▲ 39 ▼ Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones (www.404media.co) submitted 1 week ago by rssbot@lemmy.bestiver.se [M, B] to c/hackernews@lemmy.bestiver.se 12 comments fedilink hide all child comments Comments
[+] newton@piefed.social -14 points 1 week ago* (9 children) You guys still use iPhones 😂 permalink fedilink source hideshow 9 child comments replies: [–] fartsparkles@lemmy.world 19 points 1 week ago (5 children) Judging by the value of iOS exploit bounties posted by these orgs vs the surprisingly low value for Android, they clearly have a far harder time cracking iOS devices than they do Android. permalink fedilink source parent hideshow 5 child comments replies: [–] newton@piefed.social 6 points 1 week ago Iam on grspheneOS permalink fedilink source parent [–] ChairmanMeow@programming.dev 1 point 1 week ago (3 children) That means that they believe there's more value in having those exploits, not necessarily that they're harder to find. Though I imagine it's at least a little bit harder because iPhones are closed source. That does also mean that if Apple doesn't discover the vulnerability, it's unlikely to get a patch. With Android, these security issues are found more easily, but also patched much faster. Which I suppose makes an Android vulnerability also worth less, since you get more limited use out of it. permalink fedilink source parent hideshow 3 child comments replies: [–] fartsparkles@lemmy.world 9 points 1 week ago* (2 children) Is that true though? I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. And even from an OS architecture point of view, actual Android and its IPC via intents, content providers, broadcast receivers, and component exports etc is a whole world of juicy attack surface that simply doesn’t exist on iOS. Which is a primary reason people hate iOS given apps feel so isolated and you have to use the share sheet to get data between apps. Then you have Android’s differing chipsets vs iOS’s Secure Enclave that’s on all supported handsets. Plus Android’s WebView has addJavascriptInterface() allowing native code execution via that API whereas Safari, as shit as it is, doesn’t have that enabled. Don’t get me wrong, Android is an awesome operating system and it’s openness enables some amazing distributions like GrapheneOS. But even a cursory glance at the two attack surfaces, iOS has a way smaller surface and swifter patching. permalink fedilink source parent hideshow 2 child comments replies: [–] ChairmanMeow@programming.dev 1 point 1 week ago (1 child) I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. The ones you know about, yes :). We know there are complete firms actively exploiting iOS devices though. With Android the security community can figure out what the flaws are and patch them, with iOS it's a black box. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. Most devices are legally required to get X years of security updates, and most manufacturers do push those out fairly quickly. Maybe not all the same day, sure, but they do go out. I do remember a fair few exploits for iOS devices that allowed an attacker to take over a device without any user interaction, and most mentioned they were actively being exploited by malicious (state) actors. All I think however is that the price of the exploit doesn't necessarily correspond with how secure the device actually is, but rather it's based on the value that that exploit might hold. US entities would probably also offer more than EU entities, whereas for Android it might be the other way around. permalink fedilink source parent hideshow 1 child comment replies: [–] Arcane2077@sh.itjust.works -1 points 6 days ago “Required to get updates for X amount of years” means getting an eol update one year after the previous one. And not prompted, you have to go looking for it. permalink fedilink source parent [–] Carrots@quokk.au 4 points 1 week ago (2 children) You use Android? 😂 at least graphene right? On a Google CIA sponsored phone no doubt. permalink fedilink source parent hideshow 2 child comments replies: [–] tapdattl@lemmy.world 13 points 1 week ago (1 child) You guys are using cell phones? I have a specially trained carrier pigeon that coos in AES256 permalink fedilink source parent hideshow 1 child comment replies: [–] Carrots@quokk.au 10 points 1 week ago 256 can be decrypted by any pigeon hawk. You may as well be peacock. permalink fedilink source parent
[–] fartsparkles@lemmy.world 19 points 1 week ago (5 children) Judging by the value of iOS exploit bounties posted by these orgs vs the surprisingly low value for Android, they clearly have a far harder time cracking iOS devices than they do Android. permalink fedilink source parent hideshow 5 child comments replies: [–] newton@piefed.social 6 points 1 week ago Iam on grspheneOS permalink fedilink source parent [–] ChairmanMeow@programming.dev 1 point 1 week ago (3 children) That means that they believe there's more value in having those exploits, not necessarily that they're harder to find. Though I imagine it's at least a little bit harder because iPhones are closed source. That does also mean that if Apple doesn't discover the vulnerability, it's unlikely to get a patch. With Android, these security issues are found more easily, but also patched much faster. Which I suppose makes an Android vulnerability also worth less, since you get more