Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
Maybe if more people would disclose such vulnerabilities “irresponsibly”, vendors would develop their software more responsibly. Just my 2 cents ¯\_(ツ)_/¯
IOHIDeous OS X Local Kernel Vulnerability
111–120 of 121 posts
Re: IOHIDeous OS X Local Kernel Vulnerability
#112Re: IOHIDeous OS X Local Kernel Vulnerability
#113Earlier quoted context omitted.
> I consider 24 hours notice bare minimum responsible disclosure You can't possibly be serious? Have I fallen for some trolling here?!
That would be technically impossible, since you had no prior participation in this thread. I would have happily answered questions about my choice, but if your only question is “r u trolln” then there really is very little to say. Rabble-rouse all you like, but unless you respond with whatever your personal bare minimum delay is, you risk being perceived as the troll in this exchange.
> I consider 24 hours notice bare minimum responsible disclosure
...it seems rather unfair of you to have a go at my reaction. But somewhat incredibly, it appears you are serious.
I don't have a bare minimum delay - I think the vulnerability discover should coordinate a 'sensible' and 'fair' disclose with the vendor. What 'sensible' and 'fair' means, really depends - how serious is the vulnerability? How many systems are affected? How quickly can the vendor patch, test and document a fix? How quickly can the fix be distributed?
It's a stretch to imagine a scenario where 24 hours is in any way sensible, fair or responsible. I'd be intrigued to know your reasoning.
Re: IOHIDeous OS X Local Kernel Vulnerability
#114Oh my I feel so sorry for apple security engineer's right now. I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? Makes me wonder who brushed this guy the wrong way, or if he just wants to watch the world burn. That said, seriously impressive work and I give him props.
> I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? CVE 2018-0001, it's all about namespaces.
Re: IOHIDeous OS X Local Kernel Vulnerability
#115Earlier quoted context omitted.
Since when did the term "responsible disclosure" mean allowing the vendor unlimited time to fix it?
When Microsoft decided they needed more than 90 days to release a patch. https://bugs.chromium.org/p/project-zero/issues/detail?id=10... I'd say 30 days is enough. Google was generous with ninety. (They too live in a glass house after all).
Re: IOHIDeous OS X Local Kernel Vulnerability
#116Earlier quoted context omitted.
> I'm curious the motivations to release such a serious, and complex, 0day on new years eve!? CVE 2018-0001, it's all about namespaces.
Bonus points if they issue it as CVE-2018-65536 (pen-test the world, so to speak) EDIT: "No one would ever store the CVE incrementing fragment as a 16-bit unsigned int!"
Re: IOHIDeous OS X Local Kernel Vulnerability
#117Earlier quoted context omitted.
If it's not unlimited, what's the limit? Apparently a month isn't long enough.
They admitted they never contacted Apple product security, which means they never notified Apple to begin with. That month you see at the top of the writeup appears to be how long they waited for ZDI before deciding to publish, not how long they waited for Apple to fix it.
Unless you are taking requests from random HN commenters for software that you would like to build them for free, I suggest you rethink your suggestion for highly skilled researchers to donate charity labor to the largest corporation in the world.
Re: IOHIDeous OS X Local Kernel Vulnerability
#118Earlier quoted context omitted.
They admitted they never contacted Apple product security, which means they never notified Apple to begin with. That month you see at the top of the writeup appears to be how long they waited for ZDI before deciding to publish, not how long they waited for Apple to fix it.
So what? They owe Apple nothing. They owe you nothing. Unless you are taking requests from random HN commenters for software that you would like to build them for free, I suggest you rethink your suggestion for highly skilled researchers to donate charity labor to the largest corporation in the world.
And before you interpret this to mean never disclosing publicly, that’s not what I’m saying. But no matter what your opinion is on the best way to handle disclosure, releasing a 0day without any attempt whatsoever to notify the vendor is highly irresponsible and immoral.
Re: IOHIDeous OS X Local Kernel Vulnerability
#119Earlier quoted context omitted.
So what? They owe Apple nothing. They owe you nothing. Unless you are taking requests from random HN commenters for software that you would like to build them for free, I suggest you rethink your suggestion for highly skilled researchers to donate charity labor to the largest corporation in the world.
This has nothing to do with owing Apple anything and instead has to do with not intentionally compromising the security of millions of innocent people around the world. And before you interpret this to mean never disclosing publicly, that’s not what I’m saying. But no matter what your opinion is on the best way to handle disclosure, releasing a 0day without any attempt whatsoever to notify the vendor is highly irresp…
Re: IOHIDeous OS X Local Kernel Vulnerability
#120Earlier quoted context omitted.
The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it. Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0] "When we receive your email, we send an automatic email as acknowledgment…
As a Mac user, I feel it’s irresponsible. I don’t want zero days published before Apple has a chance to fix. I also think that the vendor has a responsibility to fix the exploit quickly, and if not the researcher should publish and shame the vendor.
Because you think you are safe until publication?
What kind of "if I don't know about it, it isn't happening" worldview is that?