It is frankly ridiculous that anybody should believe Apple when they claim to provide even minimal resistance to well-funded determined attackers. Protecting against well-funded determined attackers has been the holy grail of software security since forever and everybody in software security at least claims to be working toward that. Despite that, the prevailing state of “best-in-class” “best-practices” commercial software security is objectively terrible including Apple circa 1 year ago.
Are we supposed to believe that Apple, despite abject failure over the last few decades until as recently as the last time they announced security updates to the iPhone, has finally this time, for sure, pinky swear its true, jumped from terrible to the holy grail, or even good, because they said so?
No, this is absolute, utter, unequivocal garbage. Their claims are completely unsupported and they should be excoriated for spewing unsubstantiated bullshit that muddies the waters of the actual state of software security and misleads people into believing they are getting a meaningful degree of protection or software security.
If they want to make such claims, they should put their money where there mouth is and, instead of certifying iOS to EAL1+ and AVA_VAN.1 as they currently do, they should certify it in “Lockdown Mode” to EAL6-7 and AVA_VAN.5 which actually does certify protection against “high attack potential” attackers such as large organized crime and state-sponsored attackers. At the very least they could certify it to EAL5 and AVA_VAN.4 which certifies protection against “moderate attack potential” attackers. Until they do that, their claims to protect against state-sponsored attackers are complete unverifiable bullshit.