Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

1–10 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#2
I really wonder how different the mobile security landscape would look if researchers were treated seriously. This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that. Along with your "post privacy" world, we may as well march this as the epoch of "post security". It just depends on how much someone is willing to spend to engineer one (or three) zero-days from your target's machine. This used to be feasible, but recent ransomware and surveillance malware has proven that it's commoditized now.

Re: Disclosure of three 0-day iOS vulnerabilities

#3
post #2

I really wonder how different the mobile security landscape would look if researchers were treated seriously. This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that. Along with your "post privacy" world, we may as well march this as the epoch of "post security". It just depends on how much someone is willing to spen…

>This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that.

What consequences are we living with?

Re: Disclosure of three 0-day iOS vulnerabilities

#4
Isn't this why most researchers just sell their 0days to Zerodium or drop it publicly? I've heard of multiple companies doing this type of BS. There was a person called Polarbear/sandboxescaper who dropped a few Win10 LPE's on GitHub. They claimed that Zerodium also only pays out a small amount then resells the exploit.

Re: Disclosure of three 0-day iOS vulnerabilities

#6
post #4

Isn't this why most researchers just sell their 0days to Zerodium or drop it publicly? I've heard of multiple companies doing this type of BS. There was a person called Polarbear/sandboxescaper who dropped a few Win10 LPE's on GitHub. They claimed that Zerodium also only pays out a small amount then resells the exploit.

Yes, that person did drop 0days publicly and then promptly faced an FBI investigation causing a tremendous level of stress and irreparable mental health damage.

Re: Disclosure of three 0-day iOS vulnerabilities

#7
This is such an incredible amount of vulnerable mission-critical data.

- all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi

and formerly,

- medical info - device usage - screen time - device accessories

I don't keep anything mission critical on mobile, but this is still a gargantuan set of exploits, and each appear extremely straightforward to validate and pay out the security researcher (and maybe even patch). It's utterly tragic how Apple (and others) have devolved to become the same monolithic, careless organizations they once displaced.

I really, really hope something changes. Soon.

Re: Disclosure of three 0-day iOS vulnerabilities

#8
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

Re: Disclosure of three 0-day iOS vulnerabilities

#9
post #3
post #2

I really wonder how different the mobile security landscape would look if researchers were treated seriously. This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that. Along with your "post privacy" world, we may as well march this as the epoch of "post security". It just depends on how much someone is willing to spen…

>This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that. What consequences are we living with?

Fear of data leaks for one. That’s never going to be zero, but it could be a lot better than it is.

Re: Disclosure of three 0-day iOS vulnerabilities

#10
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

> What about an exploit that can cause the users phone to explode?

Possibly world ending, at least from the perspective of the user whose phone explodes next to their face?

Post reply on HN