12 ms·
About the security content of iOS 12.4.9
- tptacek 6y agoA tricky thing about flagging "in the wild exploited vulnerabilities" in a title like this is that it suggests that sev:crit vulnerabilities in other updates that aren't flagged like this aren't being exploited in the wild. We get confirmation of only a subset of exploited vulnerabilities. We'd be better off with a more neutral title, like "fixing severe vulnerabilities" or something like that.
- thatguy0900 6y agoI still think it's important to say that we know they are being actively exploited, even if all vulns might be
- tptacek 6y agoThat's the kind of thing you can say in a comment, rather than in the title.
- dang 6y agoWe've changed the title above to that of the page. (Submitted title was "Apple releases iOS 14.2 and 12.4.9, fixing in-the-wild exploited vulnerabilities".)
- scarybeast 6y agoI think this is a bad decision. The "in-the-wild" part is the interesting part because it is not the norm at all and it implies an interesting story.
- judge2020 6y agoI’m not sure if it actually means “being used to exploit unknowing devices” given that Apple doesn’t define how they use it on that page. It very well could be referring to news about iPhone 12 jailbreaks (not that there is one yet https://twitter.com/fce365/status/1320691136890109952?s=21 https://twitter.com/fce365/status/1320691136890109952?s=21)
- tptacek 6y agoIt's an idiosyncrasy of the site that we avoid highlighting things in titles ("stories are community property, and submitting one doesn't give anyone the right to editorialize them"). I agree that the title we ended up with is suboptimal! "Exploitable" is a word I'd have been comfortable seeing there. But you take the good with the bad with the HN title rule; the site is primarily about discussion, not about being a noticeboard, and titles determine the discussion we have.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- dang 6y agoHappy to change it to a better title, i.e. something more accurate and neutral. We're particularly happy to do that with corporate press releases, which often deliberately obscure the situation. But usually that requires a suggestion (and at least partial consensus) from users who understand the story. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sort=byDate&type=comment&query=corporate%20press%20release%20by:dang https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...
- saagarjha 6y agoYeah, Apple's page titles generally suck, especially when they are presented without context. The big things in this one is that they're pushing fixes to devices that people had considered abandoned for almost two years, and that these fixes explicitly mention that they have been exploited in the wild in what I believe is Apple's second admission of this, and the first time they did so without blaming Google Project Zero of a mischaracterization. That's clearly a bit too much to put in a title, but something like "Apple releases iOS 12.4.9, backporting fixes for severe security vulnerabilities". I'd like to put "exploited in the wild" in there somewhere as well since I think it's an important part of the story, but I am not sure if this would keep it neutral.
- sneak 6y agoThe other thing to consider is that doing a binary diff on the OS before/after patching puts a big red arrow right at the location of the bug, which means that there's no reasonable expectation that it will remain unexploited after the patch. It's not really that important, really. It's either being exploited yesterday, or tomorrow.
- baby 6y agoDisagree, if we have proof that it is currently being exploited then that’s the news more than anything else.
- swiley 6y agoMaybe I got hit with one of these, my phone stopped being able to answer phone calls and auto focus stopped working (like something re flashed the firmware on a bunch of the internal peripherals.) I was going to wait until the software on my pinephone was more mature but that pushed me over the edge to get power management working on my own and make sure it could make phone calls. I think dumping iOS has done a lot for my mental health and I'm glad to have left it.
- tptacek 6y agoPer PZ, the attacks here are targeted, meaning that the people exploiting them spent a fair bit of money to get these exploits, and are presumably very unhappy that they are burned. Unless you are special, it's unlikely that you got hit with one of these.
- deleted 6y ago[deleted]
- asimilator 6y ago> I was going to wait until the software on my pinephone was more mature but that pushed me over the edge to get power management working on my own and make sure it could make phone calls. I guess stress is personal, because this sounds way more stressful than anything I've had to deal with on iOS! And I say that as someone who'd like to get a more open (hardware and software) phone in the future.
- patio11 6y agoNote that there are similar issues in macOS, too. https://support.apple.com/en-us/HT211947 https://support.apple.com/en-us/HT211947 <-- Catalina 10.15.7 Supplemental Update notes
- 1over137 6y agoBut nothing for macOS 10.14.x, oddly.
- saagarjha 6y agoCatalina runs on all Macs that support Mojave, which I assume influenced the decision. (I didn't see an iOS 13 update, which helps bolster this theory.)
- why_only_15 6y agoMy guess is that iOS 13 didn't drop support for any devices, and Apple is only releasing a patch for devices that can't upgrade to the newest OS.
- saagarjha 6y agoThis is also my guess ;)
- heavyset_go 6y agoI think it's interesting how iOS exploits are cheaper[1] than Android exploits, because iOS exploits are so plentiful in comparison to Android exploits. [1] https://arstechnica.com/information-technology/2019/09/for-the-first-time-ever-android-0days-cost-more-than-ios-exploits/ https://arstechnica.com/information-technology/2019/09/for-t...
- duxup 6y agoIs that still the case? The article implies that before it was written that wasn't the case previously.
