iPhone's with not latest iOS; how secure are these? And better to get a new one?


Recommended Posts

Just a question... my parents both have an iPhone 8, which isn't fully supported with the upcoming latest iOS 17.

How 'bad' is it if they stay on the latest iOS 16? Are these security risks?

Or it it better to have the newest iOS at any given moment and to be fullt protected to ALL security patches [and not just like a 70% on the 16.x.x patches]?
And, in that case, they need to have a new iPhone with do support iOS17 and later.... (e.g. iPhone SE 2022, iPhone 13 or later)

I'm sure Apple won't bother...

Apple actually does bother. They release security updates for iPhone/iPad models that aren’t supported by the latest iOS or iPadOS. My original iPad Air still receive security updates and that’s a decade old. If their iPhone 8 still works fine for their purpose, there’s no concern with them using it. 

On 06/08/2023 at 19:23, tsupersonic said:

Apple actually does bother. They release security updates for iPhone/iPad models that aren’t supported by the latest iOS or iPadOS. My original iPad Air still receive security updates and that’s a decade old. If their iPhone 8 still works fine for their purpose, there’s no concern with them using it. 

I read somewhere that like 80% of the patches of the most current iOS is ported back to a lower, unsupported, version, e.g. latest iOS 16.x version and the most current iOS15.x (on older devices).

On 07/08/2023 at 02:31, kiddingguy said:

I read somewhere that like 80% of the patches of the most current iOS is ported back to a lower, unsupported, version, e.g. latest iOS 16.x version and the most current iOS15.x (on older devices).

The more recent vulnerabilities are going to be the most actively exploited so 80% or whatever is not any real protection. I wouldn't ever use a device that wasn't still getting security updates let alone allow my parents (assuming yours like mind are not tech savvy at all so worse) to use an insecure device. There is no reason to and that is not smart so anyone that tells you otherwise has no idea what they are talking about.  An used iphone that is two or three models back is not even that expensive so please upgrade them.

I am talking about security updates not OS upgrades but until like a couple of months ago security updates were only packaged with OS updates (unlike on Android) with iOS. Apple does issue just security updates now but I believe just for the very critical vulnerabilities and doubt for supported phones.

Edited by Good Bot, Bad Bot
On 07/08/2023 at 17:40, Good Bot, Bad Bot said:

The more recent vulnerabilities are going to be the most actively exploited so 80% or whatever is not any real protection. I wouldn't ever use a device that wasn't still getting security updates let alone allow my parents (assuming yours like mind are not tech savvy at all so worse) to use an insecure device. There is no reason to and that is not smart so anyone that tells you otherwise has no idea what they are talking about.  An used iphone that is two or three models back is not even that expensive so please upgrade them.

I am talking about security updates not OS upgrades but until like a couple of months ago security updates were only packaged with OS updates (unlike on Android) with iOS. Apple does issue just security updates now but I believe just for the very critical vulnerabilities and doubt for supported phones.

So it's better also to have  the latest hardware/iPhone's which fully support also the latest iOS... gotcha! Let's get some new iPhone's 🥳

On 06/08/2023 at 09:39, kiddingguy said:

Just a question... my parents both have an iPhone 8, which isn't fully supported with the upcoming latest iOS 17.

How 'bad' is it if they stay on the latest iOS 16? Are these security risks?

Or it it better to have the newest iOS at any given moment and to be fullt protected to ALL security patches [and not just like a 70% on the 16.x.x patches]?
And, in that case, they need to have a new iPhone with do support iOS17 and later.... (e.g. iPhone SE 2022, iPhone 13 or later)

I'm sure Apple won't bother...

 

I'm sure Apple won't bother...

What is this suppose to mean in english? After everything you wrote, this statement doesnt make sense. Do you know or did you bother googling when the iPhone 8 came out? The iPhone 8 came out in September of 2017. They supported your parents phones for ~7 years. Apple has committed to 5-7 years of software support and your parents phones hardware has also lasted as long.

Show me a company that commits to 5-7 years of software updates before you expect "more" from Apple. Google just RECENTLY (last ~2 years) committed to 4 years for PIXELS, before that it was 2 years. Android in general doesnt give you any gurrantees and the top manufacturers (Samsung, etc) barely make it 2 years of software updates let alone security updates. 


-----------

Now to answer your question, unless a Zero day comes out that can be easily exploitable or another such issue, your parents will be fine as long as they use their phone like normal and dont click on anything sketchy (this can be said about any OS/software).

On 08/08/2023 at 01:23, Sikh said:

 

I'm sure Apple won't bother...

