Live data from Hacker News

Google warns about two iOS zero-days 'exploited in the wild'

zdnet.com

71–80 of 89 posts

Re: Google warns about two iOS zero-days 'exploited in the wild'

#71
post #69

Earlier quoted context omitted.

That's a symptom of cybersecurity. If a law made a security bug a refundable or warrantied defect, I bet you this shit would stop. But noone gives a shit.

It would also seriously stymie innovation. If I risk having to refund an item when I push out improvements, I'm never bothering to push out improvements except bug fixes. I'm also incentivized to release a new model every month with ANY improvement in order to limit my liability to a smaller window of revenue. The current system isn't perfect, but it could be much worse.

What's worse that thousands of pieces of throwaway hardware that don't get updates? How about thousands of enterprise systems where the security updates are hidden behind support contacts?

> when I push out improvements

No, if your software has a security issue, it's refundable. Write good software.

> release a new model every month with ANY improvement

Good, but that doesn't remove your liability from your last model.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#72
post #32

Earlier quoted context omitted.

There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something (recently, seems mostly directed at Microsoft). This isn't one of those cases. They seem to have waited until Apple had a patch ready, they disclosed it to Apple and gave them an adequate amount of time to patch the vulnerability, and users are better for it. So in this case and others sim…

>There are cases that I'm all for bashing Google when they don't give the company they're targeting enough time to patch something While I understand the common ethos of our current culture supports this, has there been analysis if giving what could constitute a second chance to fix security issues leads to less prioritization of security initially? I could definitely see a business deciding to lower their security e…

I imagine they share proof of concept 100% of the time, and if that is the case, I’d say it varies: target a window, say 2 months. At that point, show progress on the bug to Google (or whoever). If at the 2 month mark it is obvious it was low priority and not really looked at, the vendor of the application failed in which case I would say disclose away (bonus points if they provide something to mitigate it, if possible, though onus is not really on them either way). If they can tell the software vendor is making progress/genuinely attempting, then I’d say an extension would be fair.

In the Microsoft case that vaguely comes to mind, I believe the issue was one that required a bit of work because it was pretty low level for Windows. I want security patches on my system ASAP, but I also don’t want someone to release something that breaks my OS’s functionality or renders my files (or the ability to open files) fubared either. If memory serves, they were making progress on it, but it went past the time period Project Zero set and they were unwilling to give an extension and as far as was reported, didn’t seem to be exploited in the wild. But then you have something unpatched that is disclosed by Google. That doesn’t help users all that much.

That is all to say it isn’t being verifiably exploited in the wild. When that is the case, that changes things to the point users need to be made aware as soon as possible and if it means “turning off” a feature, if possible, as a stopgap, give that info to them.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#73

Earlier quoted context omitted.

Or alternately, you buy from Google, keep up with OS upgrades, and plan on buying a new phone every 2-3 years or so. While not ideal, this is certainly doable.

So the only way that you can get an Android phone with any type of security is by buying one from Google. So much for Andy Rubin and his promise of openness and choices...

Motorola is pretty good too. Maybe others?

Re: Google warns about two iOS zero-days 'exploited in the wild'

#74

Side question: whatever happened to Chrome blocking autoplay videos like this horrible and incredibly loud one? It's supposed to have been in place for a year or so... but it's clearly not working. If this particular one isn't blocked, then what ones are ? I'm on up-to-date Chrome 72... [1] https://developers.google.com/web/updates/2017/09/autoplay-p...

Chrome has an overall whitelist on top of a user-specific one. I assume that ZDNet overall has a high enough MEI score across all Chrome users that it's allowed until you train the algorithm that you don't want to see it.

Additionally, if you navigate within a site (ie, click on another ZDNet article from that same page), that counts as a website interaction, and the new page will be allowed to autoplay.

Firefox's upcoming controls are user-controlled instead of based on algorithmic behavior, and they don't have a whitelist. They're available right now, but not turned on by default (yet).

Re: Google warns about two iOS zero-days 'exploited in the wild'

#75
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

Are you serious? The Pixel has gone 2 straight years without being hacked at pwn2own events while the iPhone has been hacked and brought to its knees Every Single Time.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#76
post #69

Earlier quoted context omitted.

It would also seriously stymie innovation. If I risk having to refund an item when I push out improvements, I'm never bothering to push out improvements except bug fixes. I'm also incentivized to release a new model every month with ANY improvement in order to limit my liability to a smaller window of revenue. The current system isn't perfect, but it could be much worse.

What's worse that thousands of pieces of throwaway hardware that don't get updates? How about thousands of enterprise systems where the security updates are hidden behind support contacts? > when I push out improvements No, if your software has a security issue, it's refundable. Write good software. > release a new model every month with ANY improvement Good, but that doesn't remove your liability from your last mode…

>No, if your software has a security issue, it's refundable. Write good software.

There are 0 companies that can provide consumer software on the lifecycle consumers have come to expect without any bugs. You write software. Are you willing to claim that you can just "write good software" and never ship anything with a security issues?

Because otherwise you're advocating for consumer tools that use nasa's release cycle. Which like, that's cool and all but I don't want to rely on hardware from 2012 or 2005 running software that was developed from 2010-2014 and has just finished its verification process. You're advocating for a world where we just got the verifiably bug-free Nokia 3310.

And that doesn't even begin to discuss the clusterfuck that would be open-source in this situation. Am I liable for heartbleed because I use OpenSSL? Are the openSSL devs?

Re: Google warns about two iOS zero-days 'exploited in the wild'

#77
post #46

Earlier quoted context omitted.

If only Google would hold themselves accountable to the same standard. Android is a gigantic security mess, all caused and enabled by Google.

No it isn't? Android has a bug bounty program: https://www.google.com/about/appsecurity/android-rewards/ and regularly has strong showings at pwn2own. Android's security for the past couple of years has been superb.

There are millions of unpatched Android devices, probably forming a massive botnet by now. When you read it in the news sometime in the future, remember this post. You read it here first.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#78

Earlier quoted context omitted.

Anybody can make an android phone and damage the brand. Compare pixels to iphones in pwn2own contests. They are at the very least equivalent.

That covers the 3 million phones a year that Google sells what about the other 1.2 billion plus? https://www.forbes.com/sites/chuckjones/2018/03/10/apples-io...

If you are worried about Google's security practices, why look at things other than Google's products?

Re: Google warns about two iOS zero-days 'exploited in the wild'

#79
post #38

Just a quick question for anyone more knowledgeable, has Project Zero ever bothered reporting or investigating any Google products, such as their clusterfuck of an OS more widely known as Android as I'm pretty sure that would be full of exploits if anyone was seriously looking for them.

If you navigate to https://googleprojectzero.blogspot.com the first story is about a vulnerability in skia, a library made by Google:

https://googleprojectzero.blogspot.com/2019/02/the-curious-c...

Re: Google warns about two iOS zero-days 'exploited in the wild'

#80

Earlier quoted context omitted.

Or alternately, you buy from Google, keep up with OS upgrades, and plan on buying a new phone every 2-3 years or so. While not ideal, this is certainly doable.

So the only way that you can get an Android phone with any type of security is by buying one from Google. So much for Andy Rubin and his promise of openness and choices...

The other alternative is also locked into one company.
Post reply on HN