3 ms·
Contrary to popular belief, iPhones and Android phones have really poor security and new exploits are discovered all the time. So a properly formatted text mess
by polack 5y ago
Contrary to popular belief, iPhones and Android phones have really poor security and new exploits are discovered all the time.
So a properly formatted text message is all that's required these days.
It's like in the dotcom days when 90% of the web was open to SQL injection.
- dandanua 5y agoMeanwhile, they take 30% cut from developers and force everyone to buy a new phone every year. Microsoft monopolization of Windows is a child play in comparison to this phone racket.
- sgjohnson 5y agoNobody is forcing anyone to buy a new phone every year. iPhone 5S, released more than 8 years ago, is still getting updates.
- christophilus 5y agoMy iPhone 7 is a handmedown that I got 3 years ago. I see no reason to upgrade until it A) dies or B) stops receiving security updates, at which point I’ll probably just get another handmedown from someone who likes new things more than I do.
- sgjohnson 5y agoIt’s not at all like in the dotcom days. Unlike SQL injections, these aren’t low skill attacks that can be mounted by skiddies.
- polack 5y agoYou are right in that these attacks takes more skills or a little bit of money, so in that regard it's not the same. But in multiple ways I think it's the same; like that it's obvious that security is still not a priority when building the software and that you as a user have to assume that the platforms are compromised.
- kafrofrite 5y agoAny reasonably complex piece of software will have vulnerabilities. In other words, vulnerabilities are not a variable for the security equation, they are a constant. When designing something, vulnerabilities will exist. Generally, vulnerabilities, on their own, are not a great indication of how security is prioritized internally in any company.
- polack 5y agoWhen security researchers report SERIOUS security bugs to the manufacturers, as happened again and again the last years, without them acknowledging or fixing them for many months then I think it's safe to say they don't really care about security. You can go and talk about complex software and that vulnerabilities will always exists how much you want, but there is no excuse for these big companies to not fix major bugs like this within a week from when it's been reported. I don't care if that means that the developers have to postpone their fancy AI face recognition feature that will make your face look like an emoji. NO EXCUSES.
- sgjohnson 5y agoI actually wish NSO Group would sell their spying software to absolutely anyone willing to pay them money for it. I’m not okay with anyone at all having it, so maybe if everyone could have it, the industry would have to get their shit together and actually patch the exploits.
- dogma1138 5y agoNo it’s not I don’t think you realize the skill gap. There is no SQLmap for iPhones and a “Metasploit” for iPhones costs 10’s of millions and requires you to be able to negotiation contracts on a state level… The amount of money and skill that is require to identify these vulnerabilities and develop them into functional exploits is pretty insane. It goes well beyond what even basic RCE due to say unsafe deserialization in Java requires. Anyone without any knowledge in programming could probably learn how to identify and exploit a SQL injection even without automated tools within days if not hours. On the other hand even experienced developers look at something like FORCEDENTRY and can barely comprehend it.