London Daily

Focus on the big picture.
Monday, Feb 16, 2026

We can make our phones harder to hack but complete security is a pipe dream

We can make our phones harder to hack but complete security is a pipe dream

Even the latest iPhone scare won’t persuade us to choose safety over convenience
Apple caused a stir a few weeks ago when it announced that the forthcoming update of its mobile and laptop operating systems would contain an optional high-security mode that would provide users with an unprecedented level of protection against powerful “spyware” software that surreptitiously obtains control of their devices.

It’s called Lockdown Mode and, according to Apple, “offers an extreme, optional level of security for the very few users who, because of who they are or what they do, may be personally targeted by some of the most sophisticated digital threats, such as those from NSO Group and other private companies developing state-sponsored mercenary spyware”.

Lockdown is effectively an alternative operating system mode. To turn it on, go to settings, choose it and restart your device. When you do, you find yourself with a rather different iPhone. Browsing the web is clunkier, for example, because Lockdown blocks many of the speed and efficiency tricks that Safari uses to render web pages. Some complex but widely used web technologies, like so-called just-in-time JavaScript compilation, which allow websites to run programs inside your browser, are disabled unless you specifically exclude a website from restriction. Still, more people might be persuaded to plump for greater security after vulnerabilities were revealed on Apple devices.

Lockdown also limits all kinds of incoming invitations and requests (for example, from FaceTime) unless you have specifically asked for them. In messages, the phone won’t show link previews and will block all attachments with the exception of a few standard image formats. Nor will it allow access to anything physically plugged into it. And so on.

The result of engaging Lockdown is that you have an iPhone that is more secure but less convenient to use. And, in a way, that is the most significant thing about Apple’s decision. As the security guru Bruce Schneier puts it: “It’s common to trade security off for usability and the results of that are all over Apple’s operating systems – and everywhere else on the internet. What they’re doing with Lockdown Mode is the reverse: they’re trading usability for security. The result is a user experience with fewer features, but a much smaller attack surface. And they aren’t just removing random features; they’re removing features that are common attack vectors.”

Ever since people started to worry about computer safety, the issue has been framed as striking a balance between security and convenience. Up to now, convenience has been winning hands down. Take passwords. Everyone knows that long, complex passwords are more secure than simple ones, but they’re also hard to remember. So, being human, we don’t use them: in 2021, the five most commonly used passwords were: 123456, 123456789, 12345, qwerty and password.

In the era of mainframe computers and standalone PCs, this kind of laxity didn’t matter too much. But as the world became networked, the consequences of carelessness have become more worrying. Why? Because there is no such thing as a completely secure networked device and we have been adding such devices to the so-called Internet of Things (IoT) on a maniacal scale. There are something like 13bn at the moment; by 2030, the tech industry thinks there might be 30bn.

The conventional adjective for these gizmos is “smart”. They can be “hi-tech” items such as smart speakers, fitness trackers and security cameras, but also standard household things such as fridges, lightbulbs and plugs, doorbells, thermostats and so on. From a marketing point of view, their USPs are flexibility, utility and responsiveness – in other words, convenience.

But smart is a euphemism that tactfully conceals the fact that they are tiny computers that are connected to the internet and can be remotely controlled from a smartphone or a computer. Some are made by reputable companies, but many are products of small outfits in China and elsewhere. They come with default usernames and passwords (such as “admin” and “password”) that buyers can change (but usually don’t). Because they’re networked, they are remotely accessible by their owners and, more importantly, by others. And there are billions of them out there in our homes, offices and factories.

Security researchers use the term “attack surface” to describe the number of possible points where an unauthorised user can access a system, extract data and/or inflict damage. The smaller the surface, the easier it is to protect. Unfortunately, the corollary also holds. In our Gadarene rush into the Internet of Things we are creating an attack surface of near-infinite dimensions.

The strange thing is that we already know what the consequences of this are like and yet seem unperturbed by them. In 2016, the security community was transfixed by a number of huge distributed denial-of-service attacks that caused outages, internet congestion and in one case overwhelmed the website of a prominent security guru.

Such attacks used to be conducted by botnets of thousands of infected PCs but the 2016 ones were carried out by a botnet that included perhaps half-a-million infected “smart” gizmos. The Mirai malware that assembled the botnet scoured the web for IoT devices protected by little more than factory-default usernames and passwords and then enlisted them in attacks that hurled junk traffic at an online target until it could no longer function.

