Live data from Hacker News

IOHIDeous OS X Local Kernel Vulnerability

siguza.github.io

51–60 of 121 posts

Re: IOHIDeous OS X Local Kernel Vulnerability

#52
post #4
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

They don't for macOS. And the iOS one is invite-only.

> They don't for macOS. And the iOS one is invite-only.

Which may, unfortunately, speak to what management thinks about the security/quality of the macOS codebase.

I wouldn't be surprised the recent and upcoming exploits lead Apple to increase iOS dominance over its future product pipeline.

Re: IOHIDeous OS X Local Kernel Vulnerability

#53
post #30

Earlier quoted context omitted.

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

As a Mac user, I feel it’s irresponsible. I don’t want zero days published before Apple has a chance to fix. I also think that the vendor has a responsibility to fix the exploit quickly, and if not the researcher should publish and shame the vendor.

The author has commented above. It seems Apple was aware of this issue before the author published it. I wouldn't put any blame on the author at all.

Re: IOHIDeous OS X Local Kernel Vulnerability

#54
post #50
post #30

Earlier quoted context omitted.

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

Since when did the term "responsible disclosure" mean allowing the vendor unlimited time to fix it?

If it's not unlimited, what's the limit? Apparently a month isn't long enough.

Re: IOHIDeous OS X Local Kernel Vulnerability

#55
post #10

Earlier quoted context omitted.

"Responsible Disclosure" is an Orwellian term concocted by vendors to control the actions of independent vulnerability researchers who work without real compensation, using information freely available to consumers, in competition with malicious attackers. The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it. If…

This looks like the usual greyhat posturing to me. He could have gone with "coordinated disclosure" and talked to Apple. Or he could have sold a local vulnerability for whatever that fetches on the black market. But he thought that boasting about it on the tech web would benefit his personal brand more than either of those routes, so this happened.

He did talk to Apple. They didn't coordinate with him.

Re: IOHIDeous OS X Local Kernel Vulnerability

#56
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

No mention of disclosure, reporting, or CVE in the entire article :-(

No, but it's in the thread https://news.ycombinator.com/item?id=16044060

Re: IOHIDeous OS X Local Kernel Vulnerability

#57
post #50
post #30

Earlier quoted context omitted.

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

Since when did the term "responsible disclosure" mean allowing the vendor unlimited time to fix it?

When Microsoft decided they needed more than 90 days to release a patch.

https://bugs.chromium.org/p/project-zero/issues/detail?id=10...

I'd say 30 days is enough. Google was generous with ninety. (They too live in a glass house after all).

Re: IOHIDeous OS X Local Kernel Vulnerability

#58
post #48
post #42

To all the kernel programmers out there, can we get a HN-level ELI5 for this? It looks like a total system compromise is possible. Under what conditions? Any ways to ensure we don't get pwned?

Needs to be running on the host already (nothing remote), achieves full system compromise by itself, but logs you out in the process. Can wait for logout though and is fast enough to run on shutdown/reboot until 10.13.1. On 10.13.2 it takes a fair bit longer (maybe half a minute) after logging out, so if your OS logs you out unexpectedly... maybe pull the plug? And maybe don't download & run untrusted software until…

> Also, any decent antivirus shouldn't take long to add this to their malware definitions.

Have Mac users finally started running antivirus?

Re: IOHIDeous OS X Local Kernel Vulnerability

#59
post #30

Earlier quoted context omitted.

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

> in addition to the spelling of acknowledgement "acknowledgment" is the English US form: https://en.oxforddictionaries.com/definition/acknowledgement

This made me think of judgement/judgment, so I looked it up there too. It's apparently mixed enough everywhere that there's not a localization. It always makes me pause to think what form is correct whenever I have to write it.

Re: IOHIDeous OS X Local Kernel Vulnerability

#60
post #48

Earlier quoted context omitted.

Needs to be running on the host already (nothing remote), achieves full system compromise by itself, but logs you out in the process. Can wait for logout though and is fast enough to run on shutdown/reboot until 10.13.1. On 10.13.2 it takes a fair bit longer (maybe half a minute) after logging out, so if your OS logs you out unexpectedly... maybe pull the plug? And maybe don't download & run untrusted software until…

> Also, any decent antivirus shouldn't take long to add this to their malware definitions. Have Mac users finally started running antivirus?

Well, that I don't know...
Post reply on HN