Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Pegasus was used by governments to target specific individuals. If you're being targeted by governments I would agree you're out of luck even on iOS.


So, in other words, iOS is insecure and vulnerable to malware.

Governments don't have special hacking powers, they mainly have money and manpower.

It's true, iOS might raise the bar a little bit compared to some other systems, but IMHO it's misleading and dangerous to claim that it's invulnerable.


The point is you're not going to get malware if you open the wrong email or go to the wrong site like you could on Windows. The organizations with enough resources to hack iOS devices aren't interested in sending mass emails to steal bank account details. The average iOS user who keeps their device up to date simply doesn't have to worry about malware and suggesting otherwise is misleading.


> The organizations with enough resources to hack iOS devices aren't interested in sending mass emails to steal bank account details. The average iOS user who keeps their device up to date simply doesn't have to worry about malware and suggesting otherwise is misleading.

Again, no. Here's another counterexample (which is recent and appears to have been active on the App Store for ~1yr):

https://researchcenter.paloaltonetworks.com/2016/03/acedecei...

"These malicious iOS apps provide a connection to a third party app store controlled by the author for user to download iOS apps or games. It encourages users to input their Apple IDs and passwords for more features, and provided these credentials will be uploaded to AceDeceiver’s C2 server after being encrypted."

That's not state actor stuff.

However, I shouldn't have to keep providing counterexamples to convince you of your absurd claims of practical invulnerability. Apple has not made any kind of security quantum leap: no one has. Apple's systems are vulnerable to the same types of flaws, by the same types of attackers, as any other system in wide use. The main difference is that Apple has restricted their platform to the extent they have an easier time implementing security best practices. iOS is still vulnerable to flaws Apple doesn't know about or hasn't patched, and those flaws can be exploited for as long as Apple remains unaware or fails to act. That's not fundamentally different position from Microsoft, Google, or any other similar company.


What you linked is basically an elaborate phishing scheme. The exploit allows the installation of non app store apps, but that doesn't mean the installed apps can escape the sandbox. The worst thing it can do is try to trick the user into entering passwords into the app's fields. As far as malware goes it's pretty benign.

There have been a handful of cases of iOS malware over the years, but no serious exploit has been widespread. For an exhaustive list see here: https://www.theiphonewiki.com/wiki/Malware_for_iOS

The most wide spread malicious apps are generally apps that access private apis but manage to get through Apple's review process and onto the App Store. They can be far reaching but again they can't breach the sandbox which means the absolute worst thing they do is upload your email address to some server or try to trick you into giving away your password. I still stand by my assertion that the average user doesn't need to worry about malware on iOS.


> They can be far reaching but again they can't breach the sandbox

False, they can breach the sandbox. The sandbox is software and it has exploitable flaws until proven otherwise (which hasn't happened).

Look, like I said in another comment: you'd be fine if you restricted yourself to relative comparisons, but for some reason you have to go too far and make absolute statements of security, statements which can't possibly be true. iOS might be more secure than other OSes, but it's still insecure, and it's dangerous and misleading to say that any users don't need to exercise reasonable caution.


While that was an interesting article I didn't see it making any claims of having bypassed the sandbox, but "just" the DRM to allow install of pirated apps. The heavy sandboxing of every app on iOS is fundamentally different from any desktop OS. Sandboxing of desktop apps is still very far from a complete implementation.


> The point is you're not going to get malware if you open the wrong email or go to the wrong site like you could on Windows.

So the point is that you aren't going to get malware on your small, entirely contrained and locked down portable computing device like you are on your larger, general purpose open computing device? Why even bother making that comparison?

OS X has plenty of vulnerabilities.[1] If you want to make a coherent argument, source your claims that modern windows only requires you visit a site or open an email, and we can look to see if Apple has had similar vulnerabilities in equivalent products.

1: https://www.cvedetails.com/vulnerability-list/vendor_id-49/p...


I agree with your statement here but it should be noted that a lot of cyber security is the joke about running away from a bear. I don't have to outrun the bear, I just have to out run you.


Exactly. I wouldn't have a problem if people were saying "iOS is more secure than X" or "You should pick iOS because it's one of the most secure OSes, but you should still be careful." But nooo, the fanboys go too far and spew dangerous, misleading stuff like "it is secure" and "you don't have to be careful" and "it can't get malware."


> If you're being targeted by governments I would agree you're out of luck even on iOS.

Probably true on almost every OS.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: