Live data from Hacker News

IOHIDeous OS X Local Kernel Vulnerability

siguza.github.io

11–20 of 121 posts

Re: IOHIDeous OS X Local Kernel Vulnerability

#11
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

I don't understand why Apple doesn't have a well-funded bug bounty program. You would think that companies would welcome people finding bugs in their software. Hell, they could give away free MacBook Pro laptops, phones, and IPads along with CASH!!!

I agree. Considering that giving away a dev style laptop would be a nice reward, it’s weird that they do not leverage their products as reward.

High spec MBP + some cash goes a long way. Even engrave the freaking laptop to make it “sough after”.

Re: IOHIDeous OS X Local Kernel Vulnerability

#12
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

"...turned out Apple PR channel is much more responsive than product security [...] No wonder nowadays people just throw security issues on Twitter right? What a world we live in."

https://medium.com/@khaost/your-home-was-not-so-secure-after...

Re: IOHIDeous OS X Local Kernel Vulnerability

#13
post #10
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

So a disclosure can be irresponsible but don’t call it an irresponsible disclosure?

Re: IOHIDeous OS X Local Kernel Vulnerability

#14
post #10
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

I don't like the term you made up. But fine, I think this is "Irresponsible Disclosure." Is that better? Did anything change?

Vendors and non-vendors alike are all responsible for good security, and that includes working together to make this happen. If you are working against vendors because of some preconceived notion that they are "evil," that's not a good thing.

If it turns out that the author did submit to the vendor and worked together to minimize damage then I'll retract my statement. Until then I think it's irresponsible, not just "uncoordinated".

Re: IOHIDeous OS X Local Kernel Vulnerability

#15
Oh my I feel so sorry for apple security engineer's right now. I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? Makes me wonder who brushed this guy the wrong way, or if he just wants to watch the world burn.

That said, seriously impressive work and I give him props.

Re: IOHIDeous OS X Local Kernel Vulnerability

#16
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

I don't understand why Apple doesn't have a well-funded bug bounty program. You would think that companies would welcome people finding bugs in their software. Hell, they could give away free MacBook Pro laptops, phones, and IPads along with CASH!!!

They do have a well-funded and well-publicized bounty program for security exploits.

Re: IOHIDeous OS X Local Kernel Vulnerability

#17

Oh my I feel so sorry for apple security engineer's right now. I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? Makes me wonder who brushed this guy the wrong way, or if he just wants to watch the world burn. That said, seriously impressive work and I give him props.

> Siguza, 01. Dec 2017 (published 31. Dec 2017)

If I had to guess, he waited a month, got blown off, and said, "Fuck it."

Also -- I feel like the underlying bug, ie relying on values in a volatile variable that is shared -- are the sort of thing that source code could be systematically tested for, both mechanically and by humans. But my strong impression is that Apple doesn't care about MacOS and definitely doesn't put the A team on it. Or even the B team.

Re: IOHIDeous OS X Local Kernel Vulnerability

#18
post #10
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

This looks like the usual greyhat posturing to me. He could have gone with "coordinated disclosure" and talked to Apple. Or he could have sold a local vulnerability for whatever that fetches on the black market. But he thought that boasting about it on the tech web would benefit his personal brand more than either of those routes, so this happened.

Re: IOHIDeous OS X Local Kernel Vulnerability

#19

Oh my I feel so sorry for apple security engineer's right now. I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? Makes me wonder who brushed this guy the wrong way, or if he just wants to watch the world burn. That said, seriously impressive work and I give him props.

[deleted]

Re: IOHIDeous OS X Local Kernel Vulnerability

#20
post #13
post #10

Earlier quoted context omitted.

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

So a disclosure can be irresponsible but don’t call it an irresponsible disclosure?

The "responsible" disclosure term is a pretty devious piece of marketing, because it creates situations such as this very thread.

Its use carries an implicit catch that anything that does not meet the narrow definitions of "responsible" is the opposite. Without naming names there are vendors that have been pretty terrible at handling their end of "responsible" disclosure and appear to be getting worse, down to not even acknowledging there is a problem or even that they have been notified of a problem.

The alternative to disclosing a vulnerability is non-disclosure and, frankly, that's what some vendors mean when they say "responsible".

Post reply on HN