Live data from Hacker News

Tethered Jailbreaks Are Back

blog.trailofbits.com

81–90 of 122 posts

Re: Tethered Jailbreaks Are Back

#81
post #11

Earlier quoted context omitted.

A jailbroken device allows apps to do things that a non-jailbroken device does not. I maintain my company's in-house mobile app crash reporting system and I had to remove jailbreak checks from our iOS SDK. It turned out that some of the checks were causing crashes themselves due to buggy anti-jailbreak-detection code some jailbroken devices had in place. e.g. checking whether a file could be accessed that normally iO…

Out of interest, why do you care if your users run your application on a jailbroken device? It’s been a question I’ve had for a while..

Same reason as why rooted Android devices get blocked by certain applications. Security for the user's sake. Usually it's financial applications (banking etc.) and stuff with sensitive user information.

Re: Tethered Jailbreaks Are Back

#82
post #11

Earlier quoted context omitted.

A jailbroken device allows apps to do things that a non-jailbroken device does not. I maintain my company's in-house mobile app crash reporting system and I had to remove jailbreak checks from our iOS SDK. It turned out that some of the checks were causing crashes themselves due to buggy anti-jailbreak-detection code some jailbroken devices had in place. e.g. checking whether a file could be accessed that normally iO…

They also get tripped up by Apple internal devices, which as an Apple employee is quite annoying when I get locked out of a financial app.

[deleted]

Re: Tethered Jailbreaks Are Back

#83
post #63

Earlier quoted context omitted.

Well it appears Apple are really working towards user privacy as their main sell where android is locked in with Google Play services so though I do not personally have a preference I do know why some people choose Apple devices.

You can disable Google Play Services on a rooted Android. Besides I'm pretty sure all baseband CPUs have backdoors the carriers can tap into at any time.

I keep hearing this argument, but if I'm buying an Android device I'm still supporting Google and Android. The thing is, I don't want to support them at all.

Re: Tethered Jailbreaks Are Back

#84
post #11

Earlier quoted context omitted.

A jailbroken device allows apps to do things that a non-jailbroken device does not. I maintain my company's in-house mobile app crash reporting system and I had to remove jailbreak checks from our iOS SDK. It turned out that some of the checks were causing crashes themselves due to buggy anti-jailbreak-detection code some jailbroken devices had in place. e.g. checking whether a file could be accessed that normally iO…

Out of interest, why do you care if your users run your application on a jailbroken device? It’s been a question I’ve had for a while..

We don’t care but when a crash occurs we collect diagnostic data that we think will help us narrow down the source of the crash. Sometimes a crash happens only on jailbroken devices in which case we usually don’t spend time on it.

Re: Tethered Jailbreaks Are Back

#85

Honestly, if there's a real security risk, I'm surprised Apple hasn't recalled the phones or offered to repair them. Unpatchable firmware flaws are (or should be) no different from hardware flaws in this respect.

With roughly 1 billion iOS devices in use that might be an expensive recall.

Re: Tethered Jailbreaks Are Back

#86

Honestly, if there's a real security risk, I'm surprised Apple hasn't recalled the phones or offered to repair them. Unpatchable firmware flaws are (or should be) no different from hardware flaws in this respect.

Apple isn’t really known for doing recalls until they absolutely have to

Which makes sense too. If Apple was negligent in the security space and these flaws were common then I would be all for a recall.

But Apple clearly has not been negligent in this space and they really have put forth best effort.

Re: Tethered Jailbreaks Are Back

#87

Earlier quoted context omitted.

Payment plans seem like absolute insanity to me. Everyone I know on one is paying $100+ AUD per month perpetually since as soon as they have paid it off they get a new phone. I have found that it is insanely cheap to just buy last years phone second hand. I picked up a pixel 2 recently for $300 AUD when it was about $1000 the year before.

To everyone their own. I very much respect your approach. But when I'm upgrading I don't want last year's model. My phone is the single most used "possession" in my life and after using one for two years, I like to treat myself.

The thing is if you always sit a year or 2 behind the cutting edge you still get to treat yourself because every upgrade is a huge jump in technology from what you had before. Unless you are comparing yourself to others it really doesn't matter because you still get something better and new to you.

Re: Tethered Jailbreaks Are Back

#88
post #59
post #50

Earlier quoted context omitted.

Most people don't own, they use payment plans

And if a person loses the phone one month into their payment plan they still have to pay for the entire price of the phone. So you take ownership the moment you make an agreement with the company to make payments.

Indeed. To be honest it seems like madness to me that phone contracts don't include some kind of insurance as standard.

I've always bought my phones outright but my girlfriend recently had her phone stolen in London about a month after getting it and you can imagine how painful that was for her.

Re: Tethered Jailbreaks Are Back

#89

Honestly, if there's a real security risk, I'm surprised Apple hasn't recalled the phones or offered to repair them. Unpatchable firmware flaws are (or should be) no different from hardware flaws in this respect.

You're talking about 100s of millions of devices - I can see why Apple would prefer not.

Re: Tethered Jailbreaks Are Back

#90
post #11

Earlier quoted context omitted.

A jailbroken device allows apps to do things that a non-jailbroken device does not. I maintain my company's in-house mobile app crash reporting system and I had to remove jailbreak checks from our iOS SDK. It turned out that some of the checks were causing crashes themselves due to buggy anti-jailbreak-detection code some jailbroken devices had in place. e.g. checking whether a file could be accessed that normally iO…

They also get tripped up by Apple internal devices, which as an Apple employee is quite annoying when I get locked out of a financial app.

I feel like Apple employees shouldn't be using special iPhones for personal use (out of good engineering practice; nothing special.
Post reply on HN