Why anyone at Apple decided that it was acceptable to log medical data in such an unsafe way? I currently work in an IT health care company in Europe, and we must alway store the data fully encrypted with strict access control. We even decided to not make sure to not persist any medical data on user devices to not take unnecessary risks. And there, Apple logs everything on the iPhone? Why?
Disclosure of three 0-day iOS vulnerabilities
201–210 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#202Can Apple retroactively identify apps that might have exploited these vulnerabilities to exfiltrate personal data? In my understanding they receive the full source code of an app for review, so they probably have an archive with all revisions that they could go through using automated tools to identify exploit code? Would be good to know if these exploits have been used in the wild, being able to exfiltrate the entir…
I did not know that, is that even legal that Apple gets to look at your IP.
Re: Disclosure of three 0-day iOS vulnerabilities
#203Re: Disclosure of three 0-day iOS vulnerabilities
#204Can Apple retroactively identify apps that might have exploited these vulnerabilities to exfiltrate personal data? In my understanding they receive the full source code of an app for review, so they probably have an archive with all revisions that they could go through using automated tools to identify exploit code? Would be good to know if these exploits have been used in the wild, being able to exfiltrate the entir…
Re: Disclosure of three 0-day iOS vulnerabilities
#205The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…
Re: Disclosure of three 0-day iOS vulnerabilities
#206Earlier quoted context omitted.
This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…
Microsoft has been all over the cyber security news due to their repeat vulnerabilities in Exchange and Azure AND the way they have handled disclosures made to them
but then u not need to read it. and who would given all the exquisite experiences with M$ and/or Goo compared to nightmares Apple delivers to u, overpriced, ofc
in a sense it is good reading tho after all in that it indicates that exactly those are not the one's one does meet in Apple-communities
Re: Disclosure of three 0-day iOS vulnerabilities
#207Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…
My guess would be, that MSRC and Apple's equivalent have an OKR about keeping bounties under a certain level. Security is seen as a cost centre by most companies, and what do "well run" companies do with cost centres... they minimize them :)
I don't think that organizationally either company wants to have bad security, and I don't think that individual staff in those companies want to have bad security, but I do think that incentive structures have been set-up in a way that leads to this kind of problem.
I've seen this described as lack of resources in the affected teams, but realistically these companies have effectively limitless resources, it's that they're not assigning them to these areas.
Re: Disclosure of three 0-day iOS vulnerabilities
#208Apple says it stores Health data in a protected way on the device.
In reality, health data is leaked through logs and can be accessed by any other app. It is impossible to tell whether or not this data has been accessed in the wild.
Since Apple failed to implement their claimed security features properly and you need to assume exploitation by apps in the wild in the worst case, this would require a disclosure to GDPR authorities. Did they do it? Were they fined yet?
Re: Disclosure of three 0-day iOS vulnerabilities
#209The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…
Tech workers have difficulty taking into consideration lifestyles they don't know exist, which is understandable. At the end of the day this comes as another consequence of the lack of diversity in tech, I guess.
Re: Disclosure of three 0-day iOS vulnerabilities
#210Earlier quoted context omitted.
> but iOS updates can’t be done on 4G > This isn’t an “anecdote” or an edge case, not everyone lives in a developed country and millions are just like my grandma In too many countries, mobile data is incredibly expensive. If Apple were to allow over-the-air OS updates, you can bet it would take only a week until the first class-action lawsuit by people having their data caps blown through because they did not underst…
In many other countries, 4G is so inexpensive that many people use it as their primary Internet connection though. They don't see a need for a modem hooked to a wired line necessitating a second subscription and procedures to follow when you move apartments, when in any case you will have a 4G connection that follows you around on your smartphone.