Live data from Hacker News

FaceTime bug lets you hear audio of person you are calling before they pick up

9to5mac.com

71–80 of 458 posts

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#71
post #51
post #42

Earlier quoted context omitted.

I feel like you're answering a different question that I asked. I don't think the bug is low-severity. I'm asking: Is there any historical evidence that high-severity bugs in iPhones (or really any mobile phone) are reputationally damaging, sufficiently that Apple would worry about the impact of this bug? I'm not aware of any instance in the past where a high-sev iPhone bug had noticable long-term impact. This is sim…

> Is there any historical evidence that high-severity bugs in iPhones (or really any mobile phone) are reputationally damaging, sufficiently that Apple would worry about the impact of this bug? I'm sure Apple "worries" about any bug and its potential impact on its reputation, particularly in the area of privacy, where it has a leg up on Android at least in perception. That said, what historical bug is up to this one…

https://www.zdnet.com/article/ios-mac-flaw-exposes-your-pass...

Where sending somebody a .tiff file via iMessage, web page, or email would give the attacker RCE on the device.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#72
post #44

Earlier quoted context omitted.

So… your theory is that if people understood pointers this wouldn’t have happened? I don’t think that follows.

>So… your theory is that if people understood pointers this wouldn’t have happened? Yes. But it has nothing to do with pointers specifically, just the mindset and training of the average developer who has had experience with them, vs. the average developer who has not. There's an entire generation of developers now graduating from CS programs, hiring into Apple, and getting dumped on these application teams with zero…

> The result is you have tons of brilliant people who can quickly whip up a DFS algorithm, but don't understand that using 4MB of RAM for a JPEG is unnacceptable, or that whatever dynamic thing they are asking the runtime to do might not always work as intended.

I’m not sure where you’re getting this anecdote from, because I have not found it to be at all true in practice.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#73

I'm always curious how a bug like this ships. I mean QA & Testing should catch it, sure. But even before then. Some engineer wrote code for FaceTime that has it open the microphone before the call is accepted. And transmit the audio over the network before the call is accepted. Who did that? And why? I'm not suggesting malice but I do wonder at the lack of defensive programming.

It reminds me of this MacOS bug from last year, where simply hitting the login box over and over with no password would eventually bypass the security entirely: https://www.theregister.co.uk/2017/11/28/root_access_bypass_... And this other MacOS bug, also from last year, where the password hint would contain the plain text encryption password: https://www.theregister.co.uk/2017/10/05/apple_patches_passw... All within…

I find those bugs less puzzling because the timeline makes sense. You're not logged in, there's a prompt, you're logged in. Obvious bug in the prompt, but the A happens before B happens before C order is there. Call comes in, audio is recorded, call is accepted is not the expected order. I could imagine a bug where declining the call still accepts the call, because that still obeys the proper ordering, but this bug does not.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#74
This is due to the very poor QA efforts Apple has, coupled with junior developers who lack a security-aware mindset. This is, sadly, the case with most companies these days. Zero secure coding training, zero push for security reviews, zero push for security QA, zero accountability.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#75
post #44

Earlier quoted context omitted.

So… your theory is that if people understood pointers this wouldn’t have happened? I don’t think that follows.

>So… your theory is that if people understood pointers this wouldn’t have happened? Yes. But it has nothing to do with pointers specifically, just the mindset and training of the average developer who has had experience with them, vs. the average developer who has not. There's an entire generation of developers now graduating from CS programs, hiring into Apple, and getting dumped on these application teams with zero…

Also failing to see the connection between this bug and using 4MB for a JPEG.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#76
post #71
post #51

Earlier quoted context omitted.

> Is there any historical evidence that high-severity bugs in iPhones (or really any mobile phone) are reputationally damaging, sufficiently that Apple would worry about the impact of this bug? I'm sure Apple "worries" about any bug and its potential impact on its reputation, particularly in the area of privacy, where it has a leg up on Android at least in perception. That said, what historical bug is up to this one…

https://www.zdnet.com/article/ios-mac-flaw-exposes-your-pass... Where sending somebody a .tiff file via iMessage, web page, or email would give the attacker RCE on the device.

The article slug is misleading, and suggests a fundamental misunderstanding of the scope of the bug. A RCE in Messages does not allow attackers to steal your passwords.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#78
post #3

That's a pretty huge flaw. Millions if not billions of people can suddenly remotely spy on almost any other ios or mac anywhere in the world, just by knowing their email address or phone number? Perhaps Apple should simply pull the plug on the facetime servers for now.

That's a pretty huge flaw. Millions if not... Is it just me, or is such a phrase applicable to Apple far too many times in the past several years? I think their engineering is losing quality or is falling behind on what they have to cover.

Quality concerns aside, any bug in iOS instantly affects a billion people by virtue of the number of active users it has.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#79
post #16
post #12

Security and privacy are two big parts of the marketing for the iPhone. I'm curious how they can mitigate the reputational damage. Edit: It gets worse: https://www.theverge.com/2019/1/28/18201383/apple-facetime-b... If the recipient rejects the call by pressing the power button, it starts sending video.

Why would this be any more reputationally damaging than the numerous other bugs with iPhone behavior? It’s not like iPhones have a reputation for not having bugs; it seems like every version has a passcode bypass or a DoS-via-iMessage. By some standards, this is worse (remotely triggerable, leaks audio/video), but in other cases it’s not as bad: the attacker’s Apple ID ends up in the call logs of the affected person.…

[deleted]

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#80

Earlier quoted context omitted.

You need to integrate the famous iTunes into this thesis. (people have complained about it approximately since it was released)

iTunes has always felt robust and well-architected, but it's UI has been a dumpster fire since whenever.

No way. I regularly have problems with it hanging or just ceasing to respond to “play” command. Ana this in on OS X, not windows.
Post reply on HN