Live data from Hacker News

About the security content of iOS 12.4.9

support.apple.com

121–130 of 177 posts

Re: About the security content of iOS 12.4.9

#121

I'd like to give kudos to Apple for including the iPhone 5S in this security update, which was released on September 20, 2013, over 7 years ago! Supporting a product for even 3 years is rare in the smartphone world.

My 8 (or 10?) year old AppleTV just got an update today. I was excited because the YouTube app pause function stopped working after the previous update a couple of weeks ago. Alas the problem remains.

Re: About the security content of iOS 12.4.9

#122

Earlier quoted context omitted.

I think this is a bad decision. The "in-the-wild" part is the interesting part because it is not the norm at all and it implies an interesting story.

It's an idiosyncrasy of the site that we avoid highlighting things in titles ("stories are community property, and submitting one doesn't give anyone the right to editorialize them"). I agree that the title we ended up with is suboptimal! "Exploitable" is a word I'd have been comfortable seeing there. But you take the good with the bad with the HN title rule; the site is primarily about discussion, not about being a…

[deleted]

Re: About the security content of iOS 12.4.9

#123
post #117

Earlier quoted context omitted.

So use the last sale date for both. Your point makes no sense.

Galaxy S8 on sale at Walmart, Staples, and NewEgg. Likely falls off support in 3-4 months. So Android flagships are close to zero or even negative support time?

This is what got me to finally switch to Apple. Updates take forever. I bought a Samsung off Amazon for testing and for some reason I still have to wait on T-Mobile. And then after a year, maybe two, there just aren’t anymore updates.

Re: About the security content of iOS 12.4.9

#124
post #103

Earlier quoted context omitted.

In the US, iOS has the majority of market share at 52.4%, and Android has 47%[1]. [1] https://www.statista.com/statistics/266572/market-share-held...

The US isn't representative of the rest of the world in this regard. That's why any discussion of iMessage is filled with half the people arguing that iMessage it the best thing since sliced bread (Americans) and the other half saying they never use it.

Do Americans really represent half of smart phone users? I would though it to be smaller than that given the population of the planet.

Re: About the security content of iOS 12.4.9

#125
post #122

Earlier quoted context omitted.

It's an idiosyncrasy of the site that we avoid highlighting things in titles ("stories are community property, and submitting one doesn't give anyone the right to editorialize them"). I agree that the title we ended up with is suboptimal! "Exploitable" is a word I'd have been comfortable seeing there. But you take the good with the bad with the HN title rule; the site is primarily about discussion, not about being a…

[deleted]

[deleted]

Re: About the security content of iOS 12.4.9

#127
post #11

Earlier quoted context omitted.

We've changed the title above to that of the page. (Submitted title was "Apple releases iOS 14.2 and 12.4.9, fixing in-the-wild exploited vulnerabilities".)

I think this is a bad decision. The "in-the-wild" part is the interesting part because it is not the norm at all and it implies an interesting story.

Happy to change it to a better title, i.e. something more accurate and neutral. We're particularly happy to do that with corporate press releases, which often deliberately obscure the situation. But usually that requires a suggestion (and at least partial consensus) from users who understand the story.

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

Re: About the security content of iOS 12.4.9

#128

Earlier quoted context omitted.

Apple uses this metric as well[1]. If something hasn't been sold by Apple for 5 years (but less than 7 years), it's considered vintage and you can still get hardware service and certain critical software fixes, though not necessarily any new features. The support for MacBooks is actually great. Certain Late 2013 and Mid 2014 Retina MacBook Pros, while considered vintage, will be receiving the Big Sur update[2]. 1. ht…

> The support for MacBooks is actually great. Certain Late 2013 and Mid 2014 Retina MacBook Pros, while considered vintage, will be receiving the Big Sur update. I think it's more likely that Apple's new frameworks don't require any fancy hardware features that aren't available in the Late 2013 MacBook Pros.

> I think it's more likely that Apple's new frameworks don't require any fancy hardware features

Mojave and higher isn’t “supported” on the cheese grater Mac Pro’s despite it running more than fine, including with FileVault 2 enabled on the boot volume (which an Apple exec tried to claim was technically not possible).

Re: About the security content of iOS 12.4.9

#129
post #60
post #17

Earlier quoted context omitted.

Is that still the case? The article implies that before it was written that wasn't the case previously.

Does it matter? A full-chain zero-click remote complete compromise for either system is only $2-3 million. That is absolute chump change. 4-6% of households in the US [1], 5-8 million households, have sufficient assets to fully compromise every iPhone or Android in the world. If we consider businesses, I bet that is within the reach of no less than 50% of the businesses (including small businesses) in the US. That is…

If bad actors could derive $10 on average from 1MM phones, vulnerabilities would cost substantially more than $2-3MM.

Re: About the security content of iOS 12.4.9

#130
post #116

Earlier quoted context omitted.

Yes? That sounds about right.

Which makes it kind of a pointlessly obtuse metric. To claim a device has negative months of support.

It's accurate, though. When I am evaluating devices to buy, a metric I care about is "after I buy this, how long will it remain up-to-date with security patches?" And the answer to that question is "on the day that you buy it, it is already several months behind on security patches and will not improve." That metric is not the be-all-end-all of support, but is meaningful, and low or negative values have the correct interpretation in that context.
Post reply on HN