Apple might have left these vulnerabilities for Pegasus like softwares including the sotfware used by FBI and other agencies.
Disclosure of three 0-day iOS vulnerabilities
231–240 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#232Earlier quoted context omitted.
I would be an order of magnitude less concerned with camera/mic access, compared to perfect historical proof of my usage and communication patterns. Exploits often feel like pathogens, probably why they share the term virus. If a virus has a high mortality rate, contagion is lower, because it frequently kills the host before it can spread. Similarly, I think a 'complete device compromise' is much more likely to be id…
It's hardly 'perfect historical proof', not to diminish the seriousness of the vulnerability. But more importantly, the mechanism matters a great deal. This particular vulnerability requires the install of a malicious app, a much higher bar than a 'drive by' exploitation. This leaves a trace and exposes the attacker to consequences. No (statistically speaking) app producer with any interest in continuing to use the p…
Re: Disclosure of three 0-day iOS vulnerabilities
#233> My actions are in accordance with responsible disclosure guidelines (Google Project Zero discloses vulnerabilities in 90 days after reporting them to vendor, ZDI - in 120). I have waited much longer, up to half a year in one case. "Responsible" disclosure guidelines only benefit corporations. They do not protect consumers. Why should independent researchers - working for free, no less (and sorry, the well-below-min…
Also, it's "This makes it immediately available to exploit before a fix can even _theoretically_ be developed", not "This places pressure on the corporation to fix it immediately".
Re: Disclosure of three 0-day iOS vulnerabilities
#234Earlier quoted context omitted.
> my grandma doesn’t have WiFi Tech workers have difficulty taking into consideration lifestyles they don't know exist, which is understandable. At the end of the day this comes as another consequence of the lack of diversity in tech, I guess.
So, is this the lack of grandmas working at Apple in software development? This is nothing you can fix by following some diversity ideology. This is a question of respecting different requirements from different user groups. You cannot mirror every user group in the development teams. How do you represent people of old age, with illnesses, or certain disabilities in a development team? How do you represent people liv…
Re: Disclosure of three 0-day iOS vulnerabilities
#235The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
> The problem is that cybersecurity is ridiculous hard problem. This is hard for me to believe for a company the size of Apple. They were recently the wealthiest company on the planet and are worth over a trillion dollars IIRC. They could slow down their software development process, focus less on adding new features, and prioritize fewer security holes. It seems like such a huge risk to them that their devices are b…
My inner cynic¹ has a slightly different take on that: You don't get to be the wealthiest company on the planet by doing the right thing at the expense of the profitable things.
¹ He says, pretending it isn't also his outer and all-consuming cynic!
Re: Disclosure of three 0-day iOS vulnerabilities
#236If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product. I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a…
God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…
Otherwise you don’t even need a cookie banner.
Re: Disclosure of three 0-day iOS vulnerabilities
#237Earlier quoted context omitted.
What is your definition of 0-day? Because they are exactly right, this is a 0-day. Whether it's already actively being exploited or not has no bearing on the definition. I'll refer you to https://en.wikipedia.org/wiki/Zero-day_(computing) to make up your own mind.
normally I'd define it as something found in the wild being exploited already ... not a bug thats been found, reported and "ignored" this seems to be a zero day just because Apple haven't seen fit to respond the the reporter
Yeah, but ... that's not what it means. You can choose to define "spoon" as "fork" too, but I don't see how it's useful to go around complaining about other people using the actual definition of the word.
Re: Disclosure of three 0-day iOS vulnerabilities
#238Are there any partial mitigations you can take until these are patched?
Don’t update your apps till after Apple releases a patch. The first two are API calls that apps can make. An exploit wishing to exploit these vulnerabilities has to be coded to make these calls. Most apps don’t dynamically construct arbitrary API calls. In fact, you can’t do that in Swift AFAIK. You have to drop to Objective-C or C to do that. So most apps need to be updated to exploit the vulnerability. The only exc…
In fact, the prof of concepts shown in the article are all written in Swift.
Re: Disclosure of three 0-day iOS vulnerabilities
#239The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
Apple makes ridiculous amount of money, and many Apple fanboys I know believe their devices are hack-proof.
it’s more likely they’ve considered which security issues they’re personally concerned about and decided the other choices are as bad or worse.
once we actually dig into the specifics of an issue–especially one as complicated as personal threat models combined with actual usability–it’s rarely a “my device is now unhackable” cartoon caricature.
Re: Disclosure of three 0-day iOS vulnerabilities
#240I used to believe that iphones were more secure than android and was considering making the switch. After reading this article and with some other recent news (CSAM[1], spam on the app store[2]) I don't think I'll be hopping on the iOS train anytime soon.
[1]:https://www.apple.com/child-safety/ [2]: