Stallman calls autoupdates a "universal backdoor".
Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.
41–50 of 465 posts
Stallman calls autoupdates a "universal backdoor".
Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.
Earlier quoted context omitted.
Apple does not let you back out an update you made and regret. Apple does not block apps from using the network or give you any way to find out what they are doing and who they are talking to. In fact, apple does the opposite - it blocks apps that let you firewall your phone.
Applications like Charles [1] allow you monitor network connections and data closely. Apple do not actively prevent this. You can also setup a VPN to route traffic and strictly firewall. [1] https://www.charlesproxy.com
Stallman calls autoupdates a "universal backdoor".
He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?
Stallman calls autoupdates a "universal backdoor".
Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.
Earlier quoted context omitted.
The short answer is "when the benefits outweigh the risks"; i.e. if there's a huge bugfix or new feature you need, but something like a barcode scanner is something whose change frequency should be very close to zero. The "update culture" has unfortunately trained users to obediently "bend over and take it", which is horrible from both the security and change-management point of view; but is the dream of those who wa…
Your dogmatic approach to updating would prevent you from installing a version _without_ malware attached. For example, a version of Xcode circulated in China was infected with malware and once Apple had detected it, they asked all developers to recompile and update their apps immediately. https://www.zdnet.com/article/how-malware-finally-infected-a... With your attitude, you wouldn't have necessarily seen the effica…
Ior example, had there not been the exploit risk, I would have left Chrome at the older version, as their new tabgroup implementation is horrible, and it doesn't even allow you to open a new tab without creating a group or going incognito!
Earlier quoted context omitted.
I wonder if there's a coordinated effort to exploit barcode reader apps, because (at least where I'm from) its becoming a government mandated Covid tracing thing to use a QR code to "check in" to certain classes of businesses/venues? I bet there's a _huge_ increase in use of QR code scanning apps compared to this the last year...
Its kind of amazing that there isnt an official qr code scanner app preinstalled on phones given how ubiquitous QR codes are.
I've side loaded LineageOS into a few old old Android devices, Galaxy S3 and S4s, but my S6Edge is still running the Android7 OS it has when Samsung abandoned it. My similar vintage 2015 iPhones 6S is running fully current iOS14 - but it is the oldest Apple device that'll run it. (To be fair, my Samsung S3 vintage iPhone 5 can't run anything newer that iOS10.3).
When the Apple App Store contained malware compiled by unsuspected Chinese developers using a local cache of Xcode [1], Apple emailed the developers to prompt them to update their application immediately and removed them from sale. Apple also contacted users directly to alert them of whatever apps they had purchased on the App Store were compromised so they could monitor for updates, or remove the app entirely. Has G…
Earlier quoted context omitted.
Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.
But if you were slow updating you could avoid a malware once it was known.
Apple’s (often critical) review process for app updates is shining right now! Edit: /s
Stallman calls autoupdates a "universal backdoor".