• 0 Posts
  • 14 Comments
Joined 2 years ago
cake
Cake day: December 31st, 2023

help-circle





  • Eh, it works fine in Arizona. The US uses daylight savings, but Arizona doesn’t, except for some of the reservations in Arizona that do. You can go forward and back an hour twice just crossing Arizona

    Ninja edit: As I say that, I remember why I even know that - I once spent an entire morning working out a bug in one of my daily jobs. Turned out because a team member in Arizona wrote the script and scheduled it, and a different team member not in Arizona wrote an orchestration to collect results, they ended up off-sync once daylight savings hit. Maybe it doesn’t work


  • Disclaimer: The app is closed source, so all we can go off is the developer’s word, although the fact the government removed it is a strong indicator they don’t have access to data from the app

    The developer stated they do not even retain any identifying data, so the only data the government could get is public anyway. Through Apple they’d be able to see who downloaded it, and likely when it was used. Your defense would be easy enough though: “I just wanted to make sure the libs weren’t harassing our fascist patriotic ICE agents near me”


  • Both iPhones and Android phones can be configured to your desired security level. Both are used by various government agencies around the world for their most important secrets. Neither are secure out of the box. You have to harden them to your desired level of security

    Arguing whether Android or iOS is more secure is a bit like arguing whether an SUV or pickup is safer. It doesn’t matter which you pick when basic security steps are magnitudes more important: Wearing a safety belt, having a functioning air bag, driving a safe speed, not driving drunk, etc.


  • No sideloading and no unlocked bootloader means you can’t sideload malware or install malware-preloaded ROMs

    It’s a simple configuration change to disable it and can be done with any corporate MDM system, making this a moot point. Not to mention too many people don’t understand security, so Android is taking away sideloading anyway, FoR sEcUriTY

    No root also means you can’t just install malware that uses root access

    The vast majority of Android phones do not come with root access. For both, you generally have to elevate access yourself

    Long OS support means fewer people run around with iPhones that are 5 OS versions behind

    If you’re running an out-of-date OS, clearly security is not a priority

    There’s no tiny boutique iPhone manufacturers who sell phones that come pre-loaded with malware

    Supply chain attacks absolutely can happen to iPhones as well. There are plenty of re-sellers


    You missed the actual security benefit over iOS that Android cannot compete with: Apple controls the entire software chain from security patch to OTA update. This allows them to patch and release a fix for critical vulnerabilities far faster than any Android device possibly could. Apple does not need to get the approval of an OEM (such as Samsung), and, due to special deals, they do not need to get the approval of a carrier (like Verizon). Android devices typically need to get approvals from both before releasing updates (although Google flagship phones can bypass one, and can fast track the other)

    The downside there is there are no checks on Apple. They could release a horribly vulnerable patch with no additional checks in-between


  • In terms of security alone, iPhones easily beat most Android phones

    That’s not how security works in the modern tech landscape. No major OS is going to meet a high security standard out of the box. All of them have to be configured to the desired security level, then be added to ongoing security efforts. Every major OS can be secured to the highest security standards

    The primary difference is how much effort each takes, but even then there isn’t much of a difference. You’ll find tooling and in-house expertise makes a much larger difference than the OS

    The myth that some OS are inherently secure really needs to die off