Live data from Hacker News

Google warns about two iOS zero-days 'exploited in the wild'

zdnet.com

31–40 of 89 posts

Re: Google warns about two iOS zero-days 'exploited in the wild'

#31

Side question: whatever happened to Chrome blocking autoplay videos like this horrible and incredibly loud one? It's supposed to have been in place for a year or so... but it's clearly not working. If this particular one isn't blocked, then what ones are ? I'm on up-to-date Chrome 72... [1] https://developers.google.com/web/updates/2017/09/autoplay-p...

The autoplay blocking involves a complicated set of heuristics involving the domain name and your past behavior with that domain...

So I just checked my heuristics at chrome://media-engagement/ and zdnet.com has a personal MEI of 0.0 with 7 visits (for comparison, YouTube is 0.76), and the stated threshold at the top of that page for allowing video with sound is min 0.2 max 0.3.

So just ugh. Disappointed in Chrome that zdnet.com is somehow considered high enough quality to play videos with audio automatically. :(

Re: Google warns about two iOS zero-days 'exploited in the wild'

#32

So far the two parent comments are quite negative, which surprises me. I understand the anti-Google sentiment, but Project Zero has been a much needed booster to the security of the public and it has born fruit. The fact that an iOS vulnerability is actively being exploited is notable. I think their method of responsible disclosure is reasonable.

There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something (recently, seems mostly directed at Microsoft). This isn't one of those cases.

They seem to have waited until Apple had a patch ready, they disclosed it to Apple and gave them an adequate amount of time to patch the vulnerability, and users are better for it.

So in this case and others similar to it, kudos to Google.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#33
post #28

Earlier quoted context omitted.

That's exactly right. I'm firmly of the opinion that "we'll give you 90 days to fix it before announcing" is responsible disclosure, as it motivates people to actually fix their stuff as opposed to filing the report away in the circular Jira.

I can somewhat get on board until the moment a 0day is observed in the wild, then it should be disclosed. i can not protect my systems from things I am not aware of, allowing a vulnerability to be exploited for 60 days when on day 29 of "responsible disclosure" window the vulnerability was observed being actively exploited is not responsible either.

I'm with you. On that day, I assume everyone in the world except me knows how to exploit my system, and the vendor is racing the clock.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#35
post #27

Earlier quoted context omitted.

This update is available to iPhones from the 5S and newer. The 5S was released in 2013. If your phone is older than that, it's a bit older than "not brand new".

I think the point is that he has an Android, but he can't update, while Apple users can.

If he bought an Android it's because he doesn't care about the security of his phone.

Not trying to be snarky; Android has been around for over 10 years and we all know how irresponsible all OEMs are, including Google. He had the information when he made his purchase.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#36
post #22

I wonder if one of these was used by the FBI's unlocking tool from the San Bernardino shooter case. That sort of just... fizzled out, with the FBI saying they could unlock iPhones themselves. Everybody kind of just said "yikes" to that statement and moved on... https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...

I mean, the whole point of that issue was that the FBI wanted Apple to develop tools that would make it a lot easier for the FBI to do it later if they wanted to. It probably cost them a lot of money/time to do it the way they did. Plus, wasn't that the suspect's work phone anyway? So there really couldn't even be much that would have incriminated him on that phone. The point was setting a technological precedent.

> the FBI wanted Apple to develop tools that would make it a lot easier for the FBI to do it later if they wanted to. It probably cost them a lot of money/time to do it the way they did

No, they wanted to set a legal precedent.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#37
post #22

I wonder if one of these was used by the FBI's unlocking tool from the San Bernardino shooter case. That sort of just... fizzled out, with the FBI saying they could unlock iPhones themselves. Everybody kind of just said "yikes" to that statement and moved on... https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...

I consider all of these likely-

>FBI found someone inside they could negotiate with(IE- better patents or the threat of denied patents)

>FBI found someone they could bribe

>FBI hacked and broke into the iphone

3/3 of those Apple wants to keep quiet.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#38
Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#39
post #32

So far the two parent comments are quite negative, which surprises me. I understand the anti-Google sentiment, but Project Zero has been a much needed booster to the security of the public and it has born fruit. The fact that an iOS vulnerability is actively being exploited is notable. I think their method of responsible disclosure is reasonable.

There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something (recently, seems mostly directed at Microsoft). This isn't one of those cases. They seem to have waited until Apple had a patch ready, they disclosed it to Apple and gave them an adequate amount of time to patch the vulnerability, and users are better for it. So in this case and others sim…

>There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something

While I understand the common ethos of our current culture supports this, has there been analysis if giving what could constitute a second chance to fix security issues leads to less prioritization of security initially? I could definitely see a business deciding to lower their security expenditure since if an issue is found, they will be given a grace window to fix it before the world hears about it. It would still be damaging, but it would be far less since the PR machine could spit out that it was patched before it was announced to the world.

There has to have been some agreement to limit the grace period since people will go live once a reasonable time frame to fix it has passed and they won't be judged negatively if others agree reasonable time was given. So if we won't judge someone for giving only 6 months instead of 3 years, what about the one who gives only 2 weeks instead of 6 months? How do we calculate which of two time frames is better?

Post reply on HN