limited use out of it. permalink fedilink source parent hideshow 3 child comments replies: [–] fartsparkles@lemmy.world 9 points 1 week ago* (2 children) Is that true though? I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. And even from an OS architecture point of view, actual Android and its IPC via intents, content providers, broadcast receivers, and component exports etc is a whole world of juicy attack surface that simply doesn’t exist on iOS. Which is a primary reason people hate iOS given apps feel so isolated and you have to use the share sheet to get data between apps. Then you have Android’s differing chipsets vs iOS’s Secure Enclave that’s on all supported handsets. Plus Android’s WebView has addJavascriptInterface() allowing native code execution via that API whereas Safari, as shit as it is, doesn’t have that enabled. Don’t get me wrong, Android is an awesome operating system and it’s openness enables some amazing distributions like GrapheneOS. But even a cursory glance at the two attack surfaces, iOS has a way smaller surface and swifter patching. permalink fedilink source parent hideshow 2 child comments replies: [–] ChairmanMeow@programming.dev 1 point 1 week ago (1 child) I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. The ones you know about, yes :). We know there are complete firms actively exploiting iOS devices though. With Android the security community can figure out what the flaws are and patch them, with iOS it's a black box. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. Most devices are legally required to get X years of security updates, and most manufacturers do push those out fairly quickly. Maybe not all the same day, sure, but they do go out. I do remember a fair few exploits for iOS devices that allowed an attacker to take over a device without any user interaction, and most mentioned they were actively being exploited by malicious (state) actors. All I think however is that the price of the exploit doesn't necessarily correspond with how secure the device actually is, but rather it's based on the value that that exploit might hold. US entities would probably also offer more than EU entities, whereas for Android it might be the other way around. permalink fedilink source parent hideshow 1 child comment replies: [–] Arcane2077@sh.itjust.works -1 points 6 days ago “Required to get updates for X amount of years” means getting an eol update one year after the previous one. And not prompted, you have to go looking for it. permalink fedilink source parent
[–] ChairmanMeow@programming.dev 1 point 1 week ago (3 children) That means that they believe there's more value in having those exploits, not necessarily that they're harder to find. Though I imagine it's at least a little bit harder because iPhones are closed source. That does also mean that if Apple doesn't discover the vulnerability, it's unlikely to get a patch. With Android, these security issues are found more easily, but also patched much faster. Which I suppose makes an Android vulnerability also worth less, since you get more limited use out of it. permalink fedilink source parent hideshow 3 child comments replies: [–] fartsparkles@lemmy.world 9 points 1 week ago* (2 children) Is that true though? I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. And even from an OS architecture point of view, actual Android and its IPC via intents, content providers, broadcast receivers, and component exports etc is a whole world of juicy attack surface that simply doesn’t exist on iOS. Which is a primary reason people hate iOS given apps feel so isolated and you have to use the share sheet to get data between apps. Then you have Android’s differing chipsets vs iOS’s Secure Enclave that’s on all supported handsets. Plus Android’s WebView has addJavascriptInterface() allowing native code execution via that API whereas Safari, as shit as it is, doesn’t have that enabled. Don’t get me wrong, Android is an awesome operating system and it’s openness enables some amazing distributions like GrapheneOS. But even a cursory glance at the two attack surfaces, iOS has a way smaller surface and swifter patching. permalink fedilink source parent hideshow 2 child comments replies: [–] ChairmanMeow@programming.dev 1 point 1 week ago (1 child) I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. The ones you know about, yes :). We know there are complete firms actively exploiting iOS devices though. With Android the security community can figure out what the flaws are and patch them, with iOS it's a black box. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. Most devices are legally required to get X years of security updates, and most manufacturers do push those out fairly quickly. Maybe not all the same day, sure, but they do go out. I do remember a fair few exploits for iOS devices that allowed an attacker to take over a device without any user interaction, and most mentioned they were actively being exploited by malicious (state) actors. All I think however is that the price of the exploit doesn't necessarily correspond with how secure the device actually is, but rather it's based on the value that that exploit might hold. US entities would probably also offer more than EU entities, whereas for Android it might be the other way around. permalink fedilink source parent hideshow 1 child comment replies: [–] Arcane2077@sh.itjust.works -1 points 6 days ago “Required to get updates for X amount of years” means getting an eol update one year after the previous one. And not prompted, you have to go looking for it. permalink fedilink source parent
