Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

71–80 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#71
post #32

Earlier quoted context omitted.

Is my grandma going to install a custom rom? If it’s not over the air it might as well not exist.

Maybe you could be a good grandson and do it for her?

I don’t consider it a good thing to install a custom OS for someone and not give them the same level of support.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#73
post #65
post #64

Earlier quoted context omitted.

XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.

think about it the other way: if someone who happens to use random ROM happens to be a target of a state security agency of course it would be trivial to infect and the other 999 users would be collateral damage.

If state security agency is your model threat you'll be hard pressed to stay secure even with an airgap. If it's wholesale worm-like attacks you'll be way ahead of the curve by using a niche ROM from a god-forsaken site compared to any slightly out-of-date OEM distro.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#74
post #64

Earlier quoted context omitted.

Not going to lie, if I were trying to infect some devices, it might be through “porting” unofficial “patches” (that no one will ever realistically inspect) for 10+ year old, out-of-support devices whose users have allowed root access.

XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.

Realistically, if someone makes a fringe rom that may be downloaded a few thousand times, how many people are going to bother checking for nefarious exploits hidden in there?

I hate that I wrote that lol. It reeks of the kind of cybersecurity whataboutism that leads to people inconveniencing the SHIT out of themselves for the sake of security.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#75

The iPhone 8 was sold new less than 3 years ago. Okay, new features shouldn't be expected, but patching known vulnerabilities should be required.

iPhone 8 had a patch to iOS 16 released a week ago, 6 years after it was released and 3 years after it was last sold during a global pandemic?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#76
post #16
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

It was difficult to locate but I found a new iPhone 7 for sale for $92. Seems affordable.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#77
post #64

Earlier quoted context omitted.

Not going to lie, if I were trying to infect some devices, it might be through “porting” unofficial “patches” (that no one will ever realistically inspect) for 10+ year old, out-of-support devices whose users have allowed root access.

XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.

Wait... so because you don't want to be infected because you're using an out of date OS, you load OS patches of questionable provenance, but you're not worried about that since nobody would bother to infect you anyway? Why not skip a few steps there and just run an out of date OS?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#78
post #77
post #64

Earlier quoted context omitted.

XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.

Wait... so because you don't want to be infected because you're using an out of date OS, you load OS patches of questionable provenance, but you're not worried about that since nobody would bother to infect you anyway? Why not skip a few steps there and just run an out of date OS?

Every device running an old OS is vulnerable, so it's better to throw the dice on an aftermarket ROM.

Edit: Though to keep things fair, it must be said that that particular argument only really applies to old devices. If you have a new device (or rather, one still getting regular security updates from the vendor) and a trustworthy vendor, a person could reasonably argue for staying on the stock ROM.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#79
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

What about the binary blob drivers that can’t be patched and are one of the leading attack vectors? Just look at all of the Qualcomm monthly patches alone . Unless all of your binaries, that have no source, are up to date you’ll never be secure on any XDA rom.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#80
post #6

When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.

And how's that more difficult than the loading page (exploit.svg) doing a GET/POST request to some server, after was loaded?

[flagged]
Post reply on HN