Fines and green washing are budgeted and only a small fractions of the profit they make by misbehaving.
On this very site you can read regularly people telling you we should forget about the MS of the past because now they are good guys. So they can get away with corruption, sabotage, monopoly abuse, insulting the competition, stealing, lying, patent trolling, etc. No problem. Bill Gates is a wonderful person and a great philanthropist nowadays.
The corporations and billionaires have found the recipe to get away with everything. The humans were always hackable.
However, when an unauthorized or unofficial button is used as a replacement for repair, the phone will permanently brick itself. No warning is given that the fingerprint scanner's trustworthiness can not be verified, no ability to just use the phone with the fingerprint scanner disabled. Just straight to a permanent bricking.
You don’t want phones to work if someone swaps out that specific piece of hardware without your knowledge. Bricking the phone forever makes it harder for people to find back doors around that security feature as they would risk large numbers of expensive phones. Presumably people developing replacement fingerprint readers would notice the issue before most customers where harmed. Further, anyone actually harmed would have gotten hardware from an very untrustworthy source.
They reversed course after a backlash, but I can see an argument for them standing their ground on this one.
If a compromised scanner fails to authenticate, then the security chip can just ignore the scanner. Not much it can do if its only avenue of communication is cut off. A warning message telling users to not touch their compromised fingerprint scanner would have been sufficient.
Circa 2010-15, the iphone home button was having more and more problem: https://osxdaily.com/2011/12/22/iphone-home-button-not-worki...
For a while, half the users were just using a software button as a workaround: https://osxdaily.com/2012/07/02/broken-iphone-home-button-as...
It was funny to see everyone with a very expensive phone just moving around this fake button everywhere on their screen because their physical button was not working.
But then people stopped finding it funny.
Because Apple said it was a hardware problem, and said the fix was to buy the next iphone generation.
However, a few weeks later, jailbreak iphone received a patch from the community fixing the home button problem, showing not only that it was a software issue that was easy to fix, but Apple just conned their entire customer base.
I haven't bought a single Sony product since the rootkit fiasco, but I've never been able to tell them this directly. I don't buy products with DRM in them. I just don't. I'm not going to be appearing in the balance sheet, however, and won't appear in the calculus of lost growth for an MBA.
The only time I think boycotts do work is when they cause a direct negative action to a company's bottom line that is sufficiently obvious that an accountant can see it. Long, slow protests -- such as exist against Nestlé for example -- are worthy but likely for the birds.
They sold atleast one less PS3. I caved and let my kid get a 4 and 5 when they came out. But he's gotta keep them at his mother's house.
Everyone knew how dangerous it was, changing digits, but it was left in the standard and in many implementations.
Years and years later, someone implements a turing machine using it, hacks journalist's iPhones, and the question is: why did modern systems implement it?
Just searched for some details, it's amazing, all this inside of a JBIG2 image:
"Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations."
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
The format has a lossless mode that would have saved Xerox a lot of trouble, of course it was just that mode that was used to hack the iPhones.
Also for many texts you don't need every digit to be correct, hell any single typo, smudge or bad font can fuck you over if that is the case, no need for a Xerox. Ideally your numbers either include a checksum or have some other redundancy, like requiring that they are written out as words.
So theoretically, everyone who archived during that time using Xerox WorkCentres has to question their documents.
PS: In order to have learned anything from this, there should be a rule for the digitization of archives containing core documents to use (at least) two unrelated scanning technologies, with unrelated processors and unrelated software from different sources (much like Airbus does it with flight computers). A sole, single scan should attribute to nothing.
But what do you do in case of conflict? There's no way of resolving it, so for this type of thing to be more effective, you'd need 3 different scans, and a quorum of 2 to decide the real version.
My original comment was more aimed at the point that damage would need to be admitted. But they did admit it, which makes it evermore confusing why nothing really happened after that, at least publicly.
I don't think that TMR or similar overhead would be practical. Just ban compression algorithms that do pattern matching and substitution for archival purposes (like the German BSI did).
That's not much less than a sole, single repository of paper documents that may not be climate controlled or fire protected (or the fire protection may be sprinklers which will ruin most of the documents anyway).
Document digitalization is a cost saving program, but it doesn't save money if you need to have two vendors, validate the vendors are actually separate and remain actually separate, have a comparison process and an exception process. If the requirements are too high, paper remains and nobody uses the documents because the retrieval costs in labor and time are too high.
* the OCRmyPDF docs point to the JBIG2 Wikipedia page, and the Disadvantages section - https://en.wikipedia.org/wiki/JBIG2#Disadvantages - so it's easier to avoid this bug
* I'd hoped OCR would fall out of the process, but nope
* from the Wikipedia page, huh, the Pegasus malware exploited iOS's implementation of JBIG2
Expect, in Samsung's case, some user love this.
This finding did completely invalidate the financial book keeping and backup of tax records of many companies.
I sure hope nobody uses the Samsung camera app to file their taxes and keep their books...
A lot of people take a photo of receipts for their records.
xerox use image snippets from same document, samsung use something the their "AI" made up. Both of them are trying to be smart and replace stuffs with something "similar"
https://news.ycombinator.com/item?id=34815391 - "Xerox copier flaw changes numbers in scanned docs (2013)" (theregister.com), 36 points, 3 months ago, 8 comments
https://news.ycombinator.com/item?id=32537073 - "JBIG2 Undetectable Data Corruption: Destroying Our Past, One Character at a Time" (circuitousroot.com), 67 points, 9 months ago, 34 comments
Somehow there are not really consequences on this. So either archiving stuff, at least in the business context, is not really important. Or we simply trust these copies. The latter one is of course scary.
https://hn.algolia.com/?query=Xerox%20scanners%20randomly%20...
Edit: oops, 2013 - typed on my smartphone without reading back :)
I think you mean 2013 :-)