Please read the original source at https://news.ycombinator.com/item?id=20835223
Please read the original source at https://news.ycombinator.com/item?id=20835223
So if you don’t tell me I need to reboot my iPhone, I won’t.
I can't see how any software provider (ie Microsoft, Linux, Google... ) will say "install this patch to fix this and you may or may not been hacked, good luck"... They just provide the patch.
Consider a lock manufacturer that has a key copy of each client. If someone enters in the building and steals all the keys, clearly the manufacturer should inform all their clients. But, if a vulnerability has been found in a lock model, the manufacturer can tell you about the vulnerability, but definitely they can't tell you if your house has been robbed that way (or if it has been robbed at all).
Anyway, with this story alone and without knowing if you have visited these webpages that allegedly hacked your iPhone (why aren't they listed?) the only thing you can do is renewing passwords in your most critical accounts.
It’s not big news when it happens all the time.
What is big news, that’s gotten lost in all the noise, is that Google (through it’s crawling of the web) has been able to identify that some websites were (are) indiscriminately jailbreaking iPhones for the purposes of stealing user data.
This is the kind of thing that is routine on Windows, is likely to be routine on Android (given how many unpatchable devices are in use) but wasn’t considered to be routine on iOS.
The takeaway from all this is simple: if you’re not fully patched, you’re at significant risk. It doesn’t matter which platform you use.
This is part of the reason CVEs and security bulletins exist. We're being notified about potential issues all the time by many vendors.
But CVEs are intended for specialists. "Users" don't know about CVE.
It's not bad for the phone, and whether it's bad for the battery depends on the battery technology. In fact previous battery technologies were recommending the occasional full drain!
For lithium-ion batteries the kind used in the iPhone draining to 0% can indeed strain them (though less than you think, as shown by research), but the iPhone doesn't let them go to 0% anyway. It switches off way before that (even if it shows it as 0%). Mind you that regular use cycles (defined by Apple as using 100% of a full charge, even if it's broken down as going from 100% to 80% for five days and recharging) also strains the battery. You cannot not strain it, all current technology batteries degrade over time.
Also note that getting lithium-ion batteries to 100% and keeping them charging can also harm them (although modern devices have mechanisms to prevent that). In general it's advisable to keep going from 80%-20% and back, than to go all the way to charged (or down to 0). Same, one should not store long term fully charged.
But most of this is irrelevant micromanagement unless you plan to keep your phone for years and don't ever consider replacing the battery. Even so, the battery lifespan vendors like Apple give is around 3 years of cycles.
All in all, you can fully drain your lithium-ion iPhone battery as often as the average person does (e.g. just avoid doing it all the time), and you'll see no special degradation. It will run its cycles and will degrade by regular use after a few years even if you never let it drain (and you can trivially replace it with a new one).
Why should we trust your statements over ones like these which seemingly are backed by more data and and explanations of the underlying physics?
[1] https://batteryuniversity.com/learn/article/how_to_prolong_l...
More importantly, that such tracking is marginally useful micromanagement (and, Apple's artificial throttling for degraded batteries aside, has nothing to do with affecting a device's speed. A 90% charged device is not magically faster than a 20% charged one). Apple itself, in their document about battery technology and care ignores the "fully drain" issue completely.
Sometimes I wonder if the windows 10 auto-update fiasco was really about people who rarely recharge; and finally charging their laptop the one time they needed to be prepared, only to get owned by Windows Update at the worst time.
I wish there was a good way to report it, neither apple or twitter seem interested.
If Im just browsing I use the mobile web interface since it's just better anyways.
Seems people are going out of their way to let Apple off the hook for not disclosing to the user a major risk and silently fixing it.
1) the GP quoted the part about rebooting wipes the malware. But that doesn't matter if the info was taken before the user rebooted. So this comment is really off topic.
2) the GP comment is about letting users be aware so they can help mitigate the problem and assess the threat level. For example, users need to change their passwords. If you've ever worked with any government agency their number one concern is not leak of data, but knowing what leaked (obviously they want to minimize that). Knowing what leaked is extremely important. This is what the comment is about. I don't understand how your comment addresses this.