Earlier quoted context omitted.
Most people don't even know how to install an OS. I wouldn't expect the typical person to be able to do it.
Moot point. Both Microsoft and Apple expected the user to install their own OS in the past, and the world didn't explode because of it. If stuff like UEFI and bootloader unlocking was standard again, OS installation would be easy as plugging in a dongle and rebooting. Plus, you still haven't touched the central point; tightly coupled software and hardware creates more e-waste. What people do today doesn't matter if t…
No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
231–240 of 242 posts
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#232Earlier quoted context omitted.
FYI that is exactly what Microsoft proclaimed back in the day. Doesn't sound better today does it? At least on Windows they didn't prevent you from installing a different browser.
Windows and Android both come with a "built-in" browser: Windows still ships Internet Explorer for rendering some old components, although I think they are moving to Edge (chromium) based web view. I can't find a better source right now, but something to start with: https://www.reddit.com/r/Windows11/comments/11n79xc/why_does... Android has a chromium based WebView that ships with the system and is updated via Play S…
My 10 year old android phone still runs the latest versions of both Chrome and Firefox.
Androids WebView being on the play store even allows that part of the system to be updated independently of the OS.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#233Earlier quoted context omitted.
Not when you can load an OS like Calyx [0], GrapheneOS [1] or LineageOS [2]. In this context the iPhone ends up the true "hope for the best" option. The original Pixel / Pixel XL (2016.10.04) can still run the latest LineageOS with current patches [3]. [0] https://www.lineageos.org/ [1] https://grapheneos.org/ [2] https://calyxos.org/ [3] https://download.lineageos.org/devices/sailfish/changes
I was responding to the parent who recommended using unpatched, out of support Android. People who’re comfortable (or can be bothered) installing alternative OSes on their phones have an entirely different view on device obsolescence. Statistically they’re also a rounding error in the total mobile-using population.
Understood, but that has no bearing on the point being argued. You have no control over Apple IOS hardware after Apple stops supporting it. The fact that there is that "rounding error" is good for everyone as it is a force against closing that ecosystem which currently exists. It matters.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#234Earlier quoted context omitted.
Is it really bullshit? Lenovo manages hundreds of laptop models via fwupd, and those work just fine after they lose OEM support. I've got a Thinkpad from 2009 that still gets modern Linux patches (to say nothing of my 2006 PowerBook running Arch/Plasma 5). Compared to what Apple makes off hardware and service revenue, the cost of opening iBoot and providing basic firmware support would be almost nothing. It's so econ…
> Compared to what Apple makes off hardware and service revenue Really I wish people would wake up and stop with this bullshit. Do the other manufacturers do anywhere near as much R&D as Apple does ? NO ! (2023: Lenovo 2bn vs Apple 29bn). Do the other manufacturers maintain their own OS across multiple hardware platforms ? NO ! Its easy to sit in your armchair and spout crap about "well, Lenovo does it !". Well, the…
I almost feel like you don't actually know what you're arguing against. An optionally-open bootloader is practically free to implement, and releasing driver code (or at least hardware docs) would mostly be an IP-related decision, not an effort-gated one. As-is, it feels like you're defending Apple's right to enforce petty limitations and be lazy with their trillion-dollar IP. It should be obvious why we (former Apple customers, some of us) disagree.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#235Earlier quoted context omitted.
Moot point. Both Microsoft and Apple expected the user to install their own OS in the past, and the world didn't explode because of it. If stuff like UEFI and bootloader unlocking was standard again, OS installation would be easy as plugging in a dongle and rebooting. Plus, you still haven't touched the central point; tightly coupled software and hardware creates more e-waste. What people do today doesn't matter if t…
Apple fans would say tightly coupled software and software is why Apple products are better than competitors. I don't fully agree but I can see the point.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#236I feel this is misleading as most iPhone users are totally aware that iPhone Models not running iOS 17 are not being actively updated. The list is widely published: https://support.apple.com/guide/iphone/models-compatible-wit... Any model more than 5 years old (Xr and Xs) are essentially not being updated and not secure. So an iPhone 1, 3, 5, 6, 7, 8 and X are all not secure and most people who use the iPhone are tot…
I have been a developer and nerd since 25 years, and I always expected that Apple also patches some previous versions. E.g. around a week ago they released both iOS 17.2.1 and iOS 16.7.4: https://support.apple.com/en-us/HT201222 So why should I assume that latest iOS 16 isn't completely patched? I think it's a shame to say at least that Apple has no public policy of how which OS versions are supported and which are n…
I think if something is a relatively easy fix and high severity that they will fix it. I don't think they view security updates as a tool to force people to buy new products. The low hanging fruit for large numbers of users gets fixed. The underlying software however, should not be trusted or viewed as secure.
Even though these applications are bundled with the operating system, they are probably separate code bases and if they believe the patch can be accomplished across the versions with minimal work like fixing the same line of code in the old version it probably goes out. If they have to do a major overhall of the old operating system and port the new browser version to the old software, it probably doesn't.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#237Earlier quoted context omitted.
It probably does let you grab cookies and browsing history from Chrome, though.
> probably I wish the author included a full proof of concept
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#238Earlier quoted context omitted.
This bug touches nothing hardware specific. In alternative timeline where mobile OSes arent fisher price parodies of proper operating systems, they could push the same image to all iphones and have a proper hardware abstraction layer take care of the specific details. There is nothing fundamentally incompatible about the last couple of generation of iphones. ARMv8 CPU, PowerVR derived GPU. If the mobile computing spa…
It’s not economical to support devices used by less than 1% of the user base. Linux only manages it because community members step up to support older architectures. And sometimes when no one steps up the architectures are removed. - Linux dropping support for old graphics drivers (Nov 2023) - https://www.phoronix.com/news/Linux-Drop-Old-UMS-DRM-Infra - Linux Kernel Developers Discuss Dropping A Bunch Of Old CPUs (Ja…
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#239Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#240Earlier quoted context omitted.
As much as the sales of healing crystals tells me how much people value the health and anti-aging benefits of those.
Healing crystals seems to be a much smaller market (to the point of barely existing) than “Big Pharma”, so your analogy doesn’t really make sense.