Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

21–30 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#22

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Bug bounty programs are the antithesis of Apple's internal methodology, culture, and way of doing business. They keep everything close to the chest, they shun "outsiders", etc.. The idea that someone outside of Apple, from the unwashed masses, could find a flaw in Apple's own software is a pretty big pill for them to swallow. Thus it doesn't surprise me there are problems with their bug bounty program. I think if they could they would prefer to just silence all vulnerability/bug reports with a gag order rather than acknowledging or even investigating them.

Re: Disclosure of three 0-day iOS vulnerabilities

#23

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Disclaimer: I am not an Apple insider by any means, and this is all a hypothesis.

Their management of the bug bounty program seems like a reflection of their secretive (and perhaps sometimes siloed) internal culture. I'd argue that for any bug bounty program to be successful, there needs to be an inherent level of trust and very transparent lines of communication - seeing as though Apple lacks it internally (based on what I've read in reporting about the firm) it is not particularly surprising that their program happens to be run in the shadows as the OP describes.

I forget the exact term for it, but there is a "law" in management which postulates that the internal communication structures of teams are reflected in the final product that is shipped. The Apple bug bounty seems to be an example of just that.

Edit: Its called Conway's Law

Re: Disclosure of three 0-day iOS vulnerabilities

#24
post #19

Earlier quoted context omitted.

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

You can do a lot more damage with someone's bank account than you can by exploding their phone.

Won’t matter much if it burns your house down while you’re inside.

A complete compromise can also get access to your bank, mail accounts, message history, mic and camera. Which vulnerability would you prefer be used against you?

Re: Disclosure of three 0-day iOS vulnerabilities

#25
post #10

Earlier quoted context omitted.

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

> What about an exploit that can cause the users phone to explode? Possibly world ending, at least from the perspective of the user whose phone explodes next to their face?

I’m not saying the above issues don’t matter, but they’re hardly the most critical things you could do to an iPhone.

Re: Disclosure of three 0-day iOS vulnerabilities

#26
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

I would be an order of magnitude less concerned with camera/mic access, compared to perfect historical proof of my usage and communication patterns.

Exploits often feel like pathogens, probably why they share the term virus. If a virus has a high mortality rate, contagion is lower, because it frequently kills the host before it can spread.

Similarly, I think a 'complete device compromise' is much more likely to be identified, prioritized, and patched. The vulnerabilities mentioned here represent the highest severity without an immediately noticeable fallout. Props to the researcher.

P.S. I wonder if the researcher's Russian nationality (assumed from their other post) had any impact on their lack of payout.

Re: Disclosure of three 0-day iOS vulnerabilities

#28
post #11

This is crazy. At this point it's pretty well established that Apple isn't really going to pay you much if at all. Might as well disclose in 90 days at this point.

Full disclosure is always responsible, even if the vendor is not notified in advance.

This is a part of our industry I do not follow beyond headlines. A lot of those headlines are about hackers trying to be responsible getting screwed out of supposed bounties that to my mind already appear quite small. Also responsible companies doing very little to quickly close them. Does anyone have any insight into how the market for vulnerabilities operates? Is there is a significant disparity in price between official/responsible disclosures and private sales?
Post reply on HN