After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…
Disclosure of three 0-day iOS vulnerabilities
141–150 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#142If Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? Nothing good I'm afraid. Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartpho…
It doesn't say anything about other companies, it just says that Apple doesn't give two shits about relationships with security researchers, despite their massive resources and wealth even when smaller or FOSS teams do much better. Apple are the king of user experience which made them insanely wealthy but that's about it. In every other respect they are anti-consumer, anti-developer, anti-reparability, anti-researcher, anti-openness, anti-standardization AF and act like major a-holes in general to anyone outside their org who isn't a customer.
It's not that Apple can't be better on the other fronts if they actually wanted to, it's that they actively choose not to be, as that has no impact on their stock price or consumer experience and in consequence to their executive pay. So why do things differently if people still buy your products?
At this point, I wouldn't be surprised if the "Apple is more secure and has less vulnerabilities" moniker just stems form researchers getting tired of dealing with Apple's BS of not acknowledging or paying them, so instead they just keep quiet and sell the 0-days they find on the exploit markets (hard working honest researchers still need to eat and pay rent) only for those exploits to later end up in the hands of shady companies like NSO or nation states, therefore leading to no news in the mainstream media about Apple related vulnerabilities. Win-win for Apple I guess.
Re: Disclosure of three 0-day iOS vulnerabilities
#143After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…
Re: Disclosure of three 0-day iOS vulnerabilities
#144Re: Disclosure of three 0-day iOS vulnerabilities
#145The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…
How many people probably think they need to use their E-mail account password for every one of these idiotic organizations that forces them to log in with their E-mail address? I'm guessing a SHITLOAD. Your grandma definitely is not going to understand the difference.
And that makes every one of those organizations the gatekeeper to every user's E-mail account. One disgruntled employee, one poorly secured system, or one nefarious forum operator can now access untold numbers of E-mail accounts and steal identities galore.
You don't see banks or brokerages forcing people to use a goddamned E-mail address as a user ID, but Apple has doubled down on this bullshit policy even after being called out on it. No excuse.
Re: Disclosure of three 0-day iOS vulnerabilities
#146Earlier quoted context omitted.
> crap like GDPR (which makes basically all normal interaction cumbersome) Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in. This is like passing a law making it illegal to just hit people in the street, requiring you have…
>> crap like GDPR (which makes basically all normal interaction cumbersome) GDPR do make a lot of things cumbersome, not only if you are doing "bad" things. Remember that GDPR covers information gathered and stored on paper as well. And it covers not only companies but also organisations, like children's soccer clubs. So let's say you have a printed list where kids and their parents signup with name and phone numbers…
That's a far cry from "they make these cookie banners necessary". Tracking people without consent on first visit is what makes them necessary. The anger is consistently misdirected at the people who violate the boundaries of others, not the law that requires consent for it.
> So let's say you have a printed list where kids and their parents signup with name and phone numbers, you should probably have a data integrity policy and someone akin to a DPO. In your small non-profit soccer club!
"We'll ask them if it's okay to store it, and once they leave the club we delete their contact information after N months." Now you have a policy. The person who does everything else, the person who is already secretary, receptionist, accountant, project manager, janitor, coach, counselor, CEO, is now also the PDO.
Human rights being trampled on with an ever increasing mesh of surveillance by big agencies and corporations as well as little informants are such gross violations, such a terrible trajectory we put society on, that mere complication and discomfort is not something that can ever trump them in my book. I would even say if you can't put food on the table without ignoring the human rights of others, just don't put food on the table -- because that's the negotiable part, while the preservation of human rights is not. We need human righs, we don't need ad-hoc low-effort soccer clubs. Like, at all. Just get a ball and some friends in that case.
Re: Disclosure of three 0-day iOS vulnerabilities
#147Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…
I imagine they are just overwhelmed. Let’s say they have a team of 6 engineers tasked with this. They probably receive hundreds of reports a day, many bogus, some real, but all long winded descriptions like this framed to make the vuln seem as bad as possible. In addition many vuln reports are generated by automated tools and sprayed to thousands of sites/vendors daily in the hope of one of them paying out, they seem…
Re: Disclosure of three 0-day iOS vulnerabilities
#148After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…
> Apple used to be the company that made devices that were secure and "just worked". This is a complete myth. In fact, not only did Apple devices break all the time, but they were near-impossible for regular users to repair on their own. A simple proof: how many broken iPods did people used to have lying around?
No, it isn't. Snow Leopard was awesome. Mavericks was also pretty solid. In fact, I'm still running that on my machines today.
Re: Disclosure of three 0-day iOS vulnerabilities
#149After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…
This includes arbitrary code execution with kernel privileges.
This has been the case for a long time for Apple, which forced me to break my Catalina boycott (remember the macOS Vista stories here?) because I don't want unfixed, publicized 0days on my machine.
Re: Disclosure of three 0-day iOS vulnerabilities
#150The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
Does anyone knows the technology stack Apple uses?