Beautiful Virgin Islands

Saturday, Nov 22, 2025

We can make our phones harder to hack but complete security is a pipe dream

We can make our phones harder to hack but complete security is a pipe dream

Even the latest iPhone scare won’t persuade us to choose safety over convenience
Apple caused a stir a few weeks ago when it announced that the forthcoming update of its mobile and laptop operating systems would contain an optional high-security mode that would provide users with an unprecedented level of protection against powerful “spyware” software that surreptitiously obtains control of their devices.

It’s called Lockdown Mode and, according to Apple, “offers an extreme, optional level of security for the very few users who, because of who they are or what they do, may be personally targeted by some of the most sophisticated digital threats, such as those from NSO Group and other private companies developing state-sponsored mercenary spyware”.

Lockdown is effectively an alternative operating system mode. To turn it on, go to settings, choose it and restart your device. When you do, you find yourself with a rather different iPhone. Browsing the web is clunkier, for example, because Lockdown blocks many of the speed and efficiency tricks that Safari uses to render web pages. Some complex but widely used web technologies, like so-called just-in-time JavaScript compilation, which allow websites to run programs inside your browser, are disabled unless you specifically exclude a website from restriction. Still, more people might be persuaded to plump for greater security after vulnerabilities were revealed on Apple devices.

Lockdown also limits all kinds of incoming invitations and requests (for example, from FaceTime) unless you have specifically asked for them. In messages, the phone won’t show link previews and will block all attachments with the exception of a few standard image formats. Nor will it allow access to anything physically plugged into it. And so on.

The result of engaging Lockdown is that you have an iPhone that is more secure but less convenient to use. And, in a way, that is the most significant thing about Apple’s decision. As the security guru Bruce Schneier puts it: “It’s common to trade security off for usability and the results of that are all over Apple’s operating systems – and everywhere else on the internet. What they’re doing with Lockdown Mode is the reverse: they’re trading usability for security. The result is a user experience with fewer features, but a much smaller attack surface. And they aren’t just removing random features; they’re removing features that are common attack vectors.”

Ever since people started to worry about computer safety, the issue has been framed as striking a balance between security and convenience. Up to now, convenience has been winning hands down. Take passwords. Everyone knows that long, complex passwords are more secure than simple ones, but they’re also hard to remember. So, being human, we don’t use them: in 2021, the five most commonly used passwords were: 123456, 123456789, 12345, qwerty and password.

In the era of mainframe computers and standalone PCs, this kind of laxity didn’t matter too much. But as the world became networked, the consequences of carelessness have become more worrying. Why? Because there is no such thing as a completely secure networked device and we have been adding such devices to the so-called Internet of Things (IoT) on a maniacal scale. There are something like 13bn at the moment; by 2030, the tech industry thinks there might be 30bn.

The conventional adjective for these gizmos is “smart”. They can be “hi-tech” items such as smart speakers, fitness trackers and security cameras, but also standard household things such as fridges, lightbulbs and plugs, doorbells, thermostats and so on. From a marketing point of view, their USPs are flexibility, utility and responsiveness – in other words, convenience.

But smart is a euphemism that tactfully conceals the fact that they are tiny computers that are connected to the internet and can be remotely controlled from a smartphone or a computer. Some are made by reputable companies, but many are products of small outfits in China and elsewhere. They come with default usernames and passwords (such as “admin” and “password”) that buyers can change (but usually don’t). Because they’re networked, they are remotely accessible by their owners and, more importantly, by others. And there are billions of them out there in our homes, offices and factories.

Security researchers use the term “attack surface” to describe the number of possible points where an unauthorised user can access a system, extract data and/or inflict damage. The smaller the surface, the easier it is to protect. Unfortunately, the corollary also holds. In our Gadarene rush into the Internet of Things we are creating an attack surface of near-infinite dimensions.

The strange thing is that we already know what the consequences of this are like and yet seem unperturbed by them. In 2016, the security community was transfixed by a number of huge distributed denial-of-service attacks that caused outages, internet congestion and in one case overwhelmed the website of a prominent security guru.

Such attacks used to be conducted by botnets of thousands of infected PCs but the 2016 ones were carried out by a botnet that included perhaps half-a-million infected “smart” gizmos. The Mirai malware that assembled the botnet scoured the web for IoT devices protected by little more than factory-default usernames and passwords and then enlisted them in attacks that hurled junk traffic at an online target until it could no longer function.

