Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

91–100 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#91
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

> you will always find a random ROM on xda

Installing random ROMs from random developers is an interesting take on security.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#92
post #27
post #26

Earlier quoted context omitted.

Are you really saying Apple should actively break interoperability with old software?

They should stop charging 30% App Store tax for an inferior product at the very least.

They're not charging you, the user that 30%. They're charging the developer. Yes that does trickle down to you in the developer's pricing, but, in this instance, a phone no longer receiving security updates is not an inferior product from the point of view of the transaction in question.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#93
post #18
post #14

Earlier quoted context omitted.

Touche. P.S. Keep in mind though, what is the state of security of the Android phone you bought new in November 2015?

The Nexus 6 (2014) can still run a version of android with security patches: https://wiki.lineageos.org/devices/shamu/ Google no longer offers security patches directly, but since you control the phone sufficiently to install your own OS, the community can come together and keep security updates flowing. You could do it yourself if you wanted. Apple devices make this sort of community maintainership effectively impos…

It's all well and good to say "oh you can just install a custom ROM". But you (and many here) can do that. Because you're technically inclined. But the vast majority have users have no idea what the hell you're talking about. They barely know what a security update is or what version of Android they're using, let alone being able to find, choose, and install a ROM.

Can we just choose to stop suggesting it as a legitimate solution cause outside of this bubble, it absolutely is not.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#94

How do we know they won’t patch it in like an iOS 15.8.1 update? Even iOS 12 had a security update in 2023 still.

Apple doesn't patch every security hole in older iOS versions. I don't know what the criteria is, but my guess is if it's a major security hole, or an easily backported one, they'll do it, but if it's super minor or not backportable, they won't.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#95
post #79
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

What about the binary blob drivers that can’t be patched and are one of the leading attack vectors? Just look at all of the Qualcomm monthly patches alone . Unless all of your binaries, that have no source, are up to date you’ll never be secure on any XDA rom.

That is a real problem agreed, though vendors are starting to OSS more of those lately. Still better than running an unpatched android of 4 years.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#96
post #68
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

lol! Are you really comparing Apple released operating system updates to xda?

The whole point of the article is that they don't actually do that

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#97
post #74
post #64

Earlier quoted context omitted.

XDA works a lot on reputation and realistically you will infect like 1k phones none of which will be high value targets. I don't see the motivation. Those maintainers do quite a lot of work to backport patches every week/month and offer OTA. Also I dont enable root when flashing, that is not required at all.

Realistically, if someone makes a fringe rom that may be downloaded a few thousand times, how many people are going to bother checking for nefarious exploits hidden in there? I hate that I wrote that lol. It reeks of the kind of cybersecurity whataboutism that leads to people inconveniencing the SHIT out of themselves for the sake of security.

I think human laziness can be counted on. Realistically I dont see any benefit in doing something nefarious and there is karma like on HN.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#98
post #72

Some iOS 15 phones like the 5S/SE have no newer comparable phones which makes upgrading difficult. Oh dear, I suppose not browsing the web is another option.

What’s missing from the more recent SE models?

A 4-inch screen size that allows the phone to be used single-handed with ease anywhere on the screen, which I’m using to write this comment right now. It’s uncompromising in battery longevity when considering its size, too. First-gen SE is the best phone Apple ever made. The newer SE are terrible.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#99
post #50

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.

> you will always find a random ROM on xda Installing random ROMs from random developers is an interesting take on security.

That was bad phrasing, there is karma on XDA and trusted name reputation (evolution x, pixel experience, lineage os). So it is not a random ROM from a random dev. And you always have the source for those builds.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#100
post #16
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.

Google doesn’t have enough e-fuses to update the pixel phones for seven years, the marketing department is incompetent and didn’t talk to literally the only engineers they should have.
Post reply on HN