Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

101–110 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#102

/etc/passwd is the same on every device because it is in the system image, which is world readable. I don't think this exploit can be used to read the call history database as the author implies because it is outside of the sandbox profile.

It probably does let you grab cookies and browsing history from Chrome, though.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#103
post #16

Earlier quoted context omitted.

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

You can't seriously give Apple shit for this and at the same time praise Google. iPhones have, pretty consistently since the 5 or so, received 5 or 6 years worth of OS updates since the phone's release whereas with Android phones you'll receive 2. Only after years of complaining is Google finally promising to support it for longer. And that doesn't cover Samsung, etc...

We can and should praise Google for improving things, and use their new strong points to push Apple into improving too.

This isn't a debate about what company is better. The word "now" is used for Google's promises for a reason.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#104

How do we know they won’t patch it in like an iOS 15.8.1 update? Even iOS 12 had a security update in 2023 still.

Apple doesn't patch every security hole in older iOS versions. I don't know what the criteria is, but my guess is if it's a major security hole, or an easily backported one, they'll do it, but if it's super minor or not backportable, they won't.

If I had to guess, I think it’s when they see a report that it’s been actively exploited.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#105
post #16

Earlier quoted context omitted.

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

Google doesn’t have enough e-fuses to update the pixel phones for seven years, the marketing department is incompetent and didn’t talk to literally the only engineers they should have.

Is there a reason you think most updates would even want to blow e-fuses, let alone need to?

And how many are there, then?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#106
post #51

> After contacting Apple […] I’d be very curious to see HOW they contacted Apple. Depending on if you’re reaching out to security or just filing a standard radar I’d expect a very different answer. Also, was it reported to the WebKit team? If that is where the bug is, perhaps that’s who should be taking the report?

OP here. It was reported to product-security@apple.com.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#107
post #22

Earlier quoted context omitted.

It’s an issue of expectations. If Apple advertises security support then it’s fraudulent to not deliver it; on the other hand, if they advertise an EOL date, then I’d agree there’s no reasonable expectation of security updates. But what they actually do is neither, they communicate very little, supporting some past iOS versions fully and others to degrees that only they know, resulting in them profiting off a reputat…

They do communicate it in every major release, including which devices are supported. Many major vendors release security updates for EOL devices when doing so would greatly increase the security posture of those devices and comes at little to no cost to the vendor. Notably Cisco, Microsoft, Apple, and Samsung come to mind. Is the implication that once a device is EOL that a vendor should never release an update for…

They communicate OS version device compatibility, I’m talking about communicating OS version EOL. For example, Windows 10 EOL is 2025-10-14, and we know this years in advance. For Apple, not only do we not get advance notice, we don’t even know when it’s already happened.

No, I’m not implying there’s something wrong with shipping the occasional update to EOL devices.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#108

Earlier quoted context omitted.

You can't seriously give Apple shit for this and at the same time praise Google. iPhones have, pretty consistently since the 5 or so, received 5 or 6 years worth of OS updates since the phone's release whereas with Android phones you'll receive 2. Only after years of complaining is Google finally promising to support it for longer. And that doesn't cover Samsung, etc...

We can and should praise Google for improving things, and use their new strong points to push Apple into improving too. This isn't a debate about what company is better. The word "now" is used for Google's promises for a reason.

> We can and should praise Google for improving things

Let’s talk again in 5 years, once they had the opportunity to prove their plans. So far, it’s all just talk.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#110
post #84
post #16

Earlier quoted context omitted.

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

>but still not very affordable, models The 2020 SE is available from a wide variety of sources for 200USD (still new in box); it'll be supported until 2027. The 2022 SE is 400USD, supported until 2029. By comparison the Android phones at this price point functionally went out of support 2 years before they even existed- not only is there zero support for them, but they ship with outdated OS versions to begin with. An…

You had a strong first paragraph, but your second is going too far. A Pixel 6a is $349 and supported until 2027. A galaxy A15 is $175 and supported until the end of 2028 or early 2029. The full feature updates don't go quite as far, but they're still offered for multiple years into the future.
Post reply on HN