Earlier quoted context omitted.
It's all tempered by them ultimately controlling what you can put on your phone though. As was demonstrated in LA, it's starting to have significant civil rights consequences.
Security is pointless if platform allows 90% users to be social engineered into running code disabling that security
Apple Platform Security (Jan 2026) [pdf]
101–110 of 205 posts
Re: Apple Platform Security (Jan 2026) [pdf]
#102Earlier quoted context omitted.
For some reason they don't release userdebug versions which was a dealbreaker for me.. (the device should be secure, but not against me) But if you wish to build it from source, it could probably be a good option.
You can re-sign it using https://github.com/chenxiaolong/avbroot I don't currently have any root on the phone, but I reserve the right to add it or run the userdebug build at a later date
I fully agree with your original comment - AOSP security model is NOT a proper solution to the security problem, and I'd add to it that it was also designed to be anticompetitive - Google can do what third party apps can't.
Android architecture is tainted by Google's business model and it shouldn't be used as an example of a secure operating system..
Re: Apple Platform Security (Jan 2026) [pdf]
#103Earlier quoted context omitted.
Apple is an ad company now though
Apple's ad revenue was 1% of its total in 2024. It was estimated to be 2-3% in 2025. https://www.apple.com/newsroom/pdfs/fy2024-q4/FY24_Q4_Consol... https://www.macrumors.com/2025/10/30/apple-4q-2025-earnings/
Re: Apple Platform Security (Jan 2026) [pdf]
#104Re: Apple Platform Security (Jan 2026) [pdf]
#1051. Constant popups about "application requesting access" on macOS. That often happens without any user's activity.
2. If you leave the permission popup open for some time (because it's on a different screen), it auto-denies. And then you won't be able to find ANY mention of it in the UI.
3. macOS developers can't be assed to fix mis-features, like inability to bind low ports to localhost without having root access (you can open any listening port on 0.0.0.0 but you can't open 127.0.0.1:80).
Re: Apple Platform Security (Jan 2026) [pdf]
#106Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.
Re: Apple Platform Security (Jan 2026) [pdf]
#107Earlier quoted context omitted.
Apple is an ad company now though
Apple sells some ads yes. But it’s a tiny fraction of their revenue. Would Google or Meta go bankrupt if they stopped selling ads? Yes. Apple wouldn’t.
Re: Apple Platform Security (Jan 2026) [pdf]
#108Earlier quoted context omitted.
Apple is an ad company now though
Apple's ad revenue was 1% of its total in 2024. It was estimated to be 2-3% in 2025. https://www.apple.com/newsroom/pdfs/fy2024-q4/FY24_Q4_Consol... https://www.macrumors.com/2025/10/30/apple-4q-2025-earnings/
That’s 20% of their profit
Re: Apple Platform Security (Jan 2026) [pdf]
#109Apple's commitment to privacy and security is really cool to see. It's also an amazing strategic play that they are uniquely in the position to take advantage of. Google and Meta can't commit to privacy because they need to show you ads, whereas Apple feels more like a hardware company to me.
modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…
It would be bad PR for Apple if everybody constantly kept losing their messages because they had no way to get back into their account.
Re: Apple Platform Security (Jan 2026) [pdf]
#110No mention of Pegasus and other software of such sort. Can latest iOS still be infected? There is no point creating such document if elephant in the room is not addressed.
That doesn't seem like avoiding the elephant in the room to me. It seems like very much acknowledging the issue and speaking on it head-on.