You Shall Not PASS - Analysing a NSO iOS Spyware Sample https://www.youtube.com/watch?v=wAmGU2YUa9Y
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zer...
https://www.darkreading.com/vulnerabilities-threats/apple-ze...
https://www.infosecurity-magazine.com/news/apple-update-extr...
So they do need that competence if they are to be sysadmins.
For a phone though, there is an external homogeneity that could make setting it up as a honeypot easier. I'm not incredibly familiar with phone OSs, but I see it as an interesting opportunity.
Surely it should only be generally possible if you have special monitoring.
Why shouldn't I have a choice? I could then depend on more than just Apple's security team.
> Remember that Windows exploits abound, despite the antiviral/antirootkit ecosystem that grew up around it.
Many exploits for iOS and Android, too. Seems that locking down the phone doesnt't help with that... (different security model for apps/userland does, but that's unrelated to my point)
> I have an OS for you: Linux, BSD, maybe Solaris or something exotic.
No, I want what works on phones now, with more user control.
Hahaha, do you read HN much? There are stories on here all the time of security holes in Apples products which they refuse to fix.
Heres a recent example of their M series CPUs having similar exploits in them to SPECTRE and MELTDOWN in Intel CPUs. The difference is Intel fixed it and took the 20% performance hit. Apple refuses to fix it because it would make their processors slower.
https://arstechnica.com/security/2024/03/hackers-can-extract...
I do agree that Apple and Google both played the game with moves below the table, but that’s what “the market” gets you (amoral profit seeking that has no qualms with cheating and taking measures to ensure that one isn’t somehow suddenly operating under a political regime that cares about the morality of its market participants).
Also in this case "daddy's regular updates" are indeed protecting millions of non technical users that can't "take charge" of their own security, because they are not programmers.