Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

61–70 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#61
post #53
post #48

Earlier quoted context omitted.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

Personal freedoms have always had risks, but is it really warranted to take them away in this case and not offer a way to get them back in any shape or form? Looking at recent Samsung devices, is Google Services Framework really that integral to the security of my device that I must be forbidden from disabling that package? Isn't there an alternative way to achieve a comparable level of security, but without slurping…

I think there could be an argument that the personal freedom you mention, when risks are realized, can degrade the experience of the world at large. Lazy example: a botnet running on many machines compromised as described above sending spam email to innocents.

I’m still on the fence about whether that justifies their protocols. I think I actually lean toward “no”, but I’ve also lately become keenly aware of the difficulty of even simple things like keeping everything up to date, and my lack of real insight into what those updates include. If I’m effectively trusting them anyway, might as well trust them to get it to me ASAP, right?

I’m also enough of a realist to assume there’s a Fight Club style “A times B times C > X” reputational/financial risk logic going on here. If there’s few enough of the devices out there, it’s probably cheaper to apologize (legally, as in settle).

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#62
post #21
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

It's fortunate I can buy an iphone for my mum and she hasn't had a single problem with it. On the other hand I bought my dad a laptop with Windows and despite having an antivirus he's had all kinds of problems with it, including some heavy duty adware.

Indeed, I wouldn't suggest anything other than a chromebook for my relatives

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#63

Please excuse the tinfoil hat - is there any chance that this vulnerability was reintroduced at the request of the Chinese government to allow easier access to Hong Kong protesters devices?

No need for a tinfoil hat or this specific vulnerability.

Any number of backdoors can be introduced with any update for any operating system or app. Generally governments around the world want backdoors and information from companies and companies generally comply.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#64
post #8
post #2

>A third security researcher, Stefan Esser said that people should be careful what apps they download from the App Store right now. "Any such app could have a copy of the jailbreak in it," he wrote on Twitter. Seems a bit overblown when there's a review process in place. I'm sure it's not infallible, but still..

Yes, to some extent people should be worried about apps potentially containing exploits, but then again they should be more worried about 0-days than a known vulnerability.

> A zero-day (also known as 0-day) vulnerability is a computer-software vulnerability that is unknown to, or unaddressed by, those who should be interested in mitigating the vulnerability (including the vendor of the target software)[0]

Why should a publicly known unpatched vulnerability be a lesser concern than something that you don't know exists?

[0]https://en.wikipedia.org/wiki/Zero-day_(computing)

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#65
post #49

Earlier quoted context omitted.

> general computing Apple does not consider phones devices for general computing and so prioritises stability, power consumption and security over flexibility and the ability to run arbitrary code. I'm happy with that trade-off.

They clearly consider iPads general purpose computers, so we're back to the starting concern.

I have never thought that Apple considered iPads general purpose computers. One of their biggest ads about the iPad Pro[0] even implicitly states that.

The proposition, in my mind, that Apple is trying to sell with the iPad to the majority of people who use their computers for social media, content consumption, and office tasks like email and Word document authoring is "you don't need general computing flexibility for the vast majority of things that you do".

[0] https://www.youtube.com/watch?v=llZys3xg6sU

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#66
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

I'm not sure Google really belongs here. Telcos and some companies licensing Android - sure. But unlocking actual Google phones, like Pixel, is literally available from the menu in the developer settings. It's a well known/documented process.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#67

Earlier quoted context omitted.

> general computing Apple does not consider phones devices for general computing and so prioritises stability, power consumption and security over flexibility and the ability to run arbitrary code. I'm happy with that trade-off.

This is such an unfathomably incoherent thought from an individuals perspective that i don't even know where to start. Could you give your definition of 'general computing'?

Well, I can run a Turing Machine using javascript on my phone's Safari browser. Do you have another definition of 'general computing' ?

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#68
post #48
post #32

Earlier quoted context omitted.

I think locking down a system by default, but offering a way to gain elevated priviledges, while educating and properly warning users before certain actions is better than taking away everyone's control over their own devices, and therefore restricting their freedom.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

I think this is a valid concern, and perhaps verifiable. How many Windows user actually create a non-admin account to use for their everyday work? I find, anecdotally, that a helluva lot of them don't; in fact, the very idea is foreign to them.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#69
post #52

Earlier quoted context omitted.

Apple sells plenty of unlocked phones, all you have to do is buy it from Apple. Lock restrictions only come into play if you want the mobile network to subsidize your phone.

Agreed! But a big majority of phones out there, especially in secondary markets to the US like Latin America are locked by default from within the Telcos, and will go though several hands before ending on a shelf or refurbished and sent to the middle east. Each country has different policies when it comes to unlocking. Locked phones greatly outnumber unlocked ones. Take Chile, where phones must be legally unlocked by…

Yeah it’s more law related than anything.

Here in the France the telco are compelled by law to fully unlock any phone bound to their network 6 months after the purchase (or earlier if initial contract duration was lower than 6 month).

Apple comply gracefully to this law.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#70
post #25

Earlier quoted context omitted.

I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for most people. I write iOS software for a living, and even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware. The idea that ROMs from questionable sources make your device safer sounds very stran…

> The idea that ROMs from questionable sources make your device safer sounds very strange to me. It's about owning your hardware, not safety. A person that's willing to go through the hassle knows the consequences of such actions and how to deal with them. Do "normal people" need to do that? Absolutely not. Should it be easy to do that? Absolutely not. But for those of us that really want to own our hardware, there s…

I totally agree, but I don't have any good ideas on how to implement that. I'm not even sure if such a barrier should be technological or legal.
Post reply on HN