroll animation is what I liked on this website. My
             | browser does not have any noticeable animation when I
             | scroll, it just instantly moves page where I drag
             | scrollbar.
        
       | phantomread wrote:
       | If you're on an i-device then reader view in safari (or other
       | browsers) works well to get around the scrolling issue. Ditto for
       | Android.
        
       | judge2020 wrote:
       | Here's an outline link since it has broken scrolling and seems to
       | be loading slow https://outline.com/7p3F9U
       | 
       | > Further forward to the present moment and the iPhone 13's
       | screen IC now not only acts as a ADC, enables True Tone, carries
       | a ROM for the non-genuine message but also now communicates with
       | Face ID. We believe this communication with Face ID is a bug in
       | iOS15. But it shows us a glimpse of how much more complex the
       | screen IC is going to be in the future. We expect the next
       | generations of iPhone to contain 2 biometrics in Face ID & in
       | screen Touch ID.
        
       | 1-6 wrote:
       | Getting to the real question: How does this site override my
       | iPhone's default kinetic scrolling speed?
        
         | marcosscriven wrote:
         | And why does whoever did that think it was a good idea?
        
         | [deleted]
        
         | MBCook wrote:
         | Oh wow you aren't kidding. That's terrible. Why would anyone do
         | that?
        
           | kecupochren wrote:
           | Usually devs primarily running Windows who want to have
           | smooth scrolling. They often don't disable it for MacOS
           | because they don't know it has its own thing.
           | 
           | But why does a site aimed on Apple products has it is
           | mindboggling
        
             | [deleted]
        
           | aaaaaaaaaaab wrote:
           | >Why would anyone do that?
           | 
           | This is a question that can be asked about 9 out of 10 web
           | "technologies".
        
         | gambiting wrote:
         | It's broken on Android as well in Chrome. It's horrendous.
         | Just....why. Leave the default scroll as-is.
        
         | echelon wrote:
         | https://news.ycombinator.com/newsguidelines.html
         | 
         | > Please don't complain about website formatting, back-button
         | breakage, and similar annoyances. They're too common to be
         | interesting. Exception: when the author is present. Then
         | friendly feedback might be helpful.
        
           | imwillofficial wrote:
           | I believe this doesn't apply, because the complaint, and
           | subsequent explanation isn't common, and was interesting.
        
             | echelon wrote:
             | 11 out of 13 of the comments on this post are about the
             | scrolling behavior rather than the substantive content of
             | the article.
             | 
             | I'd say this is a problem.
        
             | detaro wrote:
             | broken scrolling is absolutely a common complaint. (maybe
             | slightly less so today since devs have started to learn to
             | not do it)
        
         | lol768 wrote:
         | They have some custom JS which hijacks the scroll event and
         | manually applies a "transform: translate3d" CSS rule with its
         | own linear interpretation / velocity / acceleration logic..
        
           | 1-6 wrote:
           | That could really trip someone. It may be even possible to
           | reverse the scroll! I'm surprised that Apple doesn't block
           | this behavior.
        
       | sneak wrote:
       | The Apple Inc quest to generate and endlessly increase services
       | revenue is the literal cancer that is killing Apple's former 30+
       | year obsession with customer delight.
       | 
       | A brand new $1500 iPhone Pro will try to hustle you with ads for
       | $2/mo or something for cloud storage upgrades.
       | 
       | It it's not just cloud, too, but also repair, and 10x industry
       | standard charges for CC processing in the App Store, and now the
       | credit card, and more iCloud and TV and arcade subscription plans
       | and options.
       | 
       | It's super gross and lame.
        
       | sedatk wrote:
       | I stopped reading the article because scroll hijacking made it
       | unbearable.
        
         | ObamaBinSpying wrote:
         | I stopped ready at "504 Gateway Time-out"
        
       | xondono wrote:
       | A lot of people are claiming this is about screwing with third
       | party, but there's a lot of good technical reasons to do things
       | like that.
       | 
       | For instance, the serialization of batteries (they're not only
       | serialized, they have a symmetric key pair) is a key safety
       | feature.
       | 
       | I've designed devices with the same ICs and screwing up the
       | configuration (or copy pasting the config and install cells with
       | different chemistry) can set them on fire.
       | 
       | In the case of the screen, I think it's much of a security issue.
        
