Jan 30, 2020

Apple's closed security model is great until it isn't

Photo: Alex Tai/SOPA Images/LightRocket via Getty Images

Last week's report that Jeff Bezos' iPhone was allegedly hacked via a WhatsApp message from Saudi Crown Prince Mohammed bin Salman discomfited a lot of Apple customers who long believed that one of the features of their high-priced phones was invulnerability.

The big picture: The flaw in this case was in WhatsApp, not the iPhone itself. But the larger lesson is that in a networked world full of incentives for digital mischief, there's no such thing as perfect security — only varying degrees of relative risk.

The iPhone has long been the safest bet for smartphone users, thanks to Apple's close control over the App Store and its tight reins on iOS.

  • The chief alternative, Google-developed Android, is an open-source project, which means phone manufacturers and software developers can easily adopt and adapt it for their own ends.
  • That flexibility has made Android cheaper and more ubiquitous than iOS, but it also means there are many "flavors" of its code with a wider range of bugs and flaws that offer hackers wider opportunities for attack.

The Washington Post lays out how iOS's and Android's differing software philosophies shape their security landscapes:

  • Open-source software like Android follows the principle that "given enough eyeballs, all bugs are shallow" — let the world pound on your system so you can find and fix as many flaws as possible. It's a messy approach that tends toward improvement as long as smart developers put their energy into squashing bugs.
  • Apple holds iOS code close, shares relatively little information about flaws, and provides all fixes and upgrades itself. That centralization keeps its software buttoned-down and clean.

The catch: Apple's approach, experts the Post talked to argue, also means that when there is an exploitable hole in iOS, it's easier to keep it secret and exploit it. That leaves "high-value targets" — like, say, billionaire Bezos — more likely to fall victim to high-value hacks.

The bottom line: As security researcher Patrick Wardle told the Post: “A lot of Apple security is amazing and really benefits the average user, but once you’re a target of an advanced adversary or three letter agency, the advanced security of these devices can be used against you."

Go deeper: The Bezos hack's shockwaves

Go deeper

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 2 p.m. ET: 5,929,312 — Total deaths: 357,781 — Total recoveries — 2,385,926Map.
  2. U.S.: Total confirmed cases as of 2 p.m. ET: 1,709,996 — Total deaths: 101,002 — Total recoveries: 391,508 — Total tested: 15,192,481Map.
  3. States: New York to allow private businesses to deny entry to customers without masks.
  4. Public health: Louisiana Sen. Cassidy wants more frequent testing of nursing home workers.
  5. Congress: Pelosi slams McConnell on stimulus delay — Sen. Tim Kaine and wife test positive for coronavirus antibodies.
  6. Business: Louisiana senator says young people are key to reopening the economy —U.S. GDP drop revised lower to 5% in the first quarter.
  7. What should I do? When you can be around others after contracting the coronavirus — Traveling, asthma, dishes, disinfectants and being contagiousMasks, lending books and self-isolatingExercise, laundry, what counts as soap — Pets, moving and personal healthAnswers about the virus from Axios expertsWhat to know about social distancingHow to minimize your risk.
  8. Other resources: CDC on how to avoid the virus, what to do if you get it, the right mask to wear.

Subscribe to Mike Allen's Axios AM to follow our coronavirus coverage each morning from your inbox.

Updated 35 mins ago - Politics & Policy

Twitter fact-checks Chinese official's claims that coronavirus originated in U.S.

Chinese Foreign Ministry spokesman Zhao Lijian. Photo: Greg Baker/AFP via Getty Images

Twitter slapped a fact-check label on a pair of months-old tweets from a Chinese government spokesperson that falsely suggested that the coronavirus originated in the U.S. and was brought to Wuhan by the U.S. military, directing users to "get the facts about COVID-19."

Why it matters: The labels were added after criticism that Twitter had fact-checked tweets from President Trump about mail-in voting, but not other false claims from Chinese Communist Party officials and other U.S. adversaries.

Podcast: Trump vs. Twitter, round two

President Trump is escalating his response to Twitter’s fact check of his recent tweets about mail-in voting, issuing an executive order that's designed to begin limiting social media's liability protections. Dan digs in with Axios' Margaret Harding McGill.

Go deeper: Twitter vs. Trump... vs. Twitter

58 mins ago - Politics & Policy