The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!).
Let’s, just for a second, propose that apple went full Monty and locked the whole shebang down with the kind of tech they’d need to resist NSO. That’s more custom silicon, signed binaries everywhere, even fewer per app permissions, literally treating any piece of software running on the device as a potential threat vector even more than they already do. What would this get you?
The BoM cost would go up, a lot. The cost of writing software would go up, a lot. And perhaps worst of all: it would only raise the cost of a chain of exploits, not eradicate it.
Right now a chain of exploits is ~$5M on iOS. What if it was $50M? Would that actually stop a nation state?
I’m sorry but there’s no world where Apple can make perfect security.
Finally, the cost of this lawsuit is a drop in the ocean compared to what they already spend trying to secure the software and hardware in iOS devices.
i think everyone knows that perfect security is not possible, the operative word being ‘perfect’. i think what we want is for apple to ‘actually try’ to provide security, in some way that results in security order of magnitudes better than we enjoy today, which would still be miles and miles away from ‘perfect’, vulnerable to nation state actors etc etc etc
That's a pretty tall order, and would likely result in a device that is much more expensive and has a user experience that users would not like. Assuming "orders of magnitude better" is even possible, of which I am skeptical.
Put a different way, is there any device with a high monthly active user count that has a higher cost to purchase a black market exploit than the iPhone?
Apple can always do better. It should also scare the living hell out of us that they’re currently the best in the world.
My point is that if Apple can’t secure your phones, who can? It’s enough to make one think about security through obscurity.
This is unfair, because there is a duopoly and the only alternative on mass market is Android. Of course in such circumstances the exploits will be expensive, even if security is awful.
Ignoring this, Purism takes security more seriously, because they give the user full control over the OS with possibility to replace/reinstall or harden it. In contrast to that, rarely updated iMessage is impossible to uninstall on iOs.
I'm going to answer about operating system rather than device.
The selling price of an Android full chain with persistence zero click is up to $2.5 million. The selling price of an iOS full chain with persistence zero click is up to $2 million.
https://zerodium.com/program.html
Both are better than any desktop operating system.
You're right that the price doesn't fully correlate with security. It will reflect supply (security and interest of researchers) and demand (how much there is to be gained by breaking into each platform).
Android is more widely used, but I gather more money is spent in the app store than the play store. I don't know the market share of "interesting" users.
My analysis would be that the number shows they're not that far apart. I'd be skeptical of anyone (IE apple's press release) saying that either platform is more secure. Security is too nuanced to be expressed as a total order.
But Apple is praising and promising to support independent security research in this press release. Meanwhile they have a reputation among independent security researchers for being standoffish, opaque, slow to respond, and even outright hostile in suing Corellium. They settled that suit but the reputation remains.
Apple is the most valuable company in the world. They do not appear to have the best security program in the world. Whatever Citizen Lab can do, Apple should be able to do better; they have a lot more resources and expertise.
I’m not doubting that Apple puts a lot of effort into securing their products. But it seems like they still have significant room for improvement.
Also, Apple's sandboxing settings and permission managing makes the most malware pretty useless with App store policies (no sideloading), so only RCE exploits are kinda useful.
What it comes to iMessages, that is the most interesting channel with Safari to deliver exploits, iMessage without user interaction and Safari with some. All you need to know is that target is using iPhone. Other non-default applications as target introduces new challenges. iMessage and Safaring being part of OS updates might indicate, that they are handled differently compared to other apps - is security policy same, worse or better? Is there larger attack interface to system by using these apps?
By what measure? That they don’t find all the security bugs? Have you seen what iOS exploit chains look like these days? They’re not exactly simple. I think there is literally no amount of money that could be spent that would eliminate all the security bugs in iOS, or Apple would be figuring out how to spend that much right now. So yes, you can always argue that they should spend more, and I’m sure they do spend more every time something like Pegasus happens, but it’s not some grand revelation. This is just how things are.
> Whatever Citizen Lab can do, Apple should be able to do better; they have a lot more resources and expertise.
At the tail, this doesn’t matter. Other people find bugs because there are always more bugs to be found. There will never be a situation where only Apple can find more bugs in its operating system.
In my opinion, most of the HN audience would be able to use it to their benefit.
Sounds amazing. Every operating system should be designed this way. Only free software should have full access. Proprietary software cannot be trusted and must be regulated and controlled.
Yes, some states yes it would. That could make it unaffordable for many of NSOs clients.
The result would not be perfect, just better.
It's a cat-and-mouse game where Apple has a distinct disadvantage, one that's likely impossible to fully overcome.
They certainly should (continue to) spend a bunch of money to make their OS and hardware as secure as possible. But at a point returns start to diminish, and perfection just isn't an attainable goal.
A fictional example: there is a character in Wheel of Time, that realized that for the good guys to win, they must win every time the bad guy attempts something, but the bad guy must win only once (since his goal is destruction of the universe), thus this character concludes that being evil is a better goal, since you can keep trying until you succeed, he imagines eventually he WILL succeed, as a matter of "when", not of "if".