3 ms·
As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an
by zmanian 10y ago
As consumers we don't face very good choices right now.
When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license.
If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device.
It's a shitty situation but it's hard not to recommend iOS to most users.
- corndoge 10y agoAnd if an iPhone is attacked the attacker...doesn't own the device? I don't follow your reasoning.
- l_zzie 10y agoOn iPhone, user-mode exploits remain sandboxed. On Android, on rooted devices, user mode code tends to be able to get root.
- vetinari 10y agoApples and oranges. On iPhone, user-mode exploits may remain sandboxed, unless they break from sandbox too. On jailbroken iPhones, that last step may be pre-made for them. On Android, user-mode exploits may remain sandboxed too, unless they break from the sandbox - same as iPhone. On rooted Android devices, the last step may be pre-made for them. You can not compare stock iPhone and rooted Androids - just like you can not compare jailbroken iPhone and stock Android.
- meowface 10y agoWhat do you mean? In this attack, the attackers leveraged a root privilege escalation exploit. So iPhones are just as owned.
- roywiggins 10y agoMy Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.
- digi_owl 10y agoWhat i would love to see is a bootlader where i can load my own signatures. Preferably done via USB only, and by putting the device into a mode that require certain button inputs during power up. Signed boot has uses, but we need to be sure that the user does the signing.
- criley2 10y agoI was tripped up trying to unlock an LG G5 yesterday by the secure boot validation. Turns out, in Android 6, there's a Developer Option called "Allow OEM Unlock" which does enable the ability to unlock the bootloader through fastboot. While I can't sign my own bootloader, having a developer option to enable the unlock that can only be triggered from inside the OS is an interesting trade off.
- givinguflac 10y ago"safe by default" except for the huge amount of userland vulns that Android has.
- deong 10y agoYeah, but that's life with a complex bundle of software. It's not as though Apple's attempt at making a walled garden makes them magically better at not writing exploitable bugs in the userland. Mostly where they're better is at making it harder for normal users to intentionally install something that turns out to be malware, which isn't nothing, but a with exploits like Trident, that makes absolutely no difference.
- StavrosK 10y agoEven the Nexus unlock where you don't need a key but need to boot into fastboot is okay. I don't think many pieces of software will be able to automatically perform the steps required for that, including a confirmation on the phone and one on the computer.
- NeutronBoy 10y ago
- oarsinsync 10y agoI guess ambiguity / assumed apple fanboyism is why you're downvoted, but if I'm understanding you correctly, then I feel largely the same way. Apple's walled garden and "moral" approach to guarding their garden is incredibly frustrating, but the sheer number of vulnerabilities affecting different levels of the Android stack is so disheartening. This is true of my PC/Mac as well, all it takes is someone to plug in a malicious USB stick and it'll infect the firmware on the USB host, and that's it, game over. Can spread from there to disk firmware, also growing increasingly complicated and opaque, and who knows where else. It's reaching a point where I trust my iOS device more than any other, depressingly because of the walled garden. I can't build suitable fences around my kit myself to protect myself against every new vuln (now even monitors can have their firmware exploited and screenloggers installed), giving up trying and sacrificing some freedom for that sense of security is terrible, but feels like the only logical course of action at this point.
- zmanian 10y agoI fully admit this line of thinking hasn't completely solidified for me. But empirically the iOS ecosystem is demonstrating that there is a close source ecosystem with better security properties than the open source one. Security advances the same virtues of user self determination as open source does.