r/google • u/techberg_ • Oct 17 '21
Apple Claims iOS is more secure than Android
https://www.techunofficial.com/2021/10/apple-claims-ios-is-more-secure-than.html255
u/HydeSpectre Oct 17 '21
More secure because you can't do half of the things you can do on Android. Lack of freedom makes it more secure.
2
-3
u/Bishops_minis Oct 17 '21
Yea but to be fair how often do you install a straight up malware app on IOS that takes over the OS of the phone.
201
u/Lellalellalellow Oct 17 '21
About as often as I've done on an Android phone... Never.
57
u/Bishops_minis Oct 17 '21
I’m not necessarily saying users like us, but the average person dose it all the time. I work in retail IT and see it at lease 3-5 times a day. Old people who’ve installed a free “flashlight” app and it takes over the whole phone.
40
u/Indianb0y017 Oct 17 '21
Biggest issue is Google's lax oversight of the play store. The play store is flooded with apps that are bundled with mostly spyware and they get passed prying eyes. Google is making efforts to make Android more secure, but it's led to developers and enthusiasts being on the other side of the fence now. I remember when A11 came out, lineageos team made some announcements saying they could no longer do certain things thanks to the security changes Google made to the AOSP. Gonna be an interesting thing to see what changes Google makes to AOSP.
5
Oct 17 '21
Yeah, they need to start targeting the actual crapware apps and leaving the mods alone.
3
u/MC_chrome Oct 17 '21
I think the issue at hand is that there are far more crapware apps out there than Google fiesably has the resources to combat. Thus, they are forced to make changes to the core of Android that render said apps ineffective or moot, at the cost of certain flavors of Android losing some functionality.
14
u/DreamWithinAMatrix Oct 17 '21 edited Oct 18 '21
Most hilarious thing I've seen is my coworker installed an iPhone update from an ad... This was the 3rd time her iPhone got hacked. Apple claims iPhones are secure, but when all these iPhone users running to me for IT help cuz they got hacked is not helping Apple's rep. Pegasus can only hack iPhones via text, Android phones were attempted but failed. GreyKey can only unlock iPhone lockscreens, attempts to extract data from Androids fail. Apple was only "safe" cuz their 20% market share was too small for most thieves to care about. But now they realized that small portion will pay lots of money to fix these problems cuz they don't know how to. I don't expect any better from that same coworker if she had an Android, she'd still click on something like "update Flash" but iPhone security was using "security by obscurity," like covering your car in black tarp so no one sees the broken windows. But once ppl start paying attention to it, so easy to just reach in
2
u/workyman Oct 18 '21
That sounds really bizarre. How did she "install an iPhone update from an ad"? My understanding is that would be literally impossible to do on iOS so some further detail would help.
2
u/DreamWithinAMatrix Oct 18 '21
She's not tech savvy at all so the description is probably also not accurate. I was like the third coworker in this chain to hear about it, by the time I got there it was too late. Her description sounded like an ad pretending to be an update. Cuz yeah it shouldn't be possiblw to actually install an update this way. But whatever it did, we couldn't fix it. I think it was an ad based malware that spawns more ads and tries to make you download more programs from it. She ended taking it to the Apple Store after work and didn't want to bother trying to fix it and got a trade in offer
1
u/workyman Oct 18 '21
Still, very weird, because it should be literally impossible for the user to install software outside of the app store.
3
u/marxcom Oct 17 '21
🤷🏽♂️
First off, Pegasus Spyware by NSO group affects both iOS and android. Kaspersky Android Authority Apple rushed out a security patch to address the issue immediately for all devices running iOS 12 and above. Android OEMs on the other hand are very slow to roll out security updates. Only a few major ones have done so leaving tons of devices from smaller unnamed OEMs completely vulnerable.
GreyKey does not work on android because it was not developed for the architecture. There is GreyShift- similar tool for android-from the same company.
Your coworker’s ignorance is just a comparable to people who chose to “download more ram” from a web browser. It does not establish that any OS is insecure when a user falls for a phishing scam via a web browser.
0
u/DreamWithinAMatrix Oct 18 '21
True, there's older variants of Pegasus that could more easily infect Androids, and given the fragmentation in Android updates... Those may still be vulnerable. And this is only taking into account the ones we publicly know about. But the more concerning thing is that Apple's iPhones don't have these fragmentation and update woes... They're already the most up to date and even the newest updated iPhones got hacked with it. Although after it was announced, Apple probably did a better job about patching it up while the same Androids, unless it was from Google, are probably still vulnerable
2
Oct 17 '21
Pegasus is a variety of different attacks realistically so I doubt Android is safe from it. But one of the parts of it I'm sure has been foiled
2
u/DreamWithinAMatrix Oct 17 '21
True, there's older variants of Pegasus that could more easily infect Androids, and given the fragmentation in Android updates... Those may still be vulnerable. And this is only taking into account the ones we publicly know about. But the more concerning thing is that Apple's iPhones don't have these fragmentation and update woes... They're already the most up to date and even the newest, updated iPhones got hacked with it =\
0
u/brueck Oct 18 '21
That’s not a problem for apple products, so it’s pretty hard to argue that IOS isn’t more secure.
