Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

151–160 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#151

Earlier quoted context omitted.

God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…

> crap like GDPR (which makes basically all normal interaction cumbersome) Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in. This is like passing a law making it illegal to just hit people in the street, requiring you have…

What’s the incentive for a user to opt-in to tracking?

Re: Disclosure of three 0-day iOS vulnerabilities

#152
post #87
post #77

Earlier quoted context omitted.

The problem is not that cyber-security is hard, but that a trillion dollar company is incapable to handle security disclosures.

In which case—if it’s a legitimate deficiency—that doesn’t bode well at all for any other commercial enterprise. This arms race is always tilted in favor of the attacker.

There are much smaller companies which handle security disclosures much better.

Re: Disclosure of three 0-day iOS vulnerabilities

#153
post #46
post #42

Are there any partial mitigations you can take until these are patched?

Don’t update your apps till after Apple releases a patch. The first two are API calls that apps can make. An exploit wishing to exploit these vulnerabilities has to be coded to make these calls. Most apps don’t dynamically construct arbitrary API calls. In fact, you can’t do that in Swift AFAIK. You have to drop to Objective-C or C to do that. So most apps need to be updated to exploit the vulnerability. The only exc…

> I wonder if Apple isn’t running static analysis tools right now to look for these vulnerabilities against all apps.

On a side note, this is one more reason Apple can cite for their App Store exclusivity. If there is a vulnerability in the OS exploitable by apps, and they can’t get a patch out in time, they can screen and prevent the download of such dangerous apps.

Not a popular position here I know. But I’m correct no?

Re: Disclosure of three 0-day iOS vulnerabilities

#154

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

Have they considered asking security questions on interviews instead of algos?

like you know, shitty performing algo can be always rewritten, leak or 0day cannot be reverted

Re: Disclosure of three 0-day iOS vulnerabilities

#155

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

The other day I tried to update my Macbook over a personal hotspot and it happily downloaded about 2GB before the computer went to sleep and I was greeted with a "Whoopsie, failed to download the update, try again" message when I woke it and, of course, it would just start over again. They don't even support resuming the download! That's just embarrassing.

Re: Disclosure of three 0-day iOS vulnerabilities

#156
post #61

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

It's interesting to me that in this entire thread, nobody is even mentioning or considering the possibility that COVID has impacted Apple's operations. It obviously has. It has affected every tech company. Certainly it has affected mine. Whether this is an example of that, I don't know, of course, but I think it's plausible.

I'm curious. Would you accept it if Apple came out and said that the reason this is happening is because of the COVID pandemic affecting their operations?

Surely even if it were true, that is no excuse for a company like Apple?

Re: Disclosure of three 0-day iOS vulnerabilities

#157

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

Microsoft has been all over the cyber security news due to their repeat vulnerabilities in Exchange and Azure AND the way they have handled disclosures made to them

Re: Disclosure of three 0-day iOS vulnerabilities

#158
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

The only mitigating factor is that they’re not remote vulnerabilities.

That being said, this is more or less the industry standard. And even if the other person mentioning this was downvoted, they are right: this has been the case since forever and can only be remedied through laws making companies responsible for their failures. But neither the US government nor said companies want this. It will have to get so bad that it visibly harms US or EU security for something to move in this space.

Re: Disclosure of three 0-day iOS vulnerabilities

#159

If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product. I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a…

Hang on, you have a coffee machine that is capable of being compromised? How exactly?

Further to this, you claim that you have been compromised on HUNDREDS of sites even though you use a unique password everywhere?

How is this happening to you? Isn't this a huge concern?

Re: Disclosure of three 0-day iOS vulnerabilities

#160
post #148

Earlier quoted context omitted.

> Apple used to be the company that made devices that were secure and "just worked". This is a complete myth. In fact, not only did Apple devices break all the time, but they were near-impossible for regular users to repair on their own. A simple proof: how many broken iPods did people used to have lying around?

> This is a complete myth. No, it isn't. Snow Leopard was awesome. Mavericks was also pretty solid. In fact, I'm still running that on my machines today.

Yes, it is. Snow Leopard and Mavericks are not devices. The quote I am responding to is:

> Apple used to be the company that made devices that were secure and "just worked".

Unless your first generation iPod still works wonders.

Post reply on HN