Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

111–120 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#113

Maybe it's just me, but these aren't what I think of when I hear 0-day. These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though. That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.

There needs to be a distinction between 0-days that make remote code execution possible and those that don't. This is still a pretty damning data leak.

Re: Disclosure of three 0-day iOS vulnerabilities

#114

Earlier quoted context omitted.

GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.

Cookie consent banners have nothing to do with GDPR, but with the ePrivacy directive. GDPR clarifies what is "consent", but this is not what leaded to the proliferation of cookie banners. Please note if you have strictly necessary cookies, you don't need to have cookie banners, and if your cookies are anonymous, you don't need them either ! The proliferation of cookie banners just means that people running such websi…

Non-essential cookies are personal data as regulated by the GDPR. It is true the EPD started the cookie consent popup craze though.

Re: Disclosure of three 0-day iOS vulnerabilities

#115

I really hate the path Apple is taking. They make excellent products, really the average Joe simply loves Apple products. But they need to stop acting anti-consumer and anti-developer to “protect” their IP. At this point they could release the schematics of iPhone 13 and still people will buy Apple’s iPhone than someone who copied them. Rant over.

Actually, these vulnerabilities are good evidence that Apple does not make excellent products.

Probably means they make "good looking" products. But underneath the hood, it's spaghetti.

Re: Disclosure of three 0-day iOS vulnerabilities

#116

Earlier quoted context omitted.

Haven't they done this in the past? "Oh thank you!" then "Actually we already knew about it and had a fix planned, so no bounty for you"?

Yes. In some cases when they did pay, they paid significantly less than their published rates.

From the PoV of a security researcher - why even bother disclosing responsibly (moral obligations aside)?

Best case scenario: you don't get sued into oblivion, will be ghosted and gaslightened, receive pocket change arbitrary amount of time later.

Compared to that, i suppose the exploit brokers got their stuff together - after all, time is money - chances are someone else may stumble upon the same vulnerability...

Re: Disclosure of three 0-day iOS vulnerabilities

#117
If Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? Nothing good I'm afraid.

Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartphone.

Re: Disclosure of three 0-day iOS vulnerabilities

#118
post #42

Are there any partial mitigations you can take until these are patched?

Delete any apps you don't want others know you downloaded or be linked to you immediately. If your wifi name for some reason is something sensitive rename it. The address book/sms one is tricky, maybe make a backup of your iPhone and if you're truly paranoid delete all your contacts and sms messages and restore them when Apple releases a patch?

This is truly a massive fail on the part of Apple and I hope there is as big of a backlash from their users.

Re: Disclosure of three 0-day iOS vulnerabilities

#119
post #98
post #49

Earlier quoted context omitted.

that's just dumb, like third parties do all the work and contact you about critical bugs the only effort on Apple's part of verification and some coordination which shouldn't be a huge issue for a company the size of apple.. just hire a team to do it and be done with it the whole 'secrecy culture' is a bunch of hogwash

I’ve worked on the bug bounty program for a large company. We did the whole thing. It’s hard. The part you’re talking about can be the hardest. Is probably less than believable to read because it sounds like it should be easy. I don’t have any good answers there. I’m also not suggesting that customers and researchers accept that, but saying it’s easy just diminishes the efforts of those that run good ones.

could you try litle bit harder to provide any example why it is "harder than it looks". you repeated multiple times that its hard, but what exactly(aproximately) makes it hard?

Re: Disclosure of three 0-day iOS vulnerabilities

#120

If Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? Nothing good I'm afraid. Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartpho…

Would you consider something like the PinePhone once it’s a bit more usable?
Post reply on HN