Apple issues security update for the almost 10-year-old iPhone 5S
theverge.com
theverge.com
Fuck you apple. Even in the apple universe compability sucks
As for the hotspot, I don’t see why the old iPad shouldn’t be able to connect to your phone’s wifi as long as you have “Maximize compatibility” enabled. I think I’ve had circa 2008 devices connect to my phone that way but I’ll have to test to see if I’m misremembering or not.
The core problem was that ipad and iphone have the same user account and because of that apple wants to share the network some other way then classic wifi. And this protocol aint updated in my ipad
And screen mirroring is working when I use a new ipad :/
I feel like that's the "we don't give a shit about resources" development mantra for you, banking on the ever increasing hardware limits that everyone will purchase in never-ending ~2 year cycles.
"Ah, it's a nice morning with so many free gigabytes of RAM, calm CPU cycles and sunshine. Let's slap a few questionable libraries and a bunch of chatty analytics modules into the build."
It doesn't help that a lot of major businesses work with contractors and consultants in relatively short-term gigs where feature development is king even if your application is reasonably feature complete. It's hard to improve a complex application if your domain knowledge and technical knowledge isn't quite there due to short time spent at the company (and likely no real personal invest in the product).
Also, in mid to large sized companies, constant unwarranted changes to please a fat layer of middle management which needs to pretend to have some sort of impact may lead to crappy development. Let's just change the UI and UX for the sake of it with 5 additional libraries, 2 more processes so that manager XYZ has something to show for his PowerPoint presentation. Don't you dare work on technical debt and refactoring, we need new features to make management happy!
Excluding possible external dependencies that might have broken or standards that might have changed, what did Netflix REALLY add to their app from a user perspective since it ran perfectly well on the iPad mini 2 in 2014?
It's just not cost-effective.
I've heard of cases where mobile game firms have actually given high spenders a new modern device for free instead of dealing with the issues caused by their relatively ancient device :D
For this specific use-case try https://b98.tv, though I couldn't get it working on my old iPhone 5C.
To be fair, this is often the claimed solution with AT&T and at least sometimes I'm certain it's BS (e.g. for a Samsung S10e, Verizon told my elderly friend the same thing last year). Hence my question.
Verizon doesn’t do that luckily, I believe they suspended new line activate with 5S however for existing lines they are not disable your line like AT&T yet.
I also don't really understand what you mean by "slowly force everyone ASAP". That's sort of a self-contradictory phrase.
4G: 600 MHz, 700 MHz, 1700/2100 MHz, 2300 MHz, and 2500 MHz, bands.
5G: 24 GHz up to 54 GHz.
Sure, it's an eventuality. But in the near term, is 6g really going to use 900MHz?
Almost everything supports GSM, so almost everything can manage, and then nobody needs to throw out their 2G only (or 2G/3G) car junk or power meters or who knows what else. Yeah, it's going to be slow, but whatever; people who want something better can upgrade in most cases, and the 2G usage can't be that high anymore. Carriers could even gasp cooperate and allow roaming on 2g, so you didn't need three of four different networks each spending a sliver of spectrum on it.
In this case, it's not quite BS from AT&T. They wanted to use the spectrum they had been using for 3G to make their LTE network better and certain old LTE devices couldn't do voice-over-LTE (the 3G network would handle voice communication). One could argue that they could have kept the 3G network alive longer (Verizon and T-Mobile shut 3G down in 2022), but at some point old devices stop being able to talk on modern networks. At some point, there's a balance between keeping old networks alive and being able to reuse that spectrum for more efficient networks that serve the vast majority of your customers.
Many countries still have working 3G networks that the iPhone 5S can connect to and they can still be used as WiFi devices in the US (oh, and I'm sure there are some regional carriers in the US that still support 3G).
India had that in the past but since 2008-09 at least we have this system where you buy your phone from the market and use whatever sim card you like.
everyone has the same plans for the same price so its a matter of preference/ network quality, etc etc.
i find this funny that w
people, if they have to buy a phone on EMI, they do that from the bank and not the network provider
Both models are VoLTE compliant. AT&T whitelisted the former supposedly because they once sold/supported this model directly, but told existing users of the latter to replace their phone or GTFO.
I gladly took the GTFO option and switched to T-Mobile...substantially reduced my monthly bill to less than $17/mo per phone and saw improved reception at the office.
Except it's more BS than you think. The iPhone 5S supports VoLTE technically. But AT&T blocked that feature on those phones.
