When does an old iPhone become unsafe to use?
intego.com
intego.com
If the phone is physically okay and you depend on few core functionalities, then it is perfectly okay to keep using it for majority of (non-critical) tasks. Most bugs in the system & features of old iOS are limited to that old OS anyway - and most likely addressed. If some advanced utility are going to be involved e.g. work communications, some security protocols, I'll perhaps work with a device which still gets critical updates at the least.
I have a iPhone 8 which I use just to Facetime my MIL and receive her iMessages (I am on Pixels since 2019). I can't foresee a old patched- often iOS with a older no-frills Facetime version to have a major risks. For these tasks, I don't see it necessary to get a new iphone.
Perhaps I'm misunderstanding you, but this is not really correct. Most vulnerabilities are not regressions.
Attention is what makes security issues discoverable, and popularity is what makes exploits valuable serious enough to warrant attention. The more popular software is, the more attention it gets from the security community (both black and white hat). The more popular software is, the higher the impact of an exploit is. The more popular the software is, the more significant the response is.
That doesn't mean older software is secure, or that it can't be exploited. It just means nobody is really looking at it. Fairly often, security alerts come up for software that doesn't list older releases because they didn't bother to check their EoL releases not because they're unaffected.
Take the Print Spooler vulnerability on Windows, or the ShellShock exploit in bash, or the Apache Log4j 2.x vulnerability. These vulnerabilities are all so old that they essentially work on any version of the affected software, including those that are more than a decade old for which no fix was even planned. Like the ShellShock bug in bash was found to go back to bash 1.03 released in 1989.
As long as you have an earlier version of software that was later found to be vulnerable, you should assume that it is unless you've explicitly investigated the vulnerability and found otherwise.
It depends. The iPhone 8 might belong to someone they’re interested in for reasons as mundane as being a control freak and the iPhone belongs to their partner. Or just someone that annoyed them on the internet.
Or the attack might woken across all device generations in the same way. Then no specific targeting would be required and the phone owner gets caught in the net like all other unpatched versions, except they never had a chance to fix the issue.
The military extensively uses older OS versions, which means they are very much targets.
The UK's new HMS Queen Elizabeth aircraft carrier uses windows XP.
(The US Navy also has a support contract beyond end-of-life for XP versions, even still as of 2022, for a handful of their own programs on warships, because it's too much expense and delay of recertifying on new PCs. https://www.quora.com/Is-the-U-S-Navy-still-using-Windows-XP and other sources.)
https://www.quora.com/Is-the-U-S-Navy-still-using-Windows-XP )
It fits the sentiment perfectly. Developers who exclusively think in terms of commercial internet are prone to thinking that everyone uses up-to-date browsers, and therefore OSs.
The world is actually messier than that common misconception.
It fits rather well.
Well, it was.
If you are in the business of compromising, why would you not?
I don't think Apple's patching every major security flaw on current - 1, but right at this moment, they're still able to run n - 1, which would probably put them roughly on par with the average on smartphone security, so I don't think it would be especially any more child's play than compromising an average phone, all things being equal (all things being equal, some people update, some don't; the iphone 8 on the latest iOS 16 is probably better than a later model lagged 3 years on updates)
Although it's all downhill from here.
I know it won't install iOS 17. So I figure I have about 12 months more of reasonable security updates. At this point, I'll likely get an iPhone SE 3rd generation to replace it.
If everyone is using message service X, then we'll start seeing more attacks on X.
The exploits we've seen over the last few years haven't been in iMessage the app, they've been in a host of different things. The most recent security brouhaha was apparently in the webp library[1] that also effected chrome, webkit, Firefox, every electron app, and I assume every app on android, iOS, macOS, that uses system image decoders, etc. But if you want a specific target then you aren't going to use something like a random webpage or phishing email if you have something that you can guarantee will go to only one device that you know is exploitable, and you can guarantee how it will be handled - i.e. the builtin system messaging apps.
[1] and even here the attack didn't happen from iMessage
I'm actually now curious whether the various awful web notification standards allow images?
As I recall, the disclosures of major vulnerabilities in iMessage don't say that regular SMS messaging is effected.
But also, in answer to the question: yes, every messaging app on Mac or iOS that could display webp was susceptible to this exploit. If they use ImageIO then the OS update fixes them, if they use their own copy of libwebp they are exploitable until they ship an updated version.