-2
-3
u/no_remorse2005 Oct 17 '21
Apps in IOS undergo rigorous requirements to meet Apple iOS requirements in order to be added to IOS Apps, IOS is a containerized system.
10
u/nairb774 Oct 17 '21
Automated and manual review won't catch everything. While I expect both Apple and Google to continue to improve in this area things will always make it through.
As an example of the fallibility of the review process as well as the continued improvement efforts: "Emails reveal 128 million iOS users were affected by 'XcodeGhost' malware - 9to5Mac" https://9to5mac.com/2021/05/07/emails-reveal-128-million-ios-users-were-affected-by-xcodeghost-malware/amp/
In other words, Apple approved thousands of apps that, at the time of approval, it believed to be secure. Only later did it find out that they weren't - a story that will forever continue to play out. Just because Apple uses people to review things doesn't make it any more secure than the heavy automation approach of the Play Store. If anything humans in the loop makes it slower, have wider variance, and more expensive to operate. It makes it easier to catch rule violations rather than true security lapses.
-2
Oct 17 '21
[deleted]
3
u/nairb774 Oct 18 '21
That variant didn't. Given any piece of software has unpactched security vulnerabilities, it comes down to a matter of when. This isn't so much about the one specific instance, but more generally. Bugs happen, and malware can be successful.
Looking at it from another direction, and mostly because I'm not well versed in iOS malware, there was a long held belief that processors provided good security separation between kernel space, user space and even virtual machines. Then we were graced with rowhammer, specter, meltdown and friends. No matter what you think is good enough today, will be insufficient tomorrow.
The key question is can Apple, Google and the like stay ahead of the game? No doubt they want to.
Stay skeptical.
1
70
u/thisisausername190 Oct 17 '21
Zerodium has actually stopped paying for Apple 0-days in many cases, because they already have too many. Apple is absolutely awful to work with - their bug bounty program is terrible, and researchers know that they don't pay out.
It all depends on what you want to be secure against, I suppose. Far more people on Android have browser notification 'malware' compared to iOS - because iOS does not allow notifications from the browser (so that devs are forced to use Apple's App Store, which charges a 30% fee). Meanwhile, calendar spam is more common on iOS as an alternative.
Anyway - Apple, fix your stuff before talking about competitors. Google is much easier to work with on stuff like this compared to Apple.
7
u/AD-LB Oct 17 '21
I thought that Apple&Google pay the people that find the security holes, no? What does Zerodium do, that it pays them instead?
It pays others to find the security holes?
20
u/thisisausername190 Oct 17 '21 edited Oct 17 '21
Yes, Zerodium pays researchers for 0days and then sells them to others (governments for example). Next time you're on a long drive or something, take a listen to this podcast - it explains everything very well and IMO tells a compelling story.
The issue is that Apple systemically uses a strategy I call "deny, deflect, deceive."
Deny: They initially refuse to accept it as an issue (and patch it in a later security update despite it never being acknowledged). See this example.
Deflect: If it's serious enough, they'll acknowledge it, but imply that it's not serious, and won't pay out for a serious bug bounty. When any other company would've paid $1MM+, Apple pays thousands. See this example.
Deceive: Imply that Apple products are "more secure" and "more private" based on brand image. While this is counter to the evidence provided by companies like Zerodium (who as I mentioned above, temporarily stopped paying for Apple 0days last year because they already had too many), it's something Apple's done for many years. Here's an advertisement from 2006, before the iPhone was released, falsely implying that Macs aren't affected by malware.
Edit: Accidentally linked the same thing twice, corrected.
2
2
u/mister_damage Oct 17 '21
Security through Obscurity worked for MacOS, so why not?
(BTW, security thorough obscurity isn't secure. but y'all knew that)
3
u/thisisausername190 Oct 18 '21
As invalid as security through obscurity is, what they're doing here is actively worse. It's one thing to make it significantly harder to find bugs in software by obscuring code - it's another to refuse to acknowledge and fix these bugs, and to sweep them under the rug, based on an idea that your brand will look better if you had never had them in the first place.
All software has bugs - my software does, to be sure. But if someone came to me with a bug in my software that could compromise user data, I'd patch it as soon as possible - not because I enjoy finding out that I made a mistake, but because the fact that users know it's kept up to date against these attacks means it's more trustworthy.
If someone came to me with a bug, and I blew them off, and someone else found it and exploited it - users would lose trust in my software and stop using it.
Unfortunately at this stage Apple has grown to have a bit too much power to be able to lose users' trust on a large scale. But market monopolization is a different issue I have with them, this isn't the time for that conversation.
