> On my workstation and phone, where I do my banking and read emails, I'm willing to trade control and customizability for an extremely locked down high trust operating environment.
Excuse my French, but uh what? A browser accessing a bank in a Linux virtual machine running on bare metal is by far more secure than desktop MacOS running on bare metal.
At the end of the day, for the activity you described (browsing), what you must be able to defend against is the inherent insecurity of the browser. Linux provides all manners of process, network, etc isolation via CGroups and can be enhanced by SecComp to limit the usage of typical exotic syscalls used in kernel exploits.
MacOS has what for that? The best opportunity you have for defense is to run qemu so that you can run... Linux. The corporation you work for doesn't use Apple because of their stellar security posture, it uses Apple because they can buy mobile devices (phones, laptops) preconfigured with MDM which saves a lot of money.
It has sandboxing, which does all that stuff.
(iOS has even more, like JIT protections.)
Facts are most definitely not in evidence for this claim.
As it currently stands, the options for Linux VMs on an iPad are:
- iSH, a Linux kernel ABI compatible user-mode x86 emulator that uses threaded code (ROP chains) as a substitute for a proper JIT, but doesn't support all x86 applications[0].
- UTM, a port of QEMU that requires JIT (and thus, either an external debugger or a jailbreak) to run a full x86 or ARM OS.
- UTM SE (Slow Edition), which is UTM but using the threaded code technique from iSH, which is not only slower than iSH because it runs both kernel and user mode, but also got banned from TestFlight before they could even make an App Store submission (probably because it can get to a desktop while iSH can't).
All of these suck in different ways.
[0] Notably, rustc gives an illegal instruction error and mysql crashes trying to do unaligned atomics
I get a lot of hard to solve Google CAPTCHA on many websites I visit so I know Google is having a hard time tracking me :-)
In terms of security, I don't think Pixel is less secure than the iPhone. It gets security updates regularly, Google invests a lot in security and I don't think the Pixel has more zero days than the iPhone...
So all in all, I don't buy into the "iPhone is more secure and handles your privacy better than Android" narrative
I do avoid Windows for those things, though.
Very nearly every halfway serious computer-involved activity I do these days (=last seven or eight years) that matters in my actual, real life takes place on my phone, including approximately all banking. All the other computers—even the "real" ones—in my life are basically toys. 90% of my real-life important or meaningful stuff I do with computers happens on my phone, 9% on a tablet, and at-most 1% on everything else.
(in my personal life, I mean—unfortunately I still have to try to use "real" computers to accomplish allegedly-important things at work)