4 ms·
I agree... but also that computer in our pocket has our entire life wrapped in it. The desktop has some mitigations against this. PWNing your mobile device co
by virtue3 1y ago
I agree... but also that computer in our pocket has our entire life wrapped in it.
The desktop has some mitigations against this. PWNing your mobile device could completely wreck you in a lot of ways.
I switched from android to iphone because someone 0-day'd me. I'm not saying it can't happen on iOS or something; just less likely - and mostly because of these restrictions.
- cosmic_cheese 1y agoYep. With exception to apps that don’t interact with the internet in any way whatsoever (not even opening downloaded files), which is pretty rare, keeping up with library updates is pretty important if one doesn’t want to make them ever more of a sitting duck as time goes on.
- Dedime 1y agoPeople keep talking about having been hacked, but it's honestly baffling to me. I'm 28. I started using computers on a regular basis when I was ~9 years old, playing RuneScape. Since then, I've spend probably 10s of thousands of hours on the internet - downloading torrents, signing up for sketchy Russian websites, doing online banking, testing experimental software downloaded over HTTP from a .xyz domain. I graduated high school, went to a technical college for compsci, graduated, worked in helpdesk, desktop support, IT management, and more recently DevOps. I develop software using all sorts of package managers, and used hundreds of thousands of unvetted software packages that arrived as dependencies. Not once have I, or anyone I've been responsible for, been hacked. No crypto, no viruses, nothing. What the heck are you guys doing getting your Android phones hacked???? Like I only use a modicum of common sense these days, but I guess I've just been lucky and have been the odd one out. I still enjoy reading HN arrivals about security though, so maybe I just have always been slightly more security conscience? In any case, this is just a stream of consciousness / gut feeling comment. Don't put too much weight into it, I haven't.
- OutOfHere 1y agoThe way in which getting hacked works these days is that you as the user will never know. They will just silently exfil your data, and also use you to get to others. You will be none the wiser.
- exe34 1y agoIf it's so secret that nobody will ever find out, then I'm okay with it. On the other hand, it's true that some people find out their credit score is trash right before buying a house, or that their name is involved in terrorism when applying for a visa, etc.
- OutOfHere 1y agoYou should not be okay with it because they will most definitely use it to exert power over you. They are not professors or space aliens that are doing it for academic curiosity. It can be the government that wants to lock up someone, either now or in the future, or anyone that wants to steal your hard-earned crypto. It is not okay. These days they will also pass it through their AI, and potentially also use it to tune their AI.
- exe34 1y ago> If it's so secret that nobody will ever find out, then I'm okay with it. The original argument was that one would never know.
- OutOfHere 1y agoOne would never know until one loses their crypto, or one has the government hurting one's freedoms, possibly even using parallel reconstruction, or one gets blackmailed. If one doesn't know that their phone could've been hacked, one will be left wondering what happened.
- hliyan 1y agoCan OSes offer an application sandbox feature, where I can define sandboxes within which to install applications. Applications within a sandbox only has visibility into the resources I define: some folders, no camera or mic etc. I understand that app permissions do the same, but this would be more convenient than having to define granular permissions each time you install an app.
- ignoramous 1y ago> Applications within a sandbox only has visibility into the resources I define Isn't that more than a typical sandbox what you're asking for? The GrapheneOS developers said they're working on a feature where every app could be run in its own VM, like on ChromeOS: https://discuss.grapheneos.org/d/20647 https://discuss.grapheneos.org/d/20647 > some folders, no camera or mic etc. I understand that app permissions do the same The "some folders" part is already true for Android. Apps can't blanket access files/folders of other apps (save for ones stored in "external storage", which has also been scoped down in the recent releases: https://source.android.com/docs/core/storage/scoped https://source.android.com/docs/core/storage/scoped). > more convenient than having to define granular permissions each time you install an app It isn't Android that makes this inconvenient. It is the app developers that cause "prompt fatigue" (by showing permission requests repeatedly) or "blackmail" by refusing to work until permissions are granted. A new sandbox mechanism is unlikely to change much.
- exe34 1y ago> It isn't Android that makes this inconvenient. It is the app developers that cause "prompt fatigue" (by showing permission requests repeatedly) or "blackmail" by refusing to work until permissions are granted. A new sandbox mechanism is unlikely to change much. That's why spoofing should be an option. You want GPS? Timbuktu. You want my camera? Here's a close up video of a saggy scrotum. You need access to my contacts? Here's an address book with the contact details for all the funeral services within a 50 mile radius.
- nolist_policy 1y agoWait that? If someone burns 0-days against you, you have bigger problems and an iPhone won't save you.