I wonder if the culture of leaking and dissent within Apple is enabling information to leak which assists the 0day authors?
Disclosure of three 0-day iOS vulnerabilities
21–30 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#22Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…
Re: Disclosure of three 0-day iOS vulnerabilities
#23Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…
Their management of the bug bounty program seems like a reflection of their secretive (and perhaps sometimes siloed) internal culture. I'd argue that for any bug bounty program to be successful, there needs to be an inherent level of trust and very transparent lines of communication - seeing as though Apple lacks it internally (based on what I've read in reporting about the firm) it is not particularly surprising that their program happens to be run in the shadows as the OP describes.
I forget the exact term for it, but there is a "law" in management which postulates that the internal communication structures of teams are reflected in the final product that is shipped. The Apple bug bounty seems to be an example of just that.
Edit: Its called Conway's Law
Re: Disclosure of three 0-day iOS vulnerabilities
#24Earlier quoted context omitted.
If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?
You can do a lot more damage with someone's bank account than you can by exploding their phone.
A complete compromise can also get access to your bank, mail accounts, message history, mic and camera. Which vulnerability would you prefer be used against you?
Re: Disclosure of three 0-day iOS vulnerabilities
#25Earlier quoted context omitted.
If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?
> What about an exploit that can cause the users phone to explode? Possibly world ending, at least from the perspective of the user whose phone explodes next to their face?
Re: Disclosure of three 0-day iOS vulnerabilities
#26This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…
If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?
Exploits often feel like pathogens, probably why they share the term virus. If a virus has a high mortality rate, contagion is lower, because it frequently kills the host before it can spread.
Similarly, I think a 'complete device compromise' is much more likely to be identified, prioritized, and patched. The vulnerabilities mentioned here represent the highest severity without an immediately noticeable fallout. Props to the researcher.
P.S. I wonder if the researcher's Russian nationality (assumed from their other post) had any impact on their lack of payout.
Re: Disclosure of three 0-day iOS vulnerabilities
#27Re: Disclosure of three 0-day iOS vulnerabilities
#28This is crazy. At this point it's pretty well established that Apple isn't really going to pay you much if at all. Might as well disclose in 90 days at this point.
Full disclosure is always responsible, even if the vendor is not notified in advance.
Re: Disclosure of three 0-day iOS vulnerabilities
#29I like the poetic nature of exploiting that one.
Re: Disclosure of three 0-day iOS vulnerabilities
#30Why must iOS use WiFi to run critical security updates? I assume it’s a kickback from telecoms to reduce network bandwidth from users with unlimited mobile data plans?