Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

121–130 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#121

If Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? Nothing good I'm afraid. Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartpho…

I realize you don't mean it that way, but this comes off as a bit 'whatabout-ish'.

It doesn't say absolutely anything abut other companies. It just says that Apple doesn't take security nearly as seriously as their Marketing and Sales department would want us to believe.

Re: Disclosure of three 0-day iOS vulnerabilities

#122

Earlier quoted context omitted.

God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…

> crap like GDPR (which makes basically all normal interaction cumbersome) Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in. This is like passing a law making it illegal to just hit people in the street, requiring you have…

>> crap like GDPR (which makes basically all normal interaction cumbersome)

GDPR do make a lot of things cumbersome, not only if you are doing "bad" things.

Remember that GDPR covers information gathered and stored on paper as well. And it covers not only companies but also organisations, like children's soccer clubs.

So let's say you have a printed list where kids and their parents signup with name and phone numbers, you should probably have a data integrity policy and someone akin to a DPO. In your small non-profit soccer club!

(My problem with GDPR is that it doesn't really, at least so far, hinder the worst trackers, but incur large cost all across society, even where handling personal data isn't really a problem)

Re: Disclosure of three 0-day iOS vulnerabilities

#124

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

> Explain I'm naive: why would Apple's bug bounty program be so poorly run?

Hubris.

Apple's culture is still fundamentally the same from the day they ran ads saying "Macs don't get viruses" to today. They used a misleading ad copy to convince people they could just buy a Mac and be safe, not needing to do anything else... ignoring that Macs still got malware in the form of trojans, botnets and such... and encouraging a culture of ignorance that persists to this day. "It just works." etc.

So now their primary user base is majorly people who have zero safe online habits.

And that sort of mentality feeds back into the culture of the company... "Oh, we're not Windows, we don't get viruses. We don't get viruses because our security is good. Our security is good, obviously, because we don't get viruses." It, in effect, is a feedback loop of complacency and hubris. (A prime example of this is how Macs within the Cupertino campus were infected with the Flashback botnet.)

Since their culture was that of security by obscurity (unlike, say, Google's explicit design in keeping Chrome sandboxed and containered for sites), closed source and again, hubris... it's coming back to bite Apple in the ass despite their ongoing "We don't get viruses" style smugness. If it's not about Macs not getting viruses, it's about how Apple values your privacy (implying others explicitly don't) and like with everything else, it's repeated often enough to where the kool aid from within becomes the truth.

Apple's culture is that of smugness, ignorance and yep... hubris. Why should they have a serious, respectable bug bounty program if they've been busy telling themselves that they don't simply have these kinds of security problems that they've bragged about never having?

Re: Disclosure of three 0-day iOS vulnerabilities

#125

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

Apple makes ridiculous amount of money, and many Apple fanboys I know believe their devices are hack-proof.

Re: Disclosure of three 0-day iOS vulnerabilities

#126
post #77

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

The problem is not that cyber-security is hard, but that a trillion dollar company is incapable to handle security disclosures.

I remember some of early Android phones that ran manufacturer maintained Kernel turning out immune to then-undisclosed RCEs years before disclosure.

I think it’s less about disclosure handling but more about being motivated to pay for or build a black magic code analysis tools.

Re: Disclosure of three 0-day iOS vulnerabilities

#127

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

> The problem is that cybersecurity is ridiculous hard problem.

This is why I wonder why "minimize your data exposure" is such a controversial opinion.

Re: Disclosure of three 0-day iOS vulnerabilities

#128
post #89

Earlier quoted context omitted.

I guess this is the reason Apple restricts apps from executing downloaded code.

This is without downloading additional code. Reuse attacks such as ROP, or you could just embed an interpreter with the ability to alter native register state. It’s not hard to get Turing completeness into your app in a way that lets it call whatever it wants.

Yeah, it wouldn't be too hard to write an interpreter. It is a lot like compiler class.

Re: Disclosure of three 0-day iOS vulnerabilities

#129

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

You know, I'd love to think that the problem is cyber security is hard -- which it IS -- but I'm starting to get the feeling that the actual problem is that Apple doesn't care about this kind of stuff. So many incredible vulnerabilities going back generations of iPhones and iOS...the zero click iMessages one floored me.

> the zero click iMessages one floored me.

In case there is any confusion, there has been at least one of those a year for the past 3 years.

Re: Disclosure of three 0-day iOS vulnerabilities

#130

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Apple has always been infamously bad at doing anything with external bug reports. Radar is a black hole that is indistinguishable from submitting bug reports to /dev/null unless you have a backchannel contact who can ensure that the right person sees the report. Bug bounty programs are significantly more difficult to run than a normal bug reporting service, so the fact that they're so bad at handling the easy case ma…

I actually got response for a bug report saying "We fixed that, can you try it on the next beta and send as a code sample to reproduce it if the bug is still there". But that bug was about the way SwiftUI draws the UI.
Post reply on HN