Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

11–20 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#11

This is crazy. At this point it's pretty well established that Apple isn't really going to pay you much if at all. Might as well disclose in 90 days at this point.

Full disclosure is always responsible, even if the vendor is not notified in advance.

Re: Disclosure of three 0-day iOS vulnerabilities

#12
Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?)

I would think that, given the profitability and positioning of Apple in the marketplace, that they would be heavily incentivized to provide large bounties for finding such destructive vulnerabilities. And I imagine that there are plenty of security people working there who genuinely care about fixing fix these issues right away.

Re: Disclosure of three 0-day iOS vulnerabilities

#13
post #4

Isn't this why most researchers just sell their 0days to Zerodium or drop it publicly? I've heard of multiple companies doing this type of BS. There was a person called Polarbear/sandboxescaper who dropped a few Win10 LPE's on GitHub. They claimed that Zerodium also only pays out a small amount then resells the exploit.

There aren't worth anything to Zerodium afaik

Re: Disclosure of three 0-day iOS vulnerabilities

#15
If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product.

I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a unique password on every site, so it is difficult for something like this to have a significant impact. Nethertheless, I was compromised on hundreds of sites and products, and those were just the accounts that iOS Safari knew about. None of them bothered to reach out and tell me. Even my coffee machine was compromised. Ridiculous.

Re: Disclosure of three 0-day iOS vulnerabilities

#16
post #6
post #4

Isn't this why most researchers just sell their 0days to Zerodium or drop it publicly? I've heard of multiple companies doing this type of BS. There was a person called Polarbear/sandboxescaper who dropped a few Win10 LPE's on GitHub. They claimed that Zerodium also only pays out a small amount then resells the exploit.

Yes, that person did drop 0days publicly and then promptly faced an FBI investigation causing a tremendous level of stress and irreparable mental health damage.

It looks like that they no longer work for Microsoft anymore. Weren't they making some not so great comments before the FBI investigation though?

Re: Disclosure of three 0-day iOS vulnerabilities

#17

I wonder if the culture of leaking and dissent within Apple is enabling information to leak which assists the 0day authors?

did you mean 0day exploit authors? otherwise, wouldn't the actual authors of the 0day be Apple employees on the iOS team?

Re: Disclosure of three 0-day iOS vulnerabilities

#18
post #4

Isn't this why most researchers just sell their 0days to Zerodium or drop it publicly? I've heard of multiple companies doing this type of BS. There was a person called Polarbear/sandboxescaper who dropped a few Win10 LPE's on GitHub. They claimed that Zerodium also only pays out a small amount then resells the exploit.

There aren't worth anything to Zerodium afaik

Maybe they would've been to ZDI.

Re: Disclosure of three 0-day iOS vulnerabilities

#19
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

You can do a lot more damage with someone's bank account than you can by exploding their phone.

Re: Disclosure of three 0-day iOS vulnerabilities

#20
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

> I really, really hope something changes. Soon.

I would not hold my breath... it's been like this for decades at least.

Post reply on HN