news.volyx.in

About the security content of iOS 14.7.1 and iPadOS 14.7.1 (support.apple.com)

504 points by frankjr · 1886 days ago · 348 comments on HN

Article summary

Apple has released iOS 14.7.1 and iPadOS 14.7.1, which address a security issue that may have been actively exploited. The update fixes a memory corruption issue that could allow an application to execute arbitrary code with kernel privileges. The security content of the update is described on Apple's website. The update is available for various iPhone and iPad models.

Main themes

  • iOS and iPadOS updates
  • security issues and exploits
  • update distribution and caching
  • mobile network usage and overload
  • peer-to-peer update systems
  • content caching and sharing

What commenters say

  • Some commenters speculate that the update may be patching the Pegasus exploit, a collection of zero-day exploits.
  • There is a desire for Apple to enable instant over-the-air updates for 0-day fixes, but others argue that this could put a strain on mobile networks.
  • Some argue that Apple should allow updates to be downloaded over cellular networks, especially for those with unlimited data plans.
  • Others suggest that Apple could implement a peer-to-peer update system, similar to Windows, to reduce the load on their servers.
  • It is argued that a peer-to-peer system could be implemented in a way that would not overload mobile networks, such as by capping upload speeds or staggering updates.
  • Some commenters note that Apple already has a content caching system for macOS, which can cache updates for other devices on the local network.
  • There is disagreement over whether a peer-to-peer update system would be feasible and effective, with some arguing that it would not work due to the number of devices that would be downloading updates at the same time.
  • It is suggested that updates could be staggered over night, when network usage is lower, to reduce the load on mobile networks.