back
124 comments
For the author, he misses an important point that except sometimes (and rare case) for a few core libs and functionality, majority zero-days and zero-clicks are based on new features and their integration into current OS iteration. Software revisions begets new security events. Patching software bugs/loophoples is not like treating cancer - something that has existed always and keeps popping up. It is new software added to old stack and made to gell with it. That 'gluing' process churns up new security issues.

If the phone is physically okay and you depend on few core functionalities, then it is perfectly okay to keep using it for majority of (non-critical) tasks. Most bugs in the system & features of old iOS are limited to that old OS anyway - and most likely addressed. If some advanced utility are going to be involved e.g. work communications, some security protocols, I'll perhaps work with a device which still gets critical updates at the least.

I have a iPhone 8 which I use just to Facetime my MIL and receive her iMessages (I am on Pixels since 2019). I can't foresee a old patched- often iOS with a older no-frills Facetime version to have a major risks. For these tasks, I don't see it necessary to get a new iphone.

> It is new software added to old stack and made to gell with it. That 'gluing' process churns up new security issues.

Perhaps I'm misunderstanding you, but this is not really correct. Most vulnerabilities are not regressions.

Attention is what makes security issues discoverable, and popularity is what makes exploits valuable serious enough to warrant attention. The more popular software is, the more attention it gets from the security community (both black and white hat). The more popular software is, the higher the impact of an exploit is. The more popular the software is, the more significant the response is.

That doesn't mean older software is secure, or that it can't be exploited. It just means nobody is really looking at it. Fairly often, security alerts come up for software that doesn't list older releases because they didn't bother to check their EoL releases not because they're unaffected.

Take the Print Spooler vulnerability on Windows, or the ShellShock exploit in bash, or the Apache Log4j 2.x vulnerability. These vulnerabilities are all so old that they essentially work on any version of the affected software, including those that are more than a decade old for which no fix was even planned. Like the ShellShock bug in bash was found to go back to bash 1.03 released in 1989.

As long as you have an earlier version of software that was later found to be vulnerable, you should assume that it is unless you've explicitly investigated the vulnerability and found otherwise.

Except that iMessage is a perpetual source of security concerns. Once that becomes unsupported, you’ll likely have exploitable code, where the exploit is publicly and widely known (but patched on newer versions).
> I have a iPhone 8 which I use just to Facetime my MIL and receive her iMessages

You have an iPhone just to communicate with your MIL? you're surely the DIL or SIL of the year!

I’m not sure if your MIL is technical enough to do this, but you can receive FaceTime calls on the web now: https://support.apple.com/en-us/HT212619
I’m amazed how well my wife’s old 8 plus has held up.

Was one of the reasons I switched.

It depends.

For me, I consider any phone which holds very important access to data critical to my life (my email, texts, signed in apps which can spend my money, etc) to be unsafe to use once there's an update available for supported iPhones where the CVE it fixes is severe enough to allow remote access through normal use of the phone.

I just bought a new iPhone SE 3rd gen partly because of the above as I see it coming soon, but also because the battery in my iPhone 8 was getting very sad. Paying for a battery replacement for a potentially-no-longer-officially-supported phone was not going to be a wise investment for me.

My school-aged daughter still has her iPhone 8 and it's as up to date as can be with latest iOS 16 update. But she isn't signed into any email app and doesn't have any banking ability on her phone. Sure, if it gets compromised it could be a vector into my home network or be used to spy on her or impersonate her, all of those would be bad, but it's less bad than if my phone was compromised. These risks are low enough currently that we're not pressed to get her a new phone, yet, but probably will later this year if Apple doesn't issue any further updates to iOS 16.

That seems a pretty good summary. I wouldn't use a phone as my daily driver with banking apps etc. if it were out of support, but as a spare phone or something to be used primarily for specific purposes like a GPS? Sure.

Per another comment, a badly swollen battery is a physical safety issue and that point, the battery should either be replaced or the phone recycled.

In general, I also agree with the article that buying older refurb models isn't clearly good economy. There are advantages to have a not too old backup phone around. Indeed, I'm using my old iPhone X at the moment after my newer phone broke.