(But I can't find a source for this atm. I remember reading it somewhere, but maybe I'm confusing it with a previous Blastdoor exploit.)
It was triggered because the system shows a preview of the image by default.
Devices that had Lockdown Mode enabled no longer show preview images, so were not effected.
>Lockdown Mode is an extreme protection feature for iPhone. Its protections include safer wireless connectivity defaults, media handling, media sharing defaults, sandboxing, and network security optimizations.
https://support.apple.com/guide/iphone/use-lockdown-mode-iph...
> On September 7, 2023, Apple released emergency security updates to fix a buffer overflow vulnerability (CVE-2023-41064) impacting macOS, iOS, iPadOS, and watchOS products that was used in a zero-click exploitation chain by the NSO Group. Shortly after, on September 11, 2023, Google released an update to fix a buffer overflow vulnerability (CVE-2023-4863) in Google Chrome, which was reported by Apple’s Security Engineering and Architecture (SEAR) and Citizen Lab. Both vulnerabilities were nearly identical and listed as actively exploited, leading to confusion across the security community.
Note: Citizen Lab urges all at-risk users to enable Lockdown mode as this has been confirmed by Apple’s Security Engineering and Architecture team that Lockdown Mode blocks this particular attack.
You have an iPhone just to communicate with your MIL? you're surely the DIL or SIL of the year!
Was one of the reasons I switched.
For me, I consider any phone which holds very important access to data critical to my life (my email, texts, signed in apps which can spend my money, etc) to be unsafe to use once there's an update available for supported iPhones where the CVE it fixes is severe enough to allow remote access through normal use of the phone.
I just bought a new iPhone SE 3rd gen partly because of the above as I see it coming soon, but also because the battery in my iPhone 8 was getting very sad. Paying for a battery replacement for a potentially-no-longer-officially-supported phone was not going to be a wise investment for me.
My school-aged daughter still has her iPhone 8 and it's as up to date as can be with latest iOS 16 update. But she isn't signed into any email app and doesn't have any banking ability on her phone. Sure, if it gets compromised it could be a vector into my home network or be used to spy on her or impersonate her, all of those would be bad, but it's less bad than if my phone was compromised. These risks are low enough currently that we're not pressed to get her a new phone, yet, but probably will later this year if Apple doesn't issue any further updates to iOS 16.
Per another comment, a badly swollen battery is a physical safety issue and that point, the battery should either be replaced or the phone recycled.
In general, I also agree with the article that buying older refurb models isn't clearly good economy. There are advantages to have a not too old backup phone around. Indeed, I'm using my old iPhone X at the moment after my newer phone broke.
I've personally had good luck buying refurb phones direct from Apple. The discount isn't as good as 3rd parties, but they've all arrived with 0 defects and new batteries. I even got to exercise the warranty on a directly purchased from Apple refurb phone once, it was easy at an Apple store (about 30 minute drive from my house).
Unfortunately there are no other options in that form factor. The closest would be the iphone 13 mini, which has an even earlier release date than iphone SE 3rd gen.
True. And a good reminder (nudge) to change my old devices to a separate iCloud account. Thanks.
You should get her a new phone. The risk for her isn’t banking, it’s getting spied on by some creep. IMO that could be a lot worse than getting your online banking hacked…
It shouldn't work. Based on historical precedent from PC's, all of these phones should be full with the most blatant, obvious, ad-injecting/ransomwaring/account-stealing malware that simply cannot be ignored. And yet, in practice, most users are using ancient Android devices just fine.
Obviously you can't do that if you expect to be specifically targeted (either by governments or criminals), but the baffling fact is that an average user can apparently get away with it in practice.
The problem with cybersecurity is with companies that horde a great number of people's personal information or who have a great amount of privileged access and then decide to care about security.
It's unfortunately a false sense of security because you don't get security updates for any proprietary blobs that are needed for your phone. This includes baseband and SoC updates. In security, the chain is only as strong as it's weakest link.
That’s how I read it at least
It’s certainly better than just running an old Android on an unsupported device, but there are still large parts of the system that can be subject to critical vulnerabilities that can never be patched.
This is false, iPhone XS is supported on iOS 17.
