Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

61–70 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#61

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

It's interesting to me that in this entire thread, nobody is even mentioning or considering the possibility that COVID has impacted Apple's operations.

It obviously has. It has affected every tech company. Certainly it has affected mine. Whether this is an example of that, I don't know, of course, but I think it's plausible.

Re: Disclosure of three 0-day iOS vulnerabilities

#62
post #38

Maybe it's just me, but these aren't what I think of when I hear 0-day. These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though. That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.

FYI, 0-day just means "first time made public".

It means a vulnerability is made public while there is no patch available. As opposed to releasing the information a number of days after the patch was released.

Re: Disclosure of three 0-day iOS vulnerabilities

#63

Earlier quoted context omitted.

God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…

GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.

Most of the cookie consent banners I see are illegal in that case..

Re: Disclosure of three 0-day iOS vulnerabilities

#64

Earlier quoted context omitted.

There is no $100K coming. Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.

Haven't they done this in the past? "Oh thank you!" then "Actually we already knew about it and had a fix planned, so no bounty for you"?

Yes.

In some cases when they did pay, they paid significantly less than their published rates.

Re: Disclosure of three 0-day iOS vulnerabilities

#65
post #57
post #40

Earlier quoted context omitted.

Settings > Cellular It shows my carrier, amount of data used and shows remaining on my plan. Mine reads, Usage: Used 7.43GB - Unlimited If I click on it it has 3 fields. Data, Calls, Messages Data reads the same here. Calls and Messages simply say ‘Unlimited’

My phone does not have this (iPhone on 15.0 in the US, AT&T).

Huh, I’m on the US too, T-Mobile.

Re: Disclosure of three 0-day iOS vulnerabilities

#66

It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.

Don’t count someone else’s money.

Re: Disclosure of three 0-day iOS vulnerabilities

#67

It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.

This fellow has a lot more to gain than $100k by the popularity and prestige he'll gather from publishing this. Especially considering that Apple will never change their ways until they're publicly shamed, the long term outcome of shaming them is worth more than $100k if they actually change the policies to take security researchers and the bug bounty seriously

Re: Disclosure of three 0-day iOS vulnerabilities

#68

It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.

There is no $100K coming. Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.

I think the behavior is very Russian.

Hacker: You have a vulnerability bounty program. Well here are three. Pay up.

Apple: [silence]

Hacker: [interprets this correctly as a fuck you.] Fuck me? Fuck you!

Me: Love it!

Re: Disclosure of three 0-day iOS vulnerabilities

#70
Props to the author. One small critique though:

> I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7

It would have been clearer if in each of the 4 vulnerabilities the timeline was given. The article only gives a timeline for the last vuln (the fixed one).

Post reply on HN