A stronger counter to Apple's argument is the relative pricing of exploits… but the story I'm remembering is old enough that I don't want to just assume it's still true, even though it's near the top of my search results:
https://www.wired.com/story/android-zero-day-more-than-ios-z...
You can sell an iOS exploit for more because the people you're targeting with it are generally wealthier.
If you could sell it for more, but it seems you can't sell it for more.
This implies a large supply of zero-days competing with each other on price.
I suspect iOS is not worse than the more open Android simply because senior management at Kaspersky are using iPhones. If anybody is choosing their platform with security in mind, it has to be them and they are going with iOS.
Near the end, they say:
> This campaign is a good reminder that attackers do not always use exploits to achieve the permissions they need.
Endpoint protection solutions can be installed in iOS devices. The device could also be wiped clean, eliminating the malware.
The latter should not be much of an issue in any serious organization. If any executive keeps critical data in a phone, that is already an issue.
The former is a hassle, but I have had to use locked down iPhones before, and the tradeoffs are still better than facing an intrusion.
The vulnerability and the vector could also have been present in a different form in Android devices.
All in all, I don't think this is the response Kaspersky should have come forward with.
I've not idea to what extent it's possible to have a durable trojan on iOS (probably only the makers of such trojans do know).
It's absurd to say a company should not blow the whistle on a sophisticated attack when that companys job is just that!
They should definitely do it.
They should also acknowledge that they did a shoddy job. They let the malware run unchecked for several years. It is clear that the safeguards they had in place did not work, not for protection, but especially for detection.
Instead, they chose to boost the image of their own products and bash a third party vendor with a questionable reasoning.
How does "endpoint protection solution" protect from 0-day exploits? I guess it can do that only in marketing materials, not in reality.
This malware was running and spreading for years. It is actually surprising that it took a security company like Kaspersky so long to detect it.
Sorry I don't buy that this "shatters" anything besides peoples misguided assumptions that anything can be perfectly secure without being fully disconnected.
Apple's iOS 16 supports iphone 8 which was released in 2017, 5 years ago. Apple's iOs 15 supported iphone 6 which was released in 2015, 7 years ago.
> Samsung’s previous promise to provide three years of upgrades and ensures millions of Galaxy users have access to the latest features for security, productivity, visual experience and more, for as long as they own their device.
https://news.samsung.com/us/samsung-galaxy-os-upgrade-one-ui...
They only _just_ changed to 4 years, last year.
> Samsung will now provide up to five years of security updates to help protect select Galaxy devices
They do mention 5 years of updates but only for _select_ galaxy devices (presumably the top of the line).
---
I am assuming anyone rooting/flashing is taking way more risks and security concerns into their own hands. But in length of support/security updates alone apple is winning.
I also wonder how long it actually takes a vulnerability patch (let's say for a zero day) to get out on android and then through OEM security updates. (I haven't been android in too long to know this.) Apple actually just released a way for them to do this and have already used it once, they call it "Rapid Security Responses" (which you can switch off although idk why you would).
Why are Kaspersky's management using iPhones?
If Apple really wanted to improve security (instead of just producing marketing claims about it) they would provide anyone with debugging symbols, root privileges and anything else needed for research and debugging.
The point being, with Kaspersky as security experts, it really does call into question their judgement and expertise.
1. At some point, weigh probabilities of exploits
2. Update Bayesian priors as new evidence arrives
3. Even if the initial decision currently appears incorrect, there needs to be a high enough difference in probability to justify switching, because in switching, you're still exposed to any persistent exploitation via the old exploits plus new exploits on the new platform
Switching back and forth the instant your Bayesian prior swings over/under 50% for Android being more secure than iPhone is a terrible strategy. (Also, you need to risk-weight your various exploit probabilities... security is a multidimensional quantity, so collapsing to a scalar is at least context-/threat-model-dependent.)They aren’t just claiming it’s because of this one exploit or some exploit stats - they are making the claim that it’s because it’s not open source.
Since they knew this all along, we can conclude that they have poor judgment.
Kaspersky says:
“We believe that the main reason for this incident is the proprietary nature of iOS.”
If the proprietary nature is the main reason for the incident, then Android should have been overwhelmingly more secure all along, and they should know this.
If they are only just figuring this out now, then they have been ludicrously ignorant for people who claim to be experts.
Occam’s razor says they really aren’t as expert as their marketing claims and they are trying to save face by blaming Apple.
Given that the Kremlin is blaming Apple and the NSA, perhaps Kaspersky is trying to deflect blame for not having warned Russian diplomats about the issue.
This is inconsistent with their claims of expertise.
That’s the issue. I believe the claim isn’t being made because they are experts or because it is true, but rather to deflect blame for marketing and political reasons.
What should they be doing? Keep the discovery to themselves so those who claim iPhone is secure can continue living obliviously with their worldview unchanged? Wouldn't we accuse them of poor judgment if they did that?
It is quite reasonable for them to say the ecosystem being closed is making analysis and detection difficult. It is up to Apple to do what they want with that information.
I can see this point of view, but I feel expertise is more about skill in acquiring information and updating beliefs. In my view, real experts can be blatantly wrong, even about foundational facts, if they have an exceptional ability to update those beliefs.
It’s entirely possible that they are experts, but are making making a claim that is not based on their expertise, for reasons of political and marketing expediency.