Earlier quoted context omitted.
You can do a lot more damage with someone's bank account than you can by exploding their phone.
Currently holding my phone, with a full charge. Basically a hand grenade, about 12” from my face, with (thanks to oversized phones), both hands on it. At best id be blind and unable to use my hands. I don’t give a stuff about my bank account compared with that.
Disclosure of three 0-day iOS vulnerabilities
321–330 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#322I'm not defending Apple but looking at the code published here, it's clear that most, if not all, of these bugs could be caught via static analysis which Apple obviously uses as part of its approval process. Frankly, I'm a lot more concerned with bugs that have to deal with input handling than SDK bugs that developers can use to do bad things. This is likely a non-issue for those of us who haven't jailbroken our devi…
Re: Disclosure of three 0-day iOS vulnerabilities
#323It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.
There is no $100K coming. Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.
It took so little evidence for you to decide it’s hopeless and declare as fact your prediction. Maybe you felt this way before this post? Otherwise I’m just not sure how to respond.
Re: Disclosure of three 0-day iOS vulnerabilities
#324Until we understand and push through a system (whether law or practice) that makes harming others, especially against their will and intentionally, far more costly than the massive returns and profits they today produce, NONE of these kinds of behaviors will ever cease. The examples are numerous; * Violation of human right to privacy and property * Violation of human right to not being tracked * Illegitimate wars * P…
You think immigration should be illegal?
> Government theft and fractional enslavement through taxation
You really had me in agreement with the first few items. You are not a serious person.
Re: Disclosure of three 0-day iOS vulnerabilities
#325Earlier quoted context omitted.
Yes. In some cases when they did pay, they paid significantly less than their published rates.
From the PoV of a security researcher - why even bother disclosing responsibly (moral obligations aside)? Best case scenario: you don't get sued into oblivion, will be ghosted and gaslightened, receive pocket change arbitrary amount of time later. Compared to that, i suppose the exploit brokers got their stuff together - after all, time is money - chances are someone else may stumble upon the same vulnerability...
Re: Disclosure of three 0-day iOS vulnerabilities
#326The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
Re: Disclosure of three 0-day iOS vulnerabilities
#327The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
It would really help a lot if: (1) We used safe languages like Go, Rust, C#, Java, and Swift instead of 1970s YOLO languages like C and C++. (2) Our operating systems were designed from the ground up to be secure in a modern environment. Unix (all flavors) and Windows were both built long before security was anywhere near as much of a concern as it is today. Their security posture is very lax by modern standards. App…
Re: Disclosure of three 0-day iOS vulnerabilities
#328I am not able to compile the first two of these (after the first two I stopped trying) with the newest Xcode on iOS 15.0. I haven't tried the other two or older tools. The source code as given also had syntax errors in it.
Re: Disclosure of three 0-day iOS vulnerabilities
#329Security through obscurity is a very bad idea. This is the main Achilles heel of Apple.
Right now we see these negative externalities of security vulnerabilities being "paid for" by their customers, in the vast majority of cases seemingly unwittingly, but that can only go on for so long before it backfires (even if it's a long time).
Re: Disclosure of three 0-day iOS vulnerabilities
#330Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…
Evidently apple see failures like bugs as a problem to be avoided and are just trying to avoid the problem with the obvious result that they have problems and look like a failure.
Companies that accept failure as a consequence of trying will learn and improve until they achieve success.