The percent that might want to choose a different-than-latest version of OS would also of course be quite small, but I suspect it would be orders of magnitude larger than the other group we're speaking of just because that group of people is going to be so absurdly tiny.
In your world, they could be.
I imagine iPhone thefts would go way up. They’re worth $1000 and we just carry them everywhere - if they were easily resellble it would be a very obvious quick-money theft opportunity.
I don't know for certain why thieves are generally not typically interested in abusing user data, but I'd imagine it's because the penalties if caught would go way up. That'd go from what is generally just petty theft, which carries a slap on the wrist, to wire fraud and a whole slew of other charges, which can leave people spending most of the rest of their life in prison.
My assertion is that there would be way, way more theft if you could just downgrade and wipe.
Because a quick search for UK statistic shows that even though iPhones are minority of phones over here they are the overwhelmingly majority of all phone theft:
https://www.loveitcoverit.com/news/changing-world/mobile-pho...
"In terms of smartphone models, the data also indicates who might be most at risk. Looking at the entirety of the UK, 68.6% of stolen phones are iPhones."
“In 2012, the National Crime Survey – which supplies data to the ONS – reported that there were roughly 608,000 theft from a person incidents across England and Wales, which was a high for the decade. However, since then, theft from person cases – including those including smartphones – have fallen year on year. A key factor for this continual decline could be that smartphone security has improved to a point that it’s no longer worth stealing them; with Face ID, trackers, and fingerprint scanners, it’s now harder for criminals to wipe and fence stolen property. It’s also possible that, due to the ubiquity of smartphones, the desire to steal them has simply decreased.”
To me the surprising claim would be that phone theft is common - I don’t think I know of anyone who’s had their phone stolen - but if you want stats, sticking with the UK, here’s the official statistics on robbery and ‘theft from a person’: https://www.ons.gov.uk/peoplepopulationandcommunity/crimeand...
It’s more work than I have time for now, but I don’t think that any of the headline figures can be regarded as ‘common’.
More emotionally: Maybe it’s just my age showing, but it is notable to me that nowadays we’re all carrying around $1000 items at all times, and muggings aren’t through the roof. Perhaps society is kinder than I gave it credit for, but I think that the lack of utility of those $1000 items if you steal them (so, they’re not really worth $1000 to a mugger) is a major part of the reason they’re not.
It's also going to make the targets even less likely to report the crime to police as well. 'Hi, I don't live in this country and I think my phone might have been stolen somewhere at some point in time over the past several hours, maybe.' is not even going to be investigated by the police, even if somebody does decide to file a report.
Come to think of it, this may all be yet another reason why thieves don't tend to abuse personal information. That sort of stuff is going to get reported and can be viably investigated by the police.
What’s even the point of setting a password if anyone can manipulate the system without entering it in?
The entire iPhone OS is on an encrypted volume and that is the right design choice. Not having the password means no access.
There is no general purpose encrypted volume operating system that allows unauthenticated users to perform OS manipulation. If you encrypt your FreeBSD, Linux, or Windows volume, the result is the same: no password, no access.
Your choice is to enter the correct password or wipe the disk.
The fact that Apple doesn’t allow you to set up a system without full disk encryption is not a user freedom issue, it’s a very sensible design choice especially for a device sold primarily to non-technical consumers who don’t understand the security implications of leaving the volume unencrypted.
The issue here isn’t that iOS security is designed wrong, the issue is that Apple broke basic password entry with an update.
Shame on Apple for having such lazy software development practices when it comes to implementing updates like this.
The particular use case you’re asking for here has no logical reason for existing
Also people find exploits on newer OS versions as well. Downgrading makes it easier but not downgrading doesn’t make the device unhackable.
Apple should be forced to do this by law, but only after they discontinue software support. If they're willing to continue making small, incremental patches when necessary (such as to fix this obvious bug) then it's fine that they can still block downgrades. But at EOL? They should be legally required to allow old software to be installed.
This also impacts software compatibility - any 64-bit device that is now EOL that got updated to iOS 11 or newer is forever barred from running 32-bit apps just because people are worried that someone might take that old device and downgrade it as an attack?
The average person should always stay updated to the latest version for security reasons. But the power users should be able to choose which version they run, at least on devices that aren't currently supported at all.
Daily reminder that the first two iPhones and the first iPod touch had zero firmware signing, and you could freely install any supported version at any time, and can still do so today. That being the case has probably harmed 0.00001% of people at most
Citation needed. My guess is the biggest contributor to smartphones becoming e-waste is gravity.
It also harms software preservation. Sure, we have IPSWs for every single public build of iOS that exists (and if you dig around, probably a ton of betas and even internal builds). But you can't really do anything with any of them once you get to the point in the iOS product line where things were sufficiently hardened