Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

211–220 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#211

Earlier quoted context omitted.

As someone that actively works in the security industry and has spent quite a bit of time tracking this... Yes, there is a massive disconnect in pricing for private acquisitions of vulnerabilities in commonly used software. Almost always it's between a 2-5 magnitude order of difference in price between a bug bounty and what a company like Zerodium pays. When they have a valuable enough customer asking for something s…

Do you know of anyone personally who was paid?

Oh sure, Zerodium pays (over time, as long as bug is unpatched), if you don't care how your exploits are used (will it be used to target middle east journalists or jeopardize our democracies by watching over elected representatives? who knows.); sure, they vet their customers, and the customers swear they won't do anything bad with it.

Note: not sure they would pay for these private information leaks. They'd probably prefer a local escalation and then do the data collection themselves.

Re: Disclosure of three 0-day iOS vulnerabilities

#212

Earlier quoted context omitted.

>> crap like GDPR (which makes basically all normal interaction cumbersome) GDPR do make a lot of things cumbersome, not only if you are doing "bad" things. Remember that GDPR covers information gathered and stored on paper as well. And it covers not only companies but also organisations, like children's soccer clubs. So let's say you have a printed list where kids and their parents signup with name and phone numbers…

So let's say you have a printed list where kids and their parents signup with name and phone numbers, you should probably have a data integrity policy and someone akin to a DPO. In your small non-profit soccer club! Yes! You should! This is the same as if your small, non-profit club deals with dangerous chemicals - it needs to make sure that the appropriate risk assessments are done, and safety information is availab…

Your view is of course fully valid, and probably the view reflected in the GDPR legislation.

To use your metaphor of chemicals:

I see the current situation as if the soccer club is handling a 1L container of consumer-grade vinegar weedkiller, and is required to do pretty cumbersome things to document their use and keep it "safe". Many of them have consulted some firm or expert to get boiler-plate documentation, because even if fines are unlikely they are anxious about them.

At the same time, we have enormous commercial actors that handle millions of liters of radioactive wastewater in rusty containers. These companies have, for sure, spent a lot of money on "compliance". Some small improvements have surely been made, but the fundamental business practice among these actors of handling radioactive wastewater have not changed. Some "large" fines have been given, but they barley make a dent in the enormous profitability of handling these toxic things.

At least not yet, 3 years in. Maybe it will change in the future, and the big actors will fundamentally change their behaviour.

If that happens, I can agree that the weedkiller documentation is worth the cost, but so far I'm sceptical.

(Since this is an Apple thread, I think its interesting to compare the _real_ privacy gain of GDPR as a whole, vs Apple's simple tracking-popup)

Re: Disclosure of three 0-day iOS vulnerabilities

#213

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

I imagine they are just overwhelmed. Let’s say they have a team of 6 engineers tasked with this. They probably receive hundreds of reports a day, many bogus, some real, but all long winded descriptions like this framed to make the vuln seem as bad as possible. In addition many vuln reports are generated by automated tools and sprayed to thousands of sites/vendors daily in the hope of one of them paying out, they seem…

I don't buy this. They fixed one reported, got back to him and acknowledge the lack of disclosure, apologised, promised to fix it and never actually disclosed it 3 reports later.

It's not a case of "someone missed this" it's "this seems dysfunctional".

Re: Disclosure of three 0-day iOS vulnerabilities

#214

Earlier quoted context omitted.

In many other countries, 4G is so inexpensive that many people use it as their primary Internet connection though. They don't see a need for a modem hooked to a wired line necessitating a second subscription and procedures to follow when you move apartments, when in any case you will have a 4G connection that follows you around on your smartphone.

I've been using 5G as my primary internet connection since January 2020. It's much faster than wired broadband in buildings that don't have fibre installed. It's also cheaper (I pay £30/month for unlimited data), there's no contract locking you in to 12 or 24 months of service, and I can take it with me whenever I travel or if I move house.

If you have a desktop, how do you provide the 5G connection?

Is there a better way than providing a wifi hotspot with your mobile phone?

Re: Disclosure of three 0-day iOS vulnerabilities

#215

Can Apple retroactively identify apps that might have exploited these vulnerabilities to exfiltrate personal data? In my understanding they receive the full source code of an app for review, so they probably have an archive with all revisions that they could go through using automated tools to identify exploit code? Would be good to know if these exploits have been used in the wild, being able to exfiltrate the entir…

There is no way they could prove that an app HASN'T exploited this. They don't get source code, only compiled binaries, and with objective-c's extremely dynamic nature, any app could technically receive a HTTP response containing strings containing class and method names to dynamically look up and invoke, maybe even based on the app's IP address or only on specific dates. So calls to these exploitable APIs could have happened and there would be no way to prove otherwise.

Re: Disclosure of three 0-day iOS vulnerabilities

#216

If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product. I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a…

Hang on, you have a coffee machine that is capable of being compromised? How exactly? Further to this, you claim that you have been compromised on HUNDREDS of sites even though you use a unique password everywhere? How is this happening to you? Isn't this a huge concern?

Right, it’s hard to compromise a kettle and manual grinder, the only thing I could possibly consider a benefit of a networked coffee machine is you can schedule it/script it with home assistant.

But even then, I’m pretty sure you can buy simple electric ones with timers…

Re: Disclosure of three 0-day iOS vulnerabilities

#217
post #157

Earlier quoted context omitted.

Microsoft has been all over the cyber security news due to their repeat vulnerabilities in Exchange and Azure AND the way they have handled disclosures made to them

u must have missed reading this : ".. Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly) .." but then u not need to read it. and who would given all the exquisite experiences with M$ and/or Goo compared to nightmares Apple delivers to u, overpriced, ofc in a sense it is good reading tho after all in that it indicates that exactly those are not the one's one does meet in Apple-communiti…

It's spelt "you"

Re: Disclosure of three 0-day iOS vulnerabilities

#218

Earlier quoted context omitted.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

The other day I tried to update my Macbook over a personal hotspot and it happily downloaded about 2GB before the computer went to sleep and I was greeted with a "Whoopsie, failed to download the update, try again" message when I woke it and, of course, it would just start over again. They don't even support resuming the download! That's just embarrassing.

Strangely I did the same thing last night and it did resume, although you only see the resumption when it starts. There's no prior indication that it will resume.

Re: Disclosure of three 0-day iOS vulnerabilities

#219

Earlier quoted context omitted.

I've been using 5G as my primary internet connection since January 2020. It's much faster than wired broadband in buildings that don't have fibre installed. It's also cheaper (I pay £30/month for unlimited data), there's no contract locking you in to 12 or 24 months of service, and I can take it with me whenever I travel or if I move house.

If you have a desktop, how do you provide the 5G connection? Is there a better way than providing a wifi hotspot with your mobile phone?

I have a Huawei E6878-870 5G mobile WiFi (other brands are available), which provides a "proper" WiFi base station, so no need for a phone hotspot. I have a separate cheap SIM card for my phone.

Re: Disclosure of three 0-day iOS vulnerabilities

#220
post #22

Earlier quoted context omitted.

Bug bounty programs are the antithesis of Apple's internal methodology, culture, and way of doing business. They keep everything close to the chest, they shun "outsiders", etc.. The idea that someone outside of Apple, from the unwashed masses, could find a flaw in Apple's own software is a pretty big pill for them to swallow. Thus it doesn't surprise me there are problems with their bug bounty program. I think if the…

That makes apple (the org, not the fanboys) sound a bit cultish... Can't say I'm surprised though...

It is in SV after all..
Post reply on HN