Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

181–190 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#181

Earlier quoted context omitted.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

> but iOS updates can’t be done on 4G > This isn’t an “anecdote” or an edge case, not everyone lives in a developed country and millions are just like my grandma In too many countries, mobile data is incredibly expensive. If Apple were to allow over-the-air OS updates, you can bet it would take only a week until the first class-action lawsuit by people having their data caps blown through because they did not underst…

In many other countries, 4G is so inexpensive that many people use it as their primary Internet connection though.

They don't see a need for a modem hooked to a wired line necessitating a second subscription and procedures to follow when you move apartments, when in any case you will have a 4G connection that follows you around on your smartphone.

Re: Disclosure of three 0-day iOS vulnerabilities

#182

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

> The problem is that cybersecurity is ridiculous hard problem.

This is hard for me to believe for a company the size of Apple. They were recently the wealthiest company on the planet and are worth over a trillion dollars IIRC. They could slow down their software development process, focus less on adding new features, and prioritize fewer security holes. It seems like such a huge risk to them that their devices are basically always vulnerable. But the general public never really hear about these 0-days so they may have some ability to ignore the problem.

The cynic in me imagines that someone at Apple knows about these bugs and they are shared with spooks for exploitation. One could imagine that even for a responsible disclosure program, they could share details of every new vulnerability with some three letter agency who could have months of use out of them before a patch is finally released.

Re: Disclosure of three 0-day iOS vulnerabilities

#183
post #165

Earlier quoted context omitted.

> I wonder if Apple isn’t running static analysis tools right now to look for these vulnerabilities against all apps. On a side note, this is one more reason Apple can cite for their App Store exclusivity. If there is a vulnerability in the OS exploitable by apps, and they can’t get a patch out in time, they can screen and prevent the download of such dangerous apps. Not a popular position here I know. But I’m correc…

No. Those static analysis tools don't catch everything. There are relatively well known and somewhat widespread tricks to avoid being caught by them.

I speculate that GameKit is basically abandonware by Apple. They even got rid of the app a few years ago.

There probably hasn't been hardening of it in years and the initial work was probably developed in haste.

This is systemic. Apple has a bad habit of abandoning software that isn't a priority. So, one shouldn't be surprised that Apple hasn't fixed these exploits. And I wonder if the author has fully mined GameKit for exploits yet. Perhaps there are more to be found.

The architecture of iOS and OSX isn't conducive to security AFAIK. It is more of an add-on as one can see instead of being architected in.

Re: Disclosure of three 0-day iOS vulnerabilities

#184
post #19

Earlier quoted context omitted.

If these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?

You can do a lot more damage with someone's bank account than you can by exploding their phone.

Currently holding my phone, with a full charge. Basically a hand grenade, about 12” from my face, with (thanks to oversized phones), both hands on it.

At best id be blind and unable to use my hands. I don’t give a stuff about my bank account compared with that.

Re: Disclosure of three 0-day iOS vulnerabilities

#185
Can Apple retroactively identify apps that might have exploited these vulnerabilities to exfiltrate personal data? In my understanding they receive the full source code of an app for review, so they probably have an archive with all revisions that they could go through using automated tools to identify exploit code? Would be good to know if these exploits have been used in the wild, being able to exfiltrate the entire address book without any user involvement whatsoever is quite scary.

Re: Disclosure of three 0-day iOS vulnerabilities

#186
post #136

After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…

> Apple used to be the company that made devices that were secure and "just worked". This is a complete myth. In fact, not only did Apple devices break all the time, but they were near-impossible for regular users to repair on their own. A simple proof: how many broken iPods did people used to have lying around?

I've never even heard of a broken iPod, who are these people that have several lying around?

Re: Disclosure of three 0-day iOS vulnerabilities

#188

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

If companies respected and paid platform/architecture engineers, or SecOps/SysAdmin types fair amounts of money and treated them with respect, instead of just throwing more and more money at hordes of mindless devs who are "pushing product", as virtually every single company does, maybe this problem wouldn't exist.

I've had this conversation too many times. Security isn't hard, it's just that nobody has respect for it. The guy who understands software security isn't getting the respect he deserves. The situation is so bad, some companies are literally hiring people who know the equivalent of script kiddie "penetration-testing".

Pay security engineers enough and listen very carefully to what they have to say. Literally the only companies who seem to understand this basic concept seem to be the intelligence agencies, and a few other high profile companies.

Re: Disclosure of three 0-day iOS vulnerabilities

#190

Earlier quoted context omitted.

God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…

GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.

Correct. The vast majority of such cookie banners you see are illegal according to the GDPR, i.e. whenever you see one that doesn't have equal prominent "Accept"/"Reject" options next to each other.

The only reason these illegal banners still get used is a lack of enforcement. Right now, the enforcement process is rather slow, which is in part due to all this stuff being "new" (the cookie ePrivacy is technically from 2009 already, but regulatory bodies with a clear focused mandate to enforce infractions only really came into existence with the GDPR) and thus regulatory bodies and sometimes courts still trying to figure out the legal details, and acting slow and (overly) cautious in order not to embarrass themselves by issuing fines that are later thrown out in a high court. (And then there is Ireland...). And more generally, the law is rather slow regardless; the time it takes to conclude any "important" case is measured in years, and sometimes decades.

There are civil organizations such as noyb[1] trying to get things going and "nudge" regulators into action, but even with that it will be a few more years at least until the legal questions around "what is an acceptable cookie banner" are settled.

[1] https://noyb.eu/en/noyb-aims-end-cookie-banner-terror-and-is...

Post reply on HN