What is this suppose to mean in english? After everything you wrote, this statement doesnt make sense. Do you know or did you bother googling when the iPhone 8 came out? The iPhone 8 came out in September of 2017. They supported your parents phones for ~7 years. Apple has committed to 5-7 years of software support and your parents phones hardware has also lasted as long.

Show me a company that commits to 5-7 years of software updates before you expect "more" from Apple. Google just RECENTLY (last ~2 years) committed to 4 years for PIXELS, before that it was 2 years. Android in general doesnt give you any gurrantees and the top manufacturers (Samsung, etc) barely make it 2 years of software updates let alone security updates. 


-----------

Now to answer your question, unless a Zero day comes out that can be easily exploitable or another such issue, your parents will be fine as long as they use their phone like normal and dont click on anything sketchy (this can be said about any OS/software).

It's meant as a joke... like, I'm sure Apple will sure like this extra turnover 😉

Sure I get it that 5-7 years full of support is more than okay! That's not the question here.

The question is: is it still safe to use a phone which doesn't run the latest iOS, and might -therefor- be more prone to vulnerabilities.

Hello,

I would normally say that iOS is more secure than Android OS in many ways, but that also depends on which device, how it is managed, and what the device's user needs to protect.

What is the risk profile for your parents?  Are they the type to click on everything, engage with fraudsters and scammers, etc., or do they ignore all messages except those from friends and family, and don't use anything but a handful of apps?

Regards,

Aryeh Goretsky
 

Apple do still patch unsupported iOS versions but only individual extreme severity patches. Maybe one patch a year or something.

Given they support new devices for at least 5 years or more, it's probably worth getting a new one and being protected seeing as security patches won't be a concern for a long time then.

On 07/08/2023 at 19:23, Sikh said:

Show me a company that commits to 5-7 years of software updates before you expect "more" from Apple. Google just RECENTLY (last ~2 years) committed to 4 years for PIXELS, before that it was 2 years. Android in general doesnt give you any gurrantees and the top manufacturers (Samsung, etc) barely make it 2 years of software updates let alone security updates. 

-----------

Now to answer your question, unless a Zero day comes out that can be easily exploitable or another such issue, your parents will be fine as long as they use their phone like normal and dont click on anything sketchy (this can be said about any OS/software).

Your remark on Samsung software support was not accurate. They offer in some ways better support than Google with four OS updates and five years of security updates on flagship devices and some mid range devices. You should have called out the Chinese OEMs.

Older people that are not tech savvy are the kind of users that do "click" anything. How would anyone know what they are doing? It's time to replace the unsupported ihones even is get models 2 or 3 years old which are not very expensive.

 

On 08/08/2023 at 04:32, goretsky said:

Hello,

I would normally say that iOS is more secure than Android OS in many ways, but that also depends on which device, how it is managed, and what the device's user needs to protect.

What is the risk profile for your parents?  Are they the type to click on everything, engage with fraudsters and scammers, etc., or do they ignore all messages except those from friends and family, and don't use anything but a handful of apps?

Regards,

Aryeh Goretsky
 

How can one really know the risk profile of someone else? Sure maybe they don't make wireless payments or browse the web on their phones but it's common for people to say one thing and do another. Maybe his dad likes to go to porn sites when on the toilet?

Security updates are a basic level one first step to secure a device. Everyone should be using phones that are still supported and still get regular security updates. Why take that chance especially with one's parents?

It's a double-edged sword.  Yes, both the OS and the apps they are using should be patched.  If the parents are using the phones to make calls and text, then they should be fine.  However, if they are using them to check their bank account and social media, then they should upgrade their phones to make sure the OS stays patched.  Eventually, companies will require a newer OS version to continue to use their app.  Plus, you can trade in your older device to Apple for some money off a newer device as long as there's not too much damage.

On 08/08/2023 at 06:47, Good Bot, Bad Bot said:

How can one really know the risk profile of someone else? Sure maybe they don't make wireless payments or browse the web on their phones but it's common for people to say one thing and do another. Maybe his dad likes to go to porn sites when on the toilet?

Security updates are a basic level one first step to secure a device. Everyone should be using phones that are still supported and still get regular security updates. Why take that chance especially with one's parents?

 

Hello,

I would imagine it would involve asking about how the devices are used, look at sites visits, apps installed, and so forth.

Regards,

Aryeh Goretsky
 

On 09/08/2023 at 12:14, goretsky said:

 

Hello,

I would imagine it would involve asking about how the devices are used, look at sites visits, apps installed, and so forth.

