Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And yet... https://en.wikipedia.org/wiki/Juice_jacking

Specifically, note "Mactans"

https://www.forbes.com/sites/andygreenberg/2013/07/31/resear...

"As a proof of concept, the three researchers created a malicious version of an iOS Facebook app that also includes a Trojan that runs in the background, capable of taking screenshots, simulating button touches, and sending data to a remote server."



That was done by exploiting developer mode, and was fixed by asking the user before any data transmission is enabled. The only thing that is allowed "blindly", and hence the most dangerous, is charging. No need for any racketeeri-- sorry, Apple-controlled whitelist.


How is it fixed when a significant percentage of the customer base will end up clicking yes, some due to ignorance, some by pure error? This isn't how security works.


Moving goalposts will not change the fact that Apple whitelisting this or that device does nothing beyond helping their bank balance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: