It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.
There is no $100K coming. Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.
Disclosure of three 0-day iOS vulnerabilities
101–110 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#102Earlier quoted context omitted.
Settings > Cellular It shows my carrier, amount of data used and shows remaining on my plan. Mine reads, Usage: Used 7.43GB - Unlimited If I click on it it has 3 fields. Data, Calls, Messages Data reads the same here. Calls and Messages simply say ‘Unlimited’
My phone does not have this (iPhone on 15.0 in the US, AT&T).
Re: Disclosure of three 0-day iOS vulnerabilities
#103Earlier quoted context omitted.
God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…
GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.
Re: Disclosure of three 0-day iOS vulnerabilities
#104Earlier quoted context omitted.
Cybersecurity is a genuinely hard problem, but stuff like this is dropping the ball entirely. It's not hard to solve exploits like faulty permission-checking after they've been reported to you. Sure, there are always going to be problems you miss. I can forgive them shipping with zero-days, it happens. Failing to respond to reports is just that: failing.
It really helps add some color to the motivations behind notorization. It seems ridiculous to me that I have to jump through so many hoops to run an executable that I trust. Especially when Apple can’t be bothered to follow up on real vulnerabilities that have already been reported.
Re: Disclosure of three 0-day iOS vulnerabilities
#105People here are getting boggled down in details about how is it possible for this to happen and what sort of policies apple has internally for it to be possible, but that doesn't really matter. Any company even 10% the size of APple should not be given the benefit of the doubt because obviously they'd all prefer not to have the major/minor embarrassment, if they can. Bounty programs exist not because they care about security of their customers only, but it's also a way to promote the company as security-conscious and avoid having 0days sold on the black market.
But to overcome this you can just continue publishing 0-days straight to the public. Put really easy to use sourcecode on github/bucket/srht/etc... allowing script-kiddies and copy-pasters to make use of them easily. This will either drive people to lose trust or force Apple to scramble to release fixes, either way it will push them to respect researchers and fix their bounty program or setup better security guidelines in general.
Props to the author for following through and releasing.
Re: Disclosure of three 0-day iOS vulnerabilities
#106Earlier quoted context omitted.
It really helps add some color to the motivations behind notorization. It seems ridiculous to me that I have to jump through so many hoops to run an executable that I trust. Especially when Apple can’t be bothered to follow up on real vulnerabilities that have already been reported.
Exactly - any PR propaganda about notorization or signing making it safer for users is just BS. It's a gate-keeping mechanism that adds a layer of power to apple and prevent any control of the app market from slipping away.
Re: Disclosure of three 0-day iOS vulnerabilities
#107I currently work in an IT health care company in Europe, and we must alway store the data fully encrypted with strict access control. We even decided to not make sure to not persist any medical data on user devices to not take unnecessary risks. And there, Apple logs everything on the iPhone? Why?
Re: Disclosure of three 0-day iOS vulnerabilities
#108Earlier quoted context omitted.
God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…
GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.
Please note if you have strictly necessary cookies, you don't need to have cookie banners, and if your cookies are anonymous, you don't need them either !
The proliferation of cookie banners just means that people running such websites are usually terrible with regards to consent, personally identifiable information, and so on.
Re: Disclosure of three 0-day iOS vulnerabilities
#109I really hate the path Apple is taking. They make excellent products, really the average Joe simply loves Apple products. But they need to stop acting anti-consumer and anti-developer to “protect” their IP. At this point they could release the schematics of iPhone 13 and still people will buy Apple’s iPhone than someone who copied them. Rant over.