T-Mobile still has a 2G network operating in most of the country and the 5S supports voLTE so it can use both 2G and LTE for calls. It does not have any low band support, so indoor and rural coverage will suck, but it will work.
Even if it didn't have voLTE it would still work on T-Mobile on LTE data and if you were in a GSM market it would fall back to 2G to make calls. The stores won't activate it, but you can take an activated sim card and pop it in and they will not blacklist it.
T-Mobile technically still has 3G broadcasting on their femtocells so that's another option for calls/data if you're around them.
I only use it as a web development testing device since I like to maintain compatibility with older devices even if the userbase is trivial.
YouTube apps stopped working on older devices a few years ago.
Netflix on the other hand never deprecates their APIs.
Older Apple apps that you download like Numbers, Pages, etc still work. Last time I checked, Spotify still works as well as music and movies you purchased from iTunes.
I even had Apple Maps powered by Google work on a 1st gen iPod Touch (2007)
Can you run all the latest apps? Maybe not, but are you confident any device you currently have can run the apps that will be released ten years from now? In the case of Apple you know that the apps you're running right now you'll still be able to run ten years from now. That's the difference, and for a lot of people that's perfectly fine. There are still a lot of people quite happily running their early gen iPads, for instance. It still does everything they need it to do.
Where Apple is setting themselves apart is not forcing you to buy new hardware because you need critical security issues fixed. If you want new functionality and features, sure, you may need to buy new hardware - but you shouldn't have to buy new hardware to get security vulnerabilities resolved.
Meanwhile, I have 12+ year old Macs that still work great, have up-to-date browsers, can install any app, and can run the same modern software that my 6 month old machine can.
iPhones make sense from a reduce and reuse (as an egg timer) standpoint. Apple can clearly build products that can stand the test of time and still be genuinely reusable, but those products aren't iPhones.
As of at least 2 years ago, I was able to dust off an old first gen iPad from 2010 that last got updated in 2012, reset it and log on and download the “last compatible version” of apps like Netflix, Crackle, Hulu, Plex, and Google Drive.
> You'd be stuck with a 5+ year old browser that you can't upgrade because Apple bans other browsers from running on iOS
You never tried browsing modern websites on older iOS devices have you?
Is it good or bad? Please enlighten us.
I have, it's how I learned that WebP images still weren't safe to use because Safari didn't support them until ~2020. Encountered a lot of pages that were just blank white documents, assuming it's because they failed to render the markup or whatever frontend frameworks they used weren't compatible.
I'm basing my post off of my experiences of trying to reuse old iPads.
Without legislation, it probably won't become the norm. With Apple, they know they will capture the value of future device purchases since if you want an iOS device, they're the only seller. Margins can be better since they're the only seller which leaves more money to support the product long term. Long-term support positions them as a premium product.
One of the big issues is that Google can't patch an issue and then push it out to everyone. They need buy-in from phone manufacturers and even carriers who have customized Android. Apple doesn't need any coordination. They can update iOS when they want to and they control all the hardware it's running on.
Yes, you'd think that competition might lead people to become loyal to one Android manufacturer if they provided longer-term support, but I think the ecosystem encourages shopping around for the best deal/promo rather than brand loyalty and money spent on long-term support makes products more expensive.
I think part of it is even a different market segment between iOS and Android. I think a lot of iOS users are people that want something that just works that they don't have to worry about and are willing to pay for a premium product that does that. I think Android users are split between power users who want to upgrade frequently (negating the utility of long-term support) and low-end users who don't care or need to prioritize purchase price over updates/security. Again, needing 2-3 parties involved for updates makes them more expensive, more difficult, and less likely to happen.
Part of it is simply the Apple experience. Apple Stores aren't cheap. Apple could use cheap materials and try to build stores that look and feel like most retail. That's not their game. They're looking to sell a premium experience and part of that includes long-term support. Of course, that comes with a price. It's easy to find $100 Android phones, but not $100 iPhones.
And insufficient RAM is not a good reason not to support older phones?
A $1,000 Android phone will likely be slower and supported for less time than a $400 iPhone, however. Most of the Android users I know spend the same or more on their phones, they just have to replace them more frequently.
This means that the price comparison is usually the iPhone 1-2 generations back - for example, if you were considering a Samsung Galaxy S22 you could get a faster CPU with a $100 iPhone SE (2nd generation) rather than the current model.
