Earlier quoted context omitted.
Is my grandma going to install a custom rom? If it’s not over the air it might as well not exist.
Maybe you could be a good grandson and do it for her?
No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
71–80 of 242 posts
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#72Some iOS 15 phones like the 5S/SE have no newer comparable phones which makes upgrading difficult. Oh dear, I suppose not browsing the web is another option.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#73Earlier quoted context omitted.
XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.
think about it the other way: if someone who happens to use random ROM happens to be a target of a state security agency of course it would be trivial to infect and the other 999 users would be collateral damage.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#74Earlier quoted context omitted.
Not going to lie, if I were trying to infect some devices, it might be through “porting” unofficial “patches” (that no one will ever realistically inspect) for 10+ year old, out-of-support devices whose users have allowed root access.
XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.
I hate that I wrote that lol. It reeks of the kind of cybersecurity whataboutism that leads to people inconveniencing the SHIT out of themselves for the sake of security.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#75The iPhone 8 was sold new less than 3 years ago. Okay, new features shouldn't be expected, but patching known vulnerabilities should be required.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#76This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry
Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#77Earlier quoted context omitted.
Not going to lie, if I were trying to infect some devices, it might be through “porting” unofficial “patches” (that no one will ever realistically inspect) for 10+ year old, out-of-support devices whose users have allowed root access.
XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#78Earlier quoted context omitted.
XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.
Wait... so because you don't want to be infected because you're using an out of date OS, you load OS patches of questionable provenance, but you're not worried about that since nobody would bother to infect you anyway? Why not skip a few steps there and just run an out of date OS?
Edit: Though to keep things fair, it must be said that that particular argument only really applies to old devices. If you have a new device (or rather, one still getting regular security updates from the vendor) and a trustworthy vendor, a person could reasonably argue for staying on the stock ROM.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#79That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#80When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.
And how's that more difficult than the loading page (exploit.svg) doing a GET/POST request to some server, after was loaded?