36 ms·
>today’s nation-state attacker’s vulnerability could become part of tomorrow’s everyday cybercriminal’s arsenal While theoretically true, I can't find recent e
by _23sd 3y ago
>today’s nation-state attacker’s vulnerability could become part of tomorrow’s everyday cybercriminal’s arsenal
While theoretically true, I can't find recent examples of this happening with zero-click exploits on iOS or Android. Without evidence of this being a common infection vector it's not, in my opinion, enough reason to encourage people to get rid of a working phone just because the security backports might be a bit lacking.
The more important security reason to keep up with the latest OS version is the sandboxing improvements that iOS and Android make with each update. If you assume the device will be compromised with a malicious app at some point, you want to have more protections against the malware stealing data from other apps. This is (for now) a bigger deal on Android, where malware routinely makes it into the official app store and malicious APKs are floating around all over the place. But it's worth considering on iOS too, especially if you run a lot of apps from companies that hate privacy or if iOS later allows some form of sideloading.
- superq 3y ago> While theoretically true, I can't find recent examples of this happening with zero-click exploits on iOS or Android. Mostly iOS. And how would you even know? There have been some large cryptocurrency thefts recently.
- fh9302 3y agoCan you link to some evidence that these cryptocurrency thefts are related to zero-click attacks on iOS? The LastPass breach resulted in theft: https://www.theverge.com/2023/9/7/23862658/lastpass-security-breach-crypto-heists-hackers https://www.theverge.com/2023/9/7/23862658/lastpass-security...
- saagarjha 3y agoAdvanced cybercrimals occasionally do this on Android at least.
- walterbell 3y ago> I can't find recent examples of this happening Before or after a public exploit is posted alongside CVE+patch?
- _23sd 3y agoI’m mostly talking about after, but it would be even more interesting if there are examples of high value mobile exploits being used as 0-days by more common cybercriminals as opposed to government backed spyware firms.