I think it's interesting how iOS exploits are cheaper[1] than Android exploits, because iOS exploits are so plentiful in comparison to Android exploits. [1] https://arstechnica.com/information-technology/2019/09/for-t...
I’d guess it’s because the individuals worth using a targeted exploit on are more likely to be carrying iPhones.
About the security content of iOS 12.4.9
51–60 of 177 posts
Re: About the security content of iOS 12.4.9
#52Anybody get a bitter sweet feeling when ever these reported and fixed security exploits announcements happen? It's good that users aren't going to risk getting hacked by such vulnerabilities, but its bad that users can no longer uses these exploits to gain administrative control over their property.
Apple isn't going to force you to update your device, so you can stay on an older version if you want jailbreaks.
Re: About the security content of iOS 12.4.9
#53Re: About the security content of iOS 12.4.9
#54Re: About the security content of iOS 12.4.9
#55Earlier quoted context omitted.
Wasn't the purpose of that throttling to extend the life of older phones? Throttling the CPU let them stay within the limits of the worn out battery and let the device continue to be used without crashing.
It was to extend the battery life, which was a workaround for the flawed battery design (contra CPU power draw). I bought an iPhone SE in the first month available and it started throttling by month 10, I'm not a battery designer, but I did not buy a device marketed as 2x the speed of 5S only for it to silently drop to 0.8x the speed of the 5S less than a year later.
Re: About the security content of iOS 12.4.9
#56Earlier quoted context omitted.
Why are you citing a year+ old article? It's clearly out of date. iOS is a much more secure platform, and exploits are much rarer than Android exploits. HN has really gone down in quality of readers/commenters.
Functionally, iOS is a much more secure platform. Far more people are updated to the latest iOS version, which makes a huge difference. Apple invests tons of money into secure biometrics, privacy initiatives, and lots more. At the same time, Android might still have fewer vulnerabilities in the latest versions. It's possible that Android's security technology or coding practices result in fewer security bugs. I don't…
Re: About the security content of iOS 12.4.9
#57Re: About the security content of iOS 12.4.9
#58Earlier quoted context omitted.
Wouldn't last official sale date be a better indicator of true device support? For example if someone bought it in an Apple store on the last day available, how long period would they have received updates for? For example in mid 2017 it was still officially sold by Apple in India (source: https://www.iphonehacks.com/2017/05/apple-iphone-5s-iphone-s... ).
No, because devices can be and sometimes are sold with software that is already out of date. The better indicator is how long software support is provided for a device from beginning to end.
If I buy a new phone from the manufacturer and it's already unsupported, that's really bad. I don't care if it was supported for 8 years before I bought it.
Re: About the security content of iOS 12.4.9
#59Earlier quoted context omitted.
Wouldn't last official sale date be a better indicator of true device support? For example if someone bought it in an Apple store on the last day available, how long period would they have received updates for? For example in mid 2017 it was still officially sold by Apple in India (source: https://www.iphonehacks.com/2017/05/apple-iphone-5s-iphone-s... ).
No, because devices can be and sometimes are sold with software that is already out of date. The better indicator is how long software support is provided for a device from beginning to end.
Re: About the security content of iOS 12.4.9
#60I think it's interesting how iOS exploits are cheaper[1] than Android exploits, because iOS exploits are so plentiful in comparison to Android exploits. [1] https://arstechnica.com/information-technology/2019/09/for-t...
Is that still the case? The article implies that before it was written that wasn't the case previously.
If a bad actor can derive just $10 on average per phone they attack, then all they need to do is find a way to deploy their $2-3 million exploit to 1 million phones for less than $5 million to make a tidy profit. Given that we are talking about zero-click remote compromises, which means the victim only needs to receive the payload, this means that it is profitable as long as the cost per victim impression is less than $5, a CPM of $5000. With that sort of budget you can embed your attack into an ad and then outbid everybody else by a factor of 10 for placements. You can buy a mailing list and embed your attack as a "payload pixel". If it is a zero-click text message attack then you can buy access to the spam-callers and mass deploy it that way.
These systems are between a factor of 10-100x off of adequate. To care about their relative differences is like debating whether paper mache or tissue paper is better at stopping bullets. One is probably better than the other, but neither provides meaningful protection, so it hardly matters. You need fundamental, qualitative improvements before differences between the solutions provide meaningful effects on outcomes.
[1] https://dqydj.com/average-median-top-net-worth-percentiles/