Live data from Hacker News

FaceTime bug lets you hear audio of person you are calling before they pick up

9to5mac.com

281–290 of 458 posts

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#281

Earlier quoted context omitted.

This bug only applied to grub authentication, which isn't a widely used feature. And you could achieve the same result with boot from disk/USB if that is enabled. The vuln doesn't give you access to the actual accounts on the computer.

Let's not forget https://www.cvedetails.com/cve/CVE-2013-1050/ and https://www.cvedetails.com/cve/CVE-2015-7496/ and https://www.cvedetails.com/cve/CVE-2017-8900/ (to a lesser extent). Check out https://www.cvedetails.com/vulnerability-list.php?vendor_id=... for more fun.

not forgetting https://www.jwz.org/blog/2015/04/i-told-you-so-again/

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#282
"Sagem GSM phone let's you hear the other party's audio before you pick up" - Demonstrated this last time about 6 years ago calling my phone from different networks: fixed, and two other GSM. My conclusion was that it's an implementation bug easy to trip on or a provision in standard that it's easy to misread.

Now - if the audio channel is _right there_ for you to read, what chances are for this to be only a Sagem firmware bug?

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#283

Is it just me, or does it seem Apple can't secure their services as well as Google? There's always 'concerns' about Google spying, but no proof, meanwhile there's been major hacks involving Apple that are quickly forgotten because the CEO claims to be all about privacy.

the quantity of papers with major security flaws in android versus ios shows you all you need to know. there is an endless stream of android ones but very few ios okes

Key word is services. iCloud had a very public hack, now this. What Google services have been exploited?

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#284

I'm always curious how a bug like this ships. I mean QA & Testing should catch it, sure. But even before then. Some engineer wrote code for FaceTime that has it open the microphone before the call is accepted. And transmit the audio over the network before the call is accepted. Who did that? And why? I'm not suggesting malice but I do wonder at the lack of defensive programming.

Abstraction. I can tell you with 100% confidence that any of these logic bugs are created by unecessary abstraction. Anybody working in security will tell you the same. Piles of abstractions make it impossible to find out these bugs. You need a month of work to understand these codebases, often only the main developer has the architecture in its head.

> I can tell you with 100% confidence that any of these logic bugs are created by unecessary abstraction.

That's a lot of confidence…

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#285
post #273
post #271

Earlier quoted context omitted.

The genuineness of the Twitter account is absolutely irrelevant in contrast to the validity of the bug itself. Apple was reported a high priority bug at a specific time. Who reported it, how they look like, what their Twitter profile looks like should have no impact on Apple's bug fixing process and how long/short they took to fix the bug.

Oh I’m not questioning the existence or importance of the bug. It’s important and a big screwup. However, I am extra sensitive to the degree to which twitter is being manipulated for all sorts of ends. Sometimes things look more than a bit fishy. Usually major bug reports don’t come from 2019’s version of egg avatar + letters/numbers username + very recent activity consisting almost entirely of political posts + past…

What possible motivation would anyone have for reporting a real bug of this nature like this? Other than, yeah, found a crazy bug.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#286

Earlier quoted context omitted.

Several hours to a day, depending on how many components fail to build.

So every bugfix is a rebuild from current, not from "released"? This seems like not a real process.

I'm not sure if they have a special process for emergency bug fixes, but for internal testing a new build is done about daily from source, yes. One of these ends up being polished a bit and sent out to users.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#287

It may be entirely unrelated, however this is the exact sort of behaviour you would expect to see associated with providing compatibility with Australia's newly introduced AABill, or to implement GCHQ's ghost participant proposal ( https://www.lawfareblog.com/principles-more-informed-excepti... ).

I wish you weren't right.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#288

I'm always curious how a bug like this ships. I mean QA & Testing should catch it, sure. But even before then. Some engineer wrote code for FaceTime that has it open the microphone before the call is accepted. And transmit the audio over the network before the call is accepted. Who did that? And why? I'm not suggesting malice but I do wonder at the lack of defensive programming.

Lack of formal methods in the design phase. It would be trivial to express a rule that you cannot hear audio from the called person before they accept it with it.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#290

Rumor mill: FaceTime bug was submitted to Apple on 20 January 2019 by a concerned mother after .. her 14-year-old son discovered it. >My teen found a major security flaw in Apple’s new iOS. He can listen in to your iPhone/iPad without your approval. I have video. Submitted bug report to @AppleSupport...waiting to hear back to provide details. Scary stuff! #apple #bugreport @foxnews [0] https://twitter.com/mgt7500/sta…

If the mother did in fact submit a ticket a week ago, it's pretty shameful that the escalation / verification process took more than a week for a bug of this severity.

[deleted]
Post reply on HN