Are you also comfortable with camera and mic being enabled and streaming to remote servers? Old iPhones don't even have the theoretical protection of a "hardware" LED to show when those are enabled.
> I consider any [old] phone which holds very important access to data critical to my life ... to be unsafe

True. And a good reminder (nudge) to change my old devices to a separate iCloud account. Thanks.

A lot of remote vulnerabilities are in iMessage which she’d use heavily I imagine. Other messengers aren’t necessarily safer.

You should get her a new phone. The risk for her isn’t banking, it’s getting spied on by some creep. IMO that could be a lot worse than getting your online banking hacked…

Maybe you've already done this, put her device on a guest network to isolate it from others in your home.
Not sure if it's worse on iPhone (because successfully targeting one specific model means a huge user base to hit), but I've been consistently surprised with how old Android devices survive usage long after updates have expired without large-scale compromise.

It shouldn't work. Based on historical precedent from PC's, all of these phones should be full with the most blatant, obvious, ad-injecting/ransomwaring/account-stealing malware that simply cannot be ignored. And yet, in practice, most users are using ancient Android devices just fine.

Obviously you can't do that if you expect to be specifically targeted (either by governments or criminals), but the baffling fact is that an average user can apparently get away with it in practice.

Cybersecurity is akin to home security. Most people will get a alarm at most, and otherwise have a house which is totally unprepared to defend them against a special forces hit squad. Few people here have seriously considered how they will stop a gang of a dozen bloodthirsty criminals from kidnapping them and forcing them to reveal their credentials even if they're thought about post-quantum cryptography. Yet this all works out because they can easily hide in the crowd, there are plenty of other societal institutions which generally deter home invaders.

The problem with cybersecurity is with companies that horde a great number of people's personal information or who have a great amount of privileged access and then decide to care about security.

There was an article here just the other day talking about how a mass of older android devices spanning many different sectors (phones, TVs, chromebooks, etc) had been found to have malware that was installed between the refurb/shipping and delivery to retailers. These older devices also wound up in schools. So it absolutely is happening.
Security is the reason I get mad about bank apps detecting custom ROMs on Android. Support is usually shorter, but LineageOS can keep OS and software securities rolling past the manufacturers date. There aren’t custom ROMs in the Apple sphere tho since it’s all proprietary.
> but LineageOS can keep OS and software securities rolling past the manufacturers date.

It's unfortunately a false sense of security because you don't get security updates for any proprietary blobs that are needed for your phone. This includes baseband and SoC updates. In security, the chain is only as strong as it's weakest link.

LineageOS probably isn’t a great example. It uses black box firmware blobs that don’t receive updates and essentially just makes the latest Android work with those.

It’s certainly better than just running an old Android on an unsupported device, but there are still large parts of the system that can be subject to critical vulnerabilities that can never be patched.

> And with iOS 17 to be released in just a few months, Apple will be drooping the iPhone 8, iPhone X, and iPhone XS from the compatibility list.

This is false, iPhone XS is supported on iOS 17.

Yeah. I came here to post this. It’s funny that the article lists the XR as compatible when the XS and XR were released at the same time (A12 bionic SoC).
I typically belong to the bucket of users who have a working iPhone that does not support the latest major iOS release (iPhone 7), but still get Apple's security updates.

The author states that security updates on earlier iOS versions give a false sense of security.

Is that true? What is Apple's incentive to maintain old iOS versions, but only partially?

Apple does not backport all security fixes and they never have, and what they do backport they do on a delayed schedule. It's not clear whether they have an actual policy that determines what gets backported or whether it's just a judgment call, but the consequence is that indeed on any Apple device the most secure OS is the current OS.

They will however backport fixes for particularly egregious security issues quite far. For example, iOS 12 got a fix for a web-based remote code execution attack in the beginning of this year, despite at that point being over 4 years old and 4 major releases older than the current iOS.

> The author states that security updates on earlier iOS versions give a false sense of security.

The author links to this article which provides more detail:

https://www.intego.com/mac-security-blog/apples-poor-patchin...

