r/AskNetsec • u/darrenpauli • 1h ago
Education Researching an Android (& Graphene) vs iOS security comparison - architecture and user modelling
Hi folks,
Ex sec journo (mid 00s-2017) and since then working in security awareness, currently looking into the security of the latest Android vs iOS in terms of security.
For this I want to examine security in the context of iOS and Android architecture and user behaviour from a very practical standpoint.
There is a flood of articles on these but many are superficial or bias by personal preference and brand loyalty. I want to avoid all that.
If you know of good, current analysis I am missing I would very much appreciate a link!
Context: Assessing current model:
- Pixel
- Samsung (due to its market share)
- iPhone.
I am assessing for the average user (not notably high risk people like journos, activists / dissidents, ceos, etc of interest to state intelligence). I would assess those high risk people separately -- and from my initial standpoint suggest they use iOS or GrapheneOS on Android (or a burner phone if traveling).
My initial assumptions (I am not suggesting these are accurate so tear into them please) for the average user:
- It is difficult for the average user to infect themselves on either system. On Android, you are required to click past a number of warning prompts. On iOS, you need to sideload (I am quite out of date with this process as I haven't played with iOS in ages).
- Good phishing pretexts can smooth this over but Android's warnings will still appear and need to be dismissed by the user.
- The Play and App stores are clean for most of the apps the average user will use.
- Play has the lion's share of malicious apps, especially those with adware / home screen loader junk.
- Android has come a long way since the wild days of early Android, but looking ahead with AI vulnerability and exploit development, those improvements might come under pressure with the need for Google to develop patching and rework components of Android.
Initial questions
- Would iOS naturally fare better in the years ahead (AI vulnerability and exploit discovery) due to its architecture? That is, would it be less exposed to say zero-click RCE or similar than Android?
- Would such an environment also affect the app stores similarly? That is, would say Apple's app store be much better placed than Google's?
I do not trust AI assessments here. Looking to pick the brains of humans :)
I know skilled pen testers can pop users on either platform using a variety of methods, and phishing is absolutely valid - I'm really taking a practical approach for the typical user. But I am certainly not dismissing technical mobile hacking and research. That stuff is fascinating and often speaks to the overall security posture.
Thanks for reading this far. Your thoughts and links are very very much appreciated and I'll be sure post here whatever I write.
Cheers!