JailbreakMe highlights just how vulnerable iOS users are
extremetech.com
extremetech.com
I'm kind of worried by the current status of mobile securiy. I kind of need to log on my bank account on my phone (That's why I own a 'smart' phone after all). But I really don't feel safe, I try to not install suspicious applications because I'm aware of the various risks but as someone pointed out the other day: "Given a choice between dancing pigs and security, users will pick dancing pigs every time."
Time will tell, maybe we need a Blaster/Stuxnet like event on smartphones in order to realize what's really going on.
Smartphone security feels like the Windows 9x era, let's go on the internet and pray !
I think you're right. Most people who see what JailbreakMe is doing probably don't understand that you're not supposed to do be able to do that.
But on the other hand, sites like jailbreakme.com really highlight just how terrible Apple's security is. Things like this really shouldn't happen and it would probably be better that jailbreaks didn't exist. With all the different types of transactions and personal information stored on iOS devices, it's really unsettling to think that a simple website could remotely exploit a security flaw and provide complete access to my iOS device.
The thing is, these exploits exist before the jailbreaks themselves. If jailbreaks were no longer released publicly, the exploits would still be there. Who knows what would have happened if they were discovered by someone else (and who knows that they actually weren't)?
When the PDF exploit was found for the last jailbreakme exploit, the first iOS users to have a patch available to them were those who jailbroke their devices. Apple followed shortly thereafter.
Jailbrake is good, I jailbroken my 3G after one hour outside its box. (And I used your VNC implementation to allow a disabled friend in a wheelchair to use an iPhone)
That's said, exploiting a hole in the pdf renderer is scary. This shouldn't be possible.
From a product standpoint, apps are features/content (specifically, multiple thousands of little features) for Apple's devices.
The App Store is the default, curated way to get apps for iOS. However, having Cydia around hardly devalues the App Store or it's apps.
Kind of like Microsoft's (and Adobe's) views on piracy for the expansion and domination of Windows (and Photoshop/CS)...
How...insightful?
Is extremetech's audience really so unfamiliar with the basics of technology that they needed an article to point out that this remote code exploit demonstrates that users are vulnerable to a remote code exploit?
I get that there is some audience that might need to have it pointed out to them that people walking into your house and taking your stuff illustrates how vulnerable unlocked doors are, but is the audience for that article really hanging out at extremedoorlocks and commenting on Locksmith News?
I think you hugely overestimate both people's understanding of technology and the average reader of that site. (Here's a hint: this is who owns extremetech: http://www.ziffdavis.com/)
Sufficiently advanced technology turns into a black box. Jailbreaking is presented to the user as an installation process, the only difference is it's done on your phone. It isn't presented as something that could happen automatically and without your consent. Before they can understand the implications of an exploit themselves, they have to understand:
1) it can be activated merely by following a link, not by following some benign 'install procedure'
2) it has unrestricted access to your phone, it is not merely flipping a 'install whatever apps I like' switch
3) the bad guys can do it too
Not all of which are obvious to a user who has been wrapped in wool by Apple's walled garden.
In contrast, the facts of an unlocked door are so incredibly obvious and simple that they don't require more than a sentence to understand. Your analogy is better put as "Leaving your door unlocked saves time spent looking for your keys, and prevents you ever getting locked out if you forget them! However, this means anybody else can go into your house, and even take your stuff. That's why it's important to lock your door." And if extremedoorlocks is aimed at the same kind of person who would visit extremetech, yes, they probably do.
Yeah, that's a fair point, I suppose. You need some basically familiarity with the internals of the system in order to know that there is no such benign switch.