The author states that security updates on earlier iOS versions give a false sense of security.
Is that true? What is Apple's incentive to maintain old iOS versions, but only partially?
They will however backport fixes for particularly egregious security issues quite far. For example, iOS 12 got a fix for a web-based remote code execution attack in the beginning of this year, despite at that point being over 4 years old and 4 major releases older than the current iOS.
1. They leave you with a strong impression that all phones and all iOS versions are kept safe by dribbling out a few fixes from time to time for older devices. That's probably worse than on Android, because you think it's safe, but it's not.
2. The whole point of getting your hardware and software from the same place was precisely because then you knew they had a limited number of things they had to support, so it'd work better. If they have too many things to support, then maybe that argument starts to fall apart.
Android on the other hand has a lot of devices with no patches at all. Pot luck and pray that Google saves the negligent manufacturers via play store patching.
If someone has to choose between the two (using an outdated phone), it's sensible to stick with Apple.
I myself use android and still recognize what Apple does right.
The author links to this article which provides more detail:
https://www.intego.com/mac-security-blog/apples-poor-patchin...
I wouldn't take everything that's written in a random tech article for granted. Fear inducing titles generate more clicks. As soon as you do something in this world, there's a risk. Even if you do nothing, there's a risk. Nobody will be able to be completely safe using any device under the sun. And if a tech company tries to make you believe otherwise, run.
Um...how about encouraging those who can to purchase a $Nice $New $Apple $Product, while not suffering too much bad PR over the security holes in old-but-still-perfectly-functional hardware?
And 'use' in what sense? Day to day main device with security credentials, financial/banking apps, etc? Connecting to corporate/VPN resources?
For professional and important personal use, I probably wouldn't use anything not 'officially supported'. When my banking apps won't install/update, that's probably the time. But I just re-used an old wiped iphone 5s a few weeks ago to browse some news sites. No issues, other than it felt less snappy than current devices. But it's not tied to any other part of my life at this point (apple id, bank, medical, etc).
While theoretically true, I can't find recent examples of this happening with zero-click exploits on iOS or Android. Without evidence of this being a common infection vector it's not, in my opinion, enough reason to encourage people to get rid of a working phone just because the security backports might be a bit lacking.
The more important security reason to keep up with the latest OS version is the sandboxing improvements that iOS and Android make with each update. If you assume the device will be compromised with a malicious app at some point, you want to have more protections against the malware stealing data from other apps. This is (for now) a bigger deal on Android, where malware routinely makes it into the official app store and malicious APKs are floating around all over the place. But it's worth considering on iOS too, especially if you run a lot of apps from companies that hate privacy or if iOS later allows some form of sideloading.
Mostly iOS. And how would you even know? There have been some large cryptocurrency thefts recently.
The LastPass breach resulted in theft: https://www.theverge.com/2023/9/7/23862658/lastpass-security...
Before or after a public exploit is posted alongside CVE+patch?
Mobile Verification Toolkit, https://docs.mvt.re/en/latest/ios/methodology/
Forensic howto, https://www.amnesty.org/en/latest/research/2021/07/forensic-...
IOCs: https://github.com/citizenlab/malware-indicators
IOC tools and sources: https://github.com/sroberts/awesome-iocs
Device Firmware Upgrade (DFU), https://www.theiphonewiki.com/wiki/DFU_Mode
For small business, Apple offers MDM for $3/device/month, https://www.apple.com/newsroom/2022/03/apple-business-essent... . It's unfortunate that iOS MDM solutions are not allowed to scan device filesystems for public IOCs.
As mitigation for old and new devices alike, frequently rebooting an iOS device will remove a large class of non-persistent malware. If battery life or performance are suddenly reduced, and can be restored to normal by an iOS reboot, a potential cause is non-persistent malware. Use the "Force Restart" key sequence, https://support.apple.com/guide/iphone/force-restart-iphone-...
Is there an iOS VPN solution which can (opt-in) monitor network or DNS traffic for threats or connections to known C&C servers?
Mobile Verification Toolkit (MVT) is a tool to facilitate the consensual forensic analysis of Android and iOS devices, for the purpose of identifying traces of compromise. It has been developed and released by the Amnesty International Security Lab in July 2021 in the context of the Pegasus Project along with a technical forensic methodology. It continues to be maintained by Amnesty International and other contributors.
