The Talk Show with John Gruber
The Talk Show with John Gruber

351: ‘Here You Go, Cheapskate’, With Rene Ritchie

Rene Ritchie returns to the show for more on Apple’s announcements from WWDC 2022, locking devices out of Face ID and Touch ID, passkeys, and more.

Featured Speakers

John Gruber Host

Topics Discussed

Episode Summary

Executive Summary: The conversation spans WWDC logistics, practical iPhone/Mac security steps, Apple’s new Passkeys system, privacy implications after Roe v. Wade, and criticism of the M2 MacBook Pro’s base-storage performance. The speakers repeatedly stress threat modeling: match security choices to real risks, keep checklists, and understand the trade-offs between recoverability, convenience, and end-to-end encryption.

Main Topics: WWDC logistics and COVID precautions (Priority: 3/5): The speakers recap arriving in rainy Cupertino, Apple’s mostly improvised bad-weather plan, the outdoor keynote setup, and the company’s COVID screening process, including daily negative-test uploads and masks/sunscreen in event bags. How to hard-lock an iPhone for privacy and safety (Priority: 5/5): A detailed walkthrough explains how to force iPhone into a passcode-only state, why it matters for police encounters, border crossings, theft, or protests, and how it differs from simply locking the screen. Hard-locking Macs and Apple Watch complications (Priority: 5/5): The discussion expands the same idea to MacBooks, including shutdown versus Touch ID lockout, risks from Apple Watch auto-unlock, and why travel/security checklists should include device states before checkpoints. Passkeys as the future of authentication (Priority: 5/5): The speakers explain passkeys as public/private-key authentication that removes passwords, reduces phishing and SIM-swap risk, and works cross-platform through major vendors and password managers. iCloud, health data, and post-Roe privacy concerns (Priority: 5/5): They examine how iCloud backups and Health data are protected, when they are end-to-end encrypted, how two-factor authentication changes the security model, and why reproductive-health data deserves special caution now. M2 MacBook Pro storage controversy (Priority: 4/5): They analyze reports that the 256GB M2 13-inch MacBook Pro uses a single NAND chip, reducing I/O versus M1 models with dual chips, while arguing the headline is misleading because the issue is limited to the base configuration.

Key Arguments: Apple’s outdoor WWDC setup and COVID procedures were imperfect but effective enough that no outbreak was observed among attendees. Users should know how to put an iPhone into passcode-only mode because Face ID/Touch ID can be compelled, while passcodes are legally protected in the U.S. The iPhone hard-lock gesture is valuable because it can be done discreetly in a pocket or bag, before a checkpoint or confrontation. Mac security is more awkward than iPhone security because Touch ID, Apple Watch unlock, and shutdown costs make a true hard-lock less convenient. Passkeys are a major security advance because the private key never leaves the device, eliminating password reuse, phishing, and many 2FA/SMS weaknesses. Threat modeling matters: most people are more likely to lose access to data than to be targeted by sophisticated attackers, so security and backup strategies must balance protection with recoverability. Apple’s iCloud Health data is end-to-end encrypted only when the account uses two-factor authentication; without 2FA, it falls back to less-protected iCloud backup behavior. The M2 13-inch MacBook Pro storage criticism is real for the 256GB configuration, but headline coverage overstates the problem by implying all M2 models are affected. Apple and the broader tech press should apply the same deep component testing to non-Apple PCs and phones to avoid double standards. The best operational-security habit is a personal checklist for travel and sensitive situations rather than relying on memory. The new Apple Watch/Mac/iPhone ecosystem creates convenience but also new attack surfaces, so users should decide whether to keep the watch on during travel or disable related features. Optional end-to-end encrypted backups would improve privacy but would also make recovery much harder, which is why Apple has historically prioritized account recovery support. Data Points: WWDC test cadence: every 24 hours - Media attendees had to upload a negative COVID test daily; the system rejected some submissions until the next day’s upload. Keynote weather timing: within 40 minutes / 8 hours - A joke was made that if rain had arrived 40 minutes later or 8 hours earlier, Apple’s keynote plan would have changed significantly. Apple sunscreen bag item: Kiehl’s sunscreen - Apple included premium sunscreen and hats in attendee bags to mitigate the strong Cupertino sun. Apple Watch/Mac unlock risk: Apple Watch auto-unlock enabled - The speaker notes that an Apple Watch could defeat attempts to lock a Touch ID Mac if auto-unlock remains active. Passkey cryptography: public/private key pair - The Passkeys explanation centers on a device-held private key and server-held public key used to sign a challenge. Two-factor requirement for Health data: required - iCloud Health sync is end-to-end encrypted only when iCloud account 2FA is enabled. Texas bounty law: $10,000 - The discussion references Texas’s reported bounty for people who report illegal abortions, intensifying concern over health-data privacy. M2 base storage speed: about half the performance of M1 base model - The 256GB M2 13-inch MacBook Pro uses a single NAND chip, reducing parallelism and I/O speed. M2 MacBook Air base price: $1,200 - The base M2 MacBook Air starts at $1,200 with 256GB storage and an 8-core GPU. M2 13-inch MacBook Pro base price: $1,299 - The 13-inch M2 MacBook Pro starts at $1,299, with the 512GB upgrade bringing the faster storage configuration. MacBook Air 512GB upgrade: $1,500 - Upgrading the M2 MacBook Air from 256GB to 512GB also brings the faster dual-chip storage configuration.

Pivotal Quotes: "Let's hope it doesn't rain." — Speaker discussing Apple WWDC logistics: Apple’s supposed backup plan for rainy keynote weather in Cupertino was essentially no plan at all. "The police can force you to use Face ID and Touch ID, but cannot force you to reveal your passcode." — John Gruber: Explaining why hard-locking an iPhone matters for privacy and legal protection. "Passkeys are a great new authentication system because the private key is only on your device, only in your device, locked down behind biometrics or a password or a passcode." — Renee Ritchie: Summarizing the core security advantage of the new Apple passkey model.

Implications: Listeners should adopt a device-lock checklist, treat health and backup settings as threat-model decisions, and be skeptical of sensational hardware headlines. Passkeys and better privacy defaults are the future, but recovery and convenience will remain the key trade-offs.

🔓 Sign Up for Unlimited Episode Search

About The Talk Show with John Gruber

The director’s commentary track for Daring Fireball. Long digressions on Apple, technology, design, movies, and more.

View all episodes from The Talk Show with John Gruber