Live data from Hacker News

About the security content of iOS 12.4.9

support.apple.com

131–140 of 177 posts

Re: About the security content of iOS 12.4.9

#131
post #16
post #13

Earlier quoted context omitted.

The 5S is still the perfect iPhone.

How do you still have one that's running OK? My Apple products almost always "die" after a few years. I had the 5S but one day it crashed and would not turn back on no matter what I did. The iPhone I had before that did the same thing.

I believe you but I've honestly never heard of anybody suffering "random cellphone death" - Apple or otherwise. Everybody seems to break them or upgrade them long before that.

Re: About the security content of iOS 12.4.9

#132
post #117

Earlier quoted context omitted.

So use the last sale date for both. Your point makes no sense.

Galaxy S8 on sale at Walmart, Staples, and NewEgg. Likely falls off support in 3-4 months. So Android flagships are close to zero or even negative support time?

That sounds dangerous to me.

Re: About the security content of iOS 12.4.9

#133
post #117

Earlier quoted context omitted.

Galaxy S8 on sale at Walmart, Staples, and NewEgg. Likely falls off support in 3-4 months. So Android flagships are close to zero or even negative support time?

That sounds dangerous to me.

They have no legal requirement to update. Its also not a bait and switch, they have done this for a decade now. By an iphone if you want updates.

Re: About the security content of iOS 12.4.9

#134
post #22

Earlier quoted context omitted.

If only Google could put this much effort into supporting its own Pixel devices, which stop getting updates to the base OS after just three years.

I promise you, people inside google are equally frustrated with this unjustifiable top-down decision. (am Xoogler)

I know a google dev who says they wouldn't trust the security of an Android phone as far as they could throw it.

Re: About the security content of iOS 12.4.9

#135
The problem with these updates is that it's only for devices that can only support up to iOS 12 (in this case) - if you have another device that supports anything higher but don't want upgrade to the latest iOS, you still won't get these iOS 12 security updates - they force you to upgrade the entire OS to get them.

Re: About the security content of iOS 12.4.9

#136

Earlier quoted context omitted.

> The support for MacBooks is actually great. Certain Late 2013 and Mid 2014 Retina MacBook Pros, while considered vintage, will be receiving the Big Sur update. I think it's more likely that Apple's new frameworks don't require any fancy hardware features that aren't available in the Late 2013 MacBook Pros.

> I think it's more likely that Apple's new frameworks don't require any fancy hardware features Mojave and higher isn’t “supported” on the cheese grater Mac Pro’s despite it running more than fine, including with FileVault 2 enabled on the boot volume (which an Apple exec tried to claim was technically not possible).

> Mojave and higher isn’t “supported” on the cheese grater Mac Pro

The 2010 and 2012 Mac Pros officially support Mojave with a compatible video card:

Install macOS 10.14 Mojave on Mac Pro (Mid 2010) and Mac Pro (Mid 2012) https://support.apple.com/en-us/HT208898

Re: About the security content of iOS 12.4.9

#137
post #60

Earlier quoted context omitted.

Does it matter? A full-chain zero-click remote complete compromise for either system is only $2-3 million. That is absolute chump change. 4-6% of households in the US [1], 5-8 million households, have sufficient assets to fully compromise every iPhone or Android in the world. If we consider businesses, I bet that is within the reach of no less than 50% of the businesses (including small businesses) in the US. That is…

If bad actors could derive $10 on average from 1MM phones, vulnerabilities would cost substantially more than $2-3MM.

Not really. That is only looking at the demand-side of a supply-demand relationship. Buyers will obviously prefer a cheaper vulnerability with a comparable effect to a more expensive one, so if vulnerabilities are easy to find at a price point where it is profitable to sell them at $2-3MM, then any finder who charges a lower price than others will be more attractive to buyers. This selling competition can easily drive the price down until it is much lower than the potential upside to a buyer of $10MM with a lower bound of the actual cost of discovery (which I already postulated is low enough that $2-3MM is profitable given that Zerodium is able to acquire vulnerabilities for that price) since anything less than the actual cost of discovery is unprofitable. This is the same reason why water is cheap even though it is absolutely essential to human life, it is plentiful and easy to acquire so suppliers compete on price driving it down to a a value much closer to the cost of acquisition rather than the maximal upside to the buyer assuming no other alternatives are present.

Re: About the security content of iOS 12.4.9

#139

Earlier quoted context omitted.

You're going from a 5s to a Pro Max? That's almost a jump across product categories... like switching from an iPhone to an iPad Mini.

Or from a Commodore 64 to a first-generation iMac.

I remember the first generation imac, but i dont remember them being that bad.

Re: About the security content of iOS 12.4.9

#140

Earlier quoted context omitted.

I promise you, people inside google are equally frustrated with this unjustifiable top-down decision. (am Xoogler)

I know a google dev who says they wouldn't trust the security of an Android phone as far as they could throw it.

I know an apple dev who thinks the same about their product, lol.
Post reply on HN