Live data from Hacker News

Apple patches CVE-2020-9859 (unc0ver)

support.apple.com

21–30 of 79 posts

Re: Apple patches CVE-2020-9859 (unc0ver)

#21

Earlier quoted context omitted.

Did your boss ask you to police hn against negative apple feedback?

I currently don't have one, so…no? I do usually try to keep Hacker News clean of low-quality comments, though, which is fairly distinct from "negative apple feedback".

I'm confused by the GP's us-vs-them animosity. There was an interesting issue that got buried in a polarizing "fan" vs "hater" dynamic. :'( Sigh

Like, shouldn't most high-end consumer devices include a dedicated update storage partition or flash area so that user storage is never impacted?

Re: Apple patches CVE-2020-9859 (unc0ver)

#22
post #20

Earlier quoted context omitted.

Which two Mac drive options are only 1.5GB apart?

Strawman. An almost full 256 GB SSD MBP would obviously need the next one up, but it's moot if it's soldered on unless you're a Louis Rossmann fan with the microsoldering and microscope play-at-home pack.

No my point is 1.5 GB is too small a transient (you delete the download when done) requirement to make someone have to bump up disk sizes.

Re: Apple patches CVE-2020-9859 (unc0ver)

#24

I think this might be the fastest patch of a security issue affecting Apple's operating systems, ever. Aside from *.0.1 releases that fixed critical bugs with core features in new OSes, has anything been patched this fast? (I'm also obligated to post that the bug that this fixes is not new; it was discovered back in iOS 11, fixed, and Apple reopened it in an iOS 13 update: https://www.synacktiv.com/posts/exploit/retu…

I have a pretty clear memory of the JailbreakMe 2/3 bugs (which, for anyone else reading, were bugs that could be used from the web browser, and so were of the form "you click a link or have some evil iframe and are pwned") being fixed in six days (which I mentally cataloged as the minimum turnaround time Apple could muster).

Re: Apple patches CVE-2020-9859 (unc0ver)

#25
post #21

Earlier quoted context omitted.

I currently don't have one, so…no? I do usually try to keep Hacker News clean of low-quality comments, though, which is fairly distinct from "negative apple feedback".

I'm confused by the GP's us-vs-them animosity. There was an interesting issue that got buried in a polarizing "fan" vs "hater" dynamic. :'( Sigh Like, shouldn't most high-end consumer devices include a dedicated update storage partition or flash area so that user storage is never impacted?

And it's a much more interesting topic than trying to figure out if I'm an Apple astroturfer, which in itself is strange because the top comment in this very thread is me pointing out that Apple unpatched this bug in iOS 13…plus it's against the site guidelines, which is why I assume that the comments have been flagged.

But back on topic: there are some devices that do include a specific partition for updates, but I don't think it's usually for user storage, but for "seamless updates": you install the OS to the other partition, reboot, and the partitions swap and you have a new OS up and running immediately. I actually doubt that any manufacturer would forgo not counting that as part of their user storage, unfortunately…

Re: Apple patches CVE-2020-9859 (unc0ver)

#27
post #23

From the equivalent macOS patch: https://support.apple.com/en-us/HT211215 > Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15.5 That's interesting—did the bug exist on both 10.13 and 10.15, but not 10.14?

So, it is a bug in macOS or iOS? Both?

Fixes were pushed out for all four major platforms today, presumably as the affected system call is available on all of them.

Re: Apple patches CVE-2020-9859 (unc0ver)

#28
post #24

I think this might be the fastest patch of a security issue affecting Apple's operating systems, ever. Aside from *.0.1 releases that fixed critical bugs with core features in new OSes, has anything been patched this fast? (I'm also obligated to post that the bug that this fixes is not new; it was discovered back in iOS 11, fixed, and Apple reopened it in an iOS 13 update: https://www.synacktiv.com/posts/exploit/retu…

I have a pretty clear memory of the JailbreakMe 2/3 bugs (which, for anyone else reading, were bugs that could be used from the web browser, and so were of the form "you click a link or have some evil iframe and are pwned") being fixed in six days (which I mentally cataloged as the minimum turnaround time Apple could muster).

That's a bit before I was using iOS, so I'll take your word on that one ;) AFAIK some system call filtering went into WebKit at some point to make this specific exploit unreachable from the web process, so I guess you could call it "less severe" than JailbreakMe was. That being said, I guess "zero day affecting all current devices" is probably good enough to get priority. (FWIW, heavily publicized non-security bugs often get quicker updates, sometimes within one or two days, which I assume pushes close to how quickly they can get a fix merged and through B&I.)

Re: Apple patches CVE-2020-9859 (unc0ver)

#29

From the equivalent macOS patch: https://support.apple.com/en-us/HT211215 > Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15.5 That's interesting—did the bug exist on both 10.13 and 10.15, but not 10.14?

If it is true the bug was present in iOS 11 and fixed in iOS 12 before being reintroduced in iOS 13, that might align with macOS 10.14 (≈ iOS 12) being unaffected.

Re: Apple patches CVE-2020-9859 (unc0ver)

#30
post #24

Earlier quoted context omitted.

I have a pretty clear memory of the JailbreakMe 2/3 bugs (which, for anyone else reading, were bugs that could be used from the web browser, and so were of the form "you click a link or have some evil iframe and are pwned") being fixed in six days (which I mentally cataloged as the minimum turnaround time Apple could muster).

That's a bit before I was using iOS, so I'll take your word on that one ;) AFAIK some system call filtering went into WebKit at some point to make this specific exploit unreachable from the web process, so I guess you could call it "less severe" than JailbreakMe was. That being said, I guess "zero day affecting all current devices" is probably good enough to get priority. (FWIW, heavily publicized non-security bugs o…

That syscall filtering still exists and broke a build for three or four days recently.
Post reply on HN