Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

151–160 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#151
post #142

Earlier quoted context omitted.

This is a pretty significant shifting of the goalposts. The argument was users should have the ability to run whatever code they want on their iPhones. That is actually possible today. It costs a $100/year, which considering the costs of the phones is pretty reasonable. Part of the reason it has to cost something non-trivial is because otherwise it would encourage massive piracy, which would devalue the entire App St…

> The argument was users should have the ability to run whatever code they want on their iPhones. That is actually possible today. Technically possible, fine. But there's a big gulf between "possible" and "not extremely painful". Let's say I create a personal fork of the open source Bitwarden password manager, to add some trivial quirk that makes the software better fit my life. How do you propose I actually use my c…

It sounds like the problem you have isn't that it's not possible, but that it's not free (as in beer).

The free account is good for playing around with the environment and learning how to write code for iOS. It is not well suited for running production software on your phone. If you want to run production software on your phone, blessed or unblessed, you probably want to pay Apple $100/yr for the longer duration and higher app limit.

In my opinion, if you could do what you wanted for free, it would contribute massively to app piracy, and devalue the work of millions of developers on the App Store. $100/year is at about the right level to dissuade most people from circumventing the App Store (the average Apple user spends ~$75/year on the App Store).

> ...it's an artificial restriction explicitly created to make running un-blessed code impractical for more than rudimentary testing.

Crucially, paying Apple $100/year does not mean they ever see or have to bless code you deploy to your own devices. It just removes the limits in the development environment!

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#152

Earlier quoted context omitted.

Who is this hypothetical person who can afford a Mac and the time to learn how to how to develop iOS applications and yet cannot afford $100 a year? Usually I'm all in favour of freedom, but I just can't see who's actually affected by this.

Okay, here's a personal example: Apple does not allow dictionary apps on the App Store which actually use the word definitions built into iOS—they are required to provide their own definitions, which either take up precious storage space or are not available offline. So, I found some old WTFPL-licensed code on Github, spent an hour or so futzing around to make it compile and look pretty on iOS 12 (because I had no cl…

You spent the time to Jailbreak the phone, but couldn't you also have just paid $100/year for the license to be able to build your own personal apps which can be deployed on your personal devices for 1 year at a time?

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#153
post #139

Earlier quoted context omitted.

If you have a “near perfect functional alternative” then what exactly is the complaint? Demanding all software be free is also demanding the end to freedom. People want iOS to be more open because of the incredible value of iOS. Not because there’s an equivalent free alternative at hand they simply didn’t notice. > Darwin/XNU is libre software, so it's a contradiction to make people pay for the right to program. This…

>is the complaint? That Apple's investment of billions into the ecosystem is not an argument I see valid, given the alternatives. >all software must be free. Heavens, that's not what I'm saying. I find it contradictory that Apple have open sourced an entire operating system and an entire kernel, and are kvetching over a mere privilege to begin approaching a distro of their OS. I'm not fighting the freedom fight, I'm…

I think they are trying to protect a billion dollar ecosystem which is their App Store.

Apple's App Store earns developers something like 50%+ more revenue than equivalent apps on Android. No small part of that is due to the ease of piracy on Android.

I do not see any contradiction, nor any "bait-and-switch". The operating system and a kernel are not the services engine which keeps their company running. Open sourcing that code doesn't imperil their primary revenue streams.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#154

Earlier quoted context omitted.

but seemingly part of the frustration is that the average consumer feels powerless The average consumer could care less. They want to make phone calls, send text messages (over iMessage), surf Facebook, and take back to school pictures of their kids - and they just want it to work.

