Live data from Hacker News

How to unc0ver a 0-day in 4 hours or less

googleprojectzero.blogspot.com

91–100 of 120 posts

Re: How to unc0ver a 0-day in 4 hours or less

#91
post #82

> So, to summarize: the LightSpeed bug was fixed in iOS 12 with a patch that didn't address the root cause and instead just turned the race condition double-free into a memory leak. Then, in iOS 13, this memory leak was identified as a bug and "fixed" by reintroducing the original bug, again without addressing the root cause of the issue. And this security regression could have been found trivially by running the ori…

What’s wrong with Apple? Why is modern iOS so buggy?

Don't worry, the exploits are being used only against oppressed minorities[1].

[1]https://arstechnica.com/information-technology/2019/09/apple...

Re: How to unc0ver a 0-day in 4 hours or less

#92
post #57

Earlier quoted context omitted.

The second paragraph of the article covers this: > I wanted to find the vulnerability used in unc0ver and report it to Apple quickly in order to demonstrate that obfuscating an exploit does little to prevent the bug from winding up in the hands of bad actors.

Maybe this should read "that obfuscating an exploit does little to prevent the bug from winding up in the hands of a talented full time security researcher ". Of course if he was this talented, surely he would routinely diff new kernel versions and realize the old bug had been reintroduced before having to rediscover it in a jailbreak?

> talented full time security researcher

If a single security researcher can de-obfuscate it in under a day, then a nation state with huge funding can too. Maybe not in a day, but eventually.

Re: How to unc0ver a 0-day in 4 hours or less

#94
post #87

Earlier quoted context omitted.

I don't really have the same opinion on this, I consider the obscurity of the platform a security issue by itself. At the end of the day, remote jailbreak exploits are pretty rare nowadays so you need to have a real access to the machine. To have an idea if an app is sharing your data you need to be jailbroken, to have an idea of what is being sent from your device you need to be jailbroken, to force a stricter contr…

We're discussing this on a story about an untethered jailbreak --- a kernel RCE.

Thethered, not untethered. There hasn’t been a tethered jailbreak in quite a while.

Re: How to unc0ver a 0-day in 4 hours or less

#95
post #87

Earlier quoted context omitted.

We're discussing this on a story about an untethered jailbreak --- a kernel RCE.

Yes that's true indeed, I was talking in general. Maybe having a more opened device would help getting security fixes faster? One of the main reason this exploit was heavily obfuscated was to avoid Apple to patch it.

I would doubt that. More likely, it was to keep the script kiddies away. (There’s currently drama going on in the community right now about stolen code…not that this us anything new :/)

Re: How to unc0ver a 0-day in 4 hours or less

#96
post #62

Earlier quoted context omitted.

But then we miss out on Apple's hardware quality, industry-crushing A-Series processors, and (for the most part) rock solid and extremely efficient OS.

You better hope they don't ever bring their premium-priced laptop "hardware quality" to their phones -- failing GPUs, failing monitor ribbon cables, failing keyboards ...

ipad pros are already there, they're so thin they can arrive bent right out of the box.

ipads and iphones are amazing hardware in every other respect but Apple really needs to chill with the ultra-thin fetish.

(same goes for their PC hardware, but the hardware is not particularly amazing there.)

Re: How to unc0ver a 0-day in 4 hours or less

#97
post #82

> So, to summarize: the LightSpeed bug was fixed in iOS 12 with a patch that didn't address the root cause and instead just turned the race condition double-free into a memory leak. Then, in iOS 13, this memory leak was identified as a bug and "fixed" by reintroducing the original bug, again without addressing the root cause of the issue. And this security regression could have been found trivially by running the ori…

What’s wrong with Apple? Why is modern iOS so buggy?

A friend at Apple told me that the testing story for iOS is complete shit, and they actually rely on hundreds of humans to test their software to make up for poor automated testing.

Apple takes the approach of throwing humans instead of automation at a problem quite frequently [1]:

> The press release mentions RMSI, an India-based, geospatial data firm that creates vegetation and 3D building datasets. And the office’s large headcount (now near 5,000) [used to create Apple Maps]

The lack of automated testing is something Apple is working on fixing, but they're a ways away from having anything substantial. The terrible iOS 13 release quite significantly bumped up the internal priority of stability and testing. iOS 14 is likely to be far less buggy than iOS 13 because of this culture change.

[1]: https://www.justinobeirne.com/new-apple-maps

Re: How to unc0ver a 0-day in 4 hours or less

#98
post #15

Earlier quoted context omitted.

Project Zero researchers don’t take bounties, to my knowledge.

Nor have they been ever offered one, to my knowledge: https://twitter.com/i41nbeer/status/1027339893335154688 . I'm actually not sure Apple has ever paid a bounty for anything that wasn't a web issue…

If memory serves, they've been offered but the bounties are always been given to charity.

I'm guessing that's a policy/requirement of Project Zero as, presumably, the P0 folks are making "enough" already.

Re: How to unc0ver a 0-day in 4 hours or less

#99

> By 1 AM, I had sent Apple a POC and my analysis. > Still, I'm very happy that Apple patched this issue in a timely manner once the exploit became public. Sh- should we be happy Apple fixed this so quickly? unc0ver allows consumers to get more out of their Apple devices, and Apple's fix isn't really optional (unless you disable auto-updates and tap "Later" on every update notification). Is this exploit even an issue…

> unless you disable auto-updates and tap "Later" on every update notification

Some of us do that for this exact reason. I wish there was a way for me to just pick software to give root to though, this is way less secure.

Re: How to unc0ver a 0-day in 4 hours or less

#100

Earlier quoted context omitted.

It’s always a snake eating it’s tail scenario with jailbreaking. Apple takes popular tweaks and integrates them with the next IOS. Side-loading isn’t that bad but the method keeps changing...Usually for the better. Jail breaking cuts into their profit a small amount because the community is small. https://www.reddit.com/r/jailbreak The benefits are very much worth it though. Most have had iOS 13 features since iOS 11…

Or you could just buy an android and not worry about it. Not even to fan boy, but half of those are things that android did from the go and the rest have been added or are generally easy to do.

[deleted]
Post reply on HN