• DupaCycki@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    47
    ·
    12 hours ago

    In terms of security alone, iPhones easily beat most Android phones. Which may be a fair argument in favor of iPhones. However, to ignore Apple’s policies and long history of delisting similar apps is delusional.

    • squaresinger@lemmy.world
      link
      fedilink
      English
      arrow-up
      25
      ·
      11 hours ago

      In regards to security, Apple does have three upsides, and only those:

      • No sideloading and no unlocked bootloader means you can’t sideload malware or install malware-preloaded ROMs. No root also means you can’t just install malware that uses root access.
      • Long OS support means fewer people run around with iPhones that are 5 OS versions behind.
      • There’s no tiny boutique iPhone manufacturers who sell phones that come pre-loaded with malware.

      The solution for the first one is “don’t sideload untrusted stuff” and the solution to the second and third one is “buy an Android phone from a trusted manufacturer that has long term OS support”.

      • Taldan@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        3
        ·
        8 hours ago

        No sideloading and no unlocked bootloader means you can’t sideload malware or install malware-preloaded ROMs

        It’s a simple configuration change to disable it and can be done with any corporate MDM system, making this a moot point. Not to mention too many people don’t understand security, so Android is taking away sideloading anyway, FoR sEcUriTY

        No root also means you can’t just install malware that uses root access

        The vast majority of Android phones do not come with root access. For both, you generally have to elevate access yourself

        Long OS support means fewer people run around with iPhones that are 5 OS versions behind

        If you’re running an out-of-date OS, clearly security is not a priority

        There’s no tiny boutique iPhone manufacturers who sell phones that come pre-loaded with malware

        Supply chain attacks absolutely can happen to iPhones as well. There are plenty of re-sellers


        You missed the actual security benefit over iOS that Android cannot compete with: Apple controls the entire software chain from security patch to OTA update. This allows them to patch and release a fix for critical vulnerabilities far faster than any Android device possibly could. Apple does not need to get the approval of an OEM (such as Samsung), and, due to special deals, they do not need to get the approval of a carrier (like Verizon). Android devices typically need to get approvals from both before releasing updates (although Google flagship phones can bypass one, and can fast track the other)

        The downside there is there are no checks on Apple. They could release a horribly vulnerable patch with no additional checks in-between

        • squaresinger@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 hours ago

          You don’t seem to get my point and seem to think that I’m some apple fanboy that you need to convince or win against.

          I use android, I’ve never used iOS. I enjoy the freedom of sideloading. Still it is a fact that the overwhelming majority of malware infections on Android happen due to side loading. The percentage of devices running corporate MDM is tiny, making this a moot point.

          The vast majority of Android phones do not come with root access. For both, you generally have to elevate access yourself

          And yet quite a few devices in the wild run rooted or custom ROMs.

          If you’re running an out-of-date OS, clearly security is not a priority

          You seem to forget what this thread is about. It’s not about personal security and whether one can run a safe android device, but about an app developer not providing an Android version, because the platform as a whole (meaning the average user) is less secure.

          Personal preferences like paying for a new, non-outdated phone don’t really matter for that big picture view.

          Supply chain attacks absolutely can happen to iPhones as well. There are plenty of re-sellers

          That’s a strange argument. Getting malware that survives a factory reset onto an iPhone without apple’s approval is close to impossible. Making an Android phone from scratch that contains malware right in the system image has been done over and over again. You are argueing a hypothetical versus something that happens every day.

      • liuther9@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        9
        ·
        11 hours ago

        Long os support meant to intentionally brick your iphone so you buy new. That is 100% true as I had many apple products started degrading after upgrade and still have old models that are not upgraded and work perfectly

        • squaresinger@lemmy.world
          link
          fedilink
          English
          arrow-up
          15
          ·
          11 hours ago

          I’m not defending apple here. Short OS support (or none at all) is not a good thing, and it’s something that’s sadly still quite common if you buy the wrong Android brand.

          Samsung is doing pretty well in that regard right now.

    • Taldan@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      8 hours ago

      In terms of security alone, iPhones easily beat most Android phones

      That’s not how security works in the modern tech landscape. No major OS is going to meet a high security standard out of the box. All of them have to be configured to the desired security level, then be added to ongoing security efforts. Every major OS can be secured to the highest security standards

      The primary difference is how much effort each takes, but even then there isn’t much of a difference. You’ll find tooling and in-house expertise makes a much larger difference than the OS

      The myth that some OS are inherently secure really needs to die off

      • Encrypt-Keeper@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        7 hours ago

        Every major OS can be secured to the highest security standards

        Has Android added E2EE to their cloud backups yet like Apple has?

        Apple is no friend to any of us, but Google openly and shamelessly scrapes every piece of data you put on their phones. Apple is absolutely the lesser of these two evils with out of the box functionality. I say this as a lifelong Android fan and Apple hater that entered the cybersecurity space and am only interested in the most private option I can get out of the box.

        Like an Android can be more secure and private than an IPhone, but afaik that involves owning a Pixel specifically and installing an entirely different OS on it, one that Google a Is also out to get.

        • Xatolos@reddthat.com
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          2
          ·
          6 hours ago

          You do know that Apple privately scrapes every piece of data you put on their phones right? Go read the privacy and ad policies. Apple also gives access to a lot of their users private information (China has full access to its users iCloud), will remove apps like this (while Google still allows apps that block ad trackers like DuckDuckGo that block Google own trackers). And Google supports CSE.

          We get it from your post, your a huge and blind Apple fan that wants to do anything you can to confuse others into believing falsely like you that Apple is somehow a great company and product. But the truth is, Apple doesn’t care about your privacy, lies to your face about it, and makes you less secure and your information less private as these situations show. And if you were in cybersecurity, you’d know this.

          • Encrypt-Keeper@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            edit-2
            6 hours ago

            I’m not much of an Apple fan, I just like to get my privacy where I can. And with over a decade of experience in cybersecurity I can confidently say that as much as you shouldn’t blindly trust Apple, they at least give you a number of tools to increase your privacy out of the box.

            Android on the other hand is a nightmarish hellscape of data mining and user profiling. There is GrapheneOS which is as of today a great option to circumvent Google’s data mining, but now that its future is at stake I worry for the future of privacy on Android devices.

            But we get it from your post, you’re a pro-Google shill bot that didn’t actually read my comment and is just regurgitating nonsense to muddy the waters.

      • DupaCycki@lemmy.world
        link
        fedilink
        English
        arrow-up
        13
        arrow-down
        16
        ·
        12 hours ago

        Based on most smartphones being very insecure. Of course, iPhones aren’t extremely secure, but the competition is practically nonexistent. Pretty much the only secure Android phones are Pixels. Samsung is considered one of the more secure manufacturers too, but according to GrapheneOS devs it’s still way behind Google.

        Note that even police and government agencies sometimes have trouble getting into iPhones. They never have such troubles getting into Android smartphones, except Pixels.

        This is by no means meant to advertise iPhones. It’s just a simple observation that security in smartphones is heavily lacking.

        • Taldan@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 hours ago

          Both iPhones and Android phones can be configured to your desired security level. Both are used by various government agencies around the world for their most important secrets. Neither are secure out of the box. You have to harden them to your desired level of security

          Arguing whether Android or iOS is more secure is a bit like arguing whether an SUV or pickup is safer. It doesn’t matter which you pick when basic security steps are magnitudes more important: Wearing a safety belt, having a functioning air bag, driving a safe speed, not driving drunk, etc.

        • Potatar@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          11 hours ago

          Dude give one example so we can google and have our own opinion. You are just saying “because they said so/because someone considered it so”.