6 ms·
I use Apple products and will continue to, but... > Apple patched the bugs quickly in February 2019 so everyone who has updated their iPhone since then is prot
by jsgo 7y ago
I use Apple products and will continue to, but...
> Apple patched the bugs quickly in February 2019 so everyone who has updated their iPhone since then is protected. Rebooting the iPhone wiped the malware but the data had already been taken.
Why in the world did they silently fix the issue and remove the malware? I'm fine with all of this, but shouldn't they disclose to the user "hey, some very sensitive data from your device has been taken. It is passwords, messages, etc." so that users could at least try to mitigate the impact somewhat (contact their contacts, change passwords, maybe change numbers, etc.)?
- oarsinsync 7y agoThe websites delivered non-persistent jailbreaks. Rebooting the device removes the jailbreak. Please read the original source at https://news.ycombinator.com/item?id=20835223 https://news.ycombinator.com/item?id=20835223
- cromwellian 7y agoPeople almost never reboot their phones. I rarely reboot. So if you don’t tell me I need to reboot my iPhone, I won’t.
- departure 7y agoIn my experience iOS does an automatic reboot when updating.
- PunchTornado 7y agothat doesn't answer the question of why didn't they go public with the information? Most people don't update frequently enough. Also some people may need to change password etc. if they've visited those sites.
- professorTuring 7y agoThat's easy, apple does not know if your specific mobile has been compromised. Also, nobody stole anything from Apple... It was a vulnerability and they provided a patch (remember that software is provided "as is") I can't see how any software provider (ie Microsoft, Linux, Google... ) will say "install this patch to fix this and you may or may not been hacked, good luck"... They just provide the patch.
- gsich 7y agoWith most leaks (and just assuming this is true, and data has been collected) you get the info to change passwords.
- professorTuring 7y agoThis is not a leak from a company is a leak from your device. The only one that can know if something has leaked is you. Consider a lock manufacturer that has a key copy of each client. If someone enters in the building and steals all the keys, clearly the manufacturer should inform all their clients. But, if a vulnerability has been found in a lock model, the manufacturer can tell you about the vulnerability, but definitely they can't tell you if your house has been robbed that way (or if it has been robbed at all). Anyway, with this story alone and without knowing if you have visited these webpages that allegedly hacked your iPhone (why aren't they listed?) the only thing you can do is renewing passwords in your most critical accounts.
- gsich 7y agoYes. And they can still warn about it.
- oarsinsync 7y agoThey do. Every patch release contains release notes and security notes disclosing what vulnerabilities have been identified and patched. This is industry standard practice, because this is a regular occurrence on all software platforms. It’s not big news when it happens all the time. What is big news, that’s gotten lost in all the noise, is that Google (through it’s crawling of the web) has been able to identify that some websites were (are) indiscriminately jailbreaking iPhones for the purposes of stealing user data. This is the kind of thing that is routine on Windows, is likely to be routine on Android (given how many unpatchable devices are in use) but wasn’t considered to be routine on iOS. The takeaway from all this is simple: if you’re not fully patched, you’re at significant risk. It doesn’t matter which platform you use.
- denisw 7y agoI'd say many people actually reboot their phones frequently - every time they cannot or forget to charge in time and the phone goes black. :)
- SketchySeaBeast 7y agoThat's horrifying to me - I've had many phones, and never let that happen. It's bad for the battery, it's bad for the phone, it's just a bad option all around. You can't let your phone do that on a regular basis and then complain that it's slow and the battery doesn't last.
- coldtea 7y agoActually it's not bad at all much less "horrifying", that's all old wives tales... It's not bad for the phone, and whether it's bad for the battery depends on the battery technology. In fact previous battery technologies were recommending the occasional full drain! For lithium-ion batteries the kind used in the iPhone draining to 0% can indeed strain them (though less than you think, as shown by research), but the iPhone doesn't let them go to 0% anyway. It switches off way before that (even if it shows it as 0%). Mind you that regular use cycles (defined by Apple as using 100% of a full charge, even if it's broken down as going from 100% to 80% for five days and recharging) also strains the battery. You cannot not strain it, all current technology batteries degrade over time. Also note that getting lithium-ion batteries to 100% and keeping them charging can also harm them (although modern devices have mechanisms to prevent that). In general it's advisable to keep going from 80%-20% and back, than to go all the way to charged (or down to 0). Same, one should not store long term fully charged. But most of this is irrelevant micromanagement unless you plan to keep your phone for years and don't ever consider replacing the battery. Even so, the battery lifespan vendors like Apple give is around 3 years of cycles. All in all, you can fully drain your lithium-ion iPhone battery as often as the average person does (e.g. just avoid doing it all the time), and you'll see no special degradation. It will run its cycles and will degrade by regular use after a few years even if you never let it drain (and you can trivially replace it with a new one).
