Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

171–180 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#171

Apple, in my opinion, does a very good job of supporting old devices. Buying an iPhone and keeping it for 6 years is a great strategy and when amortising the cost of the phone over those 6 years, it's price competitive with Android. I do wish legislators forced Apple and Google to give users a path to install an alternative OS on their device. That would enable old iPhones(and Androids) to have their lifetime extende…

>Buying an iPhone and keeping it for 6 years is a great strategy and when amortising the cost of the phone over those 6 years, it's price competitive with Android. What's stopping you from keeping your Android 6 years making it an event better value? Most people I know don't throw away their Androids after 3 years but keep them as long as iPhones. Basically until it breaks/dies. So far I don't know anyone who got hac…

> So far I don't know anyone who got hacked and suffered damages for using an Android that stopped getting updates.

That’s a “hope for the best” approach to security, for me it’d be irresponsible to recommend it to even friends and family.

But if you want to do it with knowledge of the potential problems — go for it. It’s your phone and your data.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#172

Earlier quoted context omitted.

>Buying an iPhone and keeping it for 6 years is a great strategy and when amortising the cost of the phone over those 6 years, it's price competitive with Android. What's stopping you from keeping your Android 6 years making it an event better value? Most people I know don't throw away their Androids after 3 years but keep them as long as iPhones. Basically until it breaks/dies. So far I don't know anyone who got hac…

> So far I don't know anyone who got hacked and suffered damages for using an Android that stopped getting updates. That’s a “hope for the best” approach to security, for me it’d be irresponsible to recommend it to even friends and family. But if you want to do it with knowledge of the potential problems — go for it. It’s your phone and your data.

Please don't twist my words. I never said anything about recommending such a lifestyle to people. All I said was, using older devices without SW support, is the reality for a lot of people if you care to leave the tech bubble and see what devices people actually use, especially the not well off ones. Yes, a lot of people keep using their older device and they haven't got hacked. How do you get them to stop using their older devices, if they're happy with them and see no obvious threat and don't want to buy a new one?

Here's a though exercise: Most people use their device for browsing the web and messaging people, right? So as long as you keep your Play Services, browser and messenger apps up to date, how will malware get to the outdated layers of your OS to PWN you? Especially that modern web browsers and Andorid use sandboxing for apps and web tabs. I'm talking about realistic documented scenarios from the wild that have happened and are likely to repeat again, not state actors or scenarios from research labs where they hack you through the firmware vulns of the baseband modem.

Like I said, I'm not recommending you still use unpatched devices, but the realistic risk from using an Andorid device that stopped getting updates a year or so is relatively minimal in practice, otherwise there would be mass hacks and credential thefts left and right on a daily basis considering how many unpatched Android phones are out there.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#173

Earlier quoted context omitted.

It’s absolutely economical. Apple only has to support a tiny number of devices that they themselves manufactured, they have the easiest job in the world. Think about how many devices Microsoft has to support in Windows, it’s orders of magnitude more. Apple doesn’t want to support older devices because they don’t see a benefit to themselves. 5 years of support is pitifully short. Pretty much everything I own lasts lon…

[flagged]

> New devices = New components = New Firmware = The updates have to stop sometime

So how does microsoft do it? My PC is about the same age yet it is still supported. And not even barely, but without a hitch.

> Apple is an OEM for most parts on their board, if upstream support ends for the components on the board then its game over as far as firmware updates goes.

But this is not an issue with a chip's firmware. Do you believe apple can't compile code for their 10 year old hardware or how do you think this happens?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#174
post #16

Earlier quoted context omitted.

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

You can't seriously give Apple shit for this and at the same time praise Google. iPhones have, pretty consistently since the 5 or so, received 5 or 6 years worth of OS updates since the phone's release whereas with Android phones you'll receive 2. Only after years of complaining is Google finally promising to support it for longer. And that doesn't cover Samsung, etc...

I feel like the security update period should really be measured from the date of last "as new" sale, not date of original release.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#176
post #144
post #111

Always a smile when I see my blog posted on hn:) To answer three questions: 1) this was not reported in the context of any bug bounty[0], and the total conversation between me and Apple is 4 emails (1: hello do you plan to fix this? 2: can you reproduce this on the newest ios17? 3: no. 4: if you are able to reproduce it on ios17 let us know) 2) exfiltration is obviously possible, I’m not sure why I would even need to…

> exfiltration is obviously possible, I’m not sure why I would even need to specify that any page is able to read its own contents using JavaScript Things that are obvious to you may be non-obvious to other people, including the readers of your blog.

In the context of their blog post, it's assumed that the reader has some knowledge of web technologies — if you can print data to your own webpage, you can also exfiltrate it.

It's not reasonable to expect the author to explain _every_ underlying technology involved since that was likely not the scope of the post.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#177
post #137
post #89

Earlier quoted context omitted.

That’s not really a need for smartphone users. I can access an LLM on a website for free right now. I also don’t see any indication that there will be impactful local LLM silicon at the smartphone scale anytime soon.

You can yes, but the rumor is that Apple is focusing on adding them directly to your device, and if they integrate it deeply in the OS, then it will require the chips to run it. I’m sure you will be able to run old devices but without the latest Siri for example.

Can I get a user replaceable battery instead?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#178
I feel this is misleading as most iPhone users are totally aware that iPhone Models not running iOS 17 are not being actively updated.

The list is widely published: https://support.apple.com/guide/iphone/models-compatible-wit...

Any model more than 5 years old (Xr and Xs) are essentially not being updated and not secure. So an iPhone 1, 3, 5, 6, 7, 8 and X are all not secure and most people who use the iPhone are totally aware of this.

It's like writing an article that Windows 7 is insecure and Microsoft isn't patching it. This is essentially their policy in most cases.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#179

Earlier quoted context omitted.

It’s absolutely economical. Apple only has to support a tiny number of devices that they themselves manufactured, they have the easiest job in the world. Think about how many devices Microsoft has to support in Windows, it’s orders of magnitude more. Apple doesn’t want to support older devices because they don’t see a benefit to themselves. 5 years of support is pitifully short. Pretty much everything I own lasts lon…

[flagged]

>And its certainly NOT economical to keep stuff running forever. Look at OpenBSD and Theo famously begging for money to keep his basement of antique equipment running at enormous expense !

If OpenBSD can do it on a budget that's pocket change for Apple, with much more diverse hardware which they have no control over, then Apple definitely can do it.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#180

I feel this is misleading as most iPhone users are totally aware that iPhone Models not running iOS 17 are not being actively updated. The list is widely published: https://support.apple.com/guide/iphone/models-compatible-wit... Any model more than 5 years old (Xr and Xs) are essentially not being updated and not secure. So an iPhone 1, 3, 5, 6, 7, 8 and X are all not secure and most people who use the iPhone are tot…

According to the link Xs is supported.
Post reply on HN