Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

191–200 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#191

Earlier quoted context omitted.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

> but iOS updates can’t be done on 4G > This isn’t an “anecdote” or an edge case, not everyone lives in a developed country and millions are just like my grandma In too many countries, mobile data is incredibly expensive. If Apple were to allow over-the-air OS updates, you can bet it would take only a week until the first class-action lawsuit by people having their data caps blown through because they did not underst…

I get that, but given that some countries have insanely restrictive Wi-Fi data caps (I heard 200GB, which I would probably blow through in a week or less), I don't see the problem. Even if updates-over-4G are disabled by default, power users should be able to turn it on. My grandma has 70GB for 15€ a month; she only makes FaceTime calls, so uses on average 4GB of data a month. I'd love to use SharePlay to share her screen, and teach her how to use her phone, but that won't be possible, because she can't install the update; it'll have to wait until the next time I travel to see her.

I hear that Android lets you enable updates-over-4G, but allows carriers to block the feature. That's detestable! Surely, if I pay for data, I should be able to use it for anything (legal) I deem important? I don't like corporations making those decisions for me.

Re: Disclosure of three 0-day iOS vulnerabilities

#192
> medical information (heart rate, count of detected atrial fibrillation and irregular heart rythm events)

> menstrual cycle length, biological sex and age, whether user is logging sexual activity, cervical mucus quality, etc.

Wat? How, and under what circumstances is it collecting stuff like cervical mucus quality??

Edit: ah, maybe I misread - it's "whether the user is logging cervical mucus quality" I think. Still, wtf?

Re: Disclosure of three 0-day iOS vulnerabilities

#193

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

> The problem is that cybersecurity is ridiculous hard problem.

I don't believe that. Making perfectly secure software at large scale is indeed very hard, but a lot of security issues we see every day have little to do with lack of perfection. There's a ton of low hanging fruit out there.

> The junior to senior developers are just using existing frameworks with poor documentation.

Yes, I do believe that the modern way of quickly ducktaping junk together while paying little attention to security does make for lots of security issues, which might give someone the impression that cybersecurity is ridiculously hard.

Security requires proactive effort. It's not ridiculously hard, but it needs to be done, it requires time (just as anything). Leaving it for "hope you don't write buggy code" and "does colleague notice the gaping hole in code review" is not doing security, it's just winging it.

And I've never really been asked to do security, even when literally working on a security product. Everyone just seems to assume security is an automatic byproduct of skilled programming, but it's not when the pressing concern is "how many hours/days/.. does it take to ship this new feature oh and we have three dozen other features that need to be implemented soon" and "can we get it sooner?" and "why is it taking so long, it's not that hard!"

It needs to be discussed, planned, designed, reviewed, tested, verified, questioned, audited. Just like anything else, if you want quality. None of this is ridiculously hard, but it needs to be done for it to be done. If it's not being done, it's that the organization doesn't care about it.

In a lot of ways it's similar to technical debt. Are you taking the time to avoid it, reduce it, get rid of it? No? Then you're accumulating it. Security issues accumulate just like technical debt when ignored. And even the most skilled programmers do generate technical debt (because they don't jump into a problem with perfect knowledge of what needs to be done). Depending on the organization, they may or may not get to fix it. Many organizations just don't care and would rather have the devs work on something "more productive."

Re: Disclosure of three 0-day iOS vulnerabilities

#195

> medical information (heart rate, count of detected atrial fibrillation and irregular heart rythm events) > menstrual cycle length, biological sex and age, whether user is logging sexual activity, cervical mucus quality, etc. Wat? How, and under what circumstances is it collecting stuff like cervical mucus quality?? Edit: ah, maybe I misread - it's "whether the user is logging cervical mucus quality" I think. Still,…

You need to select female under health.

Re: Disclosure of three 0-day iOS vulnerabilities

#196
post #195

> medical information (heart rate, count of detected atrial fibrillation and irregular heart rythm events) > menstrual cycle length, biological sex and age, whether user is logging sexual activity, cervical mucus quality, etc. Wat? How, and under what circumstances is it collecting stuff like cervical mucus quality?? Edit: ah, maybe I misread - it's "whether the user is logging cervical mucus quality" I think. Still,…

You need to select female under health.

I don't have an iDevice. Is this a built in health app or an API for apps to record stuff?

Re: Disclosure of three 0-day iOS vulnerabilities

#197

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Apple has always been infamously bad at doing anything with external bug reports. Radar is a black hole that is indistinguishable from submitting bug reports to /dev/null unless you have a backchannel contact who can ensure that the right person sees the report. Bug bounty programs are significantly more difficult to run than a normal bug reporting service, so the fact that they're so bad at handling the easy case ma…

I used to submit bug reports for things I found in macOS or any other applications, like that Pages would include a huge picture in the files for no reason at all. But those bug reports would usually be closed and "linked" to another bug report you don't have access to. Essentially shutting you out. At some point you just give up. At some point bugs are getting fixed but there is no pattern to it.

Re: Disclosure of three 0-day iOS vulnerabilities

#198

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

I think they don’t want to admit such a big security breach publicly. At some extent privacy is their business.

Re: Disclosure of three 0-day iOS vulnerabilities

#199
post #136

After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…

Here, I'll save you the trouble: download the iOS 14.8 IPSW for your device, and then in the Finder when your device is connected hold down the option key and hit "Update". Then select the IPSW and it'll update your device with that.

Re: Disclosure of three 0-day iOS vulnerabilities

#200

Can Apple retroactively identify apps that might have exploited these vulnerabilities to exfiltrate personal data? In my understanding they receive the full source code of an app for review, so they probably have an archive with all revisions that they could go through using automated tools to identify exploit code? Would be good to know if these exploits have been used in the wild, being able to exfiltrate the entir…

It would probably take the exploitation of a security hole in Apple's systems to find out, as they clearly have no desire nor incentive to do this.

Is it odd that I'm now hoping this might happen while also hoping for them to start patching up security holes?

Edit: typo

Post reply on HN