It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…
Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
131–140 of 182 posts
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#132Earlier quoted context omitted.
Goodness me it gets tiring seeing a post like this every time an article about iOS comes up. It's a legitimate point to make, but it should rather be that we talk about the content of the article rather than bring out the 'Apple's taking our freedom away' soapbox. It inevitably turns into a debate between one side who values personal freedoms but won't be told to buy Android phones widespread safety, security, and pr…
Well there aren't any great alternatives. The state of general computing (as parent puts it) is frustrating, and people talk about it, sometimes by switching from a related topic. It's venting. Are there more productive ways of dealing with this? Maybe; but seemingly part of the frustration is that the average consumer feels powerless. Even your meta-post could be classed as a way to deal with this frustration. And,…
The average consumer could care less. They want to make phone calls, send text messages (over iMessage), surf Facebook, and take back to school pictures of their kids - and they just want it to work.
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#133Earlier quoted context omitted.
I mean... does every single patch need a regression test? If I did free(p); p[i] = 1; and then I fixed it by doing p[i] = 1; free(p); do I really need a regression test to trigger the dumb use-after-free I'd introduced?
I think the answer to your question is not obvious. Here, it would have prevented the problem of Apple. 12 years ago while working on a military project on sun, I have encountered a similar vulnerability caused by a regression https://blog.erratasec.com/2007/02/trivial-remote-solaris-0d... Adding this kind of non regression test is costly, but it protects against source code management mistakes.
You mean the answer could be "yes, every single patch must have a regression test"?
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#134Earlier quoted context omitted.
> You can get a developer account, build and sign your own executables, and run whatever you want on your iPhone. Sure, for an extra $100 every single year. Apple charging money for a feature does not protect users.
If you want to develop applications (or run arbitrary code) on their stack, which they spend billions of dollars developing and maintaining, yes, it will cost you $100/year. Or you can get a free dev account, but the feature set it more limited and signatures are only good for 7 days. Apple charges money for features so that they remain in business to keep making more features, and security updates too. So it is, in…
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#135Earlier quoted context omitted.
Goodness me it gets tiring seeing a post like this every time an article about iOS comes up. It's a legitimate point to make, but it should rather be that we talk about the content of the article rather than bring out the 'Apple's taking our freedom away' soapbox. It inevitably turns into a debate between one side who values personal freedoms but won't be told to buy Android phones widespread safety, security, and pr…
So let me ask, why make this comment? Why reply like this? To shut people's concerns down? There's no value here. There's nothing to be gained. Conversely, sometimes it's OK just to let people complain: without the sentiment, how do you know if people still care?
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#136Earlier quoted context omitted.
I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for most people. I write iOS software for a living, and even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware. The idea that ROMs from questionable sources make your device safer sounds very stran…
I think locking down a system by default, but offering a way to gain elevated priviledges, while educating and properly warning users before certain actions is better than taking away everyone's control over their own devices, and therefore restricting their freedom.
Now what? Millions of users have to wipe and restore their phones or throw them away and buy new ones because someone's app trashed the phone? That would cripple Apple
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#137It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…
> general computing Apple does not consider phones devices for general computing and so prioritises stability, power consumption and security over flexibility and the ability to run arbitrary code. I'm happy with that trade-off.
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#138I've never understood why iOS isn't more like macOS. There aren't really any technical reasons why this couldn't be. It's common for the security argument to be used to justify Apple's practices, but Mac users have been perfectly fine installing third party apps such as Transmit, Adobe Photoshop, or even Google Chrome from outside of Apple's walled garden. I've been using macOS since 2007 and I've never had a virus o…
Market share is an appreciable concern here. Macs haven't been more than 20% of the market for a long time. iPhones are a much larger market share, especially among affluent users. I don't think we'd see any widespread viruses, but there would certainly be a ton of people losing their financial info from their own irresponsibility.
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#139Earlier quoted context omitted.
If you want to develop applications (or run arbitrary code) on their stack, which they spend billions of dollars developing and maintaining, yes, it will cost you $100/year. Or you can get a free dev account, but the feature set it more limited and signatures are only good for 7 days. Apple charges money for features so that they remain in business to keep making more features, and security updates too. So it is, in…
Really? GNU/Linux doesn't thrive on billions and provides a near perfect functional alternative. Darwin/XNU is libre software, so it's a contradiction to make people pay for the right to program.
Demanding all software be free is also demanding the end to freedom. People want iOS to be more open because of the incredible value of iOS. Not because there’s an equivalent free alternative at hand they simply didn’t notice.
> Darwin/XNU is libre software, so it's a contradiction to make people pay for the right to program.
This does not make logical sense? That other free software exists is not an argument that all software must be free. Apple has a business model which increasingly relies on selling services and licenses on iOS over selling new hardware. That’s their choice for how to fund their operations, which I’m very happy that they are free to make!
Being forced to make all my code freely available would be an appalling restriction on my own personal freedom. Not to diminish the brutal history of slavery, but what gives someone the right to free access to my work?
Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak
#140Please excuse the tinfoil hat - is there any chance that this vulnerability was reintroduced at the request of the Chinese government to allow easier access to Hong Kong protesters devices?
no