Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

41–50 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#41

This is true for pretty much every vendor. Security fixes do not all get backported to every previous version of something. Newer iPhone do not just run the latest version of iOS, but they are more secure from a hardware perspective too.

"every previous version"

No reasonable person is asking for this.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#42
post #15

Earlier quoted context omitted.

Correct. The issue is it is not commonly known that Apple isn't actually backporting fixes for exploits while it has been claiming to update the phones: this is earth-shaking[^1] news [^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Andr…

Huh, it can be totally earth shaking or completely normal depending on time and place. In current market place of smartphones it is more towards earth shaking than normal. You don't have to agree but resell value of older iPhone being much-much higher than Android tells customer values the support and quality of iPhone.

As much as the sales of healing crystals tells me how much people value the health and anti-aging benefits of those.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#43

When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.

Yea, this reads like someone was denied a bounty for a "exploit" and decided to make it a whole thing as retribution.

I don't see how. Apple is choosing to not patch known vulnerabilities on hardware sold new less than 3 years ago. Hardware they're happy to charge for repairs on.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#44
post #36
post #34

Earlier quoted context omitted.

App Store purchases aren't tied to a particular device; you can buy an app on an old device and keep using it when you get a newer device. Do you have a coherent, reasonable suggestion for how Apple could modify their business model without completely breaking it, or are you just desperate to shoehorn complaints about the App Store fees into the conversation?

Easy: offer a discount if purchase is made on an unsupported device, just like how grocery stores offer discounts for food that's about to expire. I don't think there is a real concern about app store economics collapsing, the app marketplace business is very lucrative. We can see this in related cases: you can avoid certain iOS taxes by purchasing your subscriptions on the web: Twitter Blue is $11 on iOS and $8 on t…

> Why should users pay full bundled iOS tax that supports security updates,

I don't think I've ever seen someone express the expectation that Apple's App Store fees are for the purpose of supporting iOS development and maintenance. Mostly I've seen and heard the expectation that those fees are connected to running the App Store itself (payment processing, hosting, app review, etc.) and beyond that, vague profiteering. iOS itself isn't a subscription service, and Apple seems quite happy to sell you devices even if you don't spend money in the App Store. So you seem to be stretching a bit by attributing those fees to iOS maintenance and then turning around to say that unsupported iOS versions should get a discount on the fees for any services that still work.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#45
post #20

When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.

Isn't the JS exfiltration part trivial? The attack assumes that the victim is visiting an attacker-controlled web server. If the attacker can put secret data in the DOM within the victim's browser, the attacker can also add JS on the same page that POSTs the DOM contents to the server once they're populated with secrets.

If it's "trivial", then perhaps the article should've demonstrated that.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#47

This is true for pretty much every vendor. Security fixes do not all get backported to every previous version of something. Newer iPhone do not just run the latest version of iOS, but they are more secure from a hardware perspective too.

"every previous version" No reasonable person is asking for this.

Okay replace that with "more than the latest version / LTS".

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#48

Earlier quoted context omitted.

What does this mean? The App Store fees are paid by the developers / vendors. Are you saying they should pay less proportionate to the number of times their apps are downloaded to older devices?

> What does this mean? It means they’re shoehorning another issue into this discussion.

I think it’s a completely valid point. Apple is still making (potentially a lot) of money off these old devices yet isn’t willing to fully support them. It seems very unethical.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#49
post #27

Earlier quoted context omitted.

They should stop charging 30% App Store tax for an inferior product at the very least.

15% for the vast majority of developers and apps FWIW.

Probably true, but is it the same for the vast majority of the app revenue? Quite possibly not.
Post reply on HN