Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

171–180 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#171

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

> but iOS updates can’t be done on 4G

> This isn’t an “anecdote” or an edge case, not everyone lives in a developed country and millions are just like my grandma

In too many countries, mobile data is incredibly expensive. If Apple were to allow over-the-air OS updates, you can bet it would take only a week until the first class-action lawsuit by people having their data caps blown through because they did not understand that updates are huge.

Re: Disclosure of three 0-day iOS vulnerabilities

#172

Earlier quoted context omitted.

GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.

Cookie consent banners have nothing to do with GDPR, but with the ePrivacy directive. GDPR clarifies what is "consent", but this is not what leaded to the proliferation of cookie banners. Please note if you have strictly necessary cookies, you don't need to have cookie banners, and if your cookies are anonymous, you don't need them either ! The proliferation of cookie banners just means that people running such websi…

Finally, at least one person in this thread who understands that GDPR is not cookie banners. I mean WTF, we're on hacker news. Oh wait, yeah, we're on hacker news.

Re: Disclosure of three 0-day iOS vulnerabilities

#173
post #16
post #6

Earlier quoted context omitted.

Yes, that person did drop 0days publicly and then promptly faced an FBI investigation causing a tremendous level of stress and irreparable mental health damage.

It looks like that they no longer work for Microsoft anymore. Weren't they making some not so great comments before the FBI investigation though?

She said all kinds of things that would trigger investigations, everything from threatening the president to searching for foreign state hackers to attack the US with her.

Surprisingly MSFT still hired her after this

Re: Disclosure of three 0-day iOS vulnerabilities

#174
post #113

Maybe it's just me, but these aren't what I think of when I hear 0-day. These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though. That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.

There needs to be a distinction between 0-days that make remote code execution possible and those that don't. This is still a pretty damning data leak.

There is a system, cvss scoring https://www.first.org/cvss/specification-document

Re: Disclosure of three 0-day iOS vulnerabilities

#175

Earlier quoted context omitted.

GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.

Most of the cookie consent banners I see are illegal in that case..

That's right.

Re: Disclosure of three 0-day iOS vulnerabilities

#176

Earlier quoted context omitted.

> crap like GDPR (which makes basically all normal interaction cumbersome) Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in. This is like passing a law making it illegal to just hit people in the street, requiring you have…

>> crap like GDPR (which makes basically all normal interaction cumbersome) GDPR do make a lot of things cumbersome, not only if you are doing "bad" things. Remember that GDPR covers information gathered and stored on paper as well. And it covers not only companies but also organisations, like children's soccer clubs. So let's say you have a printed list where kids and their parents signup with name and phone numbers…

So let's say you have a printed list where kids and their parents signup with name and phone numbers, you should probably have a data integrity policy and someone akin to a DPO. In your small non-profit soccer club!

Yes! You should!

This is the same as if your small, non-profit club deals with dangerous chemicals - it needs to make sure that the appropriate risk assessments are done, and safety information is available to users. Or any club dealing with children - it may need to make sure that the people have an appropriate background check.

Likewise, holding personal data is a risk to the people whose data is held. If you want to hold on to that data, your responsibility should include making sure that it is stored and used safely. If you don’t want to pay that cost, then stop holding it.

Re: Disclosure of three 0-day iOS vulnerabilities

#177

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

Apple makes ridiculous amount of money, and many Apple fanboys I know believe their devices are hack-proof.

I don’t think of my devices as being hack-proof, but as being the best set of trade-offs for me personally between security, privacy, usability, etc.

Re: Disclosure of three 0-day iOS vulnerabilities

#178

Earlier quoted context omitted.

> crap like GDPR (which makes basically all normal interaction cumbersome) Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in. This is like passing a law making it illegal to just hit people in the street, requiring you have…

What’s the incentive for a user to opt-in to tracking?

I mean, isn't that kind of the point?

Re: Disclosure of three 0-day iOS vulnerabilities

#180
post #148

Earlier quoted context omitted.

> This is a complete myth. No, it isn't. Snow Leopard was awesome. Mavericks was also pretty solid. In fact, I'm still running that on my machines today.

Yes, it is. Snow Leopard and Mavericks are not devices. The quote I am responding to is: > Apple used to be the company that made devices that were secure and "just worked". Unless your first generation iPod still works wonders.

Mechanical hard drives that lived in pockets and backpacks inevitably died. People seem to have been happy with the lifespan they got, though.
Post reply on HN