- Veserv 6y agoDoes it matter? A full-chain zero-click remote complete compromise for either system is only $2-3 million. That is absolute chump change. 4-6% of households in the US [1], 5-8 million households, have sufficient assets to fully compromise every iPhone or Android in the world. If we consider businesses, I bet that is within the reach of no less than 50% of the businesses (including small businesses) in the US. That is an absurd number of entities where that price point is totally doable. If a bad actor can derive just $10 on average per phone they attack, then all they need to do is find a way to deploy their $2-3 million exploit to 1 million phones for less than $5 million to make a tidy profit. Given that we are talking about zero-click remote compromises, which means the victim only needs to receive the payload, this means that it is profitable as long as the cost per victim impression is less than $5, a CPM of $5000. With that sort of budget you can embed your attack into an ad and then outbid everybody else by a factor of 10 for placements. You can buy a mailing list and embed your attack as a "payload pixel". If it is a zero-click text message attack then you can buy access to the spam-callers and mass deploy it that way. These systems are between a factor of 10-100x off of adequate. To care about their relative differences is like debating whether paper mache or tissue paper is better at stopping bullets. One is probably better than the other, but neither provides meaningful protection, so it hardly matters. You need fundamental, qualitative improvements before differences between the solutions provide meaningful effects on outcomes. [1] https://dqydj.com/average-median-top-net-worth-percentiles/ https://dqydj.com/average-median-top-net-worth-percentiles/
- jamiehall 6y agoLinking to the 14.2 list (https://support.apple.com/en-us/HT211929 https://support.apple.com/en-us/HT211929) might be better? After clicking the headline link, it took me a few seconds to understand why we were caring about updates for the iPhone 5 and 6...
- snazz 6y agoI think it's worth linking the 12.4.9 page because it's impressive that the software update is available going all the way back to the iPhone 5s. That's some serious longevity.
- zokier 6y ago> That's some serious longevity Well, yes, its better than your average Android vendor. But on the other hand Windows 8 was released 2012 (i.e. about a year before iPhone 5s), and is scheduled to get updates until 2023. That is pretty serious longevity. And supporting handful of Apple devices must be comparatively simpler than supporting the hodgepodge fleet of Windows 8 devices.
- beagle3 6y agoApples (ha!) to Oranges. Personal computers cost, on average 2-4 times what the 5S cost in its day, and are expected to last much longer than a phone (as evidenced by the lack of uproar that all phone vendors including Microsoft drop support within 2-3 years ... except Apple).
- yabones 6y ago8.0 which was released in 2012 is no longer supported, with the last updates landing in early 2016. [1] 8.1 on the other hand _is_ supported until 2023. [2] The majority of 8.0 users immediately upgraded to 8.1 (because 8.0 was slightly terrible), so you're mostly correct. 10 years of support is pretty standard for Windows releases. [1] https://docs.microsoft.com/en-ca/lifecycle/products/windows-8 https://docs.microsoft.com/en-ca/lifecycle/products/windows-... [2] https://docs.microsoft.com/en-ca/lifecycle/products/windows-81 https://docs.microsoft.com/en-ca/lifecycle/products/windows-...
- alewi481 6y agoI'd like to give kudos to Apple for including the iPhone 5S in this security update, which was released on September 20, 2013, over 7 years ago! Supporting a product for even 3 years is rare in the smartphone world.
- ponker 6y agoThis is why Apple makes the cheapest smartphones, as long as you avoid dropping them.
- wnevets 6y agountil Apple throttles the hardware with their software updates [1] https://www.theverge.com/2020/7/13/21322867/apple-iphone-batterygate-throttling-slowdown-settlement-claims https://www.theverge.com/2020/7/13/21322867/apple-iphone-bat...
- hokumguru 6y agoWasn't the purpose of that throttling to extend the life of older phones? Throttling the CPU let them stay within the limits of the worn out battery and let the device continue to be used without crashing.
- wnevets 6y agoThat may have been their public explanation after being caught throttling the hardware.
- thebruce87m 6y agoYou just need to look at the evidence: * Only handsets with degraded batteries were throttled * Replacing the battery returned the handset to full speed * The only thing that changed after the fine was that you now have an option to stop the throttling and have unexpected reboots instead. * All iPhones since then, including brand new iPhone 12s will throttle when the battery degrades.
- MrStonedOne 6y agoAnybody get a bitter sweet feeling when ever these reported and fixed security exploits announcements happen? It's good that users aren't going to risk getting hacked by such vulnerabilities, but its bad that users can no longer uses these exploits to gain administrative control over their property.
- snazz 6y agoApple isn't going to force you to update your device, so you can stay on an older version if you want jailbreaks.
- MrStonedOne 6y agousers buying new devices that automatically update on activation aren't going to have that choice.
- nahkoots 6y agoUsers that care about having control over their devices shouldn't be buying Apple hardware in the first place. Not that I support Apple's anti-consumer practices, but if you buy one of their products, you have to know what you're getting yourself into.
- ValentineC 6y agoApple doesn't allow downgrading (and it's gotten even harder with Touch/Face ID not being downgradable with SHSH blobs), so people accidentally update, or get their hardware replaced in a repair, are SOL.
- beagle3 6y agoIf you want a phone that you have control over, don't buy one from Apple... At this point in time, choices are mostly limited to Librem and PinePhone.
- bamboozled 6y ago
- saagarjha 6y agoI think this is the first time Apple has mentioned that the bugs they fixed were exploited in the wild? A welcome change if so.
- sebastien_b 6y agoThe problem with these updates is that it's only for devices that can only support up to iOS 12 (in this case) - if you have another device that supports anything higher but don't want upgrade to the latest iOS, you still won't get these iOS 12 security updates - they force you to upgrade the entire OS to get them.
- olliej 6y agoYou're literally saying you have the ability to update, but don't want to, and so it's unfair you can't update.
- sebastien_b 6y agoNot exactly - more like being denied the ability to not have a specific OS version forced on someone if they want their device to stay secured. Being able to stay secured with the latest patches shouldn’t require one to be forced to get the unwanted memory/resource hogging “features” of newer OS releases.
- hosteur 6y agoCan these vulns be used to jailbreak a phone?