I'm not convinced any of the folks involved ability to root would prevent the situation described.
I'm not convinced any of the folks involved ability to root would prevent the situation described.
The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?
Utilizing different software implementations limits the scope of this type of attack. The current trend to increasing centralization and forced-update monoculture is a huge gift to malware authors: they only have to write one version of their malware to affect everyone.
[1] https://www.schneier.com/blog/archives/2017/01/class_breaks....
In practice we may find a monoculture within a hidden layer of the stack than we're optimizing for, such as an OS kernel method, TLS library or chipset which coincidentally has captured the entire market. When a clever enough exploit on a common resource is found, then the problem transforms to one of coordinating patching for the same, wherein a broad ecosystem of higher level components (like Android or PCs) becomes nearly impossible to thoroughly cover. As such malware authors may potentially still get away with writing a single version of their software so long as they target low-level enough. With sufficient fragmentation they don't even need to invent their own exploits, just use publicly known CVEs that they can brute-force against older devices.
(Not saying you're wrong, your recommendation may still be better in the long-run. We're after all weighing the risk level of black swan events, such as a zero-day on a low level of the stack, or a high level of the stack on a high-volume vendor)
But we were talking about the general case of monoculture, not closed source monoculture. Even for closed source software, where more eyes are prevented from looking "by definition", having a monoculture can in theory allow more code audits to be done, because of economy of scale.
> large number of people using the software doesn't imply there is also a large amount of people reviewing it.
Right, but roughly speaking, the number of reviewers should monotonically increase given an increase in users. Whether that produces better security overall is anyone's guess. My point was just that there was a counteracting force to consider.
The argument is that removing freedoms from owners in the name of security is a false dichotomy because bad actors will still gain the ability to execute arbitrary code whilst owners of devices won't be able to do so.
Also, if I could provide the software I want to run, I'd probably not have iMessage.
Which is all to say, ideally a journalist would have N phones, one per source. But that's impractical.
1. the vulnerability wasn't FOSS. It was kept under wraps because otherwise it would get discovered and apple would patch it
2. what makes you think that amateurs working in their free time can patch 0days faster than the vendors themselves?
I think I'd like to check my iPhone, but I can't reliably do that.
So that, for a start, would help.
but you can, via itunes backup.
Maybe in 1995 it was like that, it's not now.
For example, do public eyes actually catch and did more Linux bugs than three letter agencies? And would this situation be worse if Linux were a very well funded, closed source Windows?
I’m ignorant on whether the open source security mantra is founded upon religion or evidence.
> For example, do public eyes actually catch and did more Linux bugs than three letter agencies?
Is it so important, who found a bug? TLA can find a bug, and then it has a choice: TLA can use it to spy on other countries, or TLA can fix it to protect their own country.
Your TLA may choose to leave your country unprotected, but it is the problem of your country.
I bet you, that image will be provided by the trustworthy people from NSO, free of charge or at a price! Whatever makes you trust their image.
IMHO devices should be root-able but with high barriers of entry, something like soldering should be involved. If you are after doing something that you don't understand but a stranger on the internet told you to do it you shouldn't be able to do it.
I just want to remind you that quite recently a few police agencies come together, built a "secure messaging app", fed it to the criminals and tracked all their communication until gather enough information to take down their entire operation.[0]
Or the time when CIA run a Swiss encryption company[1]
Nobody would be installing a Linux kernel and use the phone like that, they would be installing a distro. There are so many vectors of attack, the person who puts the distro together doesn't need to have malicious intent, the supply chain could be compromised.
Unfortunately, the only way to secure my phone because it no longer receives updates is through rooting, but this phone is not a model that can be rooted so my plan is to buy a new phone and root that, and probably remove all text messaging apps or find a way to sandbox them in a secure environment.
Smartphone landscape of software is a huge failure aside from monetization of apps and user data.