We need something similar to Godwin's law where anyone who argues that people don't care about something automatically loses the argument. Of course people don't care more about iPhones than their own kids. Pick just about any X and people don't care more about X than their own kids. That doesn't mean X doesn't matter, or people wouldn't care more about it if the understood it better, or wouldn't be better off if it…

If we polled all smartphone owners and asked them how much they would pay to be able to own their phone in the way that Stallman owns his computer I'd bet a large amount of money that the median would be 0 cents and the average would be less than 1 cent. This isn't just a question of caring less. The huge majority of users do not care at all about this.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#155
post #59
post #48

Earlier quoted context omitted.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

If people do that, that's on them. So long as the device appropriately warns people, I fail to see how it's the companies problem to baby people who don't know what they're doing. It's their device, if they want to break out, let them. It's like saying "Why should we have knives? It's only a matter of time until $popular_social_media comes along and tells people to cut off their index fingers and before long there's…

"Appropriately warns people" is nearly impossible and shouldn't be brushed away as a non issue.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#156

Please excuse the tinfoil hat - is there any chance that this vulnerability was reintroduced at the request of the Chinese government to allow easier access to Hong Kong protesters devices?

Cool! My first negative post. Maybe more context is valuable.

We know HKers are getting more and more tracking from the mainland government and are switching to applications not typically used for communication and organization. https://www.businessinsider.com/hong-kong-youth-using-tinder...

We also know that Apple has accommodated Chinese government requests to increase their ability to monitor communications: https://boingboing.net/2018/05/21/apple-bends-to-chinese-gov...

And as one of the most valuable companies in the world that ships software, it is surprising to see regressions in their software.

The article said that right now legitimate applications on the App Store could contain jailbreak code.

Of course these things are entirely possible to be unrelated, which is why I mentioned the tongue in cheek “tinfoil hat”.

The timeliness of the response from Apple in patching this reintroduced vulnerability should be swift. If so, I’m happy to step away from this position entirely.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#157
post #30

Earlier quoted context omitted.

That idea is stupid in itself. The whole of civilization has been a process of shielding people from having to know stuff. The same way you don't know how to make fire from first principles, fix your car, make a CPU, or whatever... Even someone with a Ph.D in computer hardware is shielded from tons of complexities and never has to know the whole process end to end.

But they are allowed to learn, which Apple doesn't want you to do. They could make it so your mom doesn't get root by accident, but you would still have the right to do so.

I have a food processor that won't run unless fully assembled and locked. Is that anti consumer?

My coffee grinder won't turn on without the lid locked in place. Is that anti consumer?

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#158
post #152

Earlier quoted context omitted.

Okay, here's a personal example: Apple does not allow dictionary apps on the App Store which actually use the word definitions built into iOS—they are required to provide their own definitions, which either take up precious storage space or are not available offline. So, I found some old WTFPL-licensed code on Github, spent an hour or so futzing around to make it compile and look pretty on iOS 12 (because I had no cl…

You spent the time to Jailbreak the phone, but couldn't you also have just paid $100/year for the license to be able to build your own personal apps which can be deployed on your personal devices for 1 year at a time?

Well, that's not why I Jailbroke my phone. I Jailbroke my phone so I could:

• Install a Userscript to de-AMP pages in Google search results.

• Prevent Apple News from saving a history of what articles I read, thus disabling their recommendation engine and preventing a filter bubble.

• Add an extra row of app icons to my homescreen, so I can fit all my apps on one page.

• Get a warning when I set an alarm for PM rather than AM.

...and countless other little things.

Separately, I consider $100 an awful lot of money, especially for a subscription, which I try really hard to keep out of my life.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#159

Earlier quoted context omitted.

I'm not sure Google really belongs here. Telcos and some companies licensing Android - sure. But unlocking actual Google phones, like Pixel, is literally available from the menu in the developer settings. It's a well known/documented process.

It does. Unlocking and gaining elevated privileges through rooting trips Google's SafetyNet API which will lock you out of many apps and/or features. It also breaks your device's Widevine certification so you can't watch DRM-protected video from many services. As for the "We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent.", with stock Andro…

That's a different question. You own the device. Now you are demanding that other services interact with your device regardless of how it is configured.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#160
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

Goodness me it gets tiring seeing a post like this every time an article about iOS comes up. It's a legitimate point to make, but it should rather be that we talk about the content of the article rather than bring out the 'Apple's taking our freedom away' soapbox. It inevitably turns into a debate between one side who values personal freedoms but won't be told to buy Android phones widespread safety, security, and pr…

[deleted]
Post reply on HN