Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

141–150 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#141
post #105

Earlier quoted context omitted.

If you want to develop applications (or run arbitrary code) on their stack, which they spend billions of dollars developing and maintaining, yes, it will cost you $100/year. Or you can get a free dev account, but the feature set it more limited and signatures are only good for 7 days. Apple charges money for features so that they remain in business to keep making more features, and security updates too. So it is, in…

> And signatures are only good for 7 days. And again, how does that restriction protect users? As I see it, it's entirely user-hostile: it ensures any self-created apps aren't really usable. If the limit was significantly longer, I would mostly shut up about all of this.

Who is this hypothetical person who can afford a Mac and the time to learn how to how to develop iOS applications and yet cannot afford $100 a year? Usually I'm all in favour of freedom, but I just can't see who's actually affected by this.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#142
post #108

Earlier quoted context omitted.

> Apple charging money for a feature does not protect users. The $99 is not likely to make them money. It is a token fee to protect the app store from the simplest spam and scam apps.

Sure, it's a mere token for Apple , but it is a significant, recurring financial and logistical hurdle for me when I simply want the ability to use my pocket computing/surveillance device -- which I've already paid for -- in ways I deem fit.

This is a pretty significant shifting of the goalposts.

The argument was users should have the ability to run whatever code they want on their iPhones. That is actually possible today.

It costs a $100/year, which considering the costs of the phones is pretty reasonable. Part of the reason it has to cost something non-trivial is because otherwise it would encourage massive piracy, which would devalue the entire App Store (in fact exactly what we see on Android).

If the argument is users should be able to run whatever code they want, but they also must have free access to the development tools and resources like Xcode and Dev Center (which cost how many tens or hundreds of millions to develop?) then you’ve totally lost me.

I understand and appreciate the principle that it should generally be possible to develop and run the programs of your choosing on smartphone-type hardware. In no way should a company be forced to spends millions of dollars to facilitate that at scale if that’s not their business model, particularly when it would primarily be used to directly attack their ecosystem.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#143
post #139

Earlier quoted context omitted.

Really? GNU/Linux doesn't thrive on billions and provides a near perfect functional alternative. Darwin/XNU is libre software, so it's a contradiction to make people pay for the right to program.

If you have a “near perfect functional alternative” then what exactly is the complaint? Demanding all software be free is also demanding the end to freedom. People want iOS to be more open because of the incredible value of iOS. Not because there’s an equivalent free alternative at hand they simply didn’t notice. > Darwin/XNU is libre software, so it's a contradiction to make people pay for the right to program. This…

>is the complaint?

That Apple's investment of billions into the ecosystem is not an argument I see valid, given the alternatives.

>all software must be free.

Heavens, that's not what I'm saying. I find it contradictory that Apple have open sourced an entire operating system and an entire kernel, and are kvetching over a mere privilege to begin approaching a distro of their OS. I'm not fighting the freedom fight, I'm in awe of the bait-and-switch they're employing.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#144
post #138

Earlier quoted context omitted.

Market share is an appreciable concern here. Macs haven't been more than 20% of the market for a long time. iPhones are a much larger market share, especially among affluent users. I don't think we'd see any widespread viruses, but there would certainly be a ton of people losing their financial info from their own irresponsibility.

So your argument is that because there are more users it needs to be more secure?

I think the argument is that if an OS has a tiny market share then it tends to be more open to 3rd party developers as a way to increase market share.

MacOS used to be a more developer friendly.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#145
post #142

Earlier quoted context omitted.

Sure, it's a mere token for Apple , but it is a significant, recurring financial and logistical hurdle for me when I simply want the ability to use my pocket computing/surveillance device -- which I've already paid for -- in ways I deem fit.

This is a pretty significant shifting of the goalposts. The argument was users should have the ability to run whatever code they want on their iPhones. That is actually possible today. It costs a $100/year, which considering the costs of the phones is pretty reasonable. Part of the reason it has to cost something non-trivial is because otherwise it would encourage massive piracy, which would devalue the entire App St…

> The argument was users should have the ability to run whatever code they want on their iPhones. That is actually possible today.

Technically possible, fine. But there's a big gulf between "possible" and "not extremely painful".

Let's say I create a personal fork of the open source Bitwarden password manager, to add some trivial quirk that makes the software better fit my life. How do you propose I actually use my custom version without paying Apple an extra $100 per year?