I wouldn't take everything that's written in a random tech article for granted. Fear inducing titles generate more clicks. As soon as you do something in this world, there's a risk. Even if you do nothing, there's a risk. Nobody will be able to be completely safe using any device under the sun. And if a tech company tries to make you believe otherwise, run.

> What is Apple's incentive to maintain old iOS versions, but only partially?

Um...how about encouraging those who can to purchase a $Nice $New $Apple $Product, while not suffering too much bad PR over the security holes in old-but-still-perfectly-functional hardware?

Physically unsafe? Security unsafe?

And 'use' in what sense? Day to day main device with security credentials, financial/banking apps, etc? Connecting to corporate/VPN resources?

For professional and important personal use, I probably wouldn't use anything not 'officially supported'. When my banking apps won't install/update, that's probably the time. But I just re-used an old wiped iphone 5s a few weeks ago to browse some news sites. No issues, other than it felt less snappy than current devices. But it's not tied to any other part of my life at this point (apple id, bank, medical, etc).

>today’s nation-state attacker’s vulnerability could become part of tomorrow’s everyday cybercriminal’s arsenal

While theoretically true, I can't find recent examples of this happening with zero-click exploits on iOS or Android. Without evidence of this being a common infection vector it's not, in my opinion, enough reason to encourage people to get rid of a working phone just because the security backports might be a bit lacking.

The more important security reason to keep up with the latest OS version is the sandboxing improvements that iOS and Android make with each update. If you assume the device will be compromised with a malicious app at some point, you want to have more protections against the malware stealing data from other apps. This is (for now) a bigger deal on Android, where malware routinely makes it into the official app store and malicious APKs are floating around all over the place. But it's worth considering on iOS too, especially if you run a lot of apps from companies that hate privacy or if iOS later allows some form of sideloading.

> While theoretically true, I can't find recent examples of this happening with zero-click exploits on iOS or Android.

Mostly iOS. And how would you even know? There have been some large cryptocurrency thefts recently.

> I can't find recent examples of this happening

Before or after a public exploit is posted alongside CVE+patch?

Advanced cybercrimals occasionally do this on Android at least.
Any iOS device backup, including older ones, can be scanned for IOCs (Indicators of Compromise) for patched CVEs. If you own a macOS device, your iOS device can be hardened via the free Apple Configurator app for local MDM policy, e.g. disable AirDrop, whitelist WiFi without auto-join, disallow USB devices when locked. If the device is compromised, it can be restored after backup, erase, DFU and iOS reinstall.

Mobile Verification Toolkit, https://docs.mvt.re/en/latest/ios/methodology/

Forensic howto, https://www.amnesty.org/en/latest/research/2021/07/forensic-...

IOCs: https://github.com/citizenlab/malware-indicators

IOC tools and sources: https://github.com/sroberts/awesome-iocs

Device Firmware Upgrade (DFU), https://www.theiphonewiki.com/wiki/DFU_Mode

For small business, Apple offers MDM for $3/device/month, https://www.apple.com/newsroom/2022/03/apple-business-essent... . It's unfortunate that iOS MDM solutions are not allowed to scan device filesystems for public IOCs.

As mitigation for old and new devices alike, frequently rebooting an iOS device will remove a large class of non-persistent malware. If battery life or performance are suddenly reduced, and can be restored to normal by an iOS reboot, a potential cause is non-persistent malware. Use the "Force Restart" key sequence, https://support.apple.com/guide/iphone/force-restart-iphone-...

Is there an iOS VPN solution which can (opt-in) monitor network or DNS traffic for threats or connections to known C&C servers?

A savvy attacker is going to make sure they don’t leave traces on the device that they exploited it.
Don't know man, I like my iPhone XS and see no reason to "upgrade"; I'd pay more for a new iPhone than I did for my first car.
The only reason I buy nicer phones is for the camera. My kids are getting older and I'm not taking 100 photos a day anymore so when my iPhone 12 Pro is retired I'll likely get whatever iPhone SE is current and call it a day. Hopefully by then they'll have FaceID and a full coverage screen like every other iPhone. But hopefully no dynamic island. I can't stand that gimmick.

