The point being, with Kaspersky as security experts, it really does call into question their judgement and expertise.
The point being, with Kaspersky as security experts, it really does call into question their judgement and expertise.
1. At some point, weigh probabilities of exploits
2. Update Bayesian priors as new evidence arrives
3. Even if the initial decision currently appears incorrect, there needs to be a high enough difference in probability to justify switching, because in switching, you're still exposed to any persistent exploitation via the old exploits plus new exploits on the new platform
Switching back and forth the instant your Bayesian prior swings over/under 50% for Android being more secure than iPhone is a terrible strategy. (Also, you need to risk-weight your various exploit probabilities... security is a multidimensional quantity, so collapsing to a scalar is at least context-/threat-model-dependent.)They aren’t just claiming it’s because of this one exploit or some exploit stats - they are making the claim that it’s because it’s not open source.
Since they knew this all along, we can conclude that they have poor judgment.
What should they be doing? Keep the discovery to themselves so those who claim iPhone is secure can continue living obliviously with their worldview unchanged? Wouldn't we accuse them of poor judgment if they did that?
It is quite reasonable for them to say the ecosystem being closed is making analysis and detection difficult. It is up to Apple to do what they want with that information.
I can see this point of view, but I feel expertise is more about skill in acquiring information and updating beliefs. In my view, real experts can be blatantly wrong, even about foundational facts, if they have an exceptional ability to update those beliefs.
It’s entirely possible that they are experts, but are making making a claim that is not based on their expertise, for reasons of political and marketing expediency.
Kaspersky says:
“We believe that the main reason for this incident is the proprietary nature of iOS.”
If the proprietary nature is the main reason for the incident, then Android should have been overwhelmingly more secure all along, and they should know this.
If they are only just figuring this out now, then they have been ludicrously ignorant for people who claim to be experts.
Occam’s razor says they really aren’t as expert as their marketing claims and they are trying to save face by blaming Apple.
Given that the Kremlin is blaming Apple and the NSA, perhaps Kaspersky is trying to deflect blame for not having warned Russian diplomats about the issue.
This is inconsistent with their claims of expertise.
That’s the issue. I believe the claim isn’t being made because they are experts or because it is true, but rather to deflect blame for marketing and political reasons.