Live data from Hacker News

About the security content of iOS 12.4.9

support.apple.com

141–150 of 177 posts

Re: About the security content of iOS 12.4.9

#141
post #38

Earlier quoted context omitted.

until Apple throttles the hardware with their software updates [1] https://www.theverge.com/2020/7/13/21322867/apple-iphone-bat...

This is just great, and you see why it's so hard to be a product manufacturer. Not only does the person not understand why it was done, and that it produced a phone that would be functional for longer lifetime than if it hadn't been implement, but he also continues spreading unhelpful information to others.

>but he also continues spreading unhelpful information to others.

They were forced to pay over 500 Million Dollars for doing it

Re: About the security content of iOS 12.4.9

#142
post #98
post #38

Earlier quoted context omitted.

until Apple throttles the hardware with their software updates [1] https://www.theverge.com/2020/7/13/21322867/apple-iphone-bat...

I turned off this feature when they shipped the option and promptly turned it back on. I use Apple because they make reasonable decisions instead of requiring endless configuration, and they made the right decision here. The lawsuit feels like pure power politics... Apple can handle the cost, I don’t feel bad for them or anything, but I see it as a pure money grab rather than any culpability for Apple.

>I turned off this feature when they shipped the option and promptly turned it back on.

They didn't add that option until AFTER being caught

Re: About the security content of iOS 12.4.9

#143
post #127

Earlier quoted context omitted.

I think this is a bad decision. The "in-the-wild" part is the interesting part because it is not the norm at all and it implies an interesting story.

Happy to change it to a better title, i.e. something more accurate and neutral. We're particularly happy to do that with corporate press releases, which often deliberately obscure the situation. But usually that requires a suggestion (and at least partial consensus) from users who understand the story. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

Yeah, Apple's page titles generally suck, especially when they are presented without context. The big things in this one is that they're pushing fixes to devices that people had considered abandoned for almost two years, and that these fixes explicitly mention that they have been exploited in the wild in what I believe is Apple's second admission of this, and the first time they did so without blaming Google Project Zero of a mischaracterization. That's clearly a bit too much to put in a title, but something like "Apple releases iOS 12.4.9, backporting fixes for severe security vulnerabilities". I'd like to put "exploited in the wild" in there somewhere as well since I think it's an important part of the story, but I am not sure if this would keep it neutral.

Re: About the security content of iOS 12.4.9

#144
post #7

Note that there are similar issues in macOS, too. https://support.apple.com/en-us/HT211947 <-- Catalina 10.15.7 Supplemental Update notes

But nothing for macOS 10.14.x, oddly.

Catalina runs on all Macs that support Mojave, which I assume influenced the decision. (I didn't see an iOS 13 update, which helps bolster this theory.)

Re: About the security content of iOS 12.4.9

#145
post #137

Earlier quoted context omitted.

If bad actors could derive $10 on average from 1MM phones, vulnerabilities would cost substantially more than $2-3MM.

Not really. That is only looking at the demand-side of a supply-demand relationship. Buyers will obviously prefer a cheaper vulnerability with a comparable effect to a more expensive one, so if vulnerabilities are easy to find at a price point where it is profitable to sell them at $2-3MM, then any finder who charges a lower price than others will be more attractive to buyers. This selling competition can easily driv…

Zerodium is not generally paying out $2MM for vulnerabilities and the people who acquire vulnerabilities from Zerodium aren't monetizing them directly off the installed base of phones.

An important thing to know about the market for these things is that the "clearing price" of an exploit chain is usually a cap, not an actual price; you're paid in tranches, until the vulnerability is burned. You're hoping it isn't burned before all your tranches are paid.

That has implications for the hypothetical business model you've proposed.

Re: About the security content of iOS 12.4.9

#146
post #39

Earlier quoted context omitted.

Wouldn't last official sale date be a better indicator of true device support? For example if someone bought it in an Apple store on the last day available, how long period would they have received updates for? For example in mid 2017 it was still officially sold by Apple in India (source: https://www.iphonehacks.com/2017/05/apple-iphone-5s-iphone-s... ).

Comparatively, no. Android phones generally get a maximum of 3 years of security updates from launch, not from last device sale date. So, within mobile phones, it's more informative to compare it to their competition. It shows you just how much better Apple is at mobile device support compared to everyone else.

Well, you still get updates through the store way longer than 3 years. With more and more components (e.g. the browser) coming through the store, the picture is not as black and white anymore.

Re: About the security content of iOS 12.4.9

#147
post #117

Earlier quoted context omitted.

Galaxy S8 on sale at Walmart, Staples, and NewEgg. Likely falls off support in 3-4 months. So Android flagships are close to zero or even negative support time?

This is what got me to finally switch to Apple. Updates take forever. I bought a Samsung off Amazon for testing and for some reason I still have to wait on T-Mobile. And then after a year, maybe two, there just aren’t anymore updates.

Samsung makes superb hardware but they're clearly not at ease with software, it always feels like an afterthought.

If they were serious about competing with Apple software is where they should focus.

Re: About the security content of iOS 12.4.9

#148
post #87

Earlier quoted context omitted.

Apple uses this metric as well[1]. If something hasn't been sold by Apple for 5 years (but less than 7 years), it's considered vintage and you can still get hardware service and certain critical software fixes, though not necessarily any new features. The support for MacBooks is actually great. Certain Late 2013 and Mid 2014 Retina MacBook Pros, while considered vintage, will be receiving the Big Sur update[2]. 1. ht…

I have a Mid-2014 RMBP, there's nothing wrong with it at all. It's sad to think OS support may be dropped in the next few years.

Yes, we're bombarded with guilt messages about us destroying the planet but even when we want to do the right thing there's no path available.

I have an old Samsung tablet that doesn't work anymore. I could try to change the battery for 20€ or buy the cheapest tablet on Amazon for 40€

Re: About the security content of iOS 12.4.9

#149
post #75

Earlier quoted context omitted.

The list of old Apple devices that still work well is impressive: I still have one original iPad, an iPhone 3GS, several iPhone 4. Same goes for the more recent ones, with the exception of the few devices that I dropped on hard floors over the last 10 years...

Still have a first-generation iPod Touch running iOS 3. Works like a charm, can even download some apps from the App Store. Bit of a shock how both primitive and advanced the early versions of iOS were.

I had an iPad 1 running iOS 5 I think, but in the end I stopped using it because Safari would "crash" on most websites due to it running out of ram I guess.

IIRC there's 128M of ram on the fist iPad.

Re: About the security content of iOS 12.4.9

#150
post #22

Earlier quoted context omitted.

If only Google could put this much effort into supporting its own Pixel devices, which stop getting updates to the base OS after just three years.

Depending on your usecase, GrapheneOS may be of interest.

No support for Pixel 1, Pixel 2 are marked as obsolete, so I'm not sure it's better than Google as far as EOL is concerned.

https://grapheneos.org/releases

Post reply on HN