Disclosure of three 0-day iOS vulnerabilities
111–120 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#112Re: Disclosure of three 0-day iOS vulnerabilities
#113Maybe it's just me, but these aren't what I think of when I hear 0-day. These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though. That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.
Re: Disclosure of three 0-day iOS vulnerabilities
#114Earlier quoted context omitted.
GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.
Cookie consent banners have nothing to do with GDPR, but with the ePrivacy directive. GDPR clarifies what is "consent", but this is not what leaded to the proliferation of cookie banners. Please note if you have strictly necessary cookies, you don't need to have cookie banners, and if your cookies are anonymous, you don't need them either ! The proliferation of cookie banners just means that people running such websi…
Re: Disclosure of three 0-day iOS vulnerabilities
#115I really hate the path Apple is taking. They make excellent products, really the average Joe simply loves Apple products. But they need to stop acting anti-consumer and anti-developer to “protect” their IP. At this point they could release the schematics of iPhone 13 and still people will buy Apple’s iPhone than someone who copied them. Rant over.
Actually, these vulnerabilities are good evidence that Apple does not make excellent products.
Re: Disclosure of three 0-day iOS vulnerabilities
#116Earlier quoted context omitted.
Haven't they done this in the past? "Oh thank you!" then "Actually we already knew about it and had a fix planned, so no bounty for you"?
Yes. In some cases when they did pay, they paid significantly less than their published rates.
Best case scenario: you don't get sued into oblivion, will be ghosted and gaslightened, receive pocket change arbitrary amount of time later.
Compared to that, i suppose the exploit brokers got their stuff together - after all, time is money - chances are someone else may stumble upon the same vulnerability...
Re: Disclosure of three 0-day iOS vulnerabilities
#117Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartphone.
Re: Disclosure of three 0-day iOS vulnerabilities
#118Are there any partial mitigations you can take until these are patched?
This is truly a massive fail on the part of Apple and I hope there is as big of a backlash from their users.
Re: Disclosure of three 0-day iOS vulnerabilities
#119Earlier quoted context omitted.
that's just dumb, like third parties do all the work and contact you about critical bugs the only effort on Apple's part of verification and some coordination which shouldn't be a huge issue for a company the size of apple.. just hire a team to do it and be done with it the whole 'secrecy culture' is a bunch of hogwash
I’ve worked on the bug bounty program for a large company. We did the whole thing. It’s hard. The part you’re talking about can be the hardest. Is probably less than believable to read because it sounds like it should be easy. I don’t have any good answers there. I’m also not suggesting that customers and researchers accept that, but saying it’s easy just diminishes the efforts of those that run good ones.
Re: Disclosure of three 0-day iOS vulnerabilities
#120If Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? Nothing good I'm afraid. Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartpho…