Live data from Hacker News

Google warns about two iOS zero-days 'exploited in the wild'

zdnet.com

41–50 of 89 posts

Re: Google warns about two iOS zero-days 'exploited in the wild'

#41
post #22

I wonder if one of these was used by the FBI's unlocking tool from the San Bernardino shooter case. That sort of just... fizzled out, with the FBI saying they could unlock iPhones themselves. Everybody kind of just said "yikes" to that statement and moved on... https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...

AIUI the mechanism the FBI used was already known to not work on newer devices at that time and only worked because the iPhone in question didn't have a secure enclave.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#42
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

Yeah, it's amazing that this is not called out more often. Android is a security mess.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#43
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

I don't know about Project Zero in particular, but yes, Google has security teams investigating their own projects. Why would you think otherwise?

And if you think there are security holes, you're welcome to report them to get a bug bounty.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#44

Earlier quoted context omitted.

I mean, the whole point of that issue was that the FBI wanted Apple to develop tools that would make it a lot easier for the FBI to do it later if they wanted to. It probably cost them a lot of money/time to do it the way they did. Plus, wasn't that the suspect's work phone anyway? So there really couldn't even be much that would have incriminated him on that phone. The point was setting a technological precedent.

> the FBI wanted Apple to develop tools that would make it a lot easier for the FBI to do it later if they wanted to. It probably cost them a lot of money/time to do it the way they did No, they wanted to set a legal precedent.

[deleted]

Re: Google warns about two iOS zero-days 'exploited in the wild'

#45

Earlier quoted context omitted.

I mean, the whole point of that issue was that the FBI wanted Apple to develop tools that would make it a lot easier for the FBI to do it later if they wanted to. It probably cost them a lot of money/time to do it the way they did. Plus, wasn't that the suspect's work phone anyway? So there really couldn't even be much that would have incriminated him on that phone. The point was setting a technological precedent.

> the FBI wanted Apple to develop tools that would make it a lot easier for the FBI to do it later if they wanted to. It probably cost them a lot of money/time to do it the way they did No, they wanted to set a legal precedent.

Precedent was already on the FBI's side, just as in the Lavabit case.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#46
post #32

Earlier quoted context omitted.

There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something (recently, seems mostly directed at Microsoft). This isn't one of those cases. They seem to have waited until Apple had a patch ready, they disclosed it to Apple and gave them an adequate amount of time to patch the vulnerability, and users are better for it. So in this case and others sim…

>There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something While I understand the common ethos of our current culture supports this, has there been analysis if giving what could constitute a second chance to fix security issues leads to less prioritization of security initially? I could definitely see a business deciding to lower their security e…

If only Google would hold themselves accountable to the same standard. Android is a gigantic security mess, all caused and enabled by Google.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#47
post #27

Earlier quoted context omitted.

I think the point is that he has an Android, but he can't update, while Apple users can.

If he bought an Android it's because he doesn't care about the security of his phone. Not trying to be snarky; Android has been around for over 10 years and we all know how irresponsible all OEMs are, including Google. He had the information when he made his purchase.

Or alternately, you buy from Google, keep up with OS upgrades, and plan on buying a new phone every 2-3 years or so. While not ideal, this is certainly doable.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#48
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

I don't know about Project Zero in particular, but yes, Google has security teams investigating their own projects. Why would you think otherwise? And if you think there are security holes, you're welcome to report them to get a bug bounty.

Well personally I would like it if they had write up's on them, even if only after the fact, as Project Zero has always come across to me as kind of a publicity stunt to try to improve their reputation to the tech industry and show how important they value security when the truth is quite different.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#49
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

Yes they have, here's one example: https://googleprojectzero.blogspot.com/2018/09/oatmeal-on-un...

Re: Google warns about two iOS zero-days 'exploited in the wild'

#50
post #42
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

Yeah, it's amazing that this is not called out more often. Android is a security mess.

> Yeah, it's amazing that this is not called out more often. Android is a security mess.

Nope, Android security is quite good actually. Not as good as iOS, however very good nonetheless.

Of course, fragmentation issues and the fact that most Android devices are not updated do not help.

However there is active mitigation of security issues both in kernel and in Android user space.

Post reply on HN