Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

31–40 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#31
post #22

Earlier quoted context omitted.

It’s an issue of expectations. If Apple advertises security support then it’s fraudulent to not deliver it; on the other hand, if they advertise an EOL date, then I’d agree there’s no reasonable expectation of security updates. But what they actually do is neither, they communicate very little, supporting some past iOS versions fully and others to degrees that only they know, resulting in them profiting off a reputat…

They do communicate it in every major release, including which devices are supported. Many major vendors release security updates for EOL devices when doing so would greatly increase the security posture of those devices and comes at little to no cost to the vendor. Notably Cisco, Microsoft, Apple, and Samsung come to mind. Is the implication that once a device is EOL that a vendor should never release an update for…

They only communicate it after the fact, when the new OS is impending release. There’s no way to know at time of purchase how many years your device will be supported.

I feel like Apple changed the dynamics of smartphone market from company-issued devices like BlackBerry to BYO with the iPhone essentially on purpose so they don’t get stuck providing decades of enterprise support promises like companies like Microsoft.

Companies purchasing bulk orders of hardware probably wouldn’t tolerate a vendor unwilling to make any sort of concrete support promise for the contract. But a company who employs iPhone users can basically put the responsibility on the user and simply block access to non-compliant devices.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#32
post #18
post #14

Earlier quoted context omitted.

Touche. P.S. Keep in mind though, what is the state of security of the Android phone you bought new in November 2015?

The Nexus 6 (2014) can still run a version of android with security patches: https://wiki.lineageos.org/devices/shamu/ Google no longer offers security patches directly, but since you control the phone sufficiently to install your own OS, the community can come together and keep security updates flowing. You could do it yourself if you wanted. Apple devices make this sort of community maintainership effectively impos…

Is my grandma going to install a custom rom? If it’s not over the air it might as well not exist.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#33
post #27

Earlier quoted context omitted.

They should stop charging 30% App Store tax for an inferior product at the very least.

What does this mean? The App Store fees are paid by the developers / vendors. Are you saying they should pay less proportionate to the number of times their apps are downloaded to older devices?

> What does this mean?

It means they’re shoehorning another issue into this discussion.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#34
post #27
post #26

Earlier quoted context omitted.

Are you really saying Apple should actively break interoperability with old software?

They should stop charging 30% App Store tax for an inferior product at the very least.

App Store purchases aren't tied to a particular device; you can buy an app on an old device and keep using it when you get a newer device. Do you have a coherent, reasonable suggestion for how Apple could modify their business model without completely breaking it, or are you just desperate to shoehorn complaints about the App Store fees into the conversation?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#35
post #17
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

It's fine for a vendor to completely abandon 10 year old hardware but if you can still pay 30% App Store tax/pay for iCloud/etc, the security fixes should be backported as well. The current situation is charging full price for inferior (or maybe even dangerous) product: Apple wants to have its cake and eat it too.

I don't totally follow this argument. the 30% app store commission, iCloud subscription, etc. does not only fund security fixes for the OS and core services. I don't think the average consumer thinks that's what they're paying for either. waiving the fee for EOL'd devices would create a perverse incentive of its own.

I do wish apple would follow google's example and commit to a service lifetime upfront, but other than that, I don't object to their model. in practice, it vastly exceeds the level of support for any android phone other than the pixel 8, and we have yet to see whether google actually follows through on that.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#36
post #34
post #27

Earlier quoted context omitted.

They should stop charging 30% App Store tax for an inferior product at the very least.

App Store purchases aren't tied to a particular device; you can buy an app on an old device and keep using it when you get a newer device. Do you have a coherent, reasonable suggestion for how Apple could modify their business model without completely breaking it, or are you just desperate to shoehorn complaints about the App Store fees into the conversation?

Easy: offer a discount if purchase is made on an unsupported device, just like how grocery stores offer discounts for food that's about to expire.

I don't think there is a real concern about app store economics collapsing, the app marketplace business is very lucrative. We can see this in related cases: you can avoid certain iOS taxes by purchasing your subscriptions on the web: Twitter Blue is $11 on iOS and $8 on the web. Spotify used to be $12.99 for iOS sign-ups and $9.99 on the web.

Why should users pay full bundled iOS tax that supports security updates, if they are getting none?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#37
post #16
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

Personally I don’t think Apple’s level of support is incredibly bad when you take a look at the used device market. Even with Apple’s famously high resale values, depreciation on smartphones is huge.

Don’t buy brand new old phones new from Apple, they’re a ripoff. If you buy either an iPhone 12 or 13 used for $250-350 you can basically plan on a $50 a year budget to have a smartphone that always has the latest OS judging by their expected remaining lifespans.

I think the big flaw with the status quo is e-waste more than cost to the consumer. I think an iPhone 6S or 7 are incredibly slow and outdated devices for today’s usage but in 5 years I don’t think we will be able to say the same thing about an iPhone 12 or 13. Smartphone hardware is far more mature now than it was even 6 generations deep into the iPhone product line.

We should be able to replace batteries for $20 and replace things like broken screens for not much more, and Apple should be enthusiastic about it considering how services are their bread and butter moving forward. Apple should be happy to produce fewer phones and keep more consumer dollars allocated toward the purchase of high margin digital goods.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#38
post #32
post #18

Earlier quoted context omitted.

The Nexus 6 (2014) can still run a version of android with security patches: https://wiki.lineageos.org/devices/shamu/ Google no longer offers security patches directly, but since you control the phone sufficiently to install your own OS, the community can come together and keep security updates flowing. You could do it yourself if you wanted. Apple devices make this sort of community maintainership effectively impos…

Is my grandma going to install a custom rom? If it’s not over the air it might as well not exist.

Maybe you could be a good grandson and do it for her?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#40
post #37
post #16

Earlier quoted context omitted.

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

Personally I don’t think Apple’s level of support is incredibly bad when you take a look at the used device market. Even with Apple’s famously high resale values, depreciation on smartphones is huge. Don’t buy brand new old phones new from Apple, they’re a ripoff. If you buy either an iPhone 12 or 13 used for $250-350 you can basically plan on a $50 a year budget to have a smartphone that always has the latest OS jud…

> I don’t think we will be able to say the same thing about an iPhone 12 or 13

The wildcard here is local LLM use cases and any new hardware that increases their speed by orders of magnitude.

Post reply on HN