Mirai is still around, so you might not be the only entity benefiting from those fancy new networked lightbulbs. The cost of convenience will be higher than we think. So upgrade those passwords.
#NSO 
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Zelenskyy Signals Progress Toward Ending the War: ‘One of the Hardest Moments in History’ (end of his business model?)
U.S. Issues Alert Declaring Venezuelan Airspace a Hazard Due to Escalating Security Conditions
The U.S. State Department Announces That Mass Migration Constitutes an Existential Threat to Western Civilization and Undermines the Stability of Key American Allies
Students Challenge AI-Driven Teaching at University of Staffordshire
Pikeville Medical Center Partners with UK’s Golisano Children’s Network to Expand Pediatric Care
Germany, France and UK Confirm Full Support for Ukraine in US-Backed Security Plan
UK Low-Traffic Neighbourhoods Face Rising Backlash as Pandemic Schemes Unravel
UK Records Coldest Night of Autumn as Sub-Zero Conditions Sweep the Country
UK at Risk of Losing International Doctors as Workforce Exodus Grows, Regulator Warns
ASU Launches ASU London, Extending Its Innovation Brand to the UK Education Market
UK Prime Minister Keir Starmer to Visit China in January as Diplomatic Reset Accelerates
Google Launches Voluntary Buyouts for UK Staff Amid AI-Driven Company Realignment
UK braces for freezing snap as snow and ice warnings escalate
Majority of UK Novelists Fear AI Could Displace Their Work, Cambridge Study Finds
UK's Carrier Strike Group Achieves Full Operational Capability During NATO Drill in Mediterranean
Trump and Mamdani to Meet at the White House: “The Communist Asked”
Nvidia Again Beats Forecasts, Shares Jump in After-Hours Trading
Wintry Conditions Persist Along UK Coasts After Up to Seven Centimetres of Snow
UK Inflation Eases to 3.6 % in October, Opening Door for Rate Cut
UK Accelerates Munitions Factory Build-Out to Reinforce Warfighting Readiness
UK Consumer Optimism Plunges Ahead of November Budget
A Decade of Innovation Stagnation at Apple: The Cook Era Critique
Caribbean Reparations Commission Seeks ‘Mutually Beneficial’ Justice from UK
EU Insists UK Must Contribute Financially for Access to Electricity Market and Broader Ties
UK to Outlaw Live-Event Ticket Resales Above Face Value
President Donald Trump Hosts Saudi Crown Prince Mohammed bin Salman at White House to Seal Major Defence and Investment Deals
German Entertainment Icons Alice and Ellen Kessler Die Together at Age 89
UK Unveils Sweeping Asylum Reforms with 20-Year Settlement Wait and Conditional Status
UK Orders Twitter Hacker to Repay £4.1 Million Following 2020 High-Profile Breach
Popeyes UK Eyes Century Mark as Fried-Chicken Chain Accelerates Roll-out
Two-thirds of UK nurses report working while unwell amid staffing crisis
Britain to Reform Human-Rights Laws in Sweeping Asylum Policy Overhaul
Nearly Half of Job Losses Under Labour Government Affect UK Youth
UK Chancellor Reeves Eyes High-Value Home Levy in Budget to Raise Tens of Billions
UK Urges Poland to Choose Swedish Submarines in Multi-Billion € Defence Bid
US Border Czar Tom Homan Declares UK No Longer a ‘Friend’ Amid Intelligence Rift
UK Announces Reversal of Income Tax Hike Plans Ahead of Budget
Starmer Faces Mounting Turmoil as Leaked Briefings Ignite Leadership Plot Rumours
UK Commentator Sami Hamdi Returns Home After US Visa Revocation and Detention
UK Eyes Denmark-Style Asylum Rules in Major Migration Shift
UK Signals Intelligence Freeze Amid US Maritime Drug-Strike Campaign
TikTok Awards UK & Ireland 2025 Celebrates Top Creators Including Max Klymenko as Creator of the Year
UK Growth Nearly Stalls at 0.1% in Q3 as Cyberattack Halts Car Production
Apple Denied Permission to Appeal UK App Store Ruling, Faces Over £1bn Liability
UK Chooses Wylfa for First Small Modular Reactors, Drawing Sharp U.S. Objection
Starmer Faces Growing Labour Backlash as Briefing Sparks Authority Crisis
Reform UK Withdraws from BBC Documentary Amid Legal Storm Over Trump Speech Edit
UK Prime Minister Attempts to Reassert Authority Amid Internal Labour Leadership Drama
UK Upholds Firm Rules on Stablecoins to Shield Financial System
Brussels Divided as UK-EU Reset Stalls Over Budget Access
×