Live data from Hacker News

About the security content of iOS 12.4.9

support.apple.com

51–60 of 177 posts

Re: About the security content of iOS 12.4.9

#51
post #45

I think it's interesting how iOS exploits are cheaper[1] than Android exploits, because iOS exploits are so plentiful in comparison to Android exploits. [1] https://arstechnica.com/information-technology/2019/09/for-t...

I’d guess it’s because the individuals worth using a targeted exploit on are more likely to be carrying iPhones.

I think you've misunderstood. iOS exploits are cheaper. If your explanation held, then you'd expect them to be costlier. That said, I'm sure your explanation is a component of their price.

Re: About the security content of iOS 12.4.9

#52
post #35

Anybody get a bitter sweet feeling when ever these reported and fixed security exploits announcements happen? It's good that users aren't going to risk getting hacked by such vulnerabilities, but its bad that users can no longer uses these exploits to gain administrative control over their property.

Apple isn't going to force you to update your device, so you can stay on an older version if you want jailbreaks.

users buying new devices that automatically update on activation aren't going to have that choice.

Re: About the security content of iOS 12.4.9

#55
post #43

Earlier quoted context omitted.

Wasn't the purpose of that throttling to extend the life of older phones? Throttling the CPU let them stay within the limits of the worn out battery and let the device continue to be used without crashing.

It was to extend the battery life, which was a workaround for the flawed battery design (contra CPU power draw). I bought an iPhone SE in the first month available and it started throttling by month 10, I'm not a battery designer, but I did not buy a device marketed as 2x the speed of 5S only for it to silently drop to 0.8x the speed of the 5S less than a year later.

In which they had a whole year of really cheap, highly subsidized battery replacements to correct their error. I think Apple should be forgiven for this

Re: About the security content of iOS 12.4.9

#56
post #34
post #30

Earlier quoted context omitted.

Why are you citing a year+ old article? It's clearly out of date. iOS is a much more secure platform, and exploits are much rarer than Android exploits. HN has really gone down in quality of readers/commenters.

Functionally, iOS is a much more secure platform. Far more people are updated to the latest iOS version, which makes a huge difference. Apple invests tons of money into secure biometrics, privacy initiatives, and lots more. At the same time, Android might still have fewer vulnerabilities in the latest versions. It's possible that Android's security technology or coding practices result in fewer security bugs. I don't…

I think a major part of it is that iOS has much less variety.

Re: About the security content of iOS 12.4.9

#57
post #22

Earlier quoted context omitted.

Also to Google for finding majority of them

If only Google could put this much effort into supporting its own Pixel devices, which stop getting updates to the base OS after just three years.

Depending on your usecase, GrapheneOS may be of interest.

Re: About the security content of iOS 12.4.9

#58
post #49
post #39

Earlier quoted context omitted.

Wouldn't last official sale date be a better indicator of true device support? For example if someone bought it in an Apple store on the last day available, how long period would they have received updates for? For example in mid 2017 it was still officially sold by Apple in India (source: https://www.iphonehacks.com/2017/05/apple-iphone-5s-iphone-s... ).

No, because devices can be and sometimes are sold with software that is already out of date. The better indicator is how long software support is provided for a device from beginning to end.

Why is that a better indicator?

If I buy a new phone from the manufacturer and it's already unsupported, that's really bad. I don't care if it was supported for 8 years before I bought it.

Re: About the security content of iOS 12.4.9

#59
post #49
post #39

Earlier quoted context omitted.

Wouldn't last official sale date be a better indicator of true device support? For example if someone bought it in an Apple store on the last day available, how long period would they have received updates for? For example in mid 2017 it was still officially sold by Apple in India (source: https://www.iphonehacks.com/2017/05/apple-iphone-5s-iphone-s... ).

No, because devices can be and sometimes are sold with software that is already out of date. The better indicator is how long software support is provided for a device from beginning to end.

Hah. This bit us when I got my mother an iPhone SE (2016) to replace her iPhone 4 a year or so ago. I tried to restore from iCloud backup and it kept failing, and finally it dawned on me that the OS may have been out of date. Skipped the restore, updated the OS, and wiped the phone. The restore worked correctly.

Re: About the security content of iOS 12.4.9

#60
post #17

I think it's interesting how iOS exploits are cheaper[1] than Android exploits, because iOS exploits are so plentiful in comparison to Android exploits. [1] https://arstechnica.com/information-technology/2019/09/for-t...

Is that still the case? The article implies that before it was written that wasn't the case previously.

Does it matter? A full-chain zero-click remote complete compromise for either system is only $2-3 million. That is absolute chump change. 4-6% of households in the US [1], 5-8 million households, have sufficient assets to fully compromise every iPhone or Android in the world. If we consider businesses, I bet that is within the reach of no less than 50% of the businesses (including small businesses) in the US. That is an absurd number of entities where that price point is totally doable.

If a bad actor can derive just $10 on average per phone they attack, then all they need to do is find a way to deploy their $2-3 million exploit to 1 million phones for less than $5 million to make a tidy profit. Given that we are talking about zero-click remote compromises, which means the victim only needs to receive the payload, this means that it is profitable as long as the cost per victim impression is less than $5, a CPM of $5000. With that sort of budget you can embed your attack into an ad and then outbid everybody else by a factor of 10 for placements. You can buy a mailing list and embed your attack as a "payload pixel". If it is a zero-click text message attack then you can buy access to the spam-callers and mass deploy it that way.

These systems are between a factor of 10-100x off of adequate. To care about their relative differences is like debating whether paper mache or tissue paper is better at stopping bullets. One is probably better than the other, but neither provides meaningful protection, so it hardly matters. You need fundamental, qualitative improvements before differences between the solutions provide meaningful effects on outcomes.

[1] https://dqydj.com/average-median-top-net-worth-percentiles/

Post reply on HN