[–] fartsparkles@lemmy.world 9 points 1 week ago* (2 children) Is that true though? I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. And even from an OS architecture point of view, actual Android and its IPC via intents, content providers, broadcast receivers, and component exports etc is a whole world of juicy attack surface that simply doesn’t exist on iOS. Which is a primary reason people hate iOS given apps feel so isolated and you have to use the share sheet to get data between apps. Then you have Android’s differing chipsets vs iOS’s Secure Enclave that’s on all supported handsets. Plus Android’s WebView has addJavascriptInterface() allowing native code execution via that API whereas Safari, as shit as it is, doesn’t have that enabled. Don’t get me wrong, Android is an awesome operating system and it’s openness enables some amazing distributions like GrapheneOS. But even a cursory glance at the two attack surfaces, iOS has a way smaller surface and swifter patching. permalink fedilink source parent hideshow 2 child comments replies: [–] ChairmanMeow@programming.dev 1 point 1 week ago (1 child) I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. The ones you know about, yes :). We know there are complete firms actively exploiting iOS devices though. With Android the security community can figure out what the flaws are and patch them, with iOS it's a black box. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. Most devices are legally required to get X years of security updates, and most manufacturers do push those out fairly quickly. Maybe not all the same day, sure, but they do go out. I do remember a fair few exploits for iOS devices that allowed an attacker to take over a device without any user interaction, and most mentioned they were actively being exploited by malicious (state) actors. All I think however is that the price of the exploit doesn't necessarily correspond with how secure the device actually is, but rather it's based on the value that that exploit might hold. US entities would probably also offer more than EU entities, whereas for Android it might be the other way around. permalink fedilink source parent hideshow 1 child comment replies: [–] Arcane2077@sh.itjust.works -1 points 6 days ago “Required to get updates for X amount of years” means getting an eol update one year after the previous one. And not prompted, you have to go looking for it. permalink fedilink source parent
[–] ChairmanMeow@programming.dev 1 point 1 week ago (1 child) I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time. The ones you know about, yes :). We know there are complete firms actively exploiting iOS devices though. With Android the security community can figure out what the flaws are and patch them, with iOS it's a black box. Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support. Most devices are legally required to get X years of security updates, and most manufacturers do push those out fairly quickly. Maybe not all the same day, sure, but they do go out. I do remember a fair few exploits for iOS devices that allowed an attacker to take over a device without any user interaction, and most mentioned they were actively being exploited by malicious (state) actors. All I think however is that the price of the exploit doesn't necessarily correspond with how secure the device actually is, but rather it's based on the value that that exploit might hold. US entities would probably also offer more than EU entities, whereas for Android it might be the other way around. permalink fedilink source parent hideshow 1 child comment replies: [–] Arcane2077@sh.itjust.works -1 points 6 days ago “Required to get updates for X amount of years” means getting an eol update one year after the previous one. And not prompted, you have to go looking for it. permalink fedilink source parent
[–] Arcane2077@sh.itjust.works -1 points 6 days ago “Required to get updates for X amount of years” means getting an eol update one year after the previous one. And not prompted, you have to go looking for it. permalink fedilink source parent
[–] Carrots@quokk.au 4 points 1 week ago (2 children) You use Android? 😂 at least graphene right? On a Google CIA sponsored phone no doubt. permalink fedilink source parent hideshow 2 child comments replies: [–] tapdattl@lemmy.world 13 points 1 week ago (1 child) You guys are using cell phones? I have a specially trained carrier pigeon that coos in AES256 permalink fedilink source parent hideshow 1 child comment replies: [–] Carrots@quokk.au 10 points 1 week ago 256 can be decrypted by any pigeon hawk. You may as well be peacock. permalink fedilink source parent
[–] tapdattl@lemmy.world 13 points 1 week ago (1 child) You guys are using cell phones? I have a specially trained carrier pigeon that coos in AES256 permalink fedilink source parent hideshow 1 child comment replies: [–] Carrots@quokk.au 10 points 1 week ago 256 can be decrypted by any pigeon hawk. You may as well be peacock. permalink fedilink source parent
[–] Carrots@quokk.au 10 points 1 week ago 256 can be decrypted by any pigeon hawk. You may as well be peacock. permalink fedilink source parent