         | josephcsible wrote:
         | Under what circumstances exactly would it be a safety or
         | security issue to replace one genuine OEM part with another
         | genuine OEM part, identical in all ways except for the serial
         | number?
        
           | theranger wrote:
           | It would not be a safety issue indeed only until the
           | replacement part includes some mitm hardware that tampers the
           | face id authentication flow. And this can be planted into the
           | genuine looking replacement part as well.
        
             | josephcsible wrote:
             | I expect that at least one of these things would have to be
             | true:
             | 
             | 1. The MITM hardware could be installed into the screen
             | that's already paired with the iPhone, so the serial check
             | wouldn't help
             | 
             | 2. The MITM hardware would make the screen look non-genuine
             | regardless of serial, so the serial check wouldn't be
             | needed
        
           | loopback_device wrote:
           | Perhaps to prevent (or at least make it harder for) someone
           | shorting around the security it is supposed to provide, i.e.
           | by emulating or modifying the replacement part - not that
           | that'd really stop the determined ones
        
           | Zak wrote:
           | It's a safety issue to replace some, but not all of the cells
           | in a Li-ion battery with cells that are not the same age and
           | condition. Since smartphone batteries are almost always a
           | single cell, it's a non-issue.
           | 
           | Another scenario I can imagine is a charge controller
           | reducing the maximum charging current as the battery ages
           | based on information stored in the controller's memory, which
           | would be incorrect if the cell is replaced. Of course, it
           | would be unusual to replace a cell with one in worse
           | condition, so it would also be surprising for that to be a
           | safety concern.
        
             | gambiting wrote:
             | Keep in mind that the check done inside an iPhone doesn't
             | prevent the failure mode you describe. After all the phone
             | only checks the microcontroller attached to the battery,
             | not the actual cells(if that's even possible in any way).
        
               | Zak wrote:
               | > _not the actual cells(if that 's even possible in any
               | way)._
               | 
               | It isn't, but there are some controller circuits that
               | switch off permanently if the voltage falls out of range,
               | making changing cells more difficult.
        
           | xondono wrote:
           | It wouldn't, OEM batteries can be swapped with no issues,
           | it's non-genuine parts what causes issues.
        
             | l4yao wrote:
             | On iPhone 12 and moreso on 13, many genuine OEM parts
             | cannot be swapped by anyone other than those authorized by
             | Apple.
        
               | xondono wrote:
               | AFAIK, that's only the case for the screen, and there's a
               | warning when swapping the rear camera.
        
         | Zak wrote:
         | > _In the case of the screen, I think it's much of a security
         | issue._
         | 
         | I default to skepticism on this sort of explanation, especially
         | when it involves Apple and third-party repair.
         | 
         | Of course, it might be possible to devise a very sophisticated
         | attack using the screen's hardware interface and Face ID as a
         | vector. If the iPhone was a security-hardened specialty device,
         | I might find that to be a valid reason. It isn't; it's a
         | consumer device, and one that's not terribly hard for
         | sophisticated attackers to compromise, e.g.
         | https://www.wired.com/story/apple-imessage-zero-click-hacks/
        
           | gpt5 wrote:
           | The iPhone is one of the most desirable attack target in the
           | world. An attack that can access locked phones is extremely
           | valuable. From the police to spy agencies to totalitarian
           | regimes, everyone would buy your stuff. See NSO.
        
             | fsckboy wrote:
             | if you absolutely don't want your iPhone broken into, don't
             | use FaceID at all; this case of "disables FaceID" in that
             | case would be your best friend.
        
         | baybal2 wrote:
         | > For instance, the serialization of batteries (they're not
         | only serialized, they have a symmetric key pair) is a key
         | safety feature.
         | 
         | Unless Apple itself wasn't opting for crap battery suppliers
        
         | zython wrote:
         | I can see how this can be a safety issue but IIRC even with
         | genuine apple parts faceID stops working :/
         | 
         | so this only concerns 3rd party repair shops or individuals who
         | dont want to pay apple to replace their screen.
        
