Live data from Hacker News

IOHIDeous OS X Local Kernel Vulnerability

siguza.github.io

111–120 of 121 posts

Re: IOHIDeous OS X Local Kernel Vulnerability

#111
post #24
post #2

Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?

Maybe if more people would disclose such vulnerabilities “irresponsibly”, vendors would develop their software more responsibly. Just my 2 cents ¯\_(ツ)_/¯

Unlikely. Security is hard, and a complex product like an OS and all it’s support programs creates a ton of surface area for attack.

Re: IOHIDeous OS X Local Kernel Vulnerability

#113

Earlier quoted context omitted.

> I consider 24 hours notice bare minimum responsible disclosure You can't possibly be serious? Have I fallen for some trolling here?!

That would be technically impossible, since you had no prior participation in this thread. I would have happily answered questions about my choice, but if your only question is “r u trolln” then there really is very little to say. Rabble-rouse all you like, but unless you respond with whatever your personal bare minimum delay is, you risk being perceived as the troll in this exchange.

Given...

> I consider 24 hours notice bare minimum responsible disclosure

...it seems rather unfair of you to have a go at my reaction. But somewhat incredibly, it appears you are serious.

I don't have a bare minimum delay - I think the vulnerability discover should coordinate a 'sensible' and 'fair' disclose with the vendor. What 'sensible' and 'fair' means, really depends - how serious is the vulnerability? How many systems are affected? How quickly can the vendor patch, test and document a fix? How quickly can the fix be distributed?

It's a stretch to imagine a scenario where 24 hours is in any way sensible, fair or responsible. I'd be intrigued to know your reasoning.

Re: IOHIDeous OS X Local Kernel Vulnerability

#114

Oh my I feel so sorry for apple security engineer's right now. I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? Makes me wonder who brushed this guy the wrong way, or if he just wants to watch the world burn. That said, seriously impressive work and I give him props.

> I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? CVE 2018-0001, it's all about namespaces.

Looks like that number was already reserved for a still unpublished vuln. We’re already up to > 3000 in 2018!

Re: IOHIDeous OS X Local Kernel Vulnerability

#115
post #57
post #50

Earlier quoted context omitted.

Since when did the term "responsible disclosure" mean allowing the vendor unlimited time to fix it?

When Microsoft decided they needed more than 90 days to release a patch. https://bugs.chromium.org/p/project-zero/issues/detail?id=10... I'd say 30 days is enough. Google was generous with ninety. (They too live in a glass house after all).

Not everything is a web app that can be patched in 5 minutes and doesn't need to run in one hundred million different environments.

Re: IOHIDeous OS X Local Kernel Vulnerability

#116

Earlier quoted context omitted.

> I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? CVE 2018-0001, it's all about namespaces.

Bonus points if they issue it as CVE-2018-65536 (pen-test the world, so to speak) EDIT: "No one would ever store the CVE incrementing fragment as a 16-bit unsigned int!"

You yourself clearly do not. (-:

Re: IOHIDeous OS X Local Kernel Vulnerability

#117
post #61

Earlier quoted context omitted.

If it's not unlimited, what's the limit? Apparently a month isn't long enough.

They admitted they never contacted Apple product security, which means they never notified Apple to begin with. That month you see at the top of the writeup appears to be how long they waited for ZDI before deciding to publish, not how long they waited for Apple to fix it.

So what? They owe Apple nothing. They owe you nothing.

Unless you are taking requests from random HN commenters for software that you would like to build them for free, I suggest you rethink your suggestion for highly skilled researchers to donate charity labor to the largest corporation in the world.

Re: IOHIDeous OS X Local Kernel Vulnerability

#118
post #61

Earlier quoted context omitted.

They admitted they never contacted Apple product security, which means they never notified Apple to begin with. That month you see at the top of the writeup appears to be how long they waited for ZDI before deciding to publish, not how long they waited for Apple to fix it.

So what? They owe Apple nothing. They owe you nothing. Unless you are taking requests from random HN commenters for software that you would like to build them for free, I suggest you rethink your suggestion for highly skilled researchers to donate charity labor to the largest corporation in the world.

This has nothing to do with owing Apple anything and instead has to do with not intentionally compromising the security of millions of innocent people around the world.

And before you interpret this to mean never disclosing publicly, that’s not what I’m saying. But no matter what your opinion is on the best way to handle disclosure, releasing a 0day without any attempt whatsoever to notify the vendor is highly irresponsible and immoral.

Re: IOHIDeous OS X Local Kernel Vulnerability

#119

Earlier quoted context omitted.

So what? They owe Apple nothing. They owe you nothing. Unless you are taking requests from random HN commenters for software that you would like to build them for free, I suggest you rethink your suggestion for highly skilled researchers to donate charity labor to the largest corporation in the world.

This has nothing to do with owing Apple anything and instead has to do with not intentionally compromising the security of millions of innocent people around the world. And before you interpret this to mean never disclosing publicly, that’s not what I’m saying. But no matter what your opinion is on the best way to handle disclosure, releasing a 0day without any attempt whatsoever to notify the vendor is highly irresp…

No, it isn't.

Re: IOHIDeous OS X Local Kernel Vulnerability

#120
post #30

Earlier quoted context omitted.

The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…

As a Mac user, I feel it’s irresponsible. I don’t want zero days published before Apple has a chance to fix. I also think that the vendor has a responsibility to fix the exploit quickly, and if not the researcher should publish and shame the vendor.

I don’t want zero days published before Apple has a chance to fix.

Because you think you are safe until publication?

What kind of "if I don't know about it, it isn't happening" worldview is that?

Post reply on HN