Hacker News new | ask | show | jobs
by reducesuffering 3191 days ago
Project Zero discloses the vulnerabilities to the affected 90 days before releasing to the public. It's probable that Apple was notified and patched this because of Project Zero. Once it's been patched or 90 days are up, then Project Zero discloses to the public.
1 comments

They mentioned it’s fixed in iOS 11 so all Apple has to do is tell people to update their devices (which they always push anyway).

It’s not like there is no fix for it.

A lot of corporate customers have still not approved iOS for upgrades, so it's actually a big issue
Sounds like the corporation's problem, willingly ignoring security updates.
> Sounds like the corporation's problem, willingly ignoring security updates.

A properly vetted update requires both compatibility testing and security testing. It would be irresponsible to push an OS update without verifying that it will not damage productivity or bring down defenses.

Businesses that provide or allow iOS devices need to be ready when new OSes are released to the public, which can easily be done since Apple offers regularly-updated betas for months in advance. This is particularly important because even managed devices cannot be prevented from upgrading to new OSes unless all traffic is routed through controlled networks that block access to Apple update servers.
They had an opportunity to test via the beta period.
A saw a great T-shirt the other day: Hackers don't care about your corporate policy.
iOS 11 Installed on 25% of Devices One Week After Launch--https://www.macrumors.com/2017/09/26/ios-11-one-week-25-perc...