• fartsparkles@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 days ago

    Is that true though? I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time.

    Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support.

    And even from an OS architecture point of view, actual Android and its IPC via intents, content providers, broadcast receivers, and component exports etc is a whole world of juicy attack surface that simply doesn’t exist on iOS. Which is a primary reason people hate iOS given apps feel so isolated and you have to use the share sheet to get data between apps.

    Then you have Android’s differing chipsets vs iOS’s Secure Enclave that’s on all supported handsets. Plus Android’s WebView has addJavascriptInterface() allowing native code execution via that API whereas Safari, as shit as it is, doesn’t have that enabled.

    Don’t get me wrong, Android is an awesome operating system and it’s openness enables some amazing distributions like GrapheneOS.

    But even a cursory glance at the two attack surfaces, iOS has a way smaller surface and swifter patching.

    • I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time.

      The ones you know about, yes :). We know there are complete firms actively exploiting iOS devices though. With Android the security community can figure out what the flaws are and patch them, with iOS it’s a black box.

      Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support.

      Most devices are legally required to get X years of security updates, and most manufacturers do push those out fairly quickly. Maybe not all the same day, sure, but they do go out.

      I do remember a fair few exploits for iOS devices that allowed an attacker to take over a device without any user interaction, and most mentioned they were actively being exploited by malicious (state) actors.

      All I think however is that the price of the exploit doesn’t necessarily correspond with how secure the device actually is, but rather it’s based on the value that that exploit might hold. US entities would probably also offer more than EU entities, whereas for Android it might be the other way around.

      • Arcane2077@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        16 hours ago

        “Required to get updates for X amount of years” means getting an eol update one year after the previous one. And not prompted, you have to go looking for it.