Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

131–140 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#131

Earlier quoted context omitted.

You can't seriously give Apple shit for this and at the same time praise Google. iPhones have, pretty consistently since the 5 or so, received 5 or 6 years worth of OS updates since the phone's release whereas with Android phones you'll receive 2. Only after years of complaining is Google finally promising to support it for longer. And that doesn't cover Samsung, etc...

We can and should praise Google for improving things, and use their new strong points to push Apple into improving too. This isn't a debate about what company is better. The word "now" is used for Google's promises for a reason.

> We can and should praise Google for improving things, and use their new strong points to push Apple into improving too.

Over a decade of Nexus then Pixel devices being flashable has not moved any needle of Apple doing the same. Google promising 7 years is in line with Apple's 10 year track record of providing 6-8 years of updates, so it's more like Google aligning with Apple, not Google pushing Apple.

Still, a vague† promise in a blog post or keynote address is not going to fit the bill, at the very least it should be in the EULA or other contractually enforceable document, otherwise the promise is worth nothing.

Ideally I wish software would be treated as with e.g automotive or washing machine manufacturers, who in the EU have a legal requirement to provide parts for 10 years.

† I mean the promise is clearly worded but bears no weight, especially when pitted against Google's track record over the last decade of making grand announcements then puling the rug down the road.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#132
post #108

Earlier quoted context omitted.

We can and should praise Google for improving things, and use their new strong points to push Apple into improving too. This isn't a debate about what company is better. The word "now" is used for Google's promises for a reason.

> We can and should praise Google for improving things Let’s talk again in 5 years, once they had the opportunity to prove their plans. So far, it’s all just talk.

Especially that a 10 years old phone was very weak in terms of hardware, we haven’t reached a more plateaus era back then. It’s much easier to update a phone in the last 5 years for 10 years, than doing the same in a 5 years earlier window frame.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#133
post #27
post #26

Earlier quoted context omitted.

Are you really saying Apple should actively break interoperability with old software?

They should stop charging 30% App Store tax for an inferior product at the very least.

Why exactly? Does petrol get cheaper for an old car that barely works?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#134
post #15

Earlier quoted context omitted.

Huh, it can be totally earth shaking or completely normal depending on time and place. In current market place of smartphones it is more towards earth shaking than normal. You don't have to agree but resell value of older iPhone being much-much higher than Android tells customer values the support and quality of iPhone.

As much as the sales of healing crystals tells me how much people value the health and anti-aging benefits of those.

Healing crystals seems to be a much smaller market (to the point of barely existing) than “Big Pharma”, so your analogy doesn’t really make sense.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#135
post #16

Earlier quoted context omitted.

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

I looked it up, and the extended security updates for Google Pixel is only a recent change: Pixel 8: released in 2023, updates through 2030 Pixel 5: released in 2020, stopped getting updates in October 2023. https://support.google.com/pixelphone/answer/4457705?hl=en

Looks like I hit a 'sweet spot' with my Pixel 4a (released in August 2020, guaranteed updates until November 2023)

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#136

Would be great to get Linux running on and driver coverage for all of the system-on-chip of these devices. Talent exists for this but they are busy with their jobs or more interesting problems.

https://projectsandcastle.org/

But don’t get too excited.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#137
post #89

Earlier quoted context omitted.

> I don’t think we will be able to say the same thing about an iPhone 12 or 13 The wildcard here is local LLM use cases and any new hardware that increases their speed by orders of magnitude.

That’s not really a need for smartphone users. I can access an LLM on a website for free right now. I also don’t see any indication that there will be impactful local LLM silicon at the smartphone scale anytime soon.

You can yes, but the rumor is that Apple is focusing on adding them directly to your device, and if they integrate it deeply in the OS, then it will require the chips to run it. I’m sure you will be able to run old devices but without the latest Siri for example.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#138
post #111

Always a smile when I see my blog posted on hn:) To answer three questions: 1) this was not reported in the context of any bug bounty[0], and the total conversation between me and Apple is 4 emails (1: hello do you plan to fix this? 2: can you reproduce this on the newest ios17? 3: no. 4: if you are able to reproduce it on ios17 let us know) 2) exfiltration is obviously possible, I’m not sure why I would even need to…

It,'s always a fun and interesting read when your posts hit HN.

How much time would you estimate goes into researching? And do you have any pointers for someone which want to dip their toes into this vast sea of exploration?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#139
post #18
post #14

Earlier quoted context omitted.

Touche. P.S. Keep in mind though, what is the state of security of the Android phone you bought new in November 2015?

The Nexus 6 (2014) can still run a version of android with security patches: https://wiki.lineageos.org/devices/shamu/ Google no longer offers security patches directly, but since you control the phone sufficiently to install your own OS, the community can come together and keep security updates flowing. You could do it yourself if you wanted. Apple devices make this sort of community maintainership effectively impos…

But it is effectively impossible on Android as well. Let's ignore for a minute the fact that practically no one can install a custom ROM.

The bigger problem is that a huge bunch of software running on the phone is fully proprietary and closed source, and there are many many different versions for different phones around - making it virtually impossible to do any meaningful reverse engineering. So sure, your main OS may be up to date, but the baseband OS and virtually all of the device drivers will be left vulnerable, and they have just as much if not more access to the data on your device.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#140
post #20

Earlier quoted context omitted.

Isn't the JS exfiltration part trivial? The attack assumes that the victim is visiting an attacker-controlled web server. If the attacker can put secret data in the DOM within the victim's browser, the attacker can also add JS on the same page that POSTs the DOM contents to the server once they're populated with secrets.

If it's "trivial", then perhaps the article should've demonstrated that.

If I prove I got a shell prompt on a remote device without any authentication, do I then need to show that I can execute arbitrary code? Or is it clearly implied?

If the page body can read a file, then it can just execute an XmlHttpRequest to send that data to the origin server, which is the attacker in this scenario. This is just how the web works, nothing more to say about it, and no need to prove it.

Post reply on HN