Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

41–50 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#41
post #27
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

Or, you know, buy something else. Before the"locked devices, people had the inverse problem: everything was two open ended and complicated, could cripple the system, stuff was open for exploit (much more so than in this case of unpatched vulnerability, viruses were everyday occurence). Techies didn't have this issue, but the general public did (heck, even techies did suffer somewhat). And that might have been OK for…

> Whereas you can give a 2-year old an iPad, and they can start using it just fine...

That's because this new devices aren't "secure" but severely limited and crippled, you can't do much with them and they are far from actually usable like a computer. By that metric, my old Nokia was even more secured than an iPhone.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#42
post #14
post #13

Earlier quoted context omitted.

Do you consider https://download.lineageos.org/ a questionable source?

I do not, but you have to be lucky enough to have a device that is supported by LineageOS, or you need to spend time learning the skills to build a custom ROM for your device. Why isn't there an option in developer mode that gives us a root shell on our Android devices? Why is an escape hatch that gives back control to the user so frightening for these companies?

You don't need a custom ROM to get root on Android, you just have to unlock the bootloader and replace the "su" executable. Moto (aka Lenovo) devices can be unlocked without exploits using their online tool, for example.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#43
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

Don't forget about Telcos.

Your AT&T, Vodafone, Verizon & Co, put an enormous amount of pressure on Apple to limit and protect device unlocking.

This is a cat & mouse situation where either party might benefit from tight unlocking controls.

For example, MVNOs benefit from manufacturers with flexible and open unlocking policies that make it easy to unlock devices (without approval from the original operator), whereas long-term commitment contracts with traditional operators want to make it as hard as possible for you to leave with an unlocked device (regardless of whether you are legally entitled to or not - but that's a different story).

The economics of whether Apple would benefit from less strict unlocking policies (ignoring Telco's wishes) are not that clear.

You might think that unlocked devices would have longer lives, and therefore limit Apple's ability to push a new one to you, but you could also say that giving phones 2 or 3 different owners in their lifespans could help with app store purchases, limiting jailbreaking and possibly avoiding going with a newer less expensive android version.

Disclaimer: We unlock phones for MVNOs and individuals who get bullied around by their telcos.

Edit: Spelling

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#44
post #9

I got a lot of flak here recently for suggesting that maybe security researchers shouldn't be publishing PoCs or deep vulnerability details literally 1 week after the vendor issues a patch. Here's to hoping that, now that this happened, someone will give this idea another consideration... (P.S. for those wondering: apparently this is CVE-2019-8605: https://bugs.chromium.org/p/project-zero/issues/detail?id=18... )

[deleted]

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#45
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

> general computing

Apple does not consider phones devices for general computing and so prioritises stability, power consumption and security over flexibility and the ability to run arbitrary code. I'm happy with that trade-off.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#46
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for most people. I write iOS software for a living, and even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware. The idea that ROMs from questionable sources make your device safer sounds very stran…

> even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware

That's not the point. The point is that the community will be able to do it and auditors' lives will be much easier, which benefits everyone because it vastly increases the likelihood of an issue being found.

> The idea that ROMs from questionable sources make your device safer sounds very strange to me.

On Android by default most vendors ship a lot of bloatware and have demonstrated almost infinite incompetence or malice of both. While the developers "custom ROMs from questionable sources" (XDA forum threads) may not be experts in their fields at all and are quite likely to misconfigure the software possible creating some new holes, at least those images are compiled from open sources and are not the terrible manufacturer OS (I wouldn't onlike bank on stock Xiaomi software).

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#47
post #43
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

Don't forget about Telcos. Your AT&T, Vodafone, Verizon & Co, put an enormous amount of pressure on Apple to limit and protect device unlocking. This is a cat & mouse situation where either party might benefit from tight unlocking controls. For example, MVNOs benefit from manufacturers with flexible and open unlocking policies that make it easy to unlock devices (without approval from the original operator), whereas…

Apple sells plenty of unlocked phones, all you have to do is buy it from Apple.

Lock restrictions only come into play if you want the mobile network to subsidize your phone.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#48
post #32

Earlier quoted context omitted.

I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for most people. I write iOS software for a living, and even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware. The idea that ROMs from questionable sources make your device safer sounds very stran…

I think locking down a system by default, but offering a way to gain elevated priviledges, while educating and properly warning users before certain actions is better than taking away everyone's control over their own devices, and therefore restricting their freedom.

The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#49
post #6

It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning. We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent. We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or w…

> general computing Apple does not consider phones devices for general computing and so prioritises stability, power consumption and security over flexibility and the ability to run arbitrary code. I'm happy with that trade-off.

They clearly consider iPads general purpose computers, so we're back to the starting concern.
Post reply on HN