5 ms·
Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every fo
by tempfs 6y ago
Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others.
Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.
- etaioinshrdlu 6y agoApple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.
- viraptor 6y agoI wouldn't call it extreme when there was a known public website allowing one-click jailbreak for good few months (not sure if it was actually ever patched or just the iOS version got eol)
- ghughes 6y ago10 years ago, yeah. https://en.m.wikipedia.org/wiki/JailbreakMe https://en.m.wikipedia.org/wiki/JailbreakMe
- Wowfunhappy 6y agoActually, Safari has been used for exploits much more recently than that! https://totally-not.spyware.lol/ https://totally-not.spyware.lol/ (iOS 10, 2018)
- _underfl0w_ 6y agoThey then hired the guy creating those exploit chains.
- nemothekid 6y agoIt's unsurprising that the main vector for iOS jailbreaks would be through the web engine. The FreeBSD-based PlayStation 4 was also jailbroken via it's browser. If you have written a hardened, safe browser engine then you are free to share it to the world, otherwise I wouldn't downplay their efforts.
- ndqc 6y agoChrome/Chromium has a better track record and it is shared with the world. The number of Safari-based iOS exploits found in the wild is embarrassing. Not OP, but I'll stop complaining when Apple lets me use other browser engines.
- Hnrobert42 6y agoWhat would be an acceptable response from Apple?
- boogies 6y ago> Apple puts rather extreme security effort into preventing iOS jailbreaks. Yes, IMO their business model is more accurately described as “gilded cages/jails” than just general “gilded/good-appearing stuff”. They deeply care about the strength of their DRM — including at the expense of end-user security, eg. you can’t access the internet through the Tor browser installed the normal macOS way without macOS broadcasting that you used Tor Project products to Apple’s DRM servers.¹ > They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They definitely care about the appearance of trying to prevent that exfiltrating (they don’t publicly appear to help the FBI do it), but they don’t try hard enough to actually prevent it (including in situations were preventing exfiltration seems to have been proven possible, see nearby comment https://news.ycombinator.com/item?id=26667141 https://news.ycombinator.com/item?id=26667141). ¹Edit: ocsp.apple.com, enabling targeting of the people who need or want security the most. To the people downvoting: I’m trying to make an evidence based refutation of the less supported speculation/assertions in the parent post. If you have counter-evidence or any reason to downvote other than fanboyism, please explain it so we or I can learn.
- Hnrobert42 6y agoYou don’t provide much evidence. Your second point is just opinion, “they don’t try hard enough.” Your first point is intended to refute the effort put into stopping jailbreaking in iOS. The example you give is about privacy on Mac OS. Last, accusing folks of being fanboys is a particularly weak argument. It says, if you don’t agree with me then your blind allegiance to a corporation renders you incapable of critical thought. Basically, if you don’t agree with me, you’re dumb. There is no practical engagement with that thesis.
- deleted 6y ago[deleted]
- willio58 6y agoSecurity drives profit if it is marketed well. Apple does this. Think about even their branding for certain things, e.g. “Secure Enclave”.