Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

301–310 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#301
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

Is that really the case? Or were they just not such a big target before when everyone was spending most of their time in a windows desktop. Maybe they just got away with it more easily in the past.

Your apologetics don’t work. iOS has had humongous user counts and growing market share in its largest market for over 10 years.

Source for historical market share: https://www.statista.com/statistics/266572/market-share-held...

Re: Disclosure of three 0-day iOS vulnerabilities

#302
post #43
post #26

Earlier quoted context omitted.

I would be an order of magnitude less concerned with camera/mic access, compared to perfect historical proof of my usage and communication patterns. Exploits often feel like pathogens, probably why they share the term virus. If a virus has a high mortality rate, contagion is lower, because it frequently kills the host before it can spread. Similarly, I think a 'complete device compromise' is much more likely to be id…

It's hardly 'perfect historical proof', not to diminish the seriousness of the vulnerability. But more importantly, the mechanism matters a great deal. This particular vulnerability requires the install of a malicious app, a much higher bar than a 'drive by' exploitation. This leaves a trace and exposes the attacker to consequences. No (statistically speaking) app producer with any interest in continuing to use the p…

> No (statistically speaking) app producer with any interest in continuing to use the platform would deploy such an exploit even if they had access to it.

Except Facebook. Or another behemoth that felt they could weather Apple's wrath if it ever came to it. Or a company that Apple had granted special permission to do this, like they did with Uber.

Re: Disclosure of three 0-day iOS vulnerabilities

#303

Until we understand and push through a system (whether law or practice) that makes harming others, especially against their will and intentionally, far more costly than the massive returns and profits they today produce, NONE of these kinds of behaviors will ever cease. The examples are numerous; * Violation of human right to privacy and property * Violation of human right to not being tracked * Illegitimate wars * P…

You’re getting into implied relative privation here. Yes, bad things exist, and yes, they aren’t controlled in a way we’d like. That doesn’t excuse Apple and isn’t that relevant to an argument about Apple’s immediate responsibility for its errors.

Re: Disclosure of three 0-day iOS vulnerabilities

#304
post #293

Earlier quoted context omitted.

This makes one question whether there really are any security vulnerabilities at all. Perhaps Apple isn’t fixing these because there’s nothing to fix? I don’t know enough to say whether these vulnerabilities are real or not.

The Gamed 0-day compiles just fine. I can run it on my iPhone with iOS 14.8 and it shows 300 contact information gathered apparently from various sources without me giving any permission at all.

Which XCode version are you using to compile?

Re: Disclosure of three 0-day iOS vulnerabilities

#305
post #293

Earlier quoted context omitted.

The Gamed 0-day compiles just fine. I can run it on my iPhone with iOS 14.8 and it shows 300 contact information gathered apparently from various sources without me giving any permission at all.

Which XCode version are you using to compile?

12.5.1

Re: Disclosure of three 0-day iOS vulnerabilities

#306
post #293

Earlier quoted context omitted.

This makes one question whether there really are any security vulnerabilities at all. Perhaps Apple isn’t fixing these because there’s nothing to fix? I don’t know enough to say whether these vulnerabilities are real or not.

The Gamed 0-day compiles just fine. I can run it on my iPhone with iOS 14.8 and it shows 300 contact information gathered apparently from various sources without me giving any permission at all.

maybe they 'fixed' it by not allowing any app of this kind (specific Api call) in the appstore? wouldn't challenge you to try and publish an example app though...

Re: Disclosure of three 0-day iOS vulnerabilities

#307

Until we understand and push through a system (whether law or practice) that makes harming others, especially against their will and intentionally, far more costly than the massive returns and profits they today produce, NONE of these kinds of behaviors will ever cease. The examples are numerous; * Violation of human right to privacy and property * Violation of human right to not being tracked * Illegitimate wars * P…

I’m convinced that the modern role of US political parties is to simply keep the masses squabbling. I wish we could get rid of gerrymandering and the two party dominance.

Re: Disclosure of three 0-day iOS vulnerabilities

#308

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Best explanation I've heard was in Darknet Diaries about Zero Day Brokers, which was a fantastic listen! (https://open.spotify.com/episode/4vXyFtBk1IarDRAoXIWQFf?si=3...)

The short version is that if the bounties become too large they'll lose internal talent who can just quit to do the same thing outside the org. Another reason was that they can't offer competitive bounties for zero days because they'll be competing with nation states, effectively a bottomless bank, so price will always go up.

I don't know much about this topic, but surely there are some well structured bounty programs Apple could copy to find a happy middle ground to reward the white hats.

Re: Disclosure of three 0-day iOS vulnerabilities

#309

Until we understand and push through a system (whether law or practice) that makes harming others, especially against their will and intentionally, far more costly than the massive returns and profits they today produce, NONE of these kinds of behaviors will ever cease. The examples are numerous; * Violation of human right to privacy and property * Violation of human right to not being tracked * Illegitimate wars * P…

I’m convinced that the modern role of US political parties is to simply keep the masses squabbling. I wish we could get rid of gerrymandering and the two party dominance.

Unfortunately, the Supreme Court decided 5-4 that the courts should have no power here, so its up to state legislatures. (https://www.npr.org/2019/06/27/731847977/supreme-court-rules...)

Re: Disclosure of three 0-day iOS vulnerabilities

#310

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

It doesn’t matter how big of a company they are, the only thing that matters financially is whether they’re growing or not.
Post reply on HN