Toxic max security.

Not everyone has the same threat model as you, $BIGTECHCORP.

Isn't security just an excuse to push user hostile features?

Like, if security was a concern we would have simpler systems and still use 2fa devices for banks etc.

Sometimes it's truly useful featutes, but having no toggle in settings making it terrible.

Like iPhone idle auto-reboot every 3 days. After a while they added "Allow Idle Reboot" flag but it only accessible via MDM and require device wipe and for switching it to be a managed device.

What would that be useful for anyway? Sounds like something aimed to prevent people from reusing their old/secondary devices for IoT.

> What would that be useful for anyway?

It puts iPhone in cold boot state if for instance police or any agency confiscate it from you. Better tamper proofing.

Hides memory leaks

Right, that too. But that's a reason to recommend regular reboots[0], not to force them, and "3 days of inactivity" is a suspiciously specific time that I also saw mentioned in Android settings somewhere the other day.

--

[0] - Which I find deeply ironic, in that merely a decade ago, people would laugh at Windows with its "reboot after installs, reboot in case of problems" approach, and now frequent reboots are seen as Standard Security and Stability Practice on *nix systems, both mobile and server-bound...

I have no issue restarting my iOS/Mac/Linux machines because the time to get back to doing fun or productive stuff is measured in seconds. And usually you only have to restart one time. Windows used to take ages, and often you’d reboot only find out that something else that requires a reboot only triggered because of the previous reboot, so you were sometimes in for 2-3 restarts.

It’s not like that anymore in my experience at least but the stigma stuck.

They dont care about security; only about control.

There are hundreds of millions of outdated Android devices that all Google attestation systems consider secure even though they all running Linux kernel that was never ever updated and can be rooted by anything.

Now try to install your own firmware on them without said outdated kernel... How dare you.

Technically the security works, just for their threat model. An exploit would need root and root means you likely cannot pass attestation AFAIK. The fact that this same exploiter can download all your contacts photos and texts is immaterial to, say, Disney, who want attestation only to prevent ripping of their content.

No it doesnt actually work because its possible to do privilege escalaction without tampering with firmware or filesystem or triggering other markera. OS will be practically rooted while passing attestation just fine.

Only things attestation do is security theater and messing up people ability to use software of their choosing.

Security, but not for you, is no security.

Have you read the android security model? It's a multi party security model which considers apps and users as equals. It's a legitimate security model and just because it's not what you want doesn't mean it's wrong.is it user hostile? Maybe. But that is different than saying it offers no security. It's also not worth bickering about every small decision that is made in line with that security model. If you want a different one, push for it via alternative OS.

Ask Jeeves toolbar disagrees.

It's not even "max security". We are talking about those big tech corps which are infamous for sharing all of your private information with the government, and analyzing it so as to manipulate you in to buying things, and possibly for other obscure commercial purpuses.

They securely share your private info with their advertising partners. You know that no hackers that didnt pay google would get access to that information.