Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

21–30 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#22
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

It’s an issue of expectations. If Apple advertises security support then it’s fraudulent to not deliver it; on the other hand, if they advertise an EOL date, then I’d agree there’s no reasonable expectation of security updates. But what they actually do is neither, they communicate very little, supporting some past iOS versions fully and others to degrees that only they know, resulting in them profiting off a reputat…

They do communicate it in every major release, including which devices are supported. Many major vendors release security updates for EOL devices when doing so would greatly increase the security posture of those devices and comes at little to no cost to the vendor. Notably Cisco, Microsoft, Apple, and Samsung come to mind.

Is the implication that once a device is EOL that a vendor should never release an update for that device again?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#23
post #14

Earlier quoted context omitted.

Correct. The issue is it is not commonly known that Apple isn't actually backporting fixes for exploits while it has been claiming to update the phones: this is earth-shaking[^1] news [^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Andr…

Touche. P.S. Keep in mind though, what is the state of security of the Android phone you bought new in November 2015?

[deleted]

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#24
post #22

Earlier quoted context omitted.

It’s an issue of expectations. If Apple advertises security support then it’s fraudulent to not deliver it; on the other hand, if they advertise an EOL date, then I’d agree there’s no reasonable expectation of security updates. But what they actually do is neither, they communicate very little, supporting some past iOS versions fully and others to degrees that only they know, resulting in them profiting off a reputat…

They do communicate it in every major release, including which devices are supported. Many major vendors release security updates for EOL devices when doing so would greatly increase the security posture of those devices and comes at little to no cost to the vendor. Notably Cisco, Microsoft, Apple, and Samsung come to mind. Is the implication that once a device is EOL that a vendor should never release an update for…

> Is the implication that once a device is EOL that a vendor should never release an update for that device again?

It seems typical for vendors use "EOL" to refer to end of support life, not merely discontinuing sales of the produce. Most notably, that's how Microsoft generally frames EOL for major Windows releases, hence expectation of jumps in PC sales corresponding to EOL of XP, 7, and 10.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#25
post #16
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

I looked it up, and the extended security updates for Google Pixel is only a recent change:

Pixel 8: released in 2023, updates through 2030 Pixel 5: released in 2020, stopped getting updates in October 2023.

https://support.google.com/pixelphone/answer/4457705?hl=en

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#26
post #17
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

It's fine for a vendor to completely abandon 10 year old hardware but if you can still pay 30% App Store tax/pay for iCloud/etc, the security fixes should be backported as well. The current situation is charging full price for inferior (or maybe even dangerous) product: Apple wants to have its cake and eat it too.

Are you really saying Apple should actively break interoperability with old software?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#27
post #26
post #17

Earlier quoted context omitted.

It's fine for a vendor to completely abandon 10 year old hardware but if you can still pay 30% App Store tax/pay for iCloud/etc, the security fixes should be backported as well. The current situation is charging full price for inferior (or maybe even dangerous) product: Apple wants to have its cake and eat it too.

Are you really saying Apple should actively break interoperability with old software?

They should stop charging 30% App Store tax for an inferior product at the very least.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#28
post #27
post #26

Earlier quoted context omitted.

Are you really saying Apple should actively break interoperability with old software?

They should stop charging 30% App Store tax for an inferior product at the very least.

What does this mean? The App Store fees are paid by the developers / vendors. Are you saying they should pay less proportionate to the number of times their apps are downloaded to older devices?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#29
post #27
post #26

Earlier quoted context omitted.

Are you really saying Apple should actively break interoperability with old software?

They should stop charging 30% App Store tax for an inferior product at the very least.

15% for the vast majority of developers and apps FWIW.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#30
post #17
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

It's fine for a vendor to completely abandon 10 year old hardware but if you can still pay 30% App Store tax/pay for iCloud/etc, the security fixes should be backported as well. The current situation is charging full price for inferior (or maybe even dangerous) product: Apple wants to have its cake and eat it too.

iOS 12 was released September 2018 and

> iOS 12.5.7

> Released January 23, 2023

https://support.apple.com/en-us/103015

Post reply on HN