Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

We can make our phones harder to hack but complete security is a pipe dream

We can make our phones harder to hack but complete security is a pipe dream

Even the latest iPhone scare won’t persuade us to choose safety over convenience
Apple caused a stir a few weeks ago when it announced that the forthcoming update of its mobile and laptop operating systems would contain an optional high-security mode that would provide users with an unprecedented level of protection against powerful “spyware” software that surreptitiously obtains control of their devices.

It’s called Lockdown Mode and, according to Apple, “offers an extreme, optional level of security for the very few users who, because of who they are or what they do, may be personally targeted by some of the most sophisticated digital threats, such as those from NSO Group and other private companies developing state-sponsored mercenary spyware”.

Lockdown is effectively an alternative operating system mode. To turn it on, go to settings, choose it and restart your device. When you do, you find yourself with a rather different iPhone. Browsing the web is clunkier, for example, because Lockdown blocks many of the speed and efficiency tricks that Safari uses to render web pages. Some complex but widely used web technologies, like so-called just-in-time JavaScript compilation, which allow websites to run programs inside your browser, are disabled unless you specifically exclude a website from restriction. Still, more people might be persuaded to plump for greater security after vulnerabilities were revealed on Apple devices.

Lockdown also limits all kinds of incoming invitations and requests (for example, from FaceTime) unless you have specifically asked for them. In messages, the phone won’t show link previews and will block all attachments with the exception of a few standard image formats. Nor will it allow access to anything physically plugged into it. And so on.

The result of engaging Lockdown is that you have an iPhone that is more secure but less convenient to use. And, in a way, that is the most significant thing about Apple’s decision. As the security guru Bruce Schneier puts it: “It’s common to trade security off for usability and the results of that are all over Apple’s operating systems – and everywhere else on the internet. What they’re doing with Lockdown Mode is the reverse: they’re trading usability for security. The result is a user experience with fewer features, but a much smaller attack surface. And they aren’t just removing random features; they’re removing features that are common attack vectors.”

Ever since people started to worry about computer safety, the issue has been framed as striking a balance between security and convenience. Up to now, convenience has been winning hands down. Take passwords. Everyone knows that long, complex passwords are more secure than simple ones, but they’re also hard to remember. So, being human, we don’t use them: in 2021, the five most commonly used passwords were: 123456, 123456789, 12345, qwerty and password.

In the era of mainframe computers and standalone PCs, this kind of laxity didn’t matter too much. But as the world became networked, the consequences of carelessness have become more worrying. Why? Because there is no such thing as a completely secure networked device and we have been adding such devices to the so-called Internet of Things (IoT) on a maniacal scale. There are something like 13bn at the moment; by 2030, the tech industry thinks there might be 30bn.

The conventional adjective for these gizmos is “smart”. They can be “hi-tech” items such as smart speakers, fitness trackers and security cameras, but also standard household things such as fridges, lightbulbs and plugs, doorbells, thermostats and so on. From a marketing point of view, their USPs are flexibility, utility and responsiveness – in other words, convenience.

But smart is a euphemism that tactfully conceals the fact that they are tiny computers that are connected to the internet and can be remotely controlled from a smartphone or a computer. Some are made by reputable companies, but many are products of small outfits in China and elsewhere. They come with default usernames and passwords (such as “admin” and “password”) that buyers can change (but usually don’t). Because they’re networked, they are remotely accessible by their owners and, more importantly, by others. And there are billions of them out there in our homes, offices and factories.

Security researchers use the term “attack surface” to describe the number of possible points where an unauthorised user can access a system, extract data and/or inflict damage. The smaller the surface, the easier it is to protect. Unfortunately, the corollary also holds. In our Gadarene rush into the Internet of Things we are creating an attack surface of near-infinite dimensions.

The strange thing is that we already know what the consequences of this are like and yet seem unperturbed by them. In 2016, the security community was transfixed by a number of huge distributed denial-of-service attacks that caused outages, internet congestion and in one case overwhelmed the website of a prominent security guru.

Such attacks used to be conducted by botnets of thousands of infected PCs but the 2016 ones were carried out by a botnet that included perhaps half-a-million infected “smart” gizmos. The Mirai malware that assembled the botnet scoured the web for IoT devices protected by little more than factory-default usernames and passwords and then enlisted them in attacks that hurled junk traffic at an online target until it could no longer function.

