Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

61–70 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#62
post #51

> After contacting Apple […] I’d be very curious to see HOW they contacted Apple. Depending on if you’re reaching out to security or just filing a standard radar I’d expect a very different answer. Also, was it reported to the WebKit team? If that is where the bug is, perhaps that’s who should be taking the report?

It can make a big difference who reads the ticket. I might see something come in and think oh yeah that'll take me 5 min to fix and I'll just do it, but if someone else unknowledgeable about the feature sees it, or a PM... it might get closed as won't fix at best or just rot for 10 years.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#63
post #18
post #14

Earlier quoted context omitted.

Touche. P.S. Keep in mind though, what is the state of security of the Android phone you bought new in November 2015?

The Nexus 6 (2014) can still run a version of android with security patches: https://wiki.lineageos.org/devices/shamu/ Google no longer offers security patches directly, but since you control the phone sufficiently to install your own OS, the community can come together and keep security updates flowing. You could do it yourself if you wanted. Apple devices make this sort of community maintainership effectively impos…

Does that include updated drivers? If no, then there are still many unfixed security vulnerabilities.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#64
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

Not going to lie, if I were trying to infect some devices, it might be through “porting” unofficial “patches” (that no one will ever realistically inspect) for 10+ year old, out-of-support devices whose users have allowed root access.

XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#65
post #64

Earlier quoted context omitted.

Not going to lie, if I were trying to infect some devices, it might be through “porting” unofficial “patches” (that no one will ever realistically inspect) for 10+ year old, out-of-support devices whose users have allowed root access.

XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.

think about it the other way: if someone who happens to use random ROM happens to be a target of a state security agency of course it would be trivial to infect and the other 999 users would be collateral damage.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#67
post #17
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

It's fine for a vendor to completely abandon 10 year old hardware but if you can still pay 30% App Store tax/pay for iCloud/etc, the security fixes should be backported as well. The current situation is charging full price for inferior (or maybe even dangerous) product: Apple wants to have its cake and eat it too.

So theoretically - and I tried this a couple of years ago - I could still download the “last compatible version” of an app if it’s available on the store for my old 2010 iPad 1st generation running iOS 5.

This device had 256Mb RAM and 400Mhz 32 bit processor. Should Apple still support this with security updates?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#68
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

lol! Are you really comparing Apple released operating system updates to xda?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#69
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

How does a random image help most users?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#70

This is true for pretty much every vendor. Security fixes do not all get backported to every previous version of something. Newer iPhone do not just run the latest version of iOS, but they are more secure from a hardware perspective too.

How is hardware relevant here?
Post reply on HN