1. https://support.google.com/pixelphone/answer/4457705?hl=en#z... 2. https://grapheneos.org/releases#bluejay-stable
Since this is a technical forum, I am going to plug the blog post Alex Russell (not usually described as an Apple fanboy) made about real-world performance for web developers. One of the challenges we have is that normal people hang on to phones for a while and that's especially true for people who buy cheap phones since they often can't afford to buy a new one every year. When a developer testing on an “old” iPhone has a browser which runs code faster than the current flagship Android phone (iPhone XS ~= Galaxy S22), that means that they effectively have no idea what the web is like for a person using a $200 phone which they've had for a few years. There's a great chart here:
https://infrequently.org/2022/12/performance-baseline-2023/#...
Now, the Pixel line does have a decent camera so that's potentially a plus but it's not really relevant to the device's capabilities or long-term support situation. It's also unlikely that a single test is telling you that such an old sensor is really the best thing in the world rather than Google's ML pipeline is good at adjusting images to make them appealing to phone users.
Also, sensor doesn't matter, what matters is millions of people watching MKBHD channel think Pixel 6a makes better photos than 14 Pro Max, regardless of sensor.
For $400 you can buy a touch ID SE with 60Hz screen and camera that is ages behind what $350 Pixel 6a will give you. Ultimately it doesn't matter what you use I just hate the Kool aid "Apple has no competition" thinking, it's not like that and never was since at least 2016. Even price alone there are more expensive android flagmans than iPhones and some people go that way, so it's not just poor people choice or whatever Apple elitists tend to think.
> Also, sensor doesn't matter, what matters is millions of people watching MKBHD channel think Pixel 6a makes better photos than 14 Pro Max, regardless of sensor.
The number of views doesn’t mean that everyone voted (at 5-15 minutes per test, I’d be surprised if it was anywhere near), and it especially doesn’t tell you that a camera is better in absolute terms. His test methodology is randomized, which is good, but it shows small images side by side and they’re not perfectly consistent on composition. That favors certain types of image: higher contrast, brighter colors get the quick wow, very few people are likely to zoom in enough to notice noise or loss of detail, and that last part is especially important as ML processing becomes the norm - one thing people have commented on are the subtle processing artifacts (often described as smudging) that can produce which aren’t obvious at first glance.
That doesn’t mean that this is wrong: a ton of photos are never viewed at larger than the Facebook/Instagram default thumbnail size, and punchier photos stand out in those galleries, but it says that a single test giving a single ranking is incomplete. There’s also a selection bias concern: his audience skews towards Android users who are going to be accustomed to the camera, processing, and color matching of those devices. Familiarity matters a lot when you’re making a ton of rapid comparisons.
> For $400 you can buy a touch ID SE with 60Hz screen and camera that is ages behind what $350 Pixel 6a will give you
Ah, yes, through my amazing power of getting data rather than assuming that my preferred brand is best, I can see the iPhone SE’s 60Hz screen pales before what Google calls “up to 60Hz”:
Yet and still Microsoft figured this out with computers from different manufacturers almost 30 years ago.
E2EE requires all devices to be updated to the latest version of the OS
That thing was a tank it was OK until about a year ago then the battery got noticeably worse. Not bad for someone who always let it die all the time always charge only when 0%. She almost always used it just for voice calls a few texts no web (no data plan).
No OS updates for a while too. So it was risky I thought to keep it going. Android is much easier to deal with. Although the ringtones and notifications are all different she has to now learn after almost 10 years of iPhone to new sounds by Samsung.
Don't get me wrong, I'm not a fanboy and immensely dislike how iOS users are restricted in other ways, but updates and longevity are unparalleled in the smartphone world.
https://www.aninews.in/news/tech/mobile/samsungs-55-years-ol...
It's not like Apple is delivering all security updates to these old phones either. This one looked pretty critical to them, as the article says it “may have been actively exploited”.
I maintain endoflife.date and it’s quite hard to find any primary sources for what Apple actually guarantees as support
I would much rather use an Android device from a manufacturer or a desktop OS from Microsoft that is actually up front about their support lifecycle, than go with Apple that does not publish this at all.
Some Apple devices have had much longer support lifecycles than others, and I don't think that's OK given how expensive their devices are.
An iPhone 6 was supported through 5 major iOS versions (including the version it was shipped with).
An iPhone 6S released a year later was supported for 7 major iOS versions.
An iPhone 7 released a year later again was only supported for 6 major iOS versions.