Mirai is still around, so you might not be the only entity benefiting from those fancy new networked lightbulbs. The cost of convenience will be higher than we think. So upgrade those passwords.
#NSO 
AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
US and Saudi Arabia Sign Landmark Agreements Across Multiple Sectors
Why Saudi Arabia Rolled Out a Purple Carpet for Donald Trump Instead of Red
Flip flop: UK Introduces New Immigration Policy to Reduce Net Migration
Poland Tightens Immigration Policy with New Plan to Suspend Asylum Law
Trump says it would be 'stupid' not to accept gift of Qatari plane
8-Year-Old Orders 70,000 Lollipops Using Mother’s Phone, Prompting $4,200 Amazon Bill and Viral Facebook Plea
Quantum Computing Threatens Bitcoin Security
American citizens account for 70% of worldwide pharmaceutical sales despite comprising only 4% of global population
Michael Jordan to Serve as Analyst for NBA Games
New Details Emerge on Syrian Attacker's Motives in German Festival Stabbing
US and China Agree to Reduce Tariffs by 115% in Bilateral Trade Deal
Zelenskyy Seeks Ceasefire as Putin Proposes Direct Talks in Turkiye
Arsenal Stages Comeback to Draw 2-2 Against Liverpool in Premier League Clash
Cardinal Robert Prevost Elected as Pope Leo XIV, Marking a Historic Papacy
India-Pakistan conflict may be first test for Chinese military tech
Bill Gates Announces Plan to Wind Down Philanthropic Foundation and Disperse Wealth
Historic Papal Conclave Set to Commence in Rome
“Trump Supporter” Aims to Bring a MAGA-Style Shift to Romania
Common Sense Returns to Britain's Legal System: UK Supreme Court Declares a Woman Is… a Woman
EU Hits TikTok with €530 Million Fine Over China Data Transfers
Beijing Says U.S. Is ‘Reaching Out’ for Tariff Talks Amid Soaring Trade Tensions
Warren Buffett to Step Down as Berkshire CEO After Nearly 60 Years
Trump Shares AI-Generated Image of Himself as… Pope, Prompting Outrage Reaction
Germany's Alternative für Deutschland (AfD) party has now been officially labeled “right-wing extremist” by the federal office for the so-called “protection of the constitution.”
Amazon Launches Satellite Internet Service Amidst Competition with SpaceX
Transformative Changes in Women's Wrestling: The Rise of WWE Superstars
The Rush to the White Gold: Global Investment Surge in Natural Hydrogen Exploration
This is a day in Spain without electricity and internet
Trump Administration Removes National Security Adviser Mike Waltz Amid Signal Chat Controversy
U.S. Economy Shrink in Trump’s First Quarter as Tariff Policy Raises Questions
U.S. and Ukraine Poised to Sign Strategic Critical Minerals Deal Amid Geopolitical Shifts
Spain Restores Power After Unprecedented Nationwide Blackout
Liverpool Clinches Record-Equalling 20th English League Title Under Arne Slot
How do you fix this culture?
Corrupted from Within: How Deep State Power and Unelected Judges Hijacked Democracy Against the Will of the People
President Trump and Ukrainian President Zelensky just held an impromptu discussion on the sidelines of Pope Francis' funeral in Rome.
World Leaders Gather in Rome for Pope Francis's Funeral
Pope Francis Laid to Rest in Rome as World Leaders Attend Funeral
Not Child’s Play: How Competitive Gaming Became a Global Economic Empire
California Surpasses Japan to Become the World’s Fourth-Largest Economy
Peter Navarro: The Man Behind Trump’s Tariff Madness
Former U.S. Congressman George Santos sentenced to eighty-seven months for wide-ranging fraud
Pope Francis: head of the Catholic church who pushed for social and economic justice
China do not pay these tariffs - you pay it. This is new 145% tax you pay to the US government.
Cultural Battles in the Vatican: The Candidates in the Battle for the Holy See and Pope Francis's Testament
Global Leaders Pay Tribute to Pope Francis Following His Death
Wild Chimpanzees Observed Bonding Over Alcoholic Fruit
Greek Christians Celebrate Easter in Thessaloníki
US Federal Reserve Chair Issues Warning on Tariff Impact
China, China, China!
×