Earlier quoted context omitted.
No, their bug bounty only extends to iOS.
Doesn't mean you can't email product-security@apple.com with your bug anyway.
IOHIDeous OS X Local Kernel Vulnerability
51–60 of 121 posts
Re: IOHIDeous OS X Local Kernel Vulnerability
#52Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
They don't for macOS. And the iOS one is invite-only.
Which may, unfortunately, speak to what management thinks about the security/quality of the macOS codebase.
I wouldn't be surprised the recent and upcoming exploits lead Apple to increase iOS dominance over its future product pipeline.
Re: IOHIDeous OS X Local Kernel Vulnerability
#53Earlier quoted context omitted.
The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…
As a Mac user, I feel it’s irresponsible. I don’t want zero days published before Apple has a chance to fix. I also think that the vendor has a responsibility to fix the exploit quickly, and if not the researcher should publish and shame the vendor.
Re: IOHIDeous OS X Local Kernel Vulnerability
#54Earlier quoted context omitted.
The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…
Since when did the term "responsible disclosure" mean allowing the vendor unlimited time to fix it?
Re: IOHIDeous OS X Local Kernel Vulnerability
#55Earlier quoted context omitted.
"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…
This looks like the usual greyhat posturing to me. He could have gone with "coordinated disclosure" and talked to Apple. Or he could have sold a local vulnerability for whatever that fetches on the black market. But he thought that boasting about it on the tech web would benefit his personal brand more than either of those routes, so this happened.
Re: IOHIDeous OS X Local Kernel Vulnerability
#56Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
No mention of disclosure, reporting, or CVE in the entire article :-(
Re: IOHIDeous OS X Local Kernel Vulnerability
#57Earlier quoted context omitted.
The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…
Since when did the term "responsible disclosure" mean allowing the vendor unlimited time to fix it?
https://bugs.chromium.org/p/project-zero/issues/detail?id=10...
I'd say 30 days is enough. Google was generous with ninety. (They too live in a glass house after all).
Re: IOHIDeous OS X Local Kernel Vulnerability
#58To all the kernel programmers out there, can we get a HN-level ELI5 for this? It looks like a total system compromise is possible. Under what conditions? Any ways to ensure we don't get pwned?
Needs to be running on the host already (nothing remote), achieves full system compromise by itself, but logs you out in the process. Can wait for logout though and is fast enough to run on shutdown/reboot until 10.13.1. On 10.13.2 it takes a fair bit longer (maybe half a minute) after logging out, so if your OS logs you out unexpectedly... maybe pull the plug? And maybe don't download & run untrusted software until…
Have Mac users finally started running antivirus?
Re: IOHIDeous OS X Local Kernel Vulnerability
#59Earlier quoted context omitted.
The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…
> in addition to the spelling of acknowledgement "acknowledgment" is the English US form: https://en.oxforddictionaries.com/definition/acknowledgement
Re: IOHIDeous OS X Local Kernel Vulnerability
#60Earlier quoted context omitted.
Needs to be running on the host already (nothing remote), achieves full system compromise by itself, but logs you out in the process. Can wait for logout though and is fast enough to run on shutdown/reboot until 10.13.1. On 10.13.2 it takes a fair bit longer (maybe half a minute) after logging out, so if your OS logs you out unexpectedly... maybe pull the plug? And maybe don't download & run untrusted software until…
> Also, any decent antivirus shouldn't take long to add this to their malware definitions. Have Mac users finally started running antivirus?