Live data from Hacker News

iOS 15

apple.com

351–360 of 431 posts

Re: iOS 15

#351
post #256

Apple continues to support OS updates on the iPhone 6s, a device released almost 6 years ago. Nor is it reserved for their flagship models - the 2016 iPhone SE also gets the latest and greatest. Meanwhile, my flagship android phone from 2018, the Samsung Galaxy S9, is stuck on the last version of Android. At least it still gets security updates, some manufacturers don't even go that far.

If in October 2013 you bought a just released Google Nexus 5, you would have had official updates until December 2016. At the end of support, you could have then bought the recent Google Pixel (1). And you would have had official updates until December 2019. A little over 6 years out of two devices is as good as it gets on Android, at least it's as good as it got in the mid-late 2010s. If in October 2013 you bought a…

While I agree completely with the idea, I have trouble deciding how secure the 5S should be considered. I couldn’t find anywhere Apple state the level of support, and it seems to receive some security patches but not others. Did the June update patch all known vulnerabilities at that point? Is it now insecure again since it did not receive a patch for ForcedEntry? The 6S/SE might be better examples? iOS 15 is now available on both.

Re: iOS 15

#352

Earlier quoted context omitted.

That's why the CSAM scanner is on your device . It computes the hashes in place on then unencrypted images before uploading encrypted copies to iCloud. That's why from some perspectives it is a net privacy win versus Google/Microsoft's similar tools that require them to have decryption backdoor keys on their clouds to process these CSAM requests and other FBI/TLA/et al warrants. Apple is saying they don't have backdo…

So, again, how do they review those images? Does Apple have the key to the reporting database?

Yes, that would be why it sends copies, encrypted with a different key to the users' own storage keys.

Re: iOS 15

#353
post #81

Earlier quoted context omitted.

I smashed the iphone I had into pieces, and I'm wondering what to do with my mac. Maybe install some linux or something, but I don't really know much about that! It'll take me a couple months of reading on it.. I am still using Mojave anyways.

That's... overly dramatic.

Will never be as dramatic as spying over hundreds of millions of sheeple!!

Re: iOS 15

#354

Earlier quoted context omitted.

So, again, how do they review those images? Does Apple have the key to the reporting database?

Yes, that would be why it sends copies , encrypted with a different key to the users' own storage keys.

So in other words, the only thing stopping Apple from viewing my iCloud photos is an if statement.

Re: iOS 15

#355

Earlier quoted context omitted.

Okay, so basically they are just sort of pinky-swearing that your iCloud photos are encrypted on iCloud, but not in any way that prevents Apple or the government from decrypting them anyway. This raises the followup question of "why bother scanning the images on-device?", but I can infer two fairly obvious answers. First, the encryption still keeps AWS/Azure/GCP from seeing my photos. Second, and more cynically, they…

> Okay, so basically they are just sort of pinky-swearing that your iCloud photos are encrypted on iCloud, but not in any way that prevents Apple or the government from decrypting them anyway. How do you imagine that Google and Microsoft are able to scan the entire contents of your account? They can all read the data on their servers >This raises the followup question of "why bother scanning the images on-device? Bec…

I’m not arguing with anyone or expressing any opinion.

Re: iOS 15

#356

Earlier quoted context omitted.

But does it really do anything to secure a device that’s past EOL? Or is it a marketing action? Long official support is absolutely a benefit when looking at smartphones, however, articles keep popping up about Apple basically buying and sitting on vulnerabilities for latest and greatest iOS, because that’s what works economically.

What? Yes, Security updates for eol devices is clearly better than doing nothing. Apple’s externally facing vulnerability management program has a bunch of issues but I don’t see how that is relevant

Better for whom? It’s EOL. Are they just plugging high-visibility issues? That’s not doing anything for individual device’s security. They need a giant INSECURE sign instead of giving that false hope for people: “they might patch me past EOL if it’s bad enough”.

Re: iOS 15

#357

Earlier quoted context omitted.

If they get 30 (?) hits then they review the data and then they refer it to law enforcement if the reviewers determine that they were CSAM images. It's not for a single collision and it's not immediately referred to law enforcement. There are still major risks and concerns with this model, but at least describe it correctly.

