Live data from Hacker News

IOHIDeous OS X Local Kernel Vulnerability

siguza.github.io

1–10 of 121 posts

Re: IOHIDeous OS X Local Kernel Vulnerability

#3
There are two pieces here that I find really impressive:

First, the skills and persistence to get all these moving parts going. This must have been weeks of tiring work and exploration.

Second, the fact that the author wrote an incredibly detailed posting with a lot of detail and background information.

Wonderful work.

Re: IOHIDeous OS X Local Kernel Vulnerability

#6
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

I don't understand why Apple doesn't have a well-funded bug bounty program. You would think that companies would welcome people finding bugs in their software. Hell, they could give away free MacBook Pro laptops, phones, and IPads along with CASH!!!

Re: IOHIDeous OS X Local Kernel Vulnerability

#9
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

No mention of disclosure, reporting, or CVE in the entire article :-(

That's why they're calling it a 0day, because they haven't done any of those things.

Re: IOHIDeous OS X Local Kernel Vulnerability

#10
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers.

The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it.

If you'd like to complain that this disclosure is irresponsible, fine. But try not to do it using the vendor's marketing term, because it's not up to them to decide what is and isn't "responsible". Other reasonable people --- myself included --- will probably disagree with you, and say that getting information out to people as comprehensively as possible is usually the most responsible thing you can do with a security bug.

Post reply on HN