Regards,

Aryeh Goretsky
 

Did you not understand my point? So his dad going to tell his son he watches porn while on the toilet? LOL Security that is only takes in account the expected is poor security.

On 09/08/2023 at 11:27, Good Bot, Bad Bot said:

Did you not understand my point? So his dad going to tell his son he watches porn while on the toilet? LOL Security that is only takes in account the expected is poor security.


Hello,

That is an interesting assumption you came up with.  In any case, asking the parent if you can look over the device and checking the browsing history while away from them is a possibility.

Regards,

Aryeh Goretsky
 

On 09/08/2023 at 17:50, goretsky said:


Hello,

That is an interesting assumption you came up with.  In any case, asking the parent if you can look over the device and checking the browsing history while away from them is a possibility.

Regards,

Aryeh Goretsky
 

What? That is not going to go over well with anyone. What are you going to suggest next? Beat the info out of them? How about we just make sure they have a properly configured phone that still gets security updates.

On 09/08/2023 at 20:25, Good Bot, Bad Bot said:

What? That is not going to go over well with anyone. What are you going to suggest next? Beat the info out of them? How about we just make sure they have a properly configured phone that still gets security updates.

Hello,

It is possible that would help secure the device, but elder abuse is a specific crime in many countries.

Regards,

Aryeh Goretsky

  • Haha 2

Or you know if money is an issue, then there are certain ways to go about things. Easiest thing to do is to buy them new phones get them the SEs literally the same size/form factor and you can backup and transfer everything it would be like they never got rid of their phones to begin with. It doesn't seem like there's an issue purchasing new devices. It's the safe approach not only that they'll eventually want new phones as their battery life is only going to get worse. Just my 2 cents 🤷‍♀️

Thx for all the info. Some made me laugh!

I'll advise them for a new SE (or maybe iPhone 13 mini to have the same form factor, but with Face ID and all). I'll just wait until Apple announces the iPhone 15 next month (probably) and maybe these SE's and other earlier models might get a price drop [at least it saves them some money and the phones still working - and supported].

  • Like 2

Preferably I'd opt for the iPhone 13 mini.

However, will the iPhone 13 mini still be available on Apple's site (and for a lower price) after the introduction of the iPhone 15?

Sure, on sites like amazon and alike it  will be available I guess...

On 13/08/2023 at 10:11, kiddingguy said:

Preferably I'd opt for the iPhone 13 mini.

However, will the iPhone 13 mini still be available on Apple's site (and for a lower price) after the introduction of the iPhone 15?

Sure, on sites like amazon and alike it  will be available I guess...

If they replace the mini, it wont be available. If they dont replace the mini, theres a chance it'll be available. As for a price drop, the only please you are going to see that is third parties (amazon, best buy, etc).