Mirai is still around, so you might not be the only entity benefiting from those fancy new networked lightbulbs. The cost of convenience will be higher than we think. So upgrade those passwords.
#NSO 
Newsletter

Related Articles

0:00
0:00
Close
UK’s Top Prosecutor Says ‘No One Is Above the Law’ as Police Review Claims Against Ex-Prince Andrew
US Secretary of State Marco Rubio Comment on European allies report blaming Russia for killing late Kremlin critic Alexei Navalny using toxin from poison dart frogs
Eighty-Year-Old Lottery Winner Sentenced to 16.5 Years for Drug Trafficking
UK Quran Burner May Receive Asylum in the US Amid Legal Challenges
Rubio Calls for Sweeping U.N. Reform, Saying It Has Failed to End Wars in Gaza and Ukraine
10,000 Condoms Distributed at Winter Olympics 2026 Athlete Village Depleted Within 72 Hours
Poland's President Advocates for Evaluating Independent Nuclear Weapons Development
Prince William Meets Saudi Crown Prince as Epstein-Andrew Fallout Casts Shadow
Starmer Calls for Renewed ‘Hard Power’ Investment at European Security Summit
UK Police Establish National Taskforce to Handle Domestic Epstein-Linked Allegations
UK Court Rules Ban on Palestine Action Unlawful in Major Free Speech Test
UK Faces Prospect of Net Migration Turning Negative as Economic Impact Looms
Mayor of Serdobsk in Russia’s Penza Region Resigns After Housing Certificates Granted to Migrant Family Trigger Public Outcry
Pentagon Reviews Anthropic Partnership After Claude AI Reportedly Used in Operation Targeting Nicolás Maduro
President Donald Trump and Hip-Hop’s Political Realignment: Pardons, Public Endorsements, and the Struggle Over Cultural Influence
China’s EV Makers Face Mandatory Return to Physical Buttons and Door Handles in Driver-Distraction Safety Overhaul
Goldman Sachs and DP World Executive Resignations: Elite-Reputation Risk and Corporate Governance Fallout From the Epstein Disclosures
‘Amelia’: The UK Government’s Anti-Extremism Game Villain Who Became a Protest Symbol
Peter Mandelson Asked to Testify Before US Congress Over Jeffrey Epstein Links
Walmart's Earnings and UK Economic Data Highlight Upcoming Financial Trends
UK Green Party Considering Proposal to Legalize Heroin for an Inclusive Society
SpaceX's New Vision: Lunar City Takes Precedence Over Mars Colonization
OpenAI and DeepCent Superintelligence Race: Artificial General Intelligence and AI Agents as a National Security Arms Race
Document Suggests Prince Andrew Shared UK Briefing on Afghan Investment Opportunities with Jeffrey Epstein
We will protect them from the digital Wild West.’ Another country will ban social media for under-16s
McDonald's Shortens Breakfast Hours in Australia Due to Egg Shortage
Heineken announces cut of 6,000 jobs due to declining beer demand
Beijing Brands UK Hong Kong Visa Expansion ‘Despicable and Reprehensible’ After Jimmy Lai Sentencing
Tesco Chief Warns UK Is ‘Sleepwalking’ Toward a Joblessness Crisis
Trump’s ‘Act of Great Stupidity’ Comment on UK Chagos Deal Reverberates Through Diplomacy and Strategy
New U.S. filings say Jeffrey Epstein repaid Les Wexner one hundred million dollars after theft allegation
Commerce Secretary Howard Lutnick acknowledges 2012 visit to Jeffrey Epstein’s private island as lawmakers scrutinise past ties
Helsing and Stark Defence loitering-munition drones and Germany’s race to industrialise battlefield autonomy
UK orders deletion of Courtsdesk court-data archive, reigniting the fight over who controls public justice records
UK Police Review Fresh Claims Involving Prince Andrew as Senior Royals Respond to Epstein Files
Keir Starmer’s Premiership Faces Unprecedented Strain as Epstein Fallout Deepens
Starmer Vows to Stay in Office as UK Government Faces Turmoil After Epstein Fallout
China and UK Signal Tentative Reset with Commitment to Steadier, Professionally Managed Relations
UK Confirms Imminent Increase in ETA Fee to £20 as Entry Rules Tighten
UK Signals Possible Seizure of Russia-Linked ‘Shadow Fleet’ Tanker in Escalation of Sanctions Enforcement
Epstein Scandal Piles Unprecedented Pressure on UK Prime Minister Keir Starmer’s Leadership
UK’s ‘Most Romantic Village’ Celebrates Valentine’s Day and Explores the Festival’s Rich History
The Implications of Expanding Voting Rights to Non-EU Foreign Residents in France
Ghislaine Maxwell to Testify Before US Congress on February 9
Al.com Acquired by Crypto.com Founder for $70 Million
Apple iPhone Lockdown Mode blocks FBI data access in journalist device seizure
Belgium: Man Charged with Rape After Faking Payment to Sex Worker
KPMG Urges Auditor to Relay AI Cost Savings
US and Iran to Begin Nuclear Talks in Oman
Winklevoss-Led Gemini to Slash a Quarter of Jobs and Exit European and Australian Markets
×