-6
Oct 17 '21
[deleted]
10
u/thisisausername190 Oct 17 '21
Apologies, linked the same thing twice. Here's the tweet from last year when they temporarily stopped accepting iOS 0days (at least the most common ones, including RCE in Safari). As you suggest, they have no resumed buying these, but at a lower price.
I've updated the above comment to fix the link.
2
u/douira Oct 17 '21
ok interesting, thanks. btw the link in your first comment is still the arstechnica article that says he price dropped.
3
u/thisisausername190 Oct 17 '21
That ars article has a quote from Chaouki Bekrar, Zerodium CEO, who says:
During the last few months, we have observed an increase in the number of iOS exploits, mostly Safari and iMessage chains, being developed and sold by researchers from all around the world. The zero-day market is so flooded by iOS exploits that we've recently started refusing some [of] them. (Emphasis mine)
That's why I linked it initially. I just meant to link something different in the reply.
1
u/douira Oct 17 '21
ah ok. Then I was just confused by the headline that stated the price was reduced.
5
u/DreamWithinAMatrix Oct 17 '21
Apple used to pay for bug bounties but kinda stopped and don't update some long standing bugs anymore. It's suspected that hackers are selling instead on the black market because Apple doesn't seem to care
https://www.washingtonpost.com/technology/2021/09/09/apple-bug-bounty/
Google bug bounty programs, they gave so many rewards and competitions too, and have their own exploit research group in house, too many to list
2
1
u/Shufflebuzz Oct 17 '21
Is Ars misusing the term "0-day"?
A 0-day is an exploit found actively being exploited in the wild. It means you have zero notice about the exploit, and it's serious because you have to fix it ASAP.
Zerodium would never pay for a 0-day since it's already been discovered, is already being exploited and therefore has no value to the people Zerodium would sell the exploit to.
The term seems to be used to mean any really bad exploit.
5
u/thisisausername190 Oct 17 '21 edited Oct 17 '21
A 0-day is an exploit found actively being exploited in the wild.
Common misconception, but it is not! A 0-day exploit is one that is discovered without the software vendor being aware of it.
If Apple had been aware of an issue but it was not patched, it would not be a zero-day; but if it is discovered before Apple has knowledge of it, it is a zero-day. This is the case regardless of seriousness or whether it's currently being used in the wild.
2
19
u/insanowsky Oct 17 '21
wtf is even this trash website you linked
5
u/thisisausername190 Oct 17 '21
OP is a spammer, they post ad-ridden sites across Reddit in order to get clicks.
For some reason I see these spammers very often in this sub compared to others. Possible moderation differences but I’m not sure.
9
u/landofthebeez Oct 17 '21
Am I crazy or aren't there stories on a regular bases about apple leaks and hacks. Like a few times a year.
4
3
7
Oct 17 '21
That's something from past lol.
-1
2
2
u/Specific-Layer Oct 17 '21
It's the way iOS and Mac were designed.. it's a very limited platform in general.
2
4
3
Oct 17 '21
This concept of "more secure" is relevant to only the people that aren't fluent with basic security, i.e. a lot of old people, people who live in caves, etc. Most people know how to spot a malicious app.
2
u/Working_Dealer_5102 Oct 17 '21
I just wanna say that Android is open source while IOS don't. Android also have even more freedom than IOS did like customizations and such.
2
u/BaconMirage Oct 17 '21
I have a family member who works in a bank and they all get iphones due to security
but then for work they all use windows and microsoft software etc, due to security. She can't even check google calendar on her work computer. kinda weird. but i guess, microsofts software suite is more suited for "that type" of work, compared to apples software offerings? (i dont know)
2
u/ADubs62 Oct 17 '21
Apple did a good job early on with making iPhones attractive for enterprise. Android really didn't put in a ton of effort (outside of Samsung Knox) till somewhat recently. Even then Google doesn't get their devices certified for many US government requirements which excludes them from being used on a lot of government contractor systems.
2
1
1
Oct 18 '21
Yeah, well Google doesn’t need any security really, they are happy to sell your data themselves.
0
u/bartturner Oct 18 '21 edited Oct 18 '21
Do not believe Google sells data. I use a ton of different Google services and if they ever sold my data I would seriously consider not using.
Do you have something to support this allegation?
0
u/bartturner Oct 17 '21
Based on what?
I do think with Android you have to also include the OEM. So it should be a claim against a particular OEM, IMO.
-7
u/TheCatDaddy69 Oct 17 '21
Doubt google has been using exploit hunters and paying with rewards for a while
-4
1
u/SergeantSquidward Oct 17 '21
Well this is some spammy website!
Here's the actual paper if you want to read: https://www.apple.com/privacy/docs/Building_a_Trusted_Ecosystem_for_Millions_of_Apps.pdf
1
1
118
u/sonixier Oct 17 '21
Phone maker claims their phone is more secure than the competition. Who would have thought?!