Live data from Hacker News

IOHIDeous OS X Local Kernel Vulnerability

siguza.github.io

101–110 of 121 posts

Re: IOHIDeous OS X Local Kernel Vulnerability

#101

Earlier quoted context omitted.

> I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? CVE 2018-0001, it's all about namespaces.

Bonus points if they issue it as CVE-2018-65536 (pen-test the world, so to speak) EDIT: "No one would ever store the CVE incrementing fragment as a 16-bit unsigned int!"

Or in the pattern CVE-dddd-dddd ...

For additional fun, find a buffer overrun based on the CVE ID.

Re: IOHIDeous OS X Local Kernel Vulnerability

#102
post #30

Earlier quoted context omitted.

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

You imply by framing without explicitly stating that "coordinated disclosure" is "unlimited time", but that's not the time frame under discussion. I consider 24 hours notice bare minimum responsible disclosure, and 1 business day in the operating timezone of the company as an polite courtesy to the human beings who have to respond to uncoordinated security disclosures with emergency builds of their product. What do y…

> I consider 24 hours notice bare minimum responsible disclosure

You can't possibly be serious? Have I fallen for some trolling here?!

Re: IOHIDeous OS X Local Kernel Vulnerability

#103
post #16

Earlier quoted context omitted.

I don't understand why Apple doesn't have a well-funded bug bounty program. You would think that companies would welcome people finding bugs in their software. Hell, they could give away free MacBook Pro laptops, phones, and IPads along with CASH!!!

They do have a well-funded and well-publicized bounty program for security exploits.

... for iOS

Re: IOHIDeous OS X Local Kernel Vulnerability

#104

Earlier quoted context omitted.

> I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? CVE 2018-0001, it's all about namespaces.

CVE 2018-0002: Flaw in CVE numbering procedure incentivizes dropping zero days on New Year’s Eve.

I remember waiting to report a security issue with some trivial setuid application until January, back a few years, specifically so I could claim the first CVE of the year.

I was unlucky and it didn't work out, but come December time I do wonder if I should dedicate more time to audits ..

Re: IOHIDeous OS X Local Kernel Vulnerability

#105
post #48

Earlier quoted context omitted.

Needs to be running on the host already (nothing remote), achieves full system compromise by itself, but logs you out in the process. Can wait for logout though and is fast enough to run on shutdown/reboot until 10.13.1. On 10.13.2 it takes a fair bit longer (maybe half a minute) after logging out, so if your OS logs you out unexpectedly... maybe pull the plug? And maybe don't download & run untrusted software until…

> Also, any decent antivirus shouldn't take long to add this to their malware definitions. Have Mac users finally started running antivirus?

Some of them. But mostly of prevent forwarding windows-malware. Most corporate-managed stuff has endpoint protection, and most end-users are covered by GateKeeper, XProtect and the standard Google safe browse whatever it's called thing. And since most of the basic users simply use webmail, that vector is covered as well. It's not as bad as it once was.

Re: IOHIDeous OS X Local Kernel Vulnerability

#106
post #48

Earlier quoted context omitted.

Needs to be running on the host already (nothing remote), achieves full system compromise by itself, but logs you out in the process. Can wait for logout though and is fast enough to run on shutdown/reboot until 10.13.1. On 10.13.2 it takes a fair bit longer (maybe half a minute) after logging out, so if your OS logs you out unexpectedly... maybe pull the plug? And maybe don't download & run untrusted software until…

Indeed, I always buy iMacs instead of MacBooks because I can actually pull the plug whenever something takes longer than anticipated.

It should not be too hard to build in a hardware-switch. Sure, it would take some time but think I would prefer that over always being stationary.

Re: IOHIDeous OS X Local Kernel Vulnerability

#107

Earlier quoted context omitted.

You can just press and hold the power button to shut a Macbook off. I assume this is a hardware level interrupt as I’ve never seen it fail. Granted not quite as satisfying as physically pulling the plug!

When they had power buttons you could

They still do, it just also does Touch ID now. Source: Have one.

Re: IOHIDeous OS X Local Kernel Vulnerability

#108
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

that would have been a withholder, not disclosure. you need to disclose the vulnerability to those who are vulnerable for it to be disclosure, and nothing else is responsible.

Re: IOHIDeous OS X Local Kernel Vulnerability

#109

Earlier quoted context omitted.

You imply by framing without explicitly stating that "coordinated disclosure" is "unlimited time", but that's not the time frame under discussion. I consider 24 hours notice bare minimum responsible disclosure, and 1 business day in the operating timezone of the company as an polite courtesy to the human beings who have to respond to uncoordinated security disclosures with emergency builds of their product. What do y…

> I consider 24 hours notice bare minimum responsible disclosure You can't possibly be serious? Have I fallen for some trolling here?!

That would be technically impossible, since you had no prior participation in this thread. I would have happily answered questions about my choice, but if your only question is “r u trolln” then there really is very little to say.

Rabble-rouse all you like, but unless you respond with whatever your personal bare minimum delay is, you risk being perceived as the troll in this exchange.

Re: IOHIDeous OS X Local Kernel Vulnerability

#110

Earlier quoted context omitted.

Well, it has been disclosed to black hats - just not for money. To end users the result is the same; black hats have an unpatched 0day to play with, and we have no mitigations to deploy.

The end result is not the same. You know about the bug as well, whereas if the bug + exploit was sold to black hats, they can use it without your awareness. This would be a less serious problem if vendors pushed out fixes faster.

Note that 99.99% or more of end users remain unaware of this bug, regardless of this HN post about it.
Post reply on HN