           | wil421 wrote:
           | Unless the iPhone 13 is different FaceID does work with
           | genuine Apple parts. My wife and I have cracked lots of them.
           | If Apple doesn't have them in stock yet because it's a new
           | phone they will replace the phone. I've done it with and
           | without AppleCare.
        
           | kolbusa wrote:
           | And to add the insult to the injury, the genuine parts are
           | not available, which screws 3rd party repair shops even more.
        
             | MichaelZuo wrote:
             | Surely that's just a temporary thing as production lines
             | fill their launch orders? I imagine the authorized
             | repairers already have stock coming in Oct./Nov.
        
               | kolbusa wrote:
               | Authorized repairers often don't do repairs on component
               | level, and sometimes ship your device to some place else
               | to have the whole assembly replaced. Which is always much
               | more expensive.
        
               | gambiting wrote:
               | The point is that you shouldn't need to be an authorized
               | repairer to purchase a replacement screen from Apple. I
               | don't need to be an official Volvo dealership to purchase
               | any replacement part for my Volvo, as long as I know the
               | part number I can easily buy the OEM part or a
               | replacement and Volvo has no way to stop me.
        
         | kitsunesoba wrote:
         | It also makes it more difficult for thieves to part out stolen
         | devices to work around activation locks, and so in theory is a
         | theft deterrent.
        
           | Nullabillity wrote:
           | You know what else would lessen the demand for stolen donor
           | devices? Actually selling the parts.
        
             | vadfa wrote:
             | You can't compete with the price of a stolen part.
        
               | kitsunesoba wrote:
               | Exactly. Serialization, which enables tracking and
               | blocking of parts from stolen devices, works best
               | alongside making OEM parts readily available at-cost to
               | third party repair services.
        
         | asiachick wrote:
         | > In the case of the screen, I think it's much of a security
         | issue.
         | 
         | logic only a fanboy would dream up. I'm sure the same excuse
         | would be given by fanboys if apple shipped a car and somehow
         | managed to make the windows unreplaceable except by specially
         | signed apple glass.
        
         | donmcronald wrote:
         | > For instance, the serialization of batteries (they're not
         | only serialized, they have a symmetric key pair) is a key
         | safety feature.
         | 
         | That's the messaging from the manufacturers which is a big lie
         | IMO. You can validate keys or signatures and give a warning for
         | non-genuine parts. The only reasons to disable features are to
         | prevent competition and, ultimately, to cheat the customer.
        
           | xondono wrote:
           | It's not.
           | 
           | Modern batteries integrate the charge controller with the
           | cells, this allows to track the cell life and it allows the
           | management of the chemistry.
           | 
           | Even small changes in chemistry require modifications in the
           | charging algorithm. The only real solution for managing that
           | is bundling the algorithm with the cells.
           | 
           | Setting the wrong configuration can definitely blow the cell
           | up, or cause swelling.
           | 
           | Source: I did blow some cells while designing a battery pack
           | for a portable device
        
             | userbinator wrote:
             | Sorry, but that is complete corporate-profit-driven-
             | paranoia BS.
             | 
             | Lithium-ion cells are one of the easiest to charge -
             | there's minimum and maximum voltages, and a maximum charge
             | current. Simply limit charge current to the maximum until
             | the cell reaches its maximum voltage, and then wait for the
             | current to drop until it's nearly 0.
             | 
             | Of course, exceeding those limits at the upper end
             | certainly can result in flames, but it's seriously not that
             | hard to charge a cell. But people like to spew plenty of
             | FUD about "complex algorithms" and the like, because the
             | companies who make the ICs stand to profit from that.
             | 
             | Source: I have also worked in electronics on battery-
             | powered devices.
        
               | aaronbeekay wrote:
               | Yes, it's true that you can implement a pretty simple
               | generic lithium-ion cell charging algorithm that will get
               | the job done for most cells. But that's not a "modern
               | battery pack". If you're trying to eke hundreds or
               | thousands of charge cycles out of cells, implement fast
               | charging, do accurate state of charge estimation under
               | load and in variable thermal conditions --- those things
               | are very difficult to implement generically, and often do
               | have parameters that depend on the specific chemistry
               | being used. Modern devices have to do all of those
               | things.
               | 
               | Yes, TI makes money when people use their battery
               | management ICs with fancy cell monitoring, but I don't
               | see a lack of price pressure on those ICs. If
               | manufacturers could implement the same features with a
               | less complex, less expensive design, why would all of the
               | modern battery systems, even in competitive sectors like
               | consumer/retail electronics, integrate battery monitoring
               | with the cells?
        