If you are planning on buying them the iPhone Mini, I would recommend looking at best buy a day or two before the announcement or the day of the announcement. They will be the first ones to discount any old phones / stock and they will do it early or the day of.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Onkyo Dolby Atmos AV receivers are really solid deals by Sayan Sen Recently we covered great deals on several soundbar models from the likes of Sony, JBL, Samsung and others for really good prices (the lowest in several months). Aside from that we also reported on the Edifier S3000MKII, a hi-fi two-way bookshelf monitor that's available for only $800. Today we bring a list of AV receivers from Onkyo that are available at great prices including the Onkyo NR7100, RZ30, and 8470 (purchase links under the specs table down below). The Onkyo TX-NR7100 and Onkyo TX-RZ30 are both 9.2-channel AV receivers designed for immersive home theater setups but they occupy slightly different tiers within Onkyo’s lineup with the RZ30 positioned as the more advanced model. The TX-NR7100 is a THX Certified 9.2-channel receiver offering up to 100 W per channel (8 ohms, 2 channels driven). It supports Dolby Atmos, DTS:X, and IMAX Enhanced formats, with flexible configurations such as 5.1.4 or 7.1.2 speaker layouts. A key highlight is its built-in Dirac Live Room Correction which should help optimize sound based on your room and its acoustics. In comparison, both models share several core capabilities though the RZ30 is geared toward enthusiasts seeking more precise calibration and system flexibility, while the NR7100 is positioned as a slightly more accessible, value-focused option with strong all-round performance. The technical specs of the RZ30 and NR7100 9.2 AVRs are given in the table below: Specification Onkyo TX-RZ30 Onkyo TX-NR7100 Power Output (FTC, 2ch driven) ~100 W/ch (8Ω, 20Hz–20kHz, 0.08% THD) 100 W/ch (8Ω, 20Hz–20kHz, 0.08% THD) Dynamic / Peak Power 9 × 170 W (6Ω, 1kHz, 1% THD, 1ch driven) 220 W/ch (6Ω, 1kHz, 10% THD, 1ch driven) Frequency Response 5 Hz – 100 kHz (+1/-3 dB) 10 Hz – 100 kHz (+1/-3 dB) THD 0.08% 0.08% Room Correction Dirac Live (full bandwidth) Dirac Live (with AccuReflex support) Immersive Audio Dolby Atmos, DTS:X, IMAX Enhanced Dolby Atmos, DTS:X, IMAX Enhanced Speaker Layout Support Up to 7.2.2 / 5.2.4 / 9.2 processing Up to 7.2.4 / 5.2.4 / 9.2 processing HDMI Inputs / Outputs 6 inputs / 2 outputs (eARC) 6 inputs / 2 outputs (Main + Sub/Zone 2) HDMI 2.1 Support 8K/60, 4K/120, VRR, ALLM, QFT, DSC, eARC 8K/60, 4K/120, VRR, ALLM, QFT, DSC, eARC Video Formats HDR10+, Dolby Vision, HDCP 2.3 HDR10+, Dolby Vision, HDCP 2.3 Streaming / Network Wi-Fi, AirPlay 2, Chromecast, Bluetooth, DTS Play-Fi Wi-Fi, AirPlay 2, Chromecast, Bluetooth, DTS Play-Fi Get them at the links below: Onkyo TX-RZ30 9.2-Channel AV Receiver: $797.00 (Sold and shipped by Electronic Expo) Onkyo TX-NR7100 9.2-Channel AV Receiver: $699.00 (Sold and shipped by Adorma) Onkyo TX-8470 2 Ch Stereo Receiver: $449.00 (Sold and Shipped by Adorma) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links or authorized dealer links (at the time of article publishing); ensure that you purchase from such links only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • A different thing with Russia. When you say is it better, depends on things. It is better that we don't have the E.U making rules and laws that have nothing to do with them. Is the trading part better? No, that is really mucked up, but then we knew that was going to happen and we would have make agreements, like we do with other parts of the world. Freedom of movement is certainly better, but could be improved, we still need more control over our borders. do you live in the U.K?
    • So what am I quoting from them? I never listened to what Farage or his cronies said. I wanted the U.K to leave the E.u years before the referendum and it had nothing to do with Farage and his cronies. So what country do you live in? Did we work much better together? We were always at logger heads with the E.U because we disagreed with them so much. Maggie was always on at them. I would have thought the E.U was glad to get rid of us as we stopped the integration or made it a two tier. Now without us they can integrate more. I would not have voted out if it was just a trading block and we can still work together on somethings.
    • MPC-BE 1.9.0 by Razvan Serea Media Player Classic - BE is a free and open source audio and video player for Windows. Media Player Classic - BE is based on the original "Media Player Classic" project (Gabest) and "Media Player Classic Home Cinema" project (Casimir666), contains additional features and bug fixes. The BE mod (Black Edition Mod) is a skinned version of Media Player Classic Home Cinema, much better looking than the plain old MPC. MPC-BE 1.9.0 changelog: Splitters Fixed crashes in some situations. AudioSplitter Added support for the RF64 format. Fixed reading of channel layout for some WavPack files. Added support for ID3 tags for Wave64 files. Unknown Wave64 chunks are now ignored. AviSplitter Added support for 'y408' video. Improved support for 'HEVC' video. FLVSplitter Added support for VVC video. MP4Splitter Improved handling of corrupted files. MatroskaSplitter Expanded support for V_UNCOMPRESSED video codecs. Fixed support for frame rotation (ProjectionPoseRoll). Improved support for "V_MS/VFW/FOURCC / HEVC". MpcDvdVideoDecoder Fixed conversion to YUY2. Fixed display of menus for some