4 ms·
General purpose PCs have a security model that takes into account that the end user has root access to the machine. OSes typically have methods to detect/mitiga
by anang 6y ago
General purpose PCs have a security model that takes into account that the end user has root access to the machine. OSes typically have methods to detect/mitigate exploits.
A jail broken/rooted device may not have the same protections since jail breaking is typically circumventing that sort of threat protection.
- dintech 6y ago> A jail broken/rooted device may not have the same protections since jail breaking is typically circumventing that sort of threat protection. If it was jail-breakable, that security was never there in the first place.
- leviathan 6y agoYou are the one who jail-breaks the phone, but now third party apps you install can have much more unprotected access and you cannot be certain what they are doing behind your back.
- anang 6y agoJail breaking is a deliberate and involved process, in some cases something that the manufacturer even allows for. It’s not really the same as a random piece of JavaScript on a webpage jail breaking your phone. I think having a rootable device doesn’t inherently mean your device is insecure.
- ValentineC 6y ago> It’s not really the same as a random piece of JavaScript on a webpage jail breaking your phone. I think having a rootable device doesn’t inherently mean your device is insecure. Heh this was actually the case for a couple of Safari-based jailbreaks, all the way up to 9.3.4: https://en.wikipedia.org/wiki/JailbreakMe https://en.wikipedia.org/wiki/JailbreakMe
- AnthonyMouse 6y ago> A jail broken/rooted device may not have the same protections since jail breaking is typically circumventing that sort of threat protection. So your argument is that walled garden devices are less secure assuming there exist methods to convert it into a general purpose computer, which they empirically do. Shouldn't this be an argument for such devices to be less trusted? After all, you can't always tell when this has happened (so you better assume it has), whereas as you say the devices designed to be operated under that threat model would then be more secure.
- anang 6y agoThat’s not my argument. All I’m saying is that a bank has good reason to be concerned about a phone being jail broken/rooted. I absolute agree that a user, as the owner of the phone, should be able to do this, especially in a safe and official manner. Right now it’s an all or nothing and that is a problem.
- scarface74 6y agoWith all of the malware and ransomware that is constantly bringing down governments and organizations, the “security model” isn’t working. Would you do banking on a random computer?
- AnthonyMouse 6y ago> With all of the malware and ransomware that is constantly bringing down governments and organizations, the “security model” isn’t working. The three largest ransomware vectors are people leaving RDP exposed to the internet, phishing emails to get login credentials that are then used to gain access to internal systems, and vulnerabilities in existing software. None of those requires the user to install third party malicious software. > Would you do banking on a random computer? Would you do banking on a random iPhone? I wouldn't. There have been more than enough vulnerabilities that you have no way to know if it has already been compromised.
- scarface74 6y agoCitations?
- AnthonyMouse 6y agoI assume you're asking for the ransomware thing since the article this discussion is attached to describes several iOS vulnerabilities. https://www.digitaldefense.com/blog/top-3-attack-vectors-ransomware-loves-to-exploit/ https://www.digitaldefense.com/blog/top-3-attack-vectors-ran...
- scarface74 6y agoInitially, the thesis was that ransomware doesn’t come from installing software that has unfettered access to the file system and that it comes from RDP. As far as I know RDP is not enabled by default on consumer PCs. I just searched for “ransomware” on Google. MalwareBytes “One of the most common methods today is through malicious spam, or malspam, which is unsolicited email that is used to deliver malware. The email might include booby-trapped attachments, such as PDFs or Word documents. It might also contain links to malicious websites.” PCs and Macs are “insecure by design”. Anything that the user runs has full access to the users files and applications - without administrator access. How could this possibly be more secure than your typical iOS device? We have over 30 years of evidence of what happens when the typical user is able to install software that has free reign on their computer. “ Malvertising often uses an infected iframe, or invisible webpage element, to do its work. The iframe redirects to an exploit landing page, and malicious code attacks the system from the landing page via exploit kit. All this happens without the user’s knowledge, which is why it’s often referred to as a drive-by-download.” The browser is also another application that is not sandboxed on personal computers. Any security vulnerability in the browser leaves the computer vulnerable. Notice that most if not all mobile ransomware affects Android devices? https://blog.malwarebytes.com/threats/mobile-ransomware/ https://blog.malwarebytes.com/threats/mobile-ransomware/