Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

31–40 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#31

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Apple has always been infamously bad at doing anything with external bug reports. Radar is a black hole that is indistinguishable from submitting bug reports to /dev/null unless you have a backchannel contact who can ensure that the right person sees the report.

Bug bounty programs are significantly more difficult to run than a normal bug reporting service, so the fact that they're so bad at handling the easy case makes it no surprise that they're terrible at handling security bugs too.

Re: Disclosure of three 0-day iOS vulnerabilities

#32
Maybe it's just me, but these aren't what I think of when I hear 0-day.

These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though.

That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.

Re: Disclosure of three 0-day iOS vulnerabilities

#33
post #2

I really wonder how different the mobile security landscape would look if researchers were treated seriously. This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that. Along with your "post privacy" world, we may as well march this as the epoch of "post security". It just depends on how much someone is willing to spen…

I never thought that hacking like in Star Trek will be anytime truth. But it looks like we slowy head for it...

Re: Disclosure of three 0-day iOS vulnerabilities

#36
post #10

Earlier quoted context omitted.

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

> What about an exploit that can cause the users phone to explode? Possibly world ending, at least from the perspective of the user whose phone explodes next to their face?

Do like GM, keep your phone at least 5 feet away from other phones while not in use.

Re: Disclosure of three 0-day iOS vulnerabilities

#37
post #27

Why must iOS use WiFi to run critical security updates? I assume it’s a kickback from telecoms to reduce network bandwidth from users with unlimited mobile data plans?

Does iOS have any way of telling if you’re on an unlimited data plan? If not, maybe it’s just to prevent the footgun (and subsequent bad PR) of somebody accidentally updating the OS over an expensive metered connection. But it could also be a carrier demand, not really sure.

Re: Disclosure of three 0-day iOS vulnerabilities

#38

Maybe it's just me, but these aren't what I think of when I hear 0-day. These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though. That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.

FYI, 0-day just means "first time made public".

Re: Disclosure of three 0-day iOS vulnerabilities

#39

Maybe it's just me, but these aren't what I think of when I hear 0-day. These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though. That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.

From an earlier post: This is a boat load of mission critical data.

- all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi

- medical info - device usage - screen time - device accessories

Re: Disclosure of three 0-day iOS vulnerabilities

#40
post #37
post #27

Why must iOS use WiFi to run critical security updates? I assume it’s a kickback from telecoms to reduce network bandwidth from users with unlimited mobile data plans?

Does iOS have any way of telling if you’re on an unlimited data plan? If not, maybe it’s just to prevent the footgun (and subsequent bad PR) of somebody accidentally updating the OS over an expensive metered connection. But it could also be a carrier demand, not really sure.

Settings > Cellular

It shows my carrier, amount of data used and shows remaining on my plan.

Mine reads,

    Usage: Used 7.43GB - Unlimited
If I click on it it has 3 fields.

Data, Calls, Messages

Data reads the same here. Calls and Messages simply say ‘Unlimited’

Post reply on HN