Live data from Hacker News

IOHIDeous OS X Local Kernel Vulnerability

siguza.github.io

31–40 of 121 posts

Re: IOHIDeous OS X Local Kernel Vulnerability

#31

Oh my I feel so sorry for apple security engineer's right now. I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? Makes me wonder who brushed this guy the wrong way, or if he just wants to watch the world burn. That said, seriously impressive work and I give him props.

[deleted]

Re: IOHIDeous OS X Local Kernel Vulnerability

#32
post #30
post #14

Earlier quoted context omitted.

I don't like the term you made up. But fine, I think this is "Irresponsible Disclosure." Is that better? Did anything change? Vendors and non-vendors alike are all responsible for good security, and that includes working together to make this happen. If you are working against vendors because of some preconceived notion that they are "evil," that's not a good thing. If it turns out that the author did submit to the v…

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

As a Mac user, I feel it’s irresponsible. I don’t want zero days published before Apple has a chance to fix.

I also think that the vendor has a responsibility to fix the exploit quickly, and if not the researcher should publish and shame the vendor.

Re: IOHIDeous OS X Local Kernel Vulnerability

#33
post #23
post #17

Earlier quoted context omitted.

> Siguza, 01. Dec 2017 (published 31. Dec 2017) If I had to guess, he waited a month, got blown off, and said, "Fuck it." Also -- I feel like the underlying bug, ie relying on values in a volatile variable that is shared -- are the sort of thing that source code could be systematically tested for, both mechanically and by humans. But my strong impression is that Apple doesn't care about MacOS and definitely doesn't p…

I had actually submitted to the ZDI, but had written the exploit & write-up in the first place mainly because I like hacking rather than for money. I figured I'd see what offers I'd get anyway, but once I had spent all the time on the write-up, I mainly wanted people to see that, and the amount offered wasn't enough to convince me otherwise. I might've published this earlier even, but my December was kinda busy, firs…

Incredible work. How did you find the bug and how many hours did it take you in total?

Re: IOHIDeous OS X Local Kernel Vulnerability

#34
post #30
post #14

Earlier quoted context omitted.

I don't like the term you made up. But fine, I think this is "Irresponsible Disclosure." Is that better? Did anything change? Vendors and non-vendors alike are all responsible for good security, and that includes working together to make this happen. If you are working against vendors because of some preconceived notion that they are "evil," that's not a good thing. If it turns out that the author did submit to the v…

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

> in addition to the spelling of acknowledgement

"acknowledgment" is the English US form: https://en.oxforddictionaries.com/definition/acknowledgement

Re: IOHIDeous OS X Local Kernel Vulnerability

#35
post #14
post #10

Earlier quoted context omitted.

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

I don't like the term you made up. But fine, I think this is "Irresponsible Disclosure." Is that better? Did anything change? Vendors and non-vendors alike are all responsible for good security, and that includes working together to make this happen. If you are working against vendors because of some preconceived notion that they are "evil," that's not a good thing. If it turns out that the author did submit to the v…

> and that includes working together to make this happen

It also includes disclosure if the vendor drags their feet and does nothing, which is a very common response.

I have no preconceived notion that vendors are "evil," but I sure as hell have a preconceived notion that they're as lazy as they think they can get away with.

Re: IOHIDeous OS X Local Kernel Vulnerability

#36
post #23
post #17

Earlier quoted context omitted.

> Siguza, 01. Dec 2017 (published 31. Dec 2017) If I had to guess, he waited a month, got blown off, and said, "Fuck it." Also -- I feel like the underlying bug, ie relying on values in a volatile variable that is shared -- are the sort of thing that source code could be systematically tested for, both mechanically and by humans. But my strong impression is that Apple doesn't care about MacOS and definitely doesn't p…

I had actually submitted to the ZDI, but had written the exploit & write-up in the first place mainly because I like hacking rather than for money. I figured I'd see what offers I'd get anyway, but once I had spent all the time on the write-up, I mainly wanted people to see that, and the amount offered wasn't enough to convince me otherwise. I might've published this earlier even, but my December was kinda busy, firs…

The write-up you did on this vulnerability (not to mention the discovery of the vulnerability and coming up with a working exploit) is really top notch. Thanks for taking the time to compose such a high-quality explanation and walk-through.

Re: IOHIDeous OS X Local Kernel Vulnerability

#37
post #10

Earlier quoted context omitted.

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

This looks like the usual greyhat posturing to me. He could have gone with "coordinated disclosure" and talked to Apple. Or he could have sold a local vulnerability for whatever that fetches on the black market. But he thought that boasting about it on the tech web would benefit his personal brand more than either of those routes, so this happened.

So what? He found the vulnerability, he wrote the exploit, he gets to decide how it is "disclosed", and anyone else's opinion of his choice is irrelevant.

Re: IOHIDeous OS X Local Kernel Vulnerability

#38
post #14
post #10

Earlier quoted context omitted.

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

I don't like the term you made up. But fine, I think this is "Irresponsible Disclosure." Is that better? Did anything change? Vendors and non-vendors alike are all responsible for good security, and that includes working together to make this happen. If you are working against vendors because of some preconceived notion that they are "evil," that's not a good thing. If it turns out that the author did submit to the v…

I think "irresponsible disclosure" would involve disclosing it to black hats for money.

Re: IOHIDeous OS X Local Kernel Vulnerability

#39
post #23
post #17

Earlier quoted context omitted.

> Siguza, 01. Dec 2017 (published 31. Dec 2017) If I had to guess, he waited a month, got blown off, and said, "Fuck it." Also -- I feel like the underlying bug, ie relying on values in a volatile variable that is shared -- are the sort of thing that source code could be systematically tested for, both mechanically and by humans. But my strong impression is that Apple doesn't care about MacOS and definitely doesn't p…

I had actually submitted to the ZDI, but had written the exploit & write-up in the first place mainly because I like hacking rather than for money. I figured I'd see what offers I'd get anyway, but once I had spent all the time on the write-up, I mainly wanted people to see that, and the amount offered wasn't enough to convince me otherwise. I might've published this earlier even, but my December was kinda busy, firs…

You say you submitted it to the ZDI, but did you try sending it to Apple product security?

Re: IOHIDeous OS X Local Kernel Vulnerability

#40
post #16

Earlier quoted context omitted.

I don't understand why Apple doesn't have a well-funded bug bounty program. You would think that companies would welcome people finding bugs in their software. Hell, they could give away free MacBook Pro laptops, phones, and IPads along with CASH!!!

They do have a well-funded and well-publicized bounty program for security exploits.

Would you agree that if it were really well known and earned a fair amount to hackers people would not end up throwing this stuff online (even on Twitter) because their PR team is the only one that gets affected in these cases?
Post reply on HN