Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

101–110 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#101
post #95
post #82

Earlier quoted context omitted.

You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. I don’t think those flashed ROMs give you appreciably more “control” over your iPhone than stock iOS provides, because actual control requires usable control surfaces . More likely, you are replacing the control surfaces provided by an accountable entity (Apple) who has prioritized your security and privacy…

The iOS feature set is intended to protect Apple's business model and revenue streams by forcing you to do things in Apple's jail. Getting a developer account is obviously an absurd and impractical approach to distribute software and proposing this is frankly ridiculous. It's not free, requires you own a Mac, and is way beyond the technical abilities of most users.

> requires you own a Mac

I mostly agree with you, but you don't necessarily need a Mac in order to use your developer account for sideloading—you can also use Cydia Impactor which is available for Windows/Linux.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#102
post #25

Earlier quoted context omitted.

> The idea that ROMs from questionable sources make your device safer sounds very strange to me. It's about owning your hardware, not safety. A person that's willing to go through the hassle knows the consequences of such actions and how to deal with them. Do "normal people" need to do that? Absolutely not. Should it be easy to do that? Absolutely not. But for those of us that really want to own our hardware, there s…

I totally agree, but I don't have any good ideas on how to implement that. I'm not even sure if such a barrier should be technological or legal.

Android's option of connecting the device to a computer over USB, running a program on the computer, logging into the device, seeing a scary warning and wiping the device seems to work well. I don't think I've heard of a large number of people being tricked into unlocking their bootloader — at worst, a handful of script kiddies might have been tricked.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#103
post #28
post #20

Earlier quoted context omitted.

There are things I want to control, and there are things I do not want to control. Smartphone is not a "general purpose computer" and I want just use it not to babysit it. And more often than not having "control over your own" device means that is is just some malware that has this control, not the user.

Your smartphone has all the hardware that it needs to be a general purpose computer. If you could plug in a decent screen and connect a mouse and a keyboard it would be more powerful than the computers you used just a few years ago.

So does around twenty things in my household: My TV, my camera, my router, my wifi access point and perhaps a dozen more. Probably 3 or 4 I didn't even realize. That doesn't change the fact that I don't want to know and care about that. They are appliances, meaning I prefer a locked down system if it means they are simpler and more secure.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#104
post #82

Earlier quoted context omitted.

You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. I don’t think those flashed ROMs give you appreciably more “control” over your iPhone than stock iOS provides, because actual control requires usable control surfaces . More likely, you are replacing the control surfaces provided by an accountable entity (Apple) who has prioritized your security and privacy…

> You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. Sure, for an extra $100 every single year. Apple charging money for a feature does not protect users.

That hasn't been the case since 2016, when Apple changed it so the fee is just needed to publish to the App Store.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#105
post #82

Earlier quoted context omitted.

You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. I don’t think those flashed ROMs give you appreciably more “control” over your iPhone than stock iOS provides, because actual control requires usable control surfaces . More likely, you are replacing the control surfaces provided by an accountable entity (Apple) who has prioritized your security and privacy…

> You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. Sure, for an extra $100 every single year. Apple charging money for a feature does not protect users.

If you want to develop applications (or run arbitrary code) on their stack, which they spend billions of dollars developing and maintaining, yes, it will cost you $100/year.

Or you can get a free dev account, but the feature set it more limited and signatures are only good for 7 days.

Apple charges money for features so that they remain in business to keep making more features, and security updates too. So it is, in fact, exactly how they protect users.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#106

Earlier quoted context omitted.

But they are allowed to learn, which Apple doesn't want you to do. They could make it so your mom doesn't get root by accident, but you would still have the right to do so.

> They could make it so your mom doesn't get root by accident, but you would still have the right to do so. How? Serious, genuine question. How can they give you “the right to do so”, but prevent “mom” from accidentally doing so or worse, having someone do it to their phone without them knowing?

Android's bootloader unlock process prevents mom from doing this just fine.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#107

Earlier quoted context omitted.

I'm not sure Google really belongs here. Telcos and some companies licensing Android - sure. But unlocking actual Google phones, like Pixel, is literally available from the menu in the developer settings. It's a well known/documented process.

It does. Unlocking and gaining elevated privileges through rooting trips Google's SafetyNet API which will lock you out of many apps and/or features. It also breaks your device's Widevine certification so you can't watch DRM-protected video from many services. As for the "We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent.", with stock Andro…

Of course it breaks DRM. That's the point.

> with stock Android provided by an OEM, you have no control over the opaque and invasive monolith that is Google Play Services and there's no way to control what data exits your device, aside from installing a VPN-based firewall.

This is true of all systems (and even worse on iOS, which has the same data collection as Play Services but can't be disabled or avoided) and irrelevant to the discussion about whether a user can completely control their device if they wish.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#108
post #82

Earlier quoted context omitted.

You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. I don’t think those flashed ROMs give you appreciably more “control” over your iPhone than stock iOS provides, because actual control requires usable control surfaces . More likely, you are replacing the control surfaces provided by an accountable entity (Apple) who has prioritized your security and privacy…

> You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. Sure, for an extra $100 every single year. Apple charging money for a feature does not protect users.

> Apple charging money for a feature does not protect users.

The $99 is not likely to make them money. It is a token fee to protect the app store from the simplest spam and scam apps.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#109
post #33
post #28

Earlier quoted context omitted.

Your smartphone has all the hardware that it needs to be a general purpose computer. If you could plug in a decent screen and connect a mouse and a keyboard it would be more powerful than the computers you used just a few years ago.

> Your smartphone has all the hardware that it needs to be a general purpose computer. Which is neither here nor there. Parent doesn't mean a smartphone doesn't have the cpu power etc. of being a general purpose computing, he says it is not one.

But it has the capacities to be one if you plugged in peripherals.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#110

Earlier quoted context omitted.

> You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. Sure, for an extra $100 every single year. Apple charging money for a feature does not protect users.

That hasn't been the case since 2016, when Apple changed it so the fee is just needed to publish to the App Store.

No, it's also needed to install a self-made app on my phone for longer than 7 days at a time. That 7 day restriction is far too low to be reasonable for normal use.
Post reply on HN