Live data from Hacker News

IOHIDeous OS X Local Kernel Vulnerability

siguza.github.io

21–30 of 121 posts

Re: IOHIDeous OS X Local Kernel Vulnerability

#21
post #8
post #5

Earlier quoted context omitted.

Why do that when you can wreck a security engineer’s vacation?

On the other hand, it could teach a good lesson on technical debt?

I would claim that there is a very high likelihood that the person having to work all night to fix this on new years Eve is not the same person who prioritizes tech debt pay off vs. new features.

Re: IOHIDeous OS X Local Kernel Vulnerability

#22
post #14
post #10

Earlier quoted context omitted.

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

I don't like the term you made up. But fine, I think this is "Irresponsible Disclosure." Is that better? Did anything change? Vendors and non-vendors alike are all responsible for good security, and that includes working together to make this happen. If you are working against vendors because of some preconceived notion that they are "evil," that's not a good thing. If it turns out that the author did submit to the v…

It’s not « preconceived »: Vendors have very low bounties, not even covering the time spent on 1 issue (none for macOS I think) and the reason researchers are working with them is more the drawback of working in black hat than the reward of white hats.

Re: IOHIDeous OS X Local Kernel Vulnerability

#23
post #17

Oh my I feel so sorry for apple security engineer's right now. I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? Makes me wonder who brushed this guy the wrong way, or if he just wants to watch the world burn. That said, seriously impressive work and I give him props.

> Siguza, 01. Dec 2017 (published 31. Dec 2017) If I had to guess, he waited a month, got blown off, and said, "Fuck it." Also -- I feel like the underlying bug, ie relying on values in a volatile variable that is shared -- are the sort of thing that source code could be systematically tested for, both mechanically and by humans. But my strong impression is that Apple doesn't care about MacOS and definitely doesn't p…

I had actually submitted to the ZDI, but had written the exploit & write-up in the first place mainly because I like hacking rather than for money. I figured I'd see what offers I'd get anyway, but once I had spent all the time on the write-up, I mainly wanted people to see that, and the amount offered wasn't enough to convince me otherwise. I might've published this earlier even, but my December was kinda busy, first with the v0rtex exploit and then with 34C3.

And an engineer from Apple's security team contacted me a bit after releasing - they had found the bug a while ago, but hadn't verified the subsequent patch which actually didn't fix it. And a while ago I tweeted this https://twitter.com/s1guza/status/921889566549831680 (try diff'ing sources to find it :P). So they do have people on it. I also told that person to extend my condolences to whoever has to come in and fix that now, but they basically said that there's nothing to apologise for and that they (the team) really like such write-ups. So... I guess I'm not that evil?

And I neither wanna watch the world burn nor did anyone brush me the wrong way - I didn't publish this out of hate, but out of love for hacking. If you're concerned about skids hacking you now, they need to get code execution first on your machine. If you're concerned about people who can do that, then those can also get kernel r/w without me, so... nothing really changed for the average user.

PS: Yes, it's really me. Will add keybase proof if my karma gets >= 2. Edit: done, see my profile.

Re: IOHIDeous OS X Local Kernel Vulnerability

#24
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

Maybe if more people would disclose such vulnerabilities “irresponsibly”, vendors would develop their software more responsibly. Just my 2 cents ¯\_(ツ)_/¯

Re: IOHIDeous OS X Local Kernel Vulnerability

#25
I'm actually not too surprised. I briefly delved into Mac kernel programming in the early days of Hackintoshing (in an attempt to write some missing device drivers), and the amount of complexity there seemed excessive --- to someone who had done previous kernel work in Windows and Linux. The overall impression I had was "far too many moving pieces". And as everyone should know, complexity hides bugs.

Re: IOHIDeous OS X Local Kernel Vulnerability

#27
post #10
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

Coordinated disclosure information is here, and edits/suggestions/feedback are welcome:

http://github.com/joelparkerhenderson/coordinated_disclosure

Re: IOHIDeous OS X Local Kernel Vulnerability

#28
Sharing my screen with my browser when I saw this headline was my terminal with the output of:

/usr/bin/mdfind 'kMDItemFSName=*.kext'

I was JUST exploring the design of OS X, as I am wont to do, and looking at these OS X kernel extensions with a suspicious eye. It's some kind of surreal cosmic joke that this headline appeared #1 on Hacker News as I was looking at that.

Re: IOHIDeous OS X Local Kernel Vulnerability

#29
post #10
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

Just to strengthen your back, representatives of the Chaos Computer Club agree with you on that, and also agree that no vendor has a right to coordinated disclosure.

But they also argue that you should try to coordinate disclosure the first time at least, and only if a vendor doesn’t cooperate, you should publish future bugs. And they also suggested to coordinate disclosure at least with the club, so the disclosure is handled via official press communications of the club, and they can offer legal protection, too (very often, vendors will just sue any researcher).

This information is from a recording of the 34C3 year in review and PCWahl talks.

Re: IOHIDeous OS X Local Kernel Vulnerability

#30
post #14
post #10

Earlier quoted context omitted.

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

I don't like the term you made up. But fine, I think this is "Irresponsible Disclosure." Is that better? Did anything change? Vendors and non-vendors alike are all responsible for good security, and that includes working together to make this happen. If you are working against vendors because of some preconceived notion that they are "evil," that's not a good thing. If it turns out that the author did submit to the v…

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it.

Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0]

"When we receive your email, we send an automatic email as acknowledgment. If you do not get this email, please check the email address and send again. We will respond with additional emails if we need further information to investigate a security issue."

Something seems a bit off here. I would have expected a human to get back within a few working days for a serious security problem. That might be in the auto response email, but I wouldn't be surprised if it wasn't.

"For the protection of our customers, Apple generally does not disclose, discuss, or confirm security issues until a full investigation is complete and any necessary patches or releases are available."

Does this extend to the security researcher that reports the vulnerability? If so, that's probably why there was no coordination.

[0] https://support.apple.com/en-us/HT201220

Edit: removed spelling mistake mistake.

Post reply on HN