If the phone is physically okay and you depend on few core functionalities, then it is perfectly okay to keep using it for majority of (non-critical) tasks. Most bugs in the system & features of old iOS are limited to that old OS anyway - and most likely addressed. If some advanced utility are going to be involved e.g. work communications, some security protocols, I'll perhaps work with a device which still gets critical updates at the least.
I have a iPhone 8 which I use just to Facetime my MIL and receive her iMessages (I am on Pixels since 2019). I can't foresee a old patched- often iOS with a older no-frills Facetime version to have a major risks. For these tasks, I don't see it necessary to get a new iphone.
Perhaps I'm misunderstanding you, but this is not really correct. Most vulnerabilities are not regressions.
Attention is what makes security issues discoverable, and popularity is what makes exploits valuable serious enough to warrant attention. The more popular software is, the more attention it gets from the security community (both black and white hat). The more popular software is, the higher the impact of an exploit is. The more popular the software is, the more significant the response is.
That doesn't mean older software is secure, or that it can't be exploited. It just means nobody is really looking at it. Fairly often, security alerts come up for software that doesn't list older releases because they didn't bother to check their EoL releases not because they're unaffected.
Take the Print Spooler vulnerability on Windows, or the ShellShock exploit in bash, or the Apache Log4j 2.x vulnerability. These vulnerabilities are all so old that they essentially work on any version of the affected software, including those that are more than a decade old for which no fix was even planned. Like the ShellShock bug in bash was found to go back to bash 1.03 released in 1989.
As long as you have an earlier version of software that was later found to be vulnerable, you should assume that it is unless you've explicitly investigated the vulnerability and found otherwise.
You have an iPhone just to communicate with your MIL? you're surely the DIL or SIL of the year!
Was one of the reasons I switched.
For me, I consider any phone which holds very important access to data critical to my life (my email, texts, signed in apps which can spend my money, etc) to be unsafe to use once there's an update available for supported iPhones where the CVE it fixes is severe enough to allow remote access through normal use of the phone.
I just bought a new iPhone SE 3rd gen partly because of the above as I see it coming soon, but also because the battery in my iPhone 8 was getting very sad. Paying for a battery replacement for a potentially-no-longer-officially-supported phone was not going to be a wise investment for me.
My school-aged daughter still has her iPhone 8 and it's as up to date as can be with latest iOS 16 update. But she isn't signed into any email app and doesn't have any banking ability on her phone. Sure, if it gets compromised it could be a vector into my home network or be used to spy on her or impersonate her, all of those would be bad, but it's less bad than if my phone was compromised. These risks are low enough currently that we're not pressed to get her a new phone, yet, but probably will later this year if Apple doesn't issue any further updates to iOS 16.
Per another comment, a badly swollen battery is a physical safety issue and that point, the battery should either be replaced or the phone recycled.
In general, I also agree with the article that buying older refurb models isn't clearly good economy. There are advantages to have a not too old backup phone around. Indeed, I'm using my old iPhone X at the moment after my newer phone broke.
True. And a good reminder (nudge) to change my old devices to a separate iCloud account. Thanks.
You should get her a new phone. The risk for her isn’t banking, it’s getting spied on by some creep. IMO that could be a lot worse than getting your online banking hacked…
It shouldn't work. Based on historical precedent from PC's, all of these phones should be full with the most blatant, obvious, ad-injecting/ransomwaring/account-stealing malware that simply cannot be ignored. And yet, in practice, most users are using ancient Android devices just fine.
Obviously you can't do that if you expect to be specifically targeted (either by governments or criminals), but the baffling fact is that an average user can apparently get away with it in practice.
The problem with cybersecurity is with companies that horde a great number of people's personal information or who have a great amount of privileged access and then decide to care about security.
It's unfortunately a false sense of security because you don't get security updates for any proprietary blobs that are needed for your phone. This includes baseband and SoC updates. In security, the chain is only as strong as it's weakest link.
It’s certainly better than just running an old Android on an unsupported device, but there are still large parts of the system that can be subject to critical vulnerabilities that can never be patched.
This is false, iPhone XS is supported on iOS 17.
The author states that security updates on earlier iOS versions give a false sense of security.
Is that true? What is Apple's incentive to maintain old iOS versions, but only partially?
They will however backport fixes for particularly egregious security issues quite far. For example, iOS 12 got a fix for a web-based remote code execution attack in the beginning of this year, despite at that point being over 4 years old and 4 major releases older than the current iOS.
The author links to this article which provides more detail:
https://www.intego.com/mac-security-blog/apples-poor-patchin...
I wouldn't take everything that's written in a random tech article for granted. Fear inducing titles generate more clicks. As soon as you do something in this world, there's a risk. Even if you do nothing, there's a risk. Nobody will be able to be completely safe using any device under the sun. And if a tech company tries to make you believe otherwise, run.