Every 7 days, my version of the app will suddenly refuse to launch, until I get back to my computer and re-sign it. I would need to create a weekly calendar reminder, and never go on vacation without a computer nearby. Oh, and I'd better not have more than three of these forks, because that's another limitation for free accounts.

The 7 day limit is not Apple refusing to provide "free access to the development tools", it's an artificial restriction explicitly created to make running un-blessed code impractical for more than rudimentary testing.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#146
post #120

Earlier quoted context omitted.

Well there aren't any great alternatives. The state of general computing (as parent puts it) is frustrating, and people talk about it, sometimes by switching from a related topic. It's venting. Are there more productive ways of dealing with this? Maybe; but seemingly part of the frustration is that the average consumer feels powerless. Even your meta-post could be classed as a way to deal with this frustration. And,…

but seemingly part of the frustration is that the average consumer feels powerless The average consumer could care less. They want to make phone calls, send text messages (over iMessage), surf Facebook, and take back to school pictures of their kids - and they just want it to work.

We need something similar to Godwin's law where anyone who argues that people don't care about something automatically loses the argument.

Of course people don't care more about iPhones than their own kids. Pick just about any X and people don't care more about X than their own kids.

That doesn't mean X doesn't matter, or people wouldn't care more about it if the understood it better, or wouldn't be better off if it was different, or that we shouldn't try to do something about it.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#147

Earlier quoted context omitted.

> And signatures are only good for 7 days. And again, how does that restriction protect users? As I see it, it's entirely user-hostile: it ensures any self-created apps aren't really usable. If the limit was significantly longer, I would mostly shut up about all of this.

Who is this hypothetical person who can afford a Mac and the time to learn how to how to develop iOS applications and yet cannot afford $100 a year? Usually I'm all in favour of freedom, but I just can't see who's actually affected by this.

Okay, here's a personal example:

Apple does not allow dictionary apps on the App Store which actually use the word definitions built into iOS—they are required to provide their own definitions, which either take up precious storage space or are not available offline.

So, I found some old WTFPL-licensed code on Github, spent an hour or so futzing around to make it compile and look pretty on iOS 12 (because I had no clue what I was doing), and came up with this: https://github.com/Wowfunhappy/Dictionary. It works super well, and I use it every day on my phone.

The only reason I can use this app is because I'm Jailbroken.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#148

Earlier quoted context omitted.

> And signatures are only good for 7 days. And again, how does that restriction protect users? As I see it, it's entirely user-hostile: it ensures any self-created apps aren't really usable. If the limit was significantly longer, I would mostly shut up about all of this.

Who is this hypothetical person who can afford a Mac and the time to learn how to how to develop iOS applications and yet cannot afford $100 a year? Usually I'm all in favour of freedom, but I just can't see who's actually affected by this.

It's the person who doesn't know how to do that yet. Most people don't get started in software development by writing their own operating system kernel. They're using an existing application with published source code and want to make a little change. It's an ugly hack written by a teenager, they just want to use it for themselves. They'll get better at it as they do it more.

But now you say they have to buy a Mac and pay $100/year. Well, that's a no for that little initial change, so now they never get started to begin with.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#149
post #59
post #48

Earlier quoted context omitted.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

If people do that, that's on them. So long as the device appropriately warns people, I fail to see how it's the companies problem to baby people who don't know what they're doing. It's their device, if they want to break out, let them. It's like saying "Why should we have knives? It's only a matter of time until $popular_social_media comes along and tells people to cut off their index fingers and before long there's…

A lot of tools have safety measures which can't be circumvented by their users (e.g., you have to use both hands to start thems). The reason being that some dangers are easily underestimated, even by experienced users. Manufacturers do indeed much better about the inherent risks of their products than users.

If a knive could be built which allows to cut food, and protects you from cutting off your index finger, wouldn't that be great?

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#150
post #138

Earlier quoted context omitted.

Market share is an appreciable concern here. Macs haven't been more than 20% of the market for a long time. iPhones are a much larger market share, especially among affluent users. I don't think we'd see any widespread viruses, but there would certainly be a ton of people losing their financial info from their own irresponsibility.

So your argument is that because there are more users it needs to be more secure?

My argument is primarily that if somebody is looking to infect users, are they going to target the 86%, or the 13%? Macs have benefited for years by largely not being targeted by the majority of malware developers. If mobile devices open the walled garden, you get something similar to android's malware issues at best.
Post reply on HN