My folks both have an SE (a 2 and a 3), and the photos are much better than you'd expect for a $400 phone. I've used them and they're plenty fast, it's really only the tiny screen that would give me pause.

If ~$400 can get you 5-6 years out of a phone that's a steal.

Yes. Unmaintained proprietary OS software is a manifestation of the paperclip maximizer. Maybe we'll soon be able to pave the whole planet with "unsupported" hardware (which actually works perfectly fine).
Cargo-culting CVE bros tell me I need to throw it away if it hasn't been updated in a week.

After all, the sole purpose of every piece of hardware is to apply patches to it.

The question was: When does an old iPhone become unsafe to use?

What are you answering "Yes." to here?

> When does an old iPhone become unsafe to use?

When the Battery inside it becomes a spicy pillow shaped IED.

I don’t agree with the article’s suggestion to get a current iPhone SE if you’re on a budget.

Apple charges $429 for it at minimum, and that to me is a ripoff considering that you can go all the way back to the iPhone 13 and get the same SoC with a much better overall phone rather than having a decade-old design.

If you just want an iPhone that is supported by Apple, the best value option is probably to go with a used iPhone 12 (under $300) or a 13, for about the same price as the SE.

Even if your 12/13 has an older battery, the SE has poor battery life to begin with.

iOS 17 is supported on phones going back to the XS, which is 2 years older than the 12. So if you buy a 12 now and sell it in 2 years, you’d expect to lose a bit less than $100 on those transactions. Basically you’d spend $50 a year to have a supported phone assuming that Apple never lengthens their support window further (which I think is unlikely now that they are starting a trend of the non-Pro iPhone using the previous lithography with two model years in a row using the same processor).

But also, a whole bunch of cheap MVNO cellular carriers will just give you an old but supported iPhone for free (e.g., Metro by T-Mobile gives you an iPhone 11 for free at present). Presumably you could just shop phone carriers every couple of years and find one that’s willing to kick a less-old iPhone your way for nothing.

On the high end, you can always find a US postpaid phone company willing to essentially subsidize phone depreciation with their trade-in deals. If you are in a large family and/or have high usage requirements like tethering, postpaid with bill credits is the way to go. You basically get a free iPhone Pro device every 3 years.

The article is suspiciously lacking in actual concrete examples. I'm not an expert here, but I can't actually think of a single historical example of a hack that was targeted at "normal people" and also relied on unpatched vulnerabilities in old iPhones. Those sort of attacks happen all the time for desktops/routers/etc resulting in worms and botnets, but my suspicion is that the number of old iPhones mostly makes them not worth developing and deploying exploits for, much like how Linux has less malware than Windows.

If anyone has a counterexample (software virus, for iPhone, reliant on vulnerabilities that were patched in the latest iOS at the time the exploit was in use, ideally not by a nation state) I'd definitely be interested to hear about it.

Ironic that this site shows only a blank page asking me to "Enable JavaScript and cookies to continue", when the former is how 99% of browser exploits can work (and even those rare few which don't fundamentally require it will normally be wrapped in JS just for obfuscation.)
Until I or my loved ones start getting targeted by exploits I've got better things to do with my money than buy a new phone every couple years, and will continue to enjoy my iphone 6.
Core functionality should work forever as long as it powers up.
When the Mossad targets you
> When does an old iPhone become unsafe to use?

As soon as the new model is released ;)

Apple provides security updates for not only the latest IOS, several past versions (and the phones which cant upgrade from them) still get updates with security fixes
Thought this was going to be about old unreplacable batteries eventually catching fire.
The 2013 iPhone 5S received an OS update, 12.5.7, in January 2023!

Yes, yes, I know that the article discusses how older OS versions don't necessarily get all of the security fixes as the current ones but, still, that's impressive.

TLDR when Apple stops releasing updates to fix security issues
> When does an old iPhone become unsafe to use?

Let me fix the question:

"When does a phone become unsafe to use?"

The answer is "immediately".