97
submitted 5 months ago by jorge@feddit.cl to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] grid11@lemy.nl 1 points 5 months ago

So for the average users that only want to go on with their lives and not buy brand new phones every 2-3 years (or don't live in places where fairphone and pixel phones are available) what would be the solution?

If a person is not some POI, don't you think that wouldn't be better to flash something that at least includes some relatively up to date security patches?

And how those rootkits are being loaded to phones with outdated firmware? Bundled with the last OS that was flashed or remotely by exploiting security flaws? Not a dev, but curious about it.

[-] 9tr6gyp3@lemmy.world 2 points 5 months ago

It's generally best to get a phone that receives software updates and security patches for more than 2-3 years. This is because vulnerabilities can be discovered in older hardware that cannot be fully fixed with a software update alone. While updating the OS helps with security at that level, flaws in the underlying hardware may still exist. Additionally, threats can come from various sources like malicious apps, texts, USB devices, or physical access, not just online attacks. Choosing a manufacturer that supports phones longer can help reduce these risks over the life of the device.

[-] grid11@lemy.nl 1 points 5 months ago

It's generally best to get a phone that receives software updates and security patches for more than 2-3 years.

See first paragraph again, not everybody is as affluent as you're, look at the problem from the other perspective

Additionally, threats can come from various sources like:

malicious apps,

will take control of the phone from the inside out, nothing will withstand that

texts,

Pegasus will use 0day, nothing to do about that

USB devices, or physical access,

Once somebody have physical access because you're some POI and not an average Joe, not much you can do

Choosing a manufacturer that supports phones longer can help reduce these risks over the life of the device.

See first paragraph, parenthesis content. Also phones are made with short lifespan on purpose, this gives steady inflow of money for the manufacturers, only few will give you what you want

[-] 9tr6gyp3@lemmy.world 2 points 5 months ago

See first paragraph again, not everybody is as affluent as you’re, look at the problem from the other perspective

There is no blanket advice for which device to use. You will have to look it up yourself. But if you're using a phone beyond its supported time, then you are vulnerable.

will take control of the phone from the inside out, nothing will withstand that

Nothing can withstand a 0-day attack, but it's on your manufacturer to prevent a 1460-day attack.

Pegasus will use 0day, nothing to do about that

See above statement.

Once somebody have physical access because you’re some POI and not an average Joe, not much you can do

You can be a random person walking in a busy metro area and happen to get in range of someone who is scanning for a particular device to use a side-channel attack on. You don't have to be a POI.

See first paragraph, parenthesis content. Also phones are made with short lifespan on purpose, this gives steady inflow of money for the manufacturers, only few will give you what you want

The manufacturers are still responsible for patching their devices. Once they stop doing that, you should know that device can't be trusted with your privacy and security. This is the minimum baseline standard. If you are trying to extend the life of a device by yourself, and use it as a daily driver, you have decided that your data is free for anyone to have.

[-] grid11@lemy.nl 2 points 5 months ago

You can be a random person walking in a busy metro area and happen to get in range of someone who is scanning for a particular device to use a side-channel attack on. You don’t have to be a POI.

I guess if you're broadcasting all the beacons your phone can be pawned even if you miss the last month OS update on your latest, greatest, shiny toy. This is just inevitable.

[-] 9tr6gyp3@lemmy.world 0 points 5 months ago

You can always go the iPhone route and have Apple support your device for over six years. And you don't have to buy a phone for a very long time.

this post was submitted on 24 May 2024
97 points (73.0% liked)

Technology

59174 readers
2383 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS