Live data from Hacker News

Google warns about two iOS zero-days 'exploited in the wild'

zdnet.com

21–30 of 89 posts

Re: Google warns about two iOS zero-days 'exploited in the wild'

#21

So far the two parent comments are quite negative, which surprises me. I understand the anti-Google sentiment, but Project Zero has been a much needed booster to the security of the public and it has born fruit. The fact that an iOS vulnerability is actively being exploited is notable. I think their method of responsible disclosure is reasonable.

Google in general has a pretty bad reputation when it comes to considering others. Which is usually fine because it is their business. Project Zero is different, but they adopt largely the same, or even worse, attitude. And at the end of the day software is a "human business". But it's a contentious issue so I am not sure it is worth discussing in a popularity based forum.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#22
I wonder if one of these was used by the FBI's unlocking tool from the San Bernardino shooter case. That sort of just... fizzled out, with the FBI saying they could unlock iPhones themselves. Everybody kind of just said "yikes" to that statement and moved on...

https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...

Re: Google warns about two iOS zero-days 'exploited in the wild'

#23

Side question: whatever happened to Chrome blocking autoplay videos like this horrible and incredibly loud one? It's supposed to have been in place for a year or so... but it's clearly not working. If this particular one isn't blocked, then what ones are ? I'm on up-to-date Chrome 72... [1] https://developers.google.com/web/updates/2017/09/autoplay-p...

The autoplay blocking involves a complicated set of heuristics involving the domain name and your past behavior with that domain...

Re: Google warns about two iOS zero-days 'exploited in the wild'

#25
post #22

I wonder if one of these was used by the FBI's unlocking tool from the San Bernardino shooter case. That sort of just... fizzled out, with the FBI saying they could unlock iPhones themselves. Everybody kind of just said "yikes" to that statement and moved on... https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...

I don't think so... these look like privilege escalations for apps, not a way to unlock the phone.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#26
post #22

I wonder if one of these was used by the FBI's unlocking tool from the San Bernardino shooter case. That sort of just... fizzled out, with the FBI saying they could unlock iPhones themselves. Everybody kind of just said "yikes" to that statement and moved on... https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...

I mean, the whole point of that issue was that the FBI wanted Apple to develop tools that would make it a lot easier for the FBI to do it later if they wanted to. It probably cost them a lot of money/time to do it the way they did. Plus, wasn't that the suspect's work phone anyway? So there really couldn't even be much that would have incriminated him on that phone. The point was setting a technological precedent.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#27
post #8

Earlier quoted context omitted.

And we don't? I want my phone to be as secure as possible because I use it for work, but of course, since it's not brand new I can't get updates.

This update is available to iPhones from the 5S and newer. The 5S was released in 2013. If your phone is older than that, it's a bit older than "not brand new".

I think the point is that he has an Android, but he can't update, while Apple users can.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#28
post #11

Earlier quoted context omitted.

I can understand this. Both of these options are better than what it was like in the 90's though. Back then it was "inform company about a bug, and get a non-disclosure agreement forced on you or a visit from the FBI". People forget that one of the reasons the 90's was such a hayday for hackers was that companies tried to fight hackers with court orders instead of actually fixing their stuff.

That's exactly right. I'm firmly of the opinion that "we'll give you 90 days to fix it before announcing" is responsible disclosure, as it motivates people to actually fix their stuff as opposed to filing the report away in the circular Jira.

I can somewhat get on board until the moment a 0day is observed in the wild, then it should be disclosed.

i can not protect my systems from things I am not aware of, allowing a vulnerability to be exploited for 60 days when on day 29 of "responsible disclosure" window the vulnerability was observed being actively exploited is not responsible either.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#29

So far the two parent comments are quite negative, which surprises me. I understand the anti-Google sentiment, but Project Zero has been a much needed booster to the security of the public and it has born fruit. The fact that an iOS vulnerability is actively being exploited is notable. I think their method of responsible disclosure is reasonable.

I'm about as far from a Google fanboy as one can get, but I'm definitely seconding this comment. Project Zero, OSS-Fuzz, a host of other projects have contributed enormously to software security in the last few years.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#30

Side question: whatever happened to Chrome blocking autoplay videos like this horrible and incredibly loud one? It's supposed to have been in place for a year or so... but it's clearly not working. If this particular one isn't blocked, then what ones are ? I'm on up-to-date Chrome 72... [1] https://developers.google.com/web/updates/2017/09/autoplay-p...

The autoplay blocking involves a complicated set of heuristics involving the domain name and your past behavior with that domain...

or you can just turn it off in new firefox...
Post reply on HN