Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

81–90 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#81
post #68
post #48

Earlier quoted context omitted.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

I think this is a valid concern, and perhaps verifiable. How many Windows user actually create a non-admin account to use for their everyday work? I find, anecdotally, that a helluva lot of them don't; in fact, the very idea is foreign to them.

I'd argue this is largely a question of defaults and ergonomics.

Most users will leave the default settings if they don't have an active need to change them. Easily usable (and understandable) tools and interfaces prevent most needs from arising in the first place.

Concrete example: The root account on many Linux distros is disabled by default. I've never felt the need to enable it, because sudo does everything I need. Secure default, useful tools, unlockable system.

Historically we haven't had either of those things. Poor design and implementation led to bad choices by clueless users. The resulting mess is used as an excuse to restrict freedoms. The cure is arguably worse than the poison.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#82
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone.

I don’t think those flashed ROMs give you appreciably more “control” over your iPhone than stock iOS provides, because actual control requires usable control surfaces. More likely, you are replacing the control surfaces provided by an accountable entity (Apple) who has prioritized your security and privacy and provides a constant stream of updates to maintain that, with what exactly?

The entire iOS feature set is designed to protect your personal data, from outside attackers who would seek to compromise it, to insider threats like apps trying to siphon off more than you might expect, to end-users inadvertently giving away their own (or your) data without a care in the world.

The security that a modern iPhone provides to its owner is truly a remarkable and commendable experience overall. I am extremely happy we as consumers have the choice to purchase exactly such a device.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#83
post #21

Earlier quoted context omitted.

It's fortunate I can buy an iphone for my mum and she hasn't had a single problem with it. On the other hand I bought my dad a laptop with Windows and despite having an antivirus he's had all kinds of problems with it, including some heavy duty adware.

Indeed, I wouldn't suggest anything other than a chromebook for my relatives

You can setup Windows to be secure, just make sure to not give your parents admin accounts. Install the apps they use and give them normal user accounts.

Provide the password for elevation and educate to only type that in when they are installing something they know is secure. Likely they will forget the password and have to check with their "IT helper" anyway, and sanity check there actions then.

I have a Windows 7 machine setup like this for my parents and they have never had a problem with malware. The stuff that lives in the user profile gets caught by AV, and I have to install something for them maybe twice a year.

I would rather put in a little extra work setting up a Windows laptop than send metrics for the entire system to Google. Their Android phones take care of that invasion of privacy.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#85
post #30

Earlier quoted context omitted.

That idea is stupid in itself. The whole of civilization has been a process of shielding people from having to know stuff. The same way you don't know how to make fire from first principles, fix your car, make a CPU, or whatever... Even someone with a Ph.D in computer hardware is shielded from tons of complexities and never has to know the whole process end to end.

But they are allowed to learn, which Apple doesn't want you to do. They could make it so your mom doesn't get root by accident, but you would still have the right to do so.

> They could make it so your mom doesn't get root by accident, but you would still have the right to do so.

How? Serious, genuine question. How can they give you “the right to do so”, but prevent “mom” from accidentally doing so or worse, having someone do it to their phone without them knowing?

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#86
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

I'm not sure Google really belongs here. Telcos and some companies licensing Android - sure. But unlocking actual Google phones, like Pixel, is literally available from the menu in the developer settings. It's a well known/documented process.

It does. Unlocking and gaining elevated privileges through rooting trips Google's SafetyNet API which will lock you out of many apps and/or features. It also breaks your device's Widevine certification so you can't watch DRM-protected video from many services.

As for the "We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent.", with stock Android provided by an OEM, you have no control over the opaque and invasive monolith that is Google Play Services and there's no way to control what data exits your device, aside from installing a VPN-based firewall. You can't even control when apps have access to your data, just a binary on/off switch.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#87

Earlier quoted context omitted.

Indeed, I wouldn't suggest anything other than a chromebook for my relatives

You can setup Windows to be secure, just make sure to not give your parents admin accounts. Install the apps they use and give them normal user accounts. Provide the password for elevation and educate to only type that in when they are installing something they know is secure. Likely they will forget the password and have to check with their "IT helper" anyway, and sanity check there actions then. I have a Windows 7…

You don't need admin access for anything. Without admin privileges I can install new software, sniff your passwords, encrypt your files, participate in a DDoS attack, mine Bitcoin...

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#88
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for most people. I write iOS software for a living, and even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware. The idea that ROMs from questionable sources make your device safer sounds very stran…

>The technological complexity of any smartphone is far beyond comprehension for most people.

The exact same goes for regular computers and operating systems. And we still have those. Shouldn't we at least have the option on mobile?

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#89
post #53

Earlier quoted context omitted.

Personal freedoms have always had risks, but is it really warranted to take them away in this case and not offer a way to get them back in any shape or form? Looking at recent Samsung devices, is Google Services Framework really that integral to the security of my device that I must be forbidden from disabling that package? Isn't there an alternative way to achieve a comparable level of security, but without slurping…

Apple is not taking away personal freedoms. They create products, which they offer for sale. People can freely choose to purchase those products or not. Apple has opinions about how to make products, which are embodied in the products they offer for sale. Other companies have different opinions. This is how a market is supposed to work. I don’t think we should talk about Apple as if they are a government taking away…

I can think of many examples of how Apple victimizes its own customers, though. From soldered on RAM and SSDs to all this spy bullshit, it's a brave new world for regular folks to have to navigate, most of whom are not technically savvy enough to even understand what is going on.

"Other companies have different opinions." Currently, there isn't much choice in the smart phone space. Maybe the Librem phones when those become available, if ever, but nobody is looking out for us, it's all just NSA spy-friendly bullshit 100%.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#90

Please excuse the tinfoil hat - is there any chance that this vulnerability was reintroduced at the request of the Chinese government to allow easier access to Hong Kong protesters devices?

No need for a tinfoil hat or this specific vulnerability. Any number of backdoors can be introduced with any update for any operating system or app. Generally governments around the world want backdoors and information from companies and companies generally comply.

Last time this happened to Apple they fought it tooth-and-nail and at least from what the public knows they were victorious and did not have to add a backdoor.
Post reply on HN