             | fantyoon wrote:
             | You used to be able to replace batteries in smartphones.
             | Back then none of these things were issues. Its hard to
             | imagine why they would be now.
        
         | grayhatter wrote:
         | Oh I absolutely think the primary reason for this is an amoral
         | technical reason (please note I said amoral not immoral). But I
         | also think given Apple's aggressive history of trying to fuck
         | with 3rd parties. It would be naive to think that wasn't an
         | important factor in this design decision. Even with the most
         | charitable interpretation, someone knew that this would fuck
         | with third parties, and instead of trying to avoid it. They're
         | going with the solution, again with the most charitable
         | interpretation, appears to look like they're obstructing 3rd
         | party repair.
         | 
         | I pretend to be a security expert on TV; and I fully support
         | the decision to disable face id when there might be a hardware
         | mitm attack. But there's options available to Apple that allow
         | you to have security and 3rd party support.
         | 
         | But they're clearly still making decisions that obviously
         | obstruct user choice. And it's dishonest to pretend otherwise.
         | 
         | ps. I don't think you're being dishonest, you're clearly
         | explaining the rational. My issue generally is the apologists
         | who use these arguments without context, and pretend there's no
         | other options.
        
       | irae wrote:
       | What I am about to say has nothing to do with endorsing Apples
       | decisions. But people in developed countries tend to miss what
       | happen in less favorable places. Two major problems: Robbery and
       | used iPhone scams.
       | 
       | Where I live, I often decide to leave my 12 mini at home because
       | I don't want to be robbed. If I take it, I cannot take it out of
       | my pocket until my destination.
       | 
       | They steal you, if you are lucky that's it. If you are unlucky
       | they hold you at guns point or knifes edge until you remove your
       | iCloud account. Cops can't do much, as they use minors to do the
       | robbery and police can't enter the places they disassemble the
       | iPhones, not even if your FindMy is pointing exactly where it is.
       | Minors caught are released after about 12h of being held and are
       | found doing the same thing next day.
       | 
       | When you want to sell/buy used iPhone, you might also be at risk.
       | You can be robbed trying to sell and you can buy a completely
       | remix of a phone from scrapped parts and non original parts that
       | put together can barely work. People repairing sometimes never
       | had formal training, and it could affect safety.
       | 
       | I wonder if Apple considers this at all. It would be naive to
       | think any of what Apple is doing is intended at developing
       | countries safety, but I can't stop thinking the warnings about
       | non-legitimate parts would maybe help people buying second hand,
       | and there is a very small hope in me that it become less
       | lucrative to steal phones in the future.
        
       | LorenPechtel wrote:
       | It sounds like they are talking about third parties making such a
       | change, not an official Apple repair.
       | 
       | You don't trust hardware that a bad guy got their hands on.
       | Picture a black-hat iPhone repair shop, they're installing
       | replacement screens that appear legit but aren't--now they can
       | defeat the face ID and get into your locked phone.
       | 
       | Low probability? What if it's a government doing it? Seem more
       | likely?
        
         | Nextgrid wrote:
         | A government can just use legislation and threats of punishment
         | to compel the owner to unlock the device. This is already
         | happening in the US.
        
         | sudosysgen wrote:
         | A government or black hat could just buy one of the plethora of
         | exploits and hack any iPhone whenever they want for cheaper
         | than setting up chains of repair stores.
        
       | nikanj wrote:
       | Why use native scrolling with 0MB used when you can implement
       | your own scrolling in JS for mere tens of megabytes?
        
         | deathanatos wrote:
         | ... and now the site is down, too...
         | 
         | (...and now that I'm reading a cached version... does it
         | actually answer the question in the title?)
        
         | aemreunal wrote:
         | Clearly because you can't make scrolling horrible without some
         | JS in there.
        
       | martini333 wrote:
       | What a mess of an article and website.
        
       ___________________________________________________________________
       (page generated 2021-10-02 23:01 UTC)