10 ms·
As someone who goes as long as possible without performing updates, this is exactly the reason why. Example: Last time I updated my iPhone, the music app got a
by tpallarino 9y ago
As someone who goes as long as possible without performing updates, this is exactly the reason why.
Example: Last time I updated my iPhone, the music app got an update and now they are trying to shove iCloud down my throat. Not to mention needless UI changes when I was more than satisfied with how it was before.
- alphonsegaston 9y agoI understand this entirely, but there are some pretty bad iOS vulnerabilities out in the wild now (e.g. KRACK wpa2). It’s pretty dangerous to avoid updates nowadays. I think what needs to happen across the industry is a complete decoupling of “feature” from security patching. Too many people are exposed because of exactly the kind of unwanted UI upgrades you describe.
- miguelrochefort 9y agoDangerous? What's the worse that could happen?
- willstrafach 9y ago1. Ability to passively decrypt network activity (KRACK). 2. Ability to throw a fully persistent implant onto the device (via Wi-Fi exploit + pivot to AP kernel exploit)
- mindslight 9y agoMost phones already come with two persistent implants - the user-antagonistic OS, and the baseband processor! I'm all for trusting computing devices to act as one's agents, but attempting to do so with anything resembling a modern mobile phone is barking up the wrong tree. Even though just having one means taking the location-tracking hit from negligently designed cellular protocols, further exposure can be mitigated by using these little snitches for as little personal activity as possible.
- tscs37 9y agoYour phone will probably turn up in a botnet soon enough, but atleast you had the moral high ground.
- mindslight 9y agoOh no, not a month's allocation of mobile data down the drain! An impersonal passive botnet would likely do less damage than status quo "apps" that are built to siphon as much personal data as possible. Never mind these few Mifi devices that I have - default configs that listen on wan telnet with static passwords! Well known domestic manufacturer, not worth attempting to report - the manufacturer obviously did not care, has long moved on, and there's countless other models with the same problem. The panacea of every node being secure with an identifiable owner fell apart long ago. You can either cling to that belief in a fundamentalist manner (and prop up the totalitarians who wish to track communication ever more). Or you can work on understanding how non-technical people actually attempt to moderate their own exposure to these insecure-by-design surveillance devices.
- tscs37 9y agoYou should install security updates. Period. You don't help anyone by feeling better because instead of having the vendor maybe sniff on you, a hacker can do it instead. I also haven't found any apps yet that intentionally waste my monthly datacap.
- mindslight 9y agoSure, and I didn't advocate doing otherwise. My point is the larger context - there is no "secure" on mobile. Likewise, my point about losing a datacap was that it was preferable to having more personal info backhauled into commercial surveillance databases. It's not an either-or and I'm not desiring either one - just calling attention to the larger context of user-security versus the myopia of marketing/corporate security.
- 9y ago
- fulafel 9y agoDo you mean the worst that could happen to you personally or the worst for everyone? When your device is compromised by hostile actors I guess it depends on what your nightmares are, but getting framed for child pornography and/or blackmailed for it is a popular one. Or getting your cloud accounts hijacked and all your stuff compromised. Or getting the bad guys access to your employer's network. Etc. Collectively a widespread Android device botnet could take down a lot of infrastructure, or start a war, or ruin everyone's days with ransomware. I'm sure more imaginative people have thought about it.
- viraptor 9y agoSimilar questions were likely asked by owners of insecure routers/cameras before they got hit with Mirai
- WillReplyfFood 9y agoBetter have a bricked phone but secured phone? That is basically your argument? Security is used to euthanize perfectly working systems and harass users for money. Security has become dangerous for the user in that aspect.
- amelius 9y agoThat's one reason I'm still hoping for a Linux/Firefox phone.
- noobermin 9y agoThere's not much left to hope for as every platform that attempted one has fizzled out.
- la_oveja 9y agoYou can already have a Linux phone.
- amelius 9y agoBut it doesn't run my banking app.
- jhasse 9y agoMost banking apps are available for Android, which uses the Linux kernel.
- amelius 9y agoYeah, it uses the Linux kernel, but I wouldn't call it a "Linux phone".
- laumars 9y agoI'll grant you that GP was being pedantic but he is also correct. The only part in Debian/RHEL/Arch/whatever that is Linux is the kernel. "Linux" only refers to the kernel. So technically Android is also a distribution of Linux. I think what you're arguing is that Android isn't GNU/Linux or that Android isn't libre like what we've come to expect from desktop distributions of Linux.
- atomicnumber1 9y agoGoogle kind of does that but OEM does not seem to implement them into their phones.
- pishpash 9y agoWith the incentive structure of updates with certain popular software not supported by other revenue, you're always going to get a worse version (more ads, less features), to such an extent that I turn off all updates and only whitelist a few. Permissions are the ways to lock down phones, and security patches, not the permanent beta that is updates.
- adrianN 9y agoIf only security updates were unbundled from feature updates one could update with fewer worries.
- viraptor 9y agoMultiple release breaches are a pain for many reasons. It's very unlikely that companies would spend time doing that, even if they were given a chance to do so.
- Bartweiss 9y agoI can certainly see why multiple branches aren't popular - device fragmentation is bad enough without trying to identify which update branches are affected by some new security bug. That said, I think companies that require up-to-date devices for security fixes deserve less leeway about the contents of their non-security releases. I've gotten multiple smartphone updates which I considered entirely harmful - they traded cosmetic or vendor-friendly changes against worse battery/performance/usability - and I think "let us break your device or you can't have security" is an unacceptable proposition.
- deftturtle 9y agoExactly. Apple needs to separate UI and security releases until they can work out the bugs. So many issues with new updates and UI glitches.
- Darthy 9y agoIt's more than UI changes: the update from iOS10 to 11 removed support for 32bit applications, rendering dozens of applications that I use daily (and have paid for a lot of money) unusable. So now I have to decide between two bad options - not being secure or losing all that invested money.