- 7y ago
- oarsinsync 7y agoUntil the battery runs out, which happens to most people I know at least once a month.
- cromwellian 7y agoNever happens to me, I charge pretty much everywhere. In car, at my desk, etc Seems people are going out of their way to let Apple off the hook for not disclosing to the user a major risk and silently fixing it.
- ummonk 7y agoEvery iOS update I've had has resulted in a reboot.
- jdavis703 7y agoDo you have data to back this up? I turn off my phone whenever I need to focus or want to avoid being tracked. This happens multiple times a week.
- saagarjha 7y agoMost of the people I know never turn off their phones. I'm fairly sure my parents have not done so for at least a couple of months. I wouldn't either, if not for the fact that I need to restart for updates every couple of weeks.
- godelski 7y agoThe question is about disclosure. 1) the GP quoted the part about rebooting wipes the malware. But that doesn't matter if the info was taken before the user rebooted. So this comment is really off topic. 2) the GP comment is about letting users be aware so they can help mitigate the problem and assess the threat level. For example, users need to change their passwords. If you've ever worked with any government agency their number one concern is not leak of data, but knowing what leaked (obviously they want to minimize that). Knowing what leaked is extremely important. This is what the comment is about. I don't understand how your comment addresses this.
- scohesc 7y agoBecause then they can't keep their public image of "we never screw up, we care about your privacy, etc. etc.".
- ouid 7y agoI won't update my phone because every update drains another 300 MB from my storage and drops my battery efficiency.
- Jonnax 7y agoThen don't complain if you get hacked and your bank account gets drained.
- asdfman123 7y agoCool, I'm glad to see planned obsolescence is actually enforceable. "This is the angriest $1500 I've ever spent on a brand new iPhone, but I will probably do this again next year," says one iPhone user.
- psychometry 7y agoSo delete some videos and plug your phone in to update. Not hard problems to solve.
- coldtea 7y agoHow would they be know whether data have been indeed taken? Computers and phones (especially Android) get malware all the time, no vendor goes and informs the users...
- elorant 7y agoif this is a state actor organized attack as the article implies then perhaps the target list would be very narrow and Apple wouldn't want to go into details. Or perhaps even they don't know who's infected.
- MattSteelblade 7y agoI agree that the article implies a state actor, but it also says "There was no target discrimination." I think they don't know who was infected.
- ben509 7y agoTargeting everyone is a great way to hide who you're targeting.
- nneonneo 7y agoThe malware itself is non-persistent and doesn’t survive rebooting (typically, it would be installed in /tmp, which is a RAM file system). To survive a reboot, a piece of malware would have to somehow break the chain-of-trust extending from the boot loader (since everything is effectively revalidated on boot), which is a much smaller attack surface that is much harder to exploit. Apple is not intentionally removing malware themselves, and AFAIK they don’t have the ability to tell if a device has been compromised.
- e_proxus 7y agoI mean, they must have _some_ way of running code before performing an upgrade, no? So they could check for these processes, store some state on the phone, and after the upgrade display a notice about what happened. This would all be on-device so it's not even a privacy issue.
- lilyball 7y agoYou say that like Apple knows the device was compromised. The act of patching it requires rebooting the device. Unless the malware left evidence of itself behind in persistent storage, by the time the device is patched you wouldn't be able to detect it.
- nominated1 7y agoWarning Conspiracy Theory Ahead: I’m not yet ready to crucify Apple for not issuing a press release listing sites and services affected. Same with the Google “deep dive” with it’s vague insinuations. I suspect this is a big international incident like - “China bought hacks from Mossad to target Hong Kong” kind of big. For all we know there are gag orders in place and an ongoing investigation. I will still use iOS devices too. They are still the most secure consumer available/friendly computing devices available imo. That said, I want to know more.
- stjohnswarts 7y agoThey fix security stuff all the time. Why advertise that you failed. There's nothing to be done about it. I'm taking this point of view as a company. Telling people that you failed is not good advertising.