Every single release with iOS has been totally broken security-wise, as can seen from the existence of jailbreaks.
Apple doesn't even require seeing the source code, and so there is no way they can stop malicious applications written to evade detection from getting to the App Store.
And thanks to their policy you must browse with Safari WebKit, which is a nice juicy ~40% browser share target.
Of course, both Android and Windows Phone are broken too, since they also expose oversized monolithic kernels written in C to random applications, but at least Android doesn't require you to give up freedom to get non-security.
The jailbreaks for recent versions of iOS only allow jailbreaking unlocked devices, at which point security is already compromised.
> And thanks to their policy you must browse with Safari WebKit, which is a nice juicy ~40% browser share target.
In iOS 8 they allowed other apps to use the same JIT engine Safari does[1]. This makes me inclined to take them on their word when they say it was previously disallowed for security reasons (some early jailbreaks could be done just by visiting a web page, using security holes in Safari's javascript JIT).
[1]: http://9to5mac.com/2014/06/03/ios-8-webkit-changes-finally-a...
What? You must mean something else because unlocked devices aren't (necessarily) compromised.
I mean compromised in the sense that the malicious party now (for example) has access to the user's email, and would be able to reset a whole host of passwords for online services (assuming they don't use 2FA or something similar, which most users don't). If they wanted to install a keylogger, or get saved passwords, then yes they still have to jailbreak my device. This xkcd is relevant: https://xkcd.com/1200/
Here's a recent report from computerworld - Malware infections delivered via mobile networks - Windows 80%, Android 20%, "iOS and other operating systems were at nearly negligible percentages"
Nothing's perfect but iOS isn't that bad.
(Window's numbers seem to be mostly pcs with tethering. "Data generated from scans by Alcatel-Lucent's Motive Security Guardian technology, which is deployed worldwide by both mobile and fixed-line networks, and monitors traffic from more than 100 million devices")
http://www.computerworld.com/article/2984444/mobile-security...
Virus' primary function is to replicate itself and infect other hosts. You can not simply install apps (or viruses) on other mobile devices without user intervention. Also viruses need access to system and/or other apps to be able to propagate itself, which is not the case on mobile platforms.
None of that things is true for demons.
Btw, iOS also has long running processes if you register proper functionality (VoIP, background download..) when submitting the app to App Store. Also iOS and Android apps can be awaken from the server and perform tasks without user noticing it.
http://arstechnica.com/security/2015/09/drop-dead-simple-exp...
Which isn't to say I don't think there are advantages to Android's model and that of more open package repositories in general, especially for power users. However most of Apple's base is people who don't care about openness or extra repositories, they want their iPhone to work with a minimum of fuss and not have to worry about malware like you do on Android.
The fact that we can only point to a single (XcodeGhost) cromulent exploitation of the Apple App Store stack is a testament to how good Apple is at maintaining the relative security of the iOS ecosystem.
http://gawker.com/feds-seized-chicago-mans-computers-in-cele...
Those accounts were breached because celebs were phished and not because of bruteforcing, as some people were speculating at the time, or some other vulnerability.
'"In total, the [500] unique iCloud accounts were accessed 3,263 times," the document states.' - http://www.businessinsider.com/fbi-investigation-into-the-fa...
This was a massive failure in Apple's part.
If you want to treat users like infants, then you should hereby completely forfeit any and all rights to complain about "tech shortages" and technical illiteracy of end users.
The right thing to do is to ignore it, but on the off-chance that you might be somewhat self-aware, I thought I'd give you the opportunity to catch yourself.
Why the scare quotes? Just because it doesn't provide 100% security doesn't mean that it provides no security.