Earlier quoted context omitted.
And how's that more difficult than the loading page (exploit.svg) doing a GET/POST request to some server, after was loaded?
[flagged]
No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
101–110 of 242 posts
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#102/etc/passwd is the same on every device because it is in the system image, which is world readable. I don't think this exploit can be used to read the call history database as the author implies because it is outside of the sandbox profile.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#103Earlier quoted context omitted.
Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.
You can't seriously give Apple shit for this and at the same time praise Google. iPhones have, pretty consistently since the 5 or so, received 5 or 6 years worth of OS updates since the phone's release whereas with Android phones you'll receive 2. Only after years of complaining is Google finally promising to support it for longer. And that doesn't cover Samsung, etc...
This isn't a debate about what company is better. The word "now" is used for Google's promises for a reason.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#104How do we know they won’t patch it in like an iOS 15.8.1 update? Even iOS 12 had a security update in 2023 still.
Apple doesn't patch every security hole in older iOS versions. I don't know what the criteria is, but my guess is if it's a major security hole, or an easily backported one, they'll do it, but if it's super minor or not backportable, they won't.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#105Earlier quoted context omitted.
Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.
Google doesn’t have enough e-fuses to update the pixel phones for seven years, the marketing department is incompetent and didn’t talk to literally the only engineers they should have.
And how many are there, then?
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#106> After contacting Apple […] I’d be very curious to see HOW they contacted Apple. Depending on if you’re reaching out to security or just filing a standard radar I’d expect a very different answer. Also, was it reported to the WebKit team? If that is where the bug is, perhaps that’s who should be taking the report?
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#107Earlier quoted context omitted.
It’s an issue of expectations. If Apple advertises security support then it’s fraudulent to not deliver it; on the other hand, if they advertise an EOL date, then I’d agree there’s no reasonable expectation of security updates. But what they actually do is neither, they communicate very little, supporting some past iOS versions fully and others to degrees that only they know, resulting in them profiting off a reputat…
They do communicate it in every major release, including which devices are supported. Many major vendors release security updates for EOL devices when doing so would greatly increase the security posture of those devices and comes at little to no cost to the vendor. Notably Cisco, Microsoft, Apple, and Samsung come to mind. Is the implication that once a device is EOL that a vendor should never release an update for…
No, I’m not implying there’s something wrong with shipping the occasional update to EOL devices.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#108Earlier quoted context omitted.
You can't seriously give Apple shit for this and at the same time praise Google. iPhones have, pretty consistently since the 5 or so, received 5 or 6 years worth of OS updates since the phone's release whereas with Android phones you'll receive 2. Only after years of complaining is Google finally promising to support it for longer. And that doesn't cover Samsung, etc...
We can and should praise Google for improving things, and use their new strong points to push Apple into improving too. This isn't a debate about what company is better. The word "now" is used for Google's promises for a reason.
Let’s talk again in 5 years, once they had the opportunity to prove their plans. So far, it’s all just talk.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#109When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#110Earlier quoted context omitted.
Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.
>but still not very affordable, models The 2020 SE is available from a wide variety of sources for 200USD (still new in box); it'll be supported until 2027. The 2022 SE is 400USD, supported until 2029. By comparison the Android phones at this price point functionally went out of support 2 years before they even existed- not only is there zero support for them, but they ship with outdated OS versions to begin with. An…