Um...how about encouraging those who can to purchase a $Nice $New $Apple $Product, while not suffering too much bad PR over the security holes in old-but-still-perfectly-functional hardware?
And 'use' in what sense? Day to day main device with security credentials, financial/banking apps, etc? Connecting to corporate/VPN resources?
For professional and important personal use, I probably wouldn't use anything not 'officially supported'. When my banking apps won't install/update, that's probably the time. But I just re-used an old wiped iphone 5s a few weeks ago to browse some news sites. No issues, other than it felt less snappy than current devices. But it's not tied to any other part of my life at this point (apple id, bank, medical, etc).
While theoretically true, I can't find recent examples of this happening with zero-click exploits on iOS or Android. Without evidence of this being a common infection vector it's not, in my opinion, enough reason to encourage people to get rid of a working phone just because the security backports might be a bit lacking.
The more important security reason to keep up with the latest OS version is the sandboxing improvements that iOS and Android make with each update. If you assume the device will be compromised with a malicious app at some point, you want to have more protections against the malware stealing data from other apps. This is (for now) a bigger deal on Android, where malware routinely makes it into the official app store and malicious APKs are floating around all over the place. But it's worth considering on iOS too, especially if you run a lot of apps from companies that hate privacy or if iOS later allows some form of sideloading.
Mostly iOS. And how would you even know? There have been some large cryptocurrency thefts recently.
Before or after a public exploit is posted alongside CVE+patch?
Mobile Verification Toolkit, https://docs.mvt.re/en/latest/ios/methodology/
Forensic howto, https://www.amnesty.org/en/latest/research/2021/07/forensic-...
IOCs: https://github.com/citizenlab/malware-indicators
IOC tools and sources: https://github.com/sroberts/awesome-iocs
Device Firmware Upgrade (DFU), https://www.theiphonewiki.com/wiki/DFU_Mode
For small business, Apple offers MDM for $3/device/month, https://www.apple.com/newsroom/2022/03/apple-business-essent... . It's unfortunate that iOS MDM solutions are not allowed to scan device filesystems for public IOCs.
As mitigation for old and new devices alike, frequently rebooting an iOS device will remove a large class of non-persistent malware. If battery life or performance are suddenly reduced, and can be restored to normal by an iOS reboot, a potential cause is non-persistent malware. Use the "Force Restart" key sequence, https://support.apple.com/guide/iphone/force-restart-iphone-...
Is there an iOS VPN solution which can (opt-in) monitor network or DNS traffic for threats or connections to known C&C servers?
My folks both have an SE (a 2 and a 3), and the photos are much better than you'd expect for a $400 phone. I've used them and they're plenty fast, it's really only the tiny screen that would give me pause.
If ~$400 can get you 5-6 years out of a phone that's a steal.
After all, the sole purpose of every piece of hardware is to apply patches to it.
What are you answering "Yes." to here?
When the Battery inside it becomes a spicy pillow shaped IED.
Apple charges $429 for it at minimum, and that to me is a ripoff considering that you can go all the way back to the iPhone 13 and get the same SoC with a much better overall phone rather than having a decade-old design.
If you just want an iPhone that is supported by Apple, the best value option is probably to go with a used iPhone 12 (under $300) or a 13, for about the same price as the SE.
Even if your 12/13 has an older battery, the SE has poor battery life to begin with.
iOS 17 is supported on phones going back to the XS, which is 2 years older than the 12. So if you buy a 12 now and sell it in 2 years, you’d expect to lose a bit less than $100 on those transactions. Basically you’d spend $50 a year to have a supported phone assuming that Apple never lengthens their support window further (which I think is unlikely now that they are starting a trend of the non-Pro iPhone using the previous lithography with two model years in a row using the same processor).
But also, a whole bunch of cheap MVNO cellular carriers will just give you an old but supported iPhone for free (e.g., Metro by T-Mobile gives you an iPhone 11 for free at present). Presumably you could just shop phone carriers every couple of years and find one that’s willing to kick a less-old iPhone your way for nothing.
On the high end, you can always find a US postpaid phone company willing to essentially subsidize phone depreciation with their trade-in deals. If you are in a large family and/or have high usage requirements like tethering, postpaid with bill credits is the way to go. You basically get a free iPhone Pro device every 3 years.
If anyone has a counterexample (software virus, for iPhone, reliant on vulnerabilities that were patched in the latest iOS at the time the exploit was in use, ideally not by a nation state) I'd definitely be interested to hear about it.
As soon as the new model is released ;)
Yes, yes, I know that the article discusses how older OS versions don't necessarily get all of the security fixes as the current ones but, still, that's impressive.
Let me fix the question:
"When does a phone become unsafe to use?"
The answer is "immediately".