DVD-Videos. RoQVideoDecoder Output in NV12 and YV12 formats is allowed. Full range is used. MPC Video Decoder RGB32 format will be output as a top-down bitmap by default. Added support for the "IID_MediaSideDataDOVIMetadataV2" interface. Removed support for the deprecated "IID_MediaSideDataDOVIMetadata" interface. Fixed retrieving the name of the video adapter when using NVDEC. Fixed crashes in some situations. MPC Video Converter Added support for AYUV video format. MpcAudioRenderer Improved input format validation. Optimized retrieval of supported formats for exclusive mode. Added the "Keep audio device active when paused" setting. Fixed crashes and freezes in various situations. Subtitles Added the ability to open the properties of an external subtitle renderer in the "Subtitles" settings panel. Fixed external subtitle connections for VSFilter. Fixed a crash when rendering PGS/SUP subtitles when using AVX2. YouTube Improved support for yt-dlp. The built-in YouTube parser is no longer used. Player The HTTP read strategy has been changed. If the playlist contains one entry, more key combinations can be used to control the player (jump through chapters, adjust volume). Improved support for reading ASX playlists. The translation of the MediaInfo report for Chinese, Korean and Japanese has been removed. Added blocking of 32-bit filter "PICVideo Lossless JPEG Decompressor" (pvljpg20.dll), because it crashes. Added blocking of the system filter "AVI Decompressor", which will eliminate the crash of VFW codecs. Fixed a rare crash when using the "/slave" key. Fixed a crash when getting a list of fonts for OSD. Added the ability to load an external audio file using hotkeys. Fixed opening a network path starting with \?\UNC. The "Determine duration when adding" playlist setting now works for YouTube video URLs. The "Online media services" settings panel has been redesigned. Added a "Merge files using FFmpeg" option to the file saving dialog. This option is activated when playing multiple streams obtained using yt-dlp. Added loading of local .dpl playlists ("DAUMPLAYLIST"). Fixed a hang when the user closes the player during the URL opening process. Various interface fixes. Installer Updated MPC Video Renderer 0.10.5. Updated MPC Script Source 0.2.17. Added MPC Image Source 0.3.6. Translations Updated Japanese translation (by tsubasanouta). Updated Chinese (Traditional) and Dutch translation (by beter). Updated Romanian translation (by Andrei Miloiu). Updated Hungarian translation (by mickey). Updated Turkish translation (by cmhrky). Updated German translation (by Klaus1189). Updated Chinese (Simplified) translation (by wushantao). Updated Italian translation (by mapi68). Updated Korean translation (by Hackjjang). Updated Chinese (Traditional) (by udfbe). Updated libraries dav1d 1.5.3-6-g04b69f9; ffmpeg n8.2-dev-1857-g4653e68aab; libpng git-v1.6.55-9-g7d52a8087; Little-CMS git-lcms2.18-26-gf739cda; MediaInfo git-v26.05-38-g702c9b7fd; ZenLib git-v0.4.41-91-g073f297; zlib 1.3.2. Download: MPC-BE 64-bit | Portable MPC-BE 64-bit | ~20.0 MB (Open Source) Download: MPC-BE 32-bit | Portable MPC-BE 32-bit Link: Media Player Classic - BE Home Page Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Apple reportedly looks to blacklisted Chinese memory chips as RAM prices climb by Karthik Mudaliar Image via Apple Apple is reportedly trying to get a clearance from the Trump administration to buy memory from ChangXin Memory Technologies (CXMT) to get some relief from soaring DRAM prices. As per a report by the Financial Times, Apple approached the Commerce Department more than a month ago and also spoke to other officials and allies in Washington. For starters, CXMT is a company that's already been placed on the Pentagon's list of Chinese military companies. The Chinese company is the country's top DRAM maker. For Apple, the timing is certainly awkward but not surprising. Tim Cook had recently warned that Apple would have to raise prices because AI companies are buying up large amounts of memory for data centers, and just like that, Apple raised MacBook and iPad prices. Micron also recently revealed that customers have committed billions of dollars to secure memory supply years in advance, which shows us how aggressive securing infrastructure has become. This gives suppliers such as Samsung, SK Hynix, and Micron more leverage, while pushing hardware makers to look for alternatives. CXMT is one of those alternatives, but not the simplest one. Apple has spent many years trying to diversify parts of its supply chain away from China, especially for final assembly, while still depending heavily on Chinese manufacturing and suppliers. Even domestic brands from China are moving towards CXMT and YMTC instead of relying on Samsung, Micron, and SK Hynix. For Apple, though, it would invite more scrutiny than local Chinese companies. For now, this is more like a lobbying effort rather than a confirmed supply deal. There's no official statement from either of the parties. What is clearer, though, is the pressure behind such a request. AI demand has certainly made hardware a bottleneck, and companies are trying everything they can to bring things back to normal, even if that means making politically sensitive choices. Source: Financial Times
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      498
    2. 2
      +Edouard
      225
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      74
    5. 5
      FloatingFatMan
      70
  • Tell a friend

    Love Neowin? Tell a friend!