Anybody get a bitter sweet feeling when ever these reported and fixed security exploits announcements happen? It's good that users aren't going to risk getting hacked by such vulnerabilities, but its bad that users can no longer uses these exploits to gain administrative control over their property.
Apple isn't going to force you to update your device, so you can stay on an older version if you want jailbreaks.
About the security content of iOS 12.4.9
81–90 of 177 posts
Re: About the security content of iOS 12.4.9
#82Earlier quoted context omitted.
No, because devices can be and sometimes are sold with software that is already out of date. The better indicator is how long software support is provided for a device from beginning to end.
Sure but that doesn't change how long they supported after end of sale which wasn't in 2013 but at least until 2017. So ~3 years of software updates from end of sale. Still OK but not anything special.
Certainly not the Pixel phones, they get 3 years support from first launch only, and they're supposedly the gold standard for Android software support. It's pretty much the reason they exist. Yet after last sale support for the 5S matched the Pixel's from launch support, and we don't even know that this is the last update the 5S will get.
Re: About the security content of iOS 12.4.9
#83Earlier quoted context omitted.
In which they had a whole year of really cheap, highly subsidized battery replacements to correct their error. I think Apple should be forgiven for this
I was unable to benefit from the battery replacement due to a chip in the screen they discovered after I got a CS code to do it: https://i.imgur.com/Gr1bPTU.jpg
Re: About the security content of iOS 12.4.9
#84Earlier quoted context omitted.
Apple uses this metric as well[1]. If something hasn't been sold by Apple for 5 years (but less than 7 years), it's considered vintage and you can still get hardware service and certain critical software fixes, though not necessarily any new features. The support for MacBooks is actually great. Certain Late 2013 and Mid 2014 Retina MacBook Pros, while considered vintage, will be receiving the Big Sur update[2]. 1. ht…
> The support for MacBooks is actually great. Certain Late 2013 and Mid 2014 Retina MacBook Pros, while considered vintage, will be receiving the Big Sur update. I think it's more likely that Apple's new frameworks don't require any fancy hardware features that aren't available in the Late 2013 MacBook Pros.
I wonder how much this might change when Apple Silicon comes to the Mac.
Re: About the security content of iOS 12.4.9
#85Earlier quoted context omitted.
I was unable to benefit from the battery replacement due to a chip in the screen they discovered after I got a CS code to do it: https://i.imgur.com/Gr1bPTU.jpg
What is a CS code?
Apple did not actually offer the replacement program within ~600km of my home, but I managed to convince them that an Apple Authorised Service provider in my town at least do it. They agreed and gave me a CS Code valid for the the battery replacement to be done.
But it was ultimately denied because of a tiny chip in the glass on the screen.
I really liked every other aspect of this phone though.
Re: About the security content of iOS 12.4.9
#86Earlier quoted context omitted.
The 5S is still the perfect iPhone.
Well, let's not get crazy. It's fine (I'm using it currently because my Samsung S9 died) but it's definitely no perfect phone. It doesn't even have water resistance and the screen to body ratio is pretty bad, IMO. Only upside is the thing is built in such a way that it has barely taken any damage from the years of abuse I put it through. I'm likely getting an iPhone 12 Pro Max very soon and will continue to only use…
Re: About the security content of iOS 12.4.9
#87Earlier quoted context omitted.
Wouldn't last official sale date be a better indicator of true device support? For example if someone bought it in an Apple store on the last day available, how long period would they have received updates for? For example in mid 2017 it was still officially sold by Apple in India (source: https://www.iphonehacks.com/2017/05/apple-iphone-5s-iphone-s... ).
Apple uses this metric as well[1]. If something hasn't been sold by Apple for 5 years (but less than 7 years), it's considered vintage and you can still get hardware service and certain critical software fixes, though not necessarily any new features. The support for MacBooks is actually great. Certain Late 2013 and Mid 2014 Retina MacBook Pros, while considered vintage, will be receiving the Big Sur update[2]. 1. ht…
Re: About the security content of iOS 12.4.9
#88A tricky thing about flagging "in the wild exploited vulnerabilities" in a title like this is that it suggests that sev:crit vulnerabilities in other updates that aren't flagged like this aren't being exploited in the wild. We get confirmation of only a subset of exploited vulnerabilities. We'd be better off with a more neutral title, like "fixing severe vulnerabilities" or something like that.
We've changed the title above to that of the page. (Submitted title was "Apple releases iOS 14.2 and 12.4.9, fixing in-the-wild exploited vulnerabilities".)
Re: About the security content of iOS 12.4.9
#89I think it's interesting how iOS exploits are cheaper[1] than Android exploits, because iOS exploits are so plentiful in comparison to Android exploits. [1] https://arstechnica.com/information-technology/2019/09/for-t...
What about the fact that android has 3 times the market share?
Re: About the security content of iOS 12.4.9
#90A tricky thing about flagging "in the wild exploited vulnerabilities" in a title like this is that it suggests that sev:crit vulnerabilities in other updates that aren't flagged like this aren't being exploited in the wild. We get confirmation of only a subset of exploited vulnerabilities. We'd be better off with a more neutral title, like "fixing severe vulnerabilities" or something like that.
It's not really that important, really. It's either being exploited yesterday, or tomorrow.