If you care deeply about the privacy of you data, don't hand your data on a physical device to anyone.
If you care deeply about the privacy of you data, don't hand your data on a physical device to anyone.
Something is better than nothing. And the smoke and mirrors can still help. I agree OSS would be better, but I'll take what I can get. Even if that is just a moving ecosystem.
It's hard for phone these days, but my PC's security model is I can easily lock myself out of it permanently.
It was not even a sure thing that apple could do it.
The only reason Apple wouldn't do it was that it was such an embarrassment for its marketing to be shown to be a lie by something that had made national headlines.
As far as anybody being able to buy a 0-day, the price for such a 0-day is much higher for competitors' phones with better security.
Regarding the price of a 0-day, it is clear that the fbi bought it. (maybe it wasn't 0d at the time but it was an exploit.) The cost is irrelevant considering it was a state actor. In context of this discussion, apple resisted.
I'm all for more security and will take your recommendation for a vendor with more integrity. I think we have to weigh integrity vs capability, though. Good intentions don't confound tough adversaries.
The rest was media posturing.
Do you mean the syncing of messages between logged in devices via the normal iMessage delivery mechanism (which I know is encrypted), or the "Messages in iCloud" feature?
You know independent infosec reviews are a thing, right?