iOS 7 Bug Lets Anyone Make Calls From Locked iPhones
forbes.com
forbes.com
It's not like iOS users can install an alternate browser, either.
Opera Mini isn't a true browser and offloads processing to external servers because they can't interpret JavaScript locally (thanks to Apple's anti-competitive app store rules). The off-device rendering makes for a less-than-desirable user experience.
Chrome and every other "browser" in the iOS app store is just a custom UI on top of Mobile Safari. And it's not even full-speed instance of it since it can't use the Nitro JavaScript engine. It's hobbled so it's slower than proper Mobile Safari. Chrome does add one other custom bit in that it inserts its own network stack underneath it. But it's still Mobile Safari within Chrome. It's not the Chrome/Blink engine and it likely never will be. Not unless those increasingly high walls start coming down.
UIKit Dynamics is pretty cool, and so is Sprite Kit. Two of my favourites.
They are not getting enough credit for that.
They aren't getting credit though because unless you're a developer, no one really cares. Most people want to see changes that effect them directly. That is something that I think Steve had a very good understanding of.
Android's been out for 5 yrs and it still feels rushed. ;)
The bugs seem to a bit more nuanced than just testing for a locked device; the attacks seem to rely on performing actions simultaneously to exploit race conditions much like weird glitches in games. This class of bugs is really hard to test for due to the large search space. Model checking might offer a solution, but it's not a magic bullet by any means.
Couldn't have said it better. Crazy that we're only now getting number blocking. (Okay, that's a "new feature," but it's a pretty basic one.)
[1] http://lists.apple.com/archives/security-announce/2013/Sep/i... [2] http://lists.apple.com/archives/security-announce/2013/Sep/m...
Apple regularly posts security updates and notices, and they aknowledge the people who find them.
Heck, even besides security, the claim that "Apple has never acknowledged a problem with their platform" is totally BS.
Steve Jobs himself apologized for the iPhone 4 antenna, and there was also a public statement from Apple about iOS Maps. An of course, they also have the usual recall programs, for things such as faulty batteries, HD and such.
So, FUD much?
Beyond that there are many that feel if Apple doesn't want to participate in having a more responsive approach towards security why should people go out of their way to play nice with them? Give and take, Apple has played out the "we don't respond unless it's in the interest of saving public face or potential sales losses" far too long. Being overly secretive is a bad thing today, especially with regard to consumers expectation of going to bat for them when it makes sense. They've continually lost face with me (in this particular regard) over the years in their elitist stance. It's of their own doing and approach. And it's completely in their control to change.
I'm guessing Gruber and the rest of the Apple-crowd is not going to try to spin this one as vividly as they would have done, had this been an Android-exploit.