I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.
I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.
Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android 0-day than an iOS 0-day.
Plus, the huge variability between Samsung/Google/Moto/Huawei etc makes it triply hard for a single exploit to be successful.
but what about dumb phones from late 2000s like my Samsung Alias 2? what kind of sick bastard would make zero days for this
Buy: https://skysedge.com/telecom/RUSP/index.html
Story: https://www.justine-haupt.com/rotarycellphoneinfo/index.html
Edit: wait, was she not able to get it certified? Does it really say it won’t connect to a US network?
Oh,
> This is a regulatory approval issue which will take time to resolve.
not sure about the rotary thing that looks cool tho
If we’re talking about having the microphone tapped etc, I don’t think anyone would still be developing 0-days for such old phones. If you want to be safer (assuming fear of old software having unpatched vulnerabilities) Nokia launched a dumb phone not too long ago.
However… GSM networks and cell tower level tracking is much harder/almost impossible to escape short of throwing away your phone. SMSes can be hijacked, hostile agents can force downgrade the connection to 3G/2g to break encryption (iirc, please correct me if wrong), and your location is generally known to your service provider and Uncle Sam.
Plus… the SIM card is its own mini computer, and lots of the firmware between that and the telephony modules is proprietary and closed source. If you’re familiar with intel ME you have an idea of what I’m talking about.
Honestly, if you’re not a journalist going after big names, or a top CEO/president etc you likely don’t need to worry about any of these. But if you are, or just want to be privacy conscious, your best bet is to never use cell towers and only use Wi-Fi/internet from public or untraceable places; along with Wi-Fi calling for telephony. Btw I’m not sure but I think Google fi and a few carriers/MVNOs offer virtual numbers, which can be a good first step for privacy.
A random Internet search gives iOS 30% market share to Android's 70% [1], which could also explain the higher price.
[1] https://www.statista.com/statistics/272698/global-market-sha...
* Controlling smart home devices
* Messaging and phone calls
* Checking the weather
* Recording data with Apple Health
* Uploading runs to Strava
* Setting wakeup alarms
* Listening to Apple Music
* Using Apple Maps to get around
* Connecting with CarPlay
That's why most of the exploits are targeting imessage
> Can you point to exploits that take advantage of the system integration it has?
Sure, the last pegasus attack on the image codec would not have worked on Android.
I'm replying to someone who said the important factor is android is open sourced. I pointed out the relevant android program is not open sourced.
That variability is a double-edged sword. Manufacturer-added Android bundleware is notorious for being shoddily built and could easily represent added points of ingress.
Which is why I wish it were practical to replace OEM Android versions with GrapheneOS/CalyxOS or similar on the latest devices, similar to how a cutting edge PC can run one’s choice of Linux. As long as more secure or at least more standardized Android distributions can only run on devices with some age on them, their popularity will be limited even among the technically inclined.
I.e. infection is eventually discovered, Apple isolates the vulnerability's entry point, then Apple has some ability to re-scan all devices to detect which may have also had the attack targeted against them
Hashing some data that can serve as a fingerprint makes sense from a herd standpoint (hell, even something as simple as call stack after iMessage received)
[citation needed]
Plus, I don't think the onus is on Google to monitor and alert for other OEM phones ala Samsung, Motorola, etc.
I really, really don’t think he meant he was switching to Apple because he’s a CIA spy stationed in Moscow.
Чёрт побери!
All you’ll find here are founders of highly funded startups and software developers at boring companies such as Google, Microsoft and Apple.
No point getting into these people’s phones if you’re a state actor for sure /shrug
Long ago, I co-founded a tiny startup. We had some high profile clients. I was dumb enough to put those clients on our site. I also used to be dumb enough to have a public social media profile, in my name.
I was already somewhat security aware, but one day I almost fell for a spear phishing email. Someone created a gmail account 1 character different from my gf's gmail. They sent me a well worded, but simple email along the lines of "Hey baby, check this out!" and URL shortened link. She happened to be next to me, and I said to her "Hey, what's this?" "What? I didn't send that!" I then opened it in a VM and saw that it resolved to something.ru.
It was a combo of identifying the juicy client of ours, seeing my name as co-founder, finding me on FB, finding my gf in my profile, getting her email, etc.
I then got to learn fun new terms like threat modeling.
Is it possible that someone might think that you have ssh access to a server on an interesting network? You are a target.
Sure, the average person probably doesn't need this (although as another comment pointed out, HN isn't quite representative of the average)... But the net is a hell of a lot wider than just journalists.
What?
Is this just regular Apple fanboy-ism?