Live data from Hacker News

Google warns about two iOS zero-days 'exploited in the wild'

zdnet.com

61–70 of 89 posts

Re: Google warns about two iOS zero-days 'exploited in the wild'

#61
post #46

Earlier quoted context omitted.

If only Google would hold themselves accountable to the same standard. Android is a gigantic security mess, all caused and enabled by Google.

No it isn't? Android has a bug bounty program: https://www.google.com/about/appsecurity/android-rewards/ and regularly has strong showings at pwn2own. Android's security for the past couple of years has been superb.

Android as an abstract project, yes. Android, as what's actually used by users, it's not that superb.

Google is slowly trying to fix it, but average Android device is way behind average iOS device in the wild, and that will be the case for many years to come.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#62
post #46

Earlier quoted context omitted.

If only Google would hold themselves accountable to the same standard. Android is a gigantic security mess, all caused and enabled by Google.

No it isn't? Android has a bug bounty program: https://www.google.com/about/appsecurity/android-rewards/ and regularly has strong showings at pwn2own. Android's security for the past couple of years has been superb.

It's one thing to release a security patch. It's a different thing to get it installed on user devices. If a user never has an opportunity to install the patch, that patch might as well not exist from that user's standpoint.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#63
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

I don't know about Project Zero in particular, but yes, Google has security teams investigating their own projects. Why would you think otherwise? And if you think there are security holes, you're welcome to report them to get a bug bounty.

I think it might be just harder to find exploits in your own code because of organizational blind spots.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#64
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

If there is bias it would be a good for us all in the end imo. Makes it more likely for Googles competitors like Apple to spin up similar teams and fund them aggressively to find exploits in Google tech like Android.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#65
post #48

Earlier quoted context omitted.

I don't know about Project Zero in particular, but yes, Google has security teams investigating their own projects. Why would you think otherwise? And if you think there are security holes, you're welcome to report them to get a bug bounty.

Well personally I would like it if they had write up's on them, even if only after the fact, as Project Zero has always come across to me as kind of a publicity stunt to try to improve their reputation to the tech industry and show how important they value security when the truth is quite different.

What is the truth in your view?

Re: Google warns about two iOS zero-days 'exploited in the wild'

#66
post #42

Earlier quoted context omitted.

Yeah, it's amazing that this is not called out more often. Android is a security mess.

Anybody can make an android phone and damage the brand. Compare pixels to iphones in pwn2own contests. They are at the very least equivalent.

That covers the 3 million phones a year that Google sells what about the other 1.2 billion plus?

https://www.forbes.com/sites/chuckjones/2018/03/10/apples-io...

Re: Google warns about two iOS zero-days 'exploited in the wild'

#67

Earlier quoted context omitted.

If he bought an Android it's because he doesn't care about the security of his phone. Not trying to be snarky; Android has been around for over 10 years and we all know how irresponsible all OEMs are, including Google. He had the information when he made his purchase.

Or alternately, you buy from Google, keep up with OS upgrades, and plan on buying a new phone every 2-3 years or so. While not ideal, this is certainly doable.

So the only way that you can get an Android phone with any type of security is by buying one from Google.

So much for Andy Rubin and his promise of openness and choices...

Re: Google warns about two iOS zero-days 'exploited in the wild'

#68

Earlier quoted context omitted.

No it isn't? Android has a bug bounty program: https://www.google.com/about/appsecurity/android-rewards/ and regularly has strong showings at pwn2own. Android's security for the past couple of years has been superb.

Android as an abstract project, yes. Android, as what's actually used by users, it's not that superb. Google is slowly trying to fix it, but average Android device is way behind average iOS device in the wild, and that will be the case for many years to come.

> Android, as what's actually used by users, it's not that superb.

It is, though. The Android that's most commonly used by users is the one from Samsung, who also issues monthly security patches for a large range of devices: https://security.samsungmobile.com/workScope.smsb

LG ( https://lgsecurity.lge.com/security_updates.html ) does as well, and so do at least Motorola & Nokia.

> average Android device is way behind average iOS device in the wild, and that will be the case for many years to come.

[citation needed]

Average iOS device just got hit by 2 zero-days in the wild. And jailbreaking is a long and well established practice on iOS, which is literally privilege escalation exploits. There's a constant, continuous stream of those on iOS. There doesn't seem to be many (any?) on Android for a while now.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#69
post #8

Earlier quoted context omitted.

And we don't? I want my phone to be as secure as possible because I use it for work, but of course, since it's not brand new I can't get updates.

That's a symptom of cybersecurity. If a law made a security bug a refundable or warrantied defect, I bet you this shit would stop. But noone gives a shit.

It would also seriously stymie innovation. If I risk having to refund an item when I push out improvements, I'm never bothering to push out improvements except bug fixes.

I'm also incentivized to release a new model every month with ANY improvement in order to limit my liability to a smaller window of revenue.

The current system isn't perfect, but it could be much worse.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#70

Earlier quoted context omitted.

Android as an abstract project, yes. Android, as what's actually used by users, it's not that superb. Google is slowly trying to fix it, but average Android device is way behind average iOS device in the wild, and that will be the case for many years to come.

> Android, as what's actually used by users, it's not that superb. It is, though. The Android that's most commonly used by users is the one from Samsung, who also issues monthly security patches for a large range of devices: https://security.samsungmobile.com/workScope.smsb LG ( https://lgsecurity.lge.com/security_updates.html ) does as well, and so do at least Motorola & Nokia. > average Android device is way behind…

>There doesn't seem to be many (any?) on Android for a while now.

To be fair, there are a variety of reasons why this isn't the case that have nothing to do with security. An Android jailbreak is less valuable for a few reasons, among them that you can often purchase android devices with root privs, the same isn't possible for iphone.

Post reply on HN