Live data from Hacker News

Google warns about two iOS zero-days 'exploited in the wild'

zdnet.com

51–60 of 89 posts

Re: Google warns about two iOS zero-days 'exploited in the wild'

#51
post #46

Earlier quoted context omitted.

>There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something While I understand the common ethos of our current culture supports this, has there been analysis if giving what could constitute a second chance to fix security issues leads to less prioritization of security initially? I could definitely see a business deciding to lower their security e…

If only Google would hold themselves accountable to the same standard. Android is a gigantic security mess, all caused and enabled by Google.

No it isn't? Android has a bug bounty program: https://www.google.com/about/appsecurity/android-rewards/

and regularly has strong showings at pwn2own. Android's security for the past couple of years has been superb.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#52
post #27

Earlier quoted context omitted.

I think the point is that he has an Android, but he can't update, while Apple users can.

If he bought an Android it's because he doesn't care about the security of his phone. Not trying to be snarky; Android has been around for over 10 years and we all know how irresponsible all OEMs are, including Google. He had the information when he made his purchase.

> If he bought an Android it's because he doesn't care about the security of his phone.

> Not trying to be snarky; Android has been around for over 10 years and we all know how irresponsible all OEMs are, including Google. He had the information when he made his purchase.

I care about the security of my devices and I don't want to pay the Apple tax (that is really absurd in Brazil; even with my quite good engineering salary it is still half of one month of work). I always buy supported devices and have monthly security updates on my Android One device.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#53

So far the two parent comments are quite negative, which surprises me. I understand the anti-Google sentiment, but Project Zero has been a much needed booster to the security of the public and it has born fruit. The fact that an iOS vulnerability is actively being exploited is notable. I think their method of responsible disclosure is reasonable.

Agreed — also these vulnerabilities can put human life at risk, as we’ve seen in recent months.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#54
post #42
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

Yeah, it's amazing that this is not called out more often. Android is a security mess.

Anybody can make an android phone and damage the brand. Compare pixels to iphones in pwn2own contests. They are at the very least equivalent.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#55

Earlier quoted context omitted.

The autoplay blocking involves a complicated set of heuristics involving the domain name and your past behavior with that domain...

So I just checked my heuristics at chrome://media-engagement/ and zdnet.com has a personal MEI of 0.0 with 7 visits (for comparison, YouTube is 0.76), and the stated threshold at the top of that page for allowing video with sound is min 0.2 max 0.3. So just ugh. Disappointed in Chrome that zdnet.com is somehow considered high enough quality to play videos with audio automatically. :(

zdnet.com has a score of 0 for me, and it still autoplayed.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#56
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

It is probably just a consequence of Project Zero being made up of experts on different topics. The iOS experts are quite prolific.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#57
post #50
post #42

Earlier quoted context omitted.

Yeah, it's amazing that this is not called out more often. Android is a security mess.

> Yeah, it's amazing that this is not called out more often. Android is a security mess. Nope, Android security is quite good actually. Not as good as iOS, however very good nonetheless. Of course, fragmentation issues and the fact that most Android devices are not updated do not help. However there is active mitigation of security issues both in kernel and in Android user space.

Just to complemented my previous comment, Android is probably one of the most secure Linux based devices in the world, probably only losing to ChromeOS.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#58

Earlier quoted context omitted.

The autoplay blocking involves a complicated set of heuristics involving the domain name and your past behavior with that domain...

So I just checked my heuristics at chrome://media-engagement/ and zdnet.com has a personal MEI of 0.0 with 7 visits (for comparison, YouTube is 0.76), and the stated threshold at the top of that page for allowing video with sound is min 0.2 max 0.3. So just ugh. Disappointed in Chrome that zdnet.com is somehow considered high enough quality to play videos with audio automatically. :(

Man, the first time this happened to me on ZDNet, I literally tweeted out to their Twitter account that they are idiots for putting that pattern in place. It's the loudest autoplay I have ever heard.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#59
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

[deleted]

Re: Google warns about two iOS zero-days 'exploited in the wild'

#60

Side question: whatever happened to Chrome blocking autoplay videos like this horrible and incredibly loud one? It's supposed to have been in place for a year or so... but it's clearly not working. If this particular one isn't blocked, then what ones are ? I'm on up-to-date Chrome 72... [1] https://developers.google.com/web/updates/2017/09/autoplay-p...

zdnet and a few others seem to be doing some tricks to get around it. I right click the tab and mute the site. CNN does the same and it's really freaking annoying.
Post reply on HN