This wasn't documented anywhere when people bought those devices.
Security updates for older iOS devices and macOS versions are sporadic and often incomplete.
Definitely better than most Android operators though, at least that's my impression.
I own an old Samsung Galaxy S4 mini as a "backup phone" running on /e/. It was released in 2013 I think.
Are there new non official firmware / linux distros available for old iphones ?
The newer Samsung phones get the less configuration user's have it seems.
If a phone is sold for two years, and I buy that phone at the end up the two years, then “two years of updates” means a day one purchaser will get four years of updates.
So while it’s nice that we can say “almost ten years old”, the reality is probably not more than seven years.
It’s why when you look at android manufacturers making update promises you need to make sure that they’re being honest, and similarly any legislation needs to specifically say that the mandatory update support period starts after the last sale of the device.
As an example of this:
In April 2019, I needed to rapidly obtain a device, and purchased a Samsung Galaxy J1 (2016) from a major retailer in Australia. I later discovered that this model had already been EOL for over a year when I purchased it. (It was released with 5.1.1, got its last security patch in November 2017, and was actively unsupported no later than March 2018. The handset should very obviously have been updated to Android 6, if not released with it—Android 6 was announced and in beta 7½ months before, and was the stable release 3½ months before, the handset’s January 2016 release.)
If a company is selling something and says "X years of support", that means X years of support, not "until date Y" where Y is date of release + X.
If android manufacturers are saying "X years of support" when they mean "supported until [some date]" then they are quite plainly false advertising.
I can find many sites that say that apple commits to 5 years of software support from the date of last sale, but I can't find anything on apple.com that matches that. I've found that they guarantee 5 years of hardware support (repairs, etc) from date of last sale, and then a further 2 years subject to hardware availability (presumably they stop purchasing/manufacturing parts). Note that I'm not talking about warrantee coverage (which varies but seems 1 year is standard?) just the actual ability to do repairs.
Based on this article and various others over the years, and the vast array of spammy infographic laden sites making up the first page of google search results, it seems like claims of ~5 years of major updates and a few more for security only is consistent, but again I can't find anything on apple's site to confirm that explicitly.
Google has been making significant efforts to replace insecure C components in Android with Rust though.
ARM has been adding security features that do help with any language like PAC/BTI.
You can have simple JITs that are completely safe: they generate code to bounds- and type-check unconditionally and avoid fragile optimizations. But, if you want to go faster, you have to start dropping checks and performing aggressive optimizations (peephole, inlining, object layout tricks, …) and every new optimization is an opportunity to make a mistake.
PAC and friends are an effort to make the hardware support certain checks more efficiently. But again, as they are an extra check, there’s always the chance that they’ll be slower than the unchecked alternative; if so, you can bet that one day an engineer looking to get a 0.5% perf gain will try removing those checks (“safely”) and we’ll be back to square one.
I mean… isn't that what unsafe means? A "memory-unsafe" language means a language it's possible to make a mistake in, not one where memory errors happen all the time.
As an example, the Rust compiler has some [60+ open unsoundness bugs](https://github.com/rust-lang/rust/labels/I-unsound), meaning that there are many, many ways that a sequence of ostensibly safe code could be compiled into an unsafe executable (i.e. one which exhibits an unsafe behaviour like a double free). If you allowed malicious users to run Rust code on your machine, even without unsafe features and a limited standard library (as the case with JS in the browser), they could take advantage of these compiler bugs to escape Rust’s safety guarantees and whatever protections you put in place. And these bugs exist even though Rust itself is a safe language, and even though much of the Rust compiler is itself written in a safe language.
Not that use of Rust is impossible but so far Apple’s interest in Rust has been as far as I know entirely in server usage.
This gives the attacker control over the “renderer” process that handles the webpage inside a secured sandbox. So, the attacker has to then exploit the sandbox itself to gain more permissions. The renderer communicates with the parent browser process over IPC, and there are a lot of objects and communications channels between the two. So, a second bug in the browser process can be exploited by the (compromised) renderer process via IPC. Once successful, the attacker has full control over the browser and can do anything the browser can. Sometimes this is enough for the attacker; other times, they might exploit a third bug in the OS kernel to gain root access and thoroughly own your phone.
See also Microsoft, which patched the security bug used by WannaCry over 4 years after Windows XP end of life.
only if they're was a way to update the web engine from app store.
Are you saying that the correct course of action is to leave users vulnerable to known - and clearly fixable - security bugs?