Why should technology so bad it needs thirty mulligans have the power to completely destroy your life? And exactly how are they obligated to keep those policies? Answer: they aren't. There isn't some law saying '30 hits before we report you', and Apple is certainly going to drop the number as the public gets more used to the idea of CSAM. They'll keep dropping it until the news articles start coming out about how it'…

> so bad it needs thirty mulligans

idk, Hash collisions?

Re: iOS 15

#358

Earlier quoted context omitted.

> misunderstanding/lack of knowledge both about these apps and their privileges. Yet you've been able to present none. According to your claims the zero-click escape that caussed the critical 4.8 security update to be released in the last two weeks isn't possible, and yet it happened. So please, by all means, explain why Apple's apps should be structured like this: https://googleprojectzero.blogspot.com/2020/01/remot…

"Yet you've been able to present none" What am I supposed to present? A complete history of computer science and system design? "isn't possible" Any app on any system, if exploitable, can be used for a chain attack to exploit further vulnerabilities (and 14.8 was a bandaid for just such an attack). That's ignoring that iMessages is also such a high value target for its own data , in the same way that Signal and other…

> What am I supposed to present?

Facts that support your position, like I did. I provided a couple of in-depth articles about the inner workings of iMessage, with specific emphasis on security. You've yet to even explain in technical terms what is erroneous about my critique.

> Any app on any system, if exploitable, can be used for a chain attack to exploit further vulnerabilities.

That isn't how iOS is structured. If it were normal app developers could design their own apps to gain root, but the system is specifically engineered to combat that and has been quite successful. Whereas Apple's own apps have a set of components that run with elevated privileges that allow sideways exploitation to bypass the normal UID sandboxes, and ultimate cause significant escalation including root.

The two articles I linked explain how this occurs. There's nothing akin to the SYSTEM services within normal (non-Apple) apps, therefore your comparison is technically unfounded.

> This is a not useful conversation that I hesitated engaging in at first glance (when someone does the "if only they just waved hand everything would be great" it's founded in dubious logic 100% of the time), so feel free to reply into the ether.

You're backing out of the conversation because you've shown you lack the technical foundation to participate. You assumed at the start that I knew as little as you and therefore we could both make baseless claims without anyone checking either one. The reality is that I understand iOS's internal structure and can provide founded critiques whereas, you lack the technical foundation to mount a defense of the design (and that your original defense is between confusing and just wrong).

Re: iOS 15

#359

> Now you can install Safari extensions on your iPhone Someone knows if uBlock Origin has plans/is able to develop the extension for Safari iOS? For Safari MacOS is kind of not available. Does not work for Safari 13+, and is maintained externally https://github.com/gorhill/uBlock#safari-macos

Most functionality that people use Ublock Origin for doesn't actually require Safari extensions – it can be more efficiently and privately implemented using Content Blocker extensions. These have been available on iOS for a long time now.

We develop an ad blocker [1] for iOS (and macOS) that has complete ad blocking functionality simply by using the content blocking mechanism.

The only time we've found that we've needed to resort to using Safari extensions is for our YouTube ad blocking; specifically to block the pre-roll video ads. So at least on iOS this will now be supported as well as of iOS 15.

[1] https://www.magiclasso.co/

Re: iOS 15

#360
post #256

Earlier quoted context omitted.

If in October 2013 you bought a just released Google Nexus 5, you would have had official updates until December 2016. At the end of support, you could have then bought the recent Google Pixel (1). And you would have had official updates until December 2019. A little over 6 years out of two devices is as good as it gets on Android, at least it's as good as it got in the mid-late 2010s. If in October 2013 you bought a…

>If in October 2013 you bought a just released Google Nexus 5, you would have had official updates until December 2016. Wait a second are you sure about that? The last official version released was 6.0.1 which was released in October of 2015. I remember this because the Nexus 5 was the phone that finally sealed the deal for me in leaving the Android ecosystem for good. These "engineers" on the Android team did not QA…

> Wait a second are you sure about that?

I am not, as I didn't own the device (I did own a Nexus 4 around this time). I'm going by Google's available factory images [1].

[0] https://developers.google.com/android/images#hammerhead

Post reply on HN