> they don’t leave traces on the device that they exploitedSome very expensive zero-day attacks, patched by Apple, DID leave traces/IOCs.
Some older iOS devices (e.g. iPhone 7) can be jailbroken with checkra1n due to an unpatchable bootrom bug, i.e. they are better for forensic analysis than a newer device.
Static artifacts (exploits, patches, IOCs, C&C servers) still have value.
New cats/mice with old devices can learn from years of historical public artifacts.
My folks both have an SE (a 2 and a 3), and the photos are much better than you'd expect for a $400 phone. I've used them and they're plenty fast, it's really only the tiny screen that would give me pause.
If ~$400 can get you 5-6 years out of a phone that's a steal.
I'm sure that's not true for professional photographers, but I assume that they use real cameras when the photo quality actually matters anyway?
After all, the sole purpose of every piece of hardware is to apply patches to it.
What does this even mean? I feel like you're cargo-culting the term "cargo-culting".
What are you answering "Yes." to here?
When the Battery inside it becomes a spicy pillow shaped IED.
Disappointed that the article is actually about security, and then makes a bunch of trivially falsifiable claims, but then also it says the best time to buy an iPhone is when they're brand new and just released to maximize update range. I'm really just not sure what the point of the article actually is? Yes a just released phone is going to be getting updates further in the future than one released a year ago, but that's true for literally everything iOS, android, hell, I can't get a replacement for the bowl in my rice cooker but I can for the next model.
OTOH - if (say) you're keeping an old phone for "emergency use only", then it's unsafe when the battery or electronics get too flaky to be relied upon for that.
Apple charges $429 for it at minimum, and that to me is a ripoff considering that you can go all the way back to the iPhone 13 and get the same SoC with a much better overall phone rather than having a decade-old design.
If you just want an iPhone that is supported by Apple, the best value option is probably to go with a used iPhone 12 (under $300) or a 13, for about the same price as the SE.
Even if your 12/13 has an older battery, the SE has poor battery life to begin with.
iOS 17 is supported on phones going back to the XS, which is 2 years older than the 12. So if you buy a 12 now and sell it in 2 years, you’d expect to lose a bit less than $100 on those transactions. Basically you’d spend $50 a year to have a supported phone assuming that Apple never lengthens their support window further (which I think is unlikely now that they are starting a trend of the non-Pro iPhone using the previous lithography with two model years in a row using the same processor).
But also, a whole bunch of cheap MVNO cellular carriers will just give you an old but supported iPhone for free (e.g., Metro by T-Mobile gives you an iPhone 11 for free at present). Presumably you could just shop phone carriers every couple of years and find one that’s willing to kick a less-old iPhone your way for nothing.
On the high end, you can always find a US postpaid phone company willing to essentially subsidize phone depreciation with their trade-in deals. If you are in a large family and/or have high usage requirements like tethering, postpaid with bill credits is the way to go. You basically get a free iPhone Pro device every 3 years.
The idea of the original SE was to reuse an old form factor and old production line to make a bottom tier low cost phone with newer internals.
The iPhone 12 mini was a new design that made no compromises compared to its larger iPhone 12 cousin. Exact same hardware, camera, screen tech, etc, just a smaller size battery.
I strongly disagree that “everything else is a phablet.” After shrinking some bezels the current iPhone lineup is very similar size to the iPhone 6/6S/7/8.
The iPhone 15 is 5.81 x 2.82 x 0.31 inches
The iPhone 6S is 5.44 x 2.64 x 0.28 in
I realize that fractions of an inch make a big difference on mobile devices but that’s still not a whole lot of change. Under 10mm of additional height and under 6mm of extra width.
> The 12 mini is not a successor to the original SE in neither concept nor positioning.
They’re the most similar in terms of size.
If anyone has a counterexample (software virus, for iPhone, reliant on vulnerabilities that were patched in the latest iOS at the time the exploit was in use, ideally not by a nation state) I'd definitely be interested to hear about it.
As soon as the new model is released ;)
Yes, yes, I know that the article discusses how older OS versions don't necessarily get all of the security fixes as the current ones but, still, that's impressive.
Let me fix the question:
"When does a phone become unsafe to use?"
The answer is "immediately".