Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

51–60 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#51
post #27

Earlier quoted context omitted.

Or, you know, buy something else. Before the"locked devices, people had the inverse problem: everything was two open ended and complicated, could cripple the system, stuff was open for exploit (much more so than in this case of unpatched vulnerability, viruses were everyday occurence). Techies didn't have this issue, but the general public did (heck, even techies did suffer somewhat). And that might have been OK for…

Give a child an iPad, and they’ll be bombarded with toxic advertising and apps wanting money, money, money. Back in ‘the old days’ (80s+90s), a child with access to a computer was likely to learn something, even if their primary use of it was playing games.

>Give a child an iPad, and they’ll be bombarded with toxic advertising and apps wanting money, money, money.

Every been to the modern web? Or used 90s-00s shareware?

Compared to those, the iPad is advertising and nagging free...

And can be totally free, you don't have to buy (a) adware apps, or (b) games with in-app-purchases.

I only get stuff that's in neither category, which all the best apps are...

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#52
post #43

Earlier quoted context omitted.

Don't forget about Telcos. Your AT&T, Vodafone, Verizon & Co, put an enormous amount of pressure on Apple to limit and protect device unlocking. This is a cat & mouse situation where either party might benefit from tight unlocking controls. For example, MVNOs benefit from manufacturers with flexible and open unlocking policies that make it easy to unlock devices (without approval from the original operator), whereas…

Apple sells plenty of unlocked phones, all you have to do is buy it from Apple. Lock restrictions only come into play if you want the mobile network to subsidize your phone.

Agreed! But a big majority of phones out there, especially in secondary markets to the US like Latin America are locked by default from within the Telcos, and will go though several hands before ending on a shelf or refurbished and sent to the middle east.

Each country has different policies when it comes to unlocking. Locked phones greatly outnumber unlocked ones.

Take Chile, where phones must be legally unlocked by the telco or manufacturer to work WITHIN other operators in the country, but not necessarily abroad.

Buy an "unlocked" phone from a Chilean and you might get stuck with a brick.

The different and complex type of unlocking levels Apple has for its devices (and there are many) are designed to assist the Telco and any countrywide regulatory policies that need to be enforced.

There are many parts to this jigsaw puzzle.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#53
post #48
post #32

Earlier quoted context omitted.

I think locking down a system by default, but offering a way to gain elevated priviledges, while educating and properly warning users before certain actions is better than taking away everyone's control over their own devices, and therefore restricting their freedom.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

Personal freedoms have always had risks, but is it really warranted to take them away in this case and not offer a way to get them back in any shape or form?

Looking at recent Samsung devices, is Google Services Framework really that integral to the security of my device that I must be forbidden from disabling that package? Isn't there an alternative way to achieve a comparable level of security, but without slurping up my personal data?

The consequence of security does not have to be a complete loss of control, nor the inability to prevent in a practical way the collection of our personal data.

Not to mention the whole security argument falls apart when perfectly fine Android devices are left without security updates 2-3 years after purchase.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#54
post #27

Earlier quoted context omitted.

Or, you know, buy something else. Before the"locked devices, people had the inverse problem: everything was two open ended and complicated, could cripple the system, stuff was open for exploit (much more so than in this case of unpatched vulnerability, viruses were everyday occurence). Techies didn't have this issue, but the general public did (heck, even techies did suffer somewhat). And that might have been OK for…

> Whereas you can give a 2-year old an iPad, and they can start using it just fine... That's because this new devices aren't "secure" but severely limited and crippled, you can't do much with them and they are far from actually usable like a computer. By that metric, my old Nokia was even more secured than an iPhone.

>That's because this new devices aren't "secure" but severely limited and crippled, you can't do much with them and they are far from actually usable like a computer.

That's the whole point: for them to not be as open ended and complex as computers, while having the power to run highly feature-full apps.

>By that metric, my old Nokia was even more secured than an iPhone.

It indeed was, and that's the ideal. To make extremely feature full modern smartphones as easy to use and as complexity/trouble-free as appliances...

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#55
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

> general computing Apple does not consider phones devices for general computing and so prioritises stability, power consumption and security over flexibility and the ability to run arbitrary code. I'm happy with that trade-off.

This is such an unfathomably incoherent thought from an individuals perspective that i don't even know where to start.

Could you give your definition of 'general computing'?

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#56
post #48
post #32

Earlier quoted context omitted.

I think locking down a system by default, but offering a way to gain elevated priviledges, while educating and properly warning users before certain actions is better than taking away everyone's control over their own devices, and therefore restricting their freedom.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

> The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

And the problem with a single signature authority, as we're seeing in China, is being murdered by an illicit state, or undergoing active discrimination in many other ways even in most western countries.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#59
post #48
post #32

Earlier quoted context omitted.

I think locking down a system by default, but offering a way to gain elevated priviledges, while educating and properly warning users before certain actions is better than taking away everyone's control over their own devices, and therefore restricting their freedom.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

If people do that, that's on them. So long as the device appropriately warns people, I fail to see how it's the companies problem to baby people who don't know what they're doing. It's their device, if they want to break out, let them.

It's like saying "Why should we have knives? It's only a matter of time until $popular_social_media comes along and tells people to cut off their index fingers and before long there's a significant proportion of users who can't point anymore".

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#60
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for most people. I write iOS software for a living, and even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware. The idea that ROMs from questionable sources make your device safer sounds very stran…

> The idea that ROMs from questionable sources make your device safer sounds very strange to me.

The first step on Android is usually to unlock the device boot loader in order to flash a recovery that will allow to erase partitions and install a tarball of the system. I saw no tutorial suggesting to re-lock the device boot and I bet people rarely do it.

This means anyone can take the device, boot it into recovery, plug it into USB and throw some adb/fastboot commands to do anything they want. Device encryption becomes moot because neither the recovery nor the bootloader can be trusted.

Post reply on HN