I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones.
Not much confidence when you get an update with security patches from 2-3 months ago.
> they aren't just flying around hitting random devices.
For the moment, but only until other wankers reverse engineer the security flaws based on the updated 16.6.1 firmware from Apple. After that you too are vulnerable if you haven't updated.
I understand that, and I'm partially assessing that in the context of any high targets who might be using the latest Android flagship, that frankly still suffers from the same problem as all Android phones.
Unless proven by leaked testimonials I would not fully trust GrapheneOS to be fully safe either. Maybe they have zero days as well and we just didn't discover them because of obscurity but NSO bought them and uses them.
My dad used to say "Known devil is better than unknown angel."
Not much confidence when you get an update with security patches from 2-3 months ago.