3 ms·
Android is a Linux kernel written in C, so it's memory unsafe there. The apps are in a Java-derivative, so they're memory safe. Chrome browser is not written in
by 693471 7y ago
Android is a Linux kernel written in C, so it's memory unsafe there. The apps are in a Java-derivative, so they're memory safe. Chrome browser is not written in this language, so it's memory unsafe.
iOS is a Mach+XNU kernel written in C, so it's memory unsafe there. The apps are in Swift, so they're memory safe. Safari/Webkit is not written in this language, so it's memory unsafe.
The only real difference in security here is that Apple has had better sandboxing and security (hardware) implementations.
- panpanna 7y agoAndroid has better sandboxing for apps (Java virtual machine + process isolation + user isolation + se-linux + containers & virtualization in some cases). But the permission system is so badly designed it's almost wide open. The hardware you are thinking of is mainly used for secure storage and crypto.
- on_and_off 7y agoWhat's wrong with the permission system design ? (agree otherwise on the refutal of GP, but curious about that point)
- panpanna 7y agoOld permissions were too broad. Need a file? Here is a permission to look at ALL files! More restrictive permissions (and a new model where you don't need a permission but user decides what file to access) were added later but it takes time to get developers to change.
- 693471 7y agoAndroid's hardware is extremely fractured with the majority of the devices sold being cheap and missing the good features, including hardware security. Apple's phones are more homogeneous. Certainly a larger percentage of Apple users have a Secure Enclave than Android users do.