back
2 comments
Number of CVEs in general is a fairly poor way to evaluate the security of a platform.
Agreed. In other comments here however, there are folks arguing that this shows iOS both is/isn't secure and that Project Zero has a hidden goal of making Apple look bad. I think the poster above is trying to respond/provide context to that.
Apple provides security updates longer than Android though.

One could argue being able to own a phone for 5 years and receive security updates for a higher up front cost is preferable to buying a new phone every two years.

To be blunt, that policy + the fact Apple has no business units actively incentivized to invade my privacy (no targeted marketing dept) makes me choose iOS, even if it's "less free".

My phone is home to my most intimate conversations, I need to know it's secure for the long haul.

I agree with you, and that's why I have the phone that I do. There are clear tradeoffs between the two ecosystems. My comment was providing context to the one above it.
Hum...

In this sentence: "For people who think that there is far more CVE on iOS than Android", when did I speaked about evaluating a security of a platform based on CVE? When?

I was only discussing about the fact that iOS does not have more CVE than Android, based on other discussions on this thread...

I am sorry if this message is mean but... did you read my comment at least?

Just like nobody explicitly said that iOS has more CVEs?
Read the comment just before please...
No, I did, although I should apologize for the slightly snarky response. I think your original comment was a valuable one, as it did bring up an interesting point that Android sees more CVEs than iOS does. However, I think the point is even more fundamental: counting the number of bugs on a list is not a great way of showing a platform is secure/insecure, although many people may believe so, just like they may look at this list and think "gee, iOS is so full of bugs it must be worse than Android!" Really, the point of this blog post was just a compilation of methods that achieve arbitrary code execution in the kernel based on how they did so and which iOS versions they apply to, instead of being some sort of comparison between operating systems.
Why did you have to bring Android into this comment thread though?
The parent comment didn't bring it up themselves. I